{"schema": "datahouse.tracker.v1", "version": "v63", "run_id": 6, "generated_at": "2026-09-08T20:11:24Z", "score_version": "CES v1.0 (score_v58 arithmetic, core.py reconstruction 2026-09-08)", "row_count": 1271, "columns": ["Company", "Category", "Terms & Conditions URL", "T&C Direct PDF?", "Privacy Policy URL", "Privacy Direct PDF?", "Data Sharing/Selling Flags", "Arbitration / Class Action Waiver", "Fees / Billing Flags", "Notes", "Industry (Fortune 500)", "Revenue (Fortune 500)", "Market Cap", "Employees", "HQ City", "HQ State", "CEO", "Ticker", "Website (Corporate)", "Main Mailing Address (legal/privacy notices)", "Legal / Privacy Contact Email", "Finding Type", "Severity (1-5, heuristic)", "Last Verified", "Provenance (who determined this)", "Arbitration Opt-Out Window (Days)", "Corporate Legal Notice Address (public cos.)", "URL Status", "Region Tag", "Primary Source URL", "Source Verification Status", "Region Basis", "Parent / Ultimate Owner", "Years Referenced in Finding (heuristic)", "Audit Depth", "Registered Agent (Name)", "Registered Agent Address / Service Notes", "Company Brief", "Investor Overview", "Major Issues Record", "T&C Key Provisions (paraphrased)", "Re-verify By", "Top Troubling #1", "Top Troubling #2", "Top Troubling #3", "Troubling Terms Coverage Note", "Clause Flags (v58, AI-classified)", "Opacity (Taxonomy L4)", "Opacity Basis", "Exposure Score (0-100)", "Exposure Band", "Sub: Dispute Rights /30", "Sub: Data Practices /30", "Sub: Contract Asymmetry /20", "Sub: Track Record /20", "Score Confidence (A-D)", "Score Basis", "Mid-Atlantic Legal Hooks (v58)", "Entity Type", "Ownership Path", "What Did I Sell (Itemised)", "What Did I Sell (One Sentence)", "Last Checked (Full)", "Last Checked Coverage (%)", "URL Last Validated", "SCARY (most astonishing T&C item)", "Retail-Facing? (Y/N)", "Small Business Relevant? (Y/N)"], "rows": [{"Company": "DC DMV", "Category": "State/district DMV portal", "Terms & Conditions URL": "https://dc.gov/page/terms-and-conditions-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://dmv.dc.gov/page/dc-dmv-privcy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The DC DMV Privacy Policy states: \"We also provide data as authorized by law such as voting, organ donation, selective service, jury duty, and law enforcement requests,\" and cites the Driver Privacy Protection Act (DC Official Code §50-1401.01b and 18 USC §2721, et seq.) as the governing framework. No language addresses sale of data, sharing with commercial affiliates or data brokers, or honoring Global Privacy Control signals.", "Arbitration / Class Action Waiver": "No arbitration clause found in the terms fetched. The District's district-wide Terms and Conditions of Use (which governs the dmv.dc.gov subsite) contains no arbitration, class-action-waiver, or jury-waiver language of any kind.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): The district-wide Terms and Conditions of Use state: \"The District maintains the right to modify these Terms and Conditions of Use and may do so by posting notice of such modifications on this page. Any modification is effective immediately upon posting, unless otherwise stated.\" Liability language disclaims warranties, stating use of the site \"is at your own risk\" and content is provided \"as is.\" Removal from registered areas / denial of service is described as a consequence for policy violations. No auto-renewal or fee language (consistent with a free government site).", "Notes": "LEGAL ENTITY: The District of Columbia (DC Department of Motor Vehicles)\nTERMS EFFECTIVE: Not stated | PRIVACY EFFECTIVE: Not stated\nENFORCEMENT / BREACH (one search, 2026-08-29): No enforcement/breach item found in one search (2026-08-29) — results returned only generic data-breach law-firm topic pages (jdsupra.com), none naming DC DMV specifically.\nPRIVACY CONTACT: Email: privacy.dmv@dc.gov (address portion garbled in fetch, DMV-listed privacy inbox). Mailing address: DC Department of Motor Vehicles, Office of Service Integrity, ATTN: Privacy Policy, 95 M Street, SW, Washington, DC 20024.\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: DC DMV (dmv.dc.gov) does not host its own distinct Terms of Use; the district-wide dc.gov Terms and Conditions of Use was used as the governing terms document. DC DMV does maintain a DMV-specific Privacy Policy page separate from any district-wide privacy notice. A future researcher should check whether DC DMV's online driver's license/registration portal (public.dmv.washingtondc.gov) has its own supplemental terms not surfaced here.\nFETCH LOG (2026-08-29):\nhttps://dmv.dc.gov/page/dc-dmv-privcy-policy - 200 OK\nhttps://dc.gov/page/terms-and-conditions-use - 200 OK", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Email: privacy.dmv@dc.gov (address portion garbled in fetch, DMV-listed privacy inbox). Mailing address: DC Department of Motor Vehicles, Office of Service Integrity, ATTN: Privacy Policy, 95 M Street, SW, Washington, DC 20024.", "Legal / Privacy Contact Email": "privacy.dmv@dc.gov", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "The District of Columbia (DC Department of Motor Vehicles)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-20 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[UNILATERAL_CHANGES · FL-1] DC DMV site terms take effect immediately upon posting; content is provided 'as is,' at your own risk\nWHAT THE TERMS SAY: The district-wide Terms and Conditions state modifications are 'effective immediately upon posting,' and separately disclaim warranties, stating use of the site 'is at your own risk' with content provided 'as is.'\nWHY IT MATTERS: Users get no advance-notice window before a modification takes effect, and the terms disclaim warranties -- use of the site \"is at your own risk\" and content is provided \"as is.\"\n(evidence: Fees; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[RETENTION_PERIOD · FL-2] DC DMV collects SSNs and personal IDs but states no retention period and no data-sale stance\nWHAT THE TERMS SAY: The privacy policy names collection of 'name, social security number, email, home address, phone numbers, or other information that identifies you personally' but never states how long that data is kept or the agency's position on selling/sharing it with brokers.\nWHY IT MATTERS: Residents handing over SSNs to renew a license have no way to know how long that data persists or whether it could later be shared commercially.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct harms are substantively documented in the row; no arbitration clause exists to flag, fees/auto-renewal are explicitly absent, and no breach or enforcement item was found in the one search performed.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=N; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Privacy policy names DPPA-permitted sharing but is silent on retention and data-sale posture.", "Exposure Score (0-100)": 16, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 14, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 14/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4) | Record 2/20 (severity2+2) | flags stated 9/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "DC DMV  <-  The District of Columbia (DC Department of Motor Vehicles)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action; your right to a jury; your right to stop paying by inaction.\n\nNOT YET DETERMINED (6 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using DC DMV you gave up your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 60.0, "URL Last Validated": "2026-09-08T19:21:22Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "The DMV privacy policy names collection of \"name, social security number, email, home address, phone numbers, or other information that identifies you personally\" but never states a retention period for that data or any position on data sale/sharing with brokers — both are notably ABSENT from the document actually read.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 1, "_entity_id": 2, "_entity_slug": "dc-dmv", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "MyMVA (Maryland MVA)", "Category": "State DMV portal", "Terms & Conditions URL": "https://www.maryland.gov/terms-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://mva.maryland.gov/privacy-security", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The MVA Privacy & Security page states personal information is \"private unless requested by you, the police, an insurance company, a hospital, or other MVA-approved official business purpose.\" The separate MVA Privacy Statement PDF adds that MVA shares information with \"other government agencies, law enforcement, the judicial system, other driver licensing authorities,\" and, on formal request with identification proof, with \"private detectives, security agencies, insurers, attorneys, employers (CDL holders), toll facilities, hospitals, and towing companies.\" No mention of data sale, data brokers, or Global Privacy Control appears in either document.", "Arbitration / Class Action Waiver": "No arbitration clause found in the terms fetched. Neither the Maryland.gov Acceptable Use & Linking Policy nor the MVA Privacy & Security page contains arbitration, class-action-waiver, or jury-waiver language.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): The Maryland.gov Terms of Use page is limited in scope: it \"focuses on linking policies and acceptable use guidelines rather than comprehensive terms of service.\" No unilateral-modification, liability-cap/indemnity, termination, or auto-renewal/fee language was present on the page actually fetched.", "Notes": "LEGAL ENTITY: MDOT Motor Vehicle Administration (Maryland Motor Vehicle Administration)\nTERMS EFFECTIVE: Not stated (page metadata shows last modified 2026-01-23; no explicit effective date printed in the document text) | PRIVACY EFFECTIVE: Not stated (page metadata shows last modified 2026-04-17; no explicit effective date printed in the document text)\nENFORCEMENT / BREACH (one search, 2026-08-29): No enforcement/breach item found in one search (2026-08-29) — results returned Maryland's share of the Target and Equifax breach settlements and an Uber settlement, none of which concern the Maryland MVA itself.\nPRIVACY CONTACT: MVA Privacy & Security page: 6601 Ritchie Highway N.E., Glen Burnie, MD 21062; phone 410-768-7000 (no email listed; contact form linked at mymva.maryland.gov/go/web/ContactMVA). MVA Privacy Statement PDF separately lists \"MDOT MVA's Public Information Act Coordinator at 410-768-7545\" for records requests.\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: The myMVA online account portal (mymva.maryland.gov) did not surface its own distinct Terms of Service document in search; the state-wide Maryland.gov Acceptable Use & Linking Policy was used as the closest terms document. Two separate MVA privacy documents exist — the mva.maryland.gov/privacy-security page and a standalone Maryland Motor Vehicle Administration PRIVACY STATEMENT PDF (mva.maryland.gov/Documents/privacy-statement.pdf) — both were fetched and their content merged above; a future researcher should note MVA also maintains an older legacy page at mva.maryland.gov/Pages/geninfo/privacy.aspx that was not fetched.\nFETCH LOG (2026-08-29):\nhttps://mva.maryland.gov/privacy-security - 200 OK\nhttps://www.maryland.gov/terms-use - 200 OK\nhttps://mva.maryland.gov/Documents/privacy-statement.pdf - 200 OK", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "MVA Privacy & Security page: 6601 Ritchie Highway N.E., Glen Burnie, MD 21062; phone 410-768-7000 (no email listed; contact form linked at mymva.maryland.gov/go/web/ContactMVA). MVA Privacy Statement PDF separately lists \"MDOT MVA's Public Information Act Coordinator at 410-768-7545\" for records requests.", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "MDOT Motor Vehicle Administration (Maryland Motor Vehicle Administration)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-20 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Maryland MVA shares driver data with private detectives and insurers on formal request with ID proof\nWHAT THE TERMS SAY: MVA's Privacy Statement says information is private 'unless requested by you, the police, an insurance company, a hospital, or other MVA-approved official business purpose,' and on formal request with ID, MVA will share with 'private detectives, security agencies, insurers, attorneys, employers (CDL holders), toll facilities, hospitals, and towing companies.'\nWHY IT MATTERS: MVA will share driver information with \"private detectives, security agencies, insurers, attorneys, employers (CDL holders), toll facilities, hospitals, and towing companies\" on formal request with identification proof, and separately treats data as private unless requested for \"other MVA-approved official business purpose\" -- an undefined, MVA-discretion standard.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[RETENTION_PERIOD · FL-2] MVA states no retention period for SSN, fingerprint, and photo data it collects\nWHAT THE TERMS SAY: Neither the MVA Privacy & Security page nor the standalone Privacy Statement PDF states any retention period for records that include SSN, date of birth, driver's license number, fingerprint, or photo.\nWHY IT MATTERS: Drivers cannot know how long their biometric and identity data is retained by the state.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and fees fields are both explicitly empty (no clause/contract-terms language located), leaving only the data-sharing and retention items as substantive, company-specific findings.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=N; liabcap=N; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Two separate privacy documents describe sharing categories in some detail but state no retention period and rely on an undefined discretionary disclosure standard.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 10/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "MyMVA (Maryland MVA)  <-  MDOT Motor Vehicle Administration (Maryland Motor Vehicle Administration)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction.\n\nNOT YET DETERMINED (5 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using MyMVA (Maryland MVA) you gave up your biometric identifiers and your data shared corporate-wide. 5 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 63.3, "URL Last Validated": "2026-09-08T19:21:23Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Data is described as private \"unless requested by ... other MVA-approved official business purpose\" — an undefined, MVA-discretion standard — and neither document fetched states any retention period for records that include SSN, date of birth, driver's license number, fingerprint, and photo (per the Privacy & Security page: \"fingerprint or photo\" listed among private data).", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 2, "_entity_id": 4, "_entity_slug": "mymva-maryland-mva", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Virginia DMV", "Category": "State DMV portal", "Terms & Conditions URL": "https://www.dmv.virginia.gov/policies-regulations/web-policy", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://www.dmv.virginia.gov/policies-regulations/confidentiality", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The Web Policy states explicitly: \"DMV does not share, sell or trade email addresses, information collected on surveys or any other information about our online customers.\" No mention of data brokers or Global Privacy Control. The DMV Confidentiality Statement page fetched separately is a standard email-confidentiality disclaimer and contains no additional data-sharing language.", "Arbitration / Class Action Waiver": "No arbitration clause found in the terms fetched (Web Policy page). Note: Virginia DMV's separate Mobile ID Terms and Conditions (a distinct product, not the general site) contains no arbitration clause either, but does contain a mandatory jury-trial waiver: \"The parties unconditionally waive their respective rights to a jury trial,\" with no opt-out mechanism provided.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): The Web Policy states practices \"shall not be construed as a contractual promise\" and \"We reserve the right to amend these practices and procedures at any time without prior notice.\" It also states DMV \"expressly disclaims all liability, whether direct or indirect, for any loss or damage arising out of use, reference to, or reliance on any information presented on the website.\" No termination or auto-renewal/fee language appears on this page (the separate Mobile ID product's Terms do contain termination and indemnification clauses — see notes).", "Notes": "LEGAL ENTITY: Virginia Department of Motor Vehicles (DMV)\nTERMS EFFECTIVE: Not stated (page footer shows \"© Virginia Department of Motor Vehicles (DMV) 2023\", no explicit effective date) | PRIVACY EFFECTIVE: Not stated\nENFORCEMENT / BREACH (one search, 2026-08-29): No enforcement/breach item found in one search (2026-08-29) — results returned only generic law-firm data-breach topic pages and an unrelated Google privacy settlement affecting Virginia residents generally, none specific to Virginia DMV.\nPRIVACY CONTACT: Not stated on the Confidentiality Statement page fetched; it lists only general contact options (https://www.dmv.virginia.gov/contact-us and https://www.dmv.virginia.gov/locations), no dedicated privacy-request address or email.\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: Virginia DMV has no single consolidated site-wide privacy policy page (confirmed via the full Policies & Regulations index, which lists only: Accessibility Statement, Confidentiality Statement, Copyright, Law Enforcement Division, Nondiscrimination, Service of Process, Waiver Library, and Web Policy — no item titled 'Privacy Policy'). Data-practice language lives inside the Web Policy page instead. Virginia DMV separately operates a Mobile ID product with its own dedicated Terms (https://www.dmv.virginia.gov/licenses-ids/mobile-id/terms, last updated November 2023) and Privacy page (https://www.dmv.virginia.gov/licenses-ids/mobile-id/privacy, which returned only header/navigation content on fetch and appears incomplete or JS-rendered) — these are distinct legal documents from the general DMV site and were not treated as the entity's primary terms/privacy since the input entity is \"Virginia DMV\" generally, not the Mobile ID product specifically.\nFETCH LOG (2026-08-29):\nhttps://www.dmv.virginia.gov/policies-regulations/web-policy - 200 OK\nhttps://www.dmv.virginia.gov/licenses-ids/mobile-id/terms - 200 OK\nhttps://www.dmv.virginia.gov/licenses-ids/mobile-id/privacy - 200 OK (page returned only partial/navigation content)\nhttps://www.dmv.virginia.gov/policies-regulations/confidentiality - 200 OK\nhttps://www.dmv.virginia.gov/policies-regulations - 200 OK", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Not stated on the Confidentiality Statement page fetched; it lists only general contact options (https://www.dmv.virginia.gov/contact-us and https://www.dmv.virginia.gov/locations), no dedicated privacy-request address or email.", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Virginia Department of Motor Vehicles (DMV)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-20 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[JURY_WAIVER · FL-3] Virginia DMV's Mobile ID product imposes an unconditional jury-trial waiver with no opt-out\nWHAT THE TERMS SAY: Virginia DMV's separate Mobile ID Terms and Conditions state: 'The parties unconditionally waive their respective rights to a jury trial,' with no opt-out mechanism provided.\nWHY IT MATTERS: Users of the Mobile ID product give up their right to a jury trial in any dispute, with no way to preserve that right.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[UNILATERAL_CHANGES · FL-1] Virginia DMV can change site practices anytime without notice while disclaiming all liability\nWHAT THE TERMS SAY: The Web Policy states practices 'shall not be construed as a contractual promise' and 'We reserve the right to amend these practices and procedures at any time without prior notice,' paired with a clause that DMV 'expressly disclaims all liability... for any loss or damage arising out of use... of any information presented on the website.'\nWHY IT MATTERS: Consumers have no guarantee that today's stated practices will still apply tomorrow, and no recourse if the site's information proves wrong.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct company-specific harms are documented; the Data Sharing field affirmatively disclaims selling/trading information, leaving no third distinct tag.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=Y; optout=N; datasale=N; affiliates=N; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=N; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "General Web Policy is clear on no-sale of data but pairs unrestricted unilateral changes with a sweeping liability disclaimer, and the site lacks a consolidated privacy policy.", "Exposure Score (0-100)": 19, "Exposure Band": "Low", "Sub: Dispute Rights /30": 3, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 14, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 3/30 (jury_trial_waiver+3) | Data 0/30 (none) | Contract 14/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4) | Record 2/20 (severity2+2) | flags stated 11/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Virginia DMV  <-  Virginia Department of Motor Vehicles (DMV)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to a jury.\n  2. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your data shared corporate-wide; your right to sue; your right to join a class action; your right to stop paying by inaction.\n\nNOT YET DETERMINED (4 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Virginia DMV you gave up your right to a jury, your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 4 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 66.7, "URL Last Validated": "2026-09-08T19:21:26Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "The Web Policy pairs an unrestricted unilateral-modification right (\"amend these practices and procedures at any time without prior notice\") with a sweeping liability disclaimer (\"expressly disclaims all liability... for any loss or damage arising out of use... of any information presented on the website\") — consumers are given no contractual assurance the practices they read today will still apply tomorrow, and no recourse if the site's information is wrong.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 3, "_entity_id": 6, "_entity_slug": "virginia-dmv", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Maryland Mobile ID", "Category": "State digital driver's license", "Terms & Conditions URL": "https://mva.maryland.gov/licenses-ids/get-maryland-mobile-id/mobile-id-terms-conditions/apple-wallet-mobile-id-terms-conditions-english", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://mva.maryland.gov/privacy-security", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The terms state MVA shares \"information (including information that may personally identify you) with the Digital Wallet provider\" (Apple/Google/Samsung) as necessary to provision the mobile ID, and separately shares non-personal information to improve the service. The terms explicitly state that this information \"will not be sold or used for monitoring or tracking purposes.\" No Global Privacy Control language found. The general MVA Privacy & Security page (used as the closest privacy document since no mDL-specific privacy notice was located) describes data as private \"unless requested by ... police, an insurance company, a hospital, or other MVA-approved official business purpose,\" and separately references \"fingerprint or photo\" as private data categories.", "Arbitration / Class Action Waiver": "The Mobile ID Terms & Conditions contain no arbitration clause; disputes are directed to venue in the \"Superior Court of Anne Arundel County, Maryland.\" The terms do contain a mandatory jury-trial waiver: \"the parties unconditionally waive their respective rights to a jury trial,\" with no opt-out procedure offered. Class-action-waiver language was not identified in the section fetched.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): \"MDOT MVA reserves the right to update these Terms at any time and without notice as permitted by law, and your continued use of an mDL means you agree to all such changes.\" Liability language: \"in no event will MDOT MVA... be liable... for any direct, special, indirect, punitive, consequential, or incidental damages,\" paired with an indemnification clause requiring the user to \"indemnify, defend and hold MDOT MVA... harmless from and against any actual or alleged claims.\" Termination: \"MDOT MVA reserves the right to discontinue offering or supporting the mDL... for any reason and without notice,\" and may remove the credential if expired more than one year or if the underlying license/ID is cancelled, suspended, or revoked. No auto-renewal or fee language identified.", "Notes": "LEGAL ENTITY: MDOT MVA (Maryland Motor Vehicle Administration)\nTERMS EFFECTIVE: April 12, 2022 (\"Last Updated\") | PRIVACY EFFECTIVE: Not stated\nENFORCEMENT / BREACH (one search, 2026-08-29): No enforcement/breach item found in one search (2026-08-29) — results returned unrelated data-breach litigation (Marriott, T-Mobile, AT&T MDL) with no connection to Maryland Mobile ID or MDOT MVA.\nPRIVACY CONTACT: The Mobile ID Terms reference \"the MVA website privacy statement\" without a dedicated mDL-specific contact; the general MVA contact is 6601 Ritchie Highway N.E., Glen Burnie, MD 21062, phone 410-768-7000. No dedicated email for mDL privacy requests was found in the pages fetched.\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: MVA publishes six parallel Mobile ID terms documents (Apple Wallet, Google Wallet, Samsung Wallet — each in English and Spanish); only the Apple Wallet English version was fetched successfully. A fetch of the Samsung Wallet PDF (mva.maryland.gov/Documents/mDL_Terms_and_Conditions_Samsung_Final-05-09-24.pdf) failed to return usable PDF content — record as PDF failed; a future researcher should retry that document and the Google Wallet version to check for material differences. No mDL-specific privacy policy distinct from the general MVA Privacy & Security page was located.\nFETCH LOG (2026-08-29):\nhttps://mva.maryland.gov/licenses-ids/get-maryland-mobile-id/mobile-id-terms-conditions - 200 OK (index/landing page only)\nhttps://mva.maryland.gov/licenses-ids/get-maryland-mobile-id/mobile-id-terms-conditions/apple-wallet-mobile-id-terms-conditions-english - 200 OK\nhttps://mva.maryland.gov/Documents/mDL_Terms_and_Conditions_Samsung_Final-05-09-24.pdf - PDF failed (fetch returned unrelated cached index content, not parsed PDF text)\nhttps://mva.maryland.gov/privacy-security - 200 OK (reused from MyMVA entity fetch)", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "The Mobile ID Terms reference \"the MVA website privacy statement\" without a dedicated mDL-specific contact; the general MVA contact is 6601 Ritchie Highway N.E., Glen Burnie, MD 21062, phone 410-768-7000. No dedicated email for mDL privacy requests was found in the pages fetched.", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "MDOT MVA (Maryland Motor Vehicle Administration)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-20 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[JURY_WAIVER · FL-3] Maryland Mobile ID users unconditionally waive jury trial rights with no opt-out\nWHAT THE TERMS SAY: The Mobile ID Terms & Conditions state 'the parties unconditionally waive their respective rights to a jury trial,' with no opt-out procedure offered, and direct disputes to venue in the Superior Court of Anne Arundel County, Maryland.\nWHY IT MATTERS: Users of the digital driver's license cannot preserve a jury-trial right in any dispute with MDOT MVA.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[TERMINATION_CONFISCATION · FL-4] MDOT MVA can discontinue your digital driver's license at any time, for any reason, without notice\nWHAT THE TERMS SAY: 'MDOT MVA reserves the right to discontinue offering or supporting the mDL... for any reason and without notice,' and may remove the credential if expired more than one year or if the underlying license/ID is cancelled, suspended, or revoked.\nWHY IT MATTERS: A driver who relies on a mobile ID for identification can lose access to it abruptly, with no advance warning.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[UNILATERAL_CHANGES · FL-1] MDOT MVA can update Mobile ID terms at any time without notice; continued use means acceptance\nWHAT THE TERMS SAY: 'MDOT MVA reserves the right to update these Terms at any time and without notice as permitted by law, and your continued use of an mDL means you agree to all such changes.'\nWHY IT MATTERS: Users are bound to terms they may never see change, simply by continuing to use their mobile ID.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=Y; optout=N; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=N; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Terms are fetched and specific but rely on a reused general MVA privacy page since no mDL-specific privacy notice exists.", "Exposure Score (0-100)": 23, "Exposure Band": "Low", "Sub: Dispute Rights /30": 3, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 14, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 3/30 (jury_trial_waiver+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 14/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4) | Record 2/20 (severity2+2) | flags stated 10/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Maryland Mobile ID  <-  MDOT MVA (Maryland Motor Vehicle Administration)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to a jury.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to stop paying by inaction.\n\nNOT YET DETERMINED (5 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Maryland Mobile ID you gave up your data shared corporate-wide, your right to a jury, your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 5 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 63.3, "URL Last Validated": "2026-09-08T19:21:28Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "MVA reserves unilateral, no-notice rights both to change the Terms (\"reserves the right to update these Terms at any time and without notice\") and to \"discontinue offering or supporting the mDL... for any reason and without notice,\" while the user is bound to an unconditional jury-trial waiver with no opt-out — a driver who has come to rely on a mobile ID for identification can lose it, or find its governing terms changed, with zero advance notice and no jury-trial recourse.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 4, "_entity_id": 8, "_entity_slug": "maryland-mobile-id", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Thrift Savings Plan (TSP)", "Category": "Federal employee retirement account", "Terms & Conditions URL": "Not retrieved — not found", "T&C Direct PDF?": "Not retrieved", "Privacy Policy URL": "https://www.tsp.gov/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The Website Privacy Policy states: \"We will not share your email address or other personal information you provide to us other than as provided by law.\" No language on data sale, sharing with commercial affiliates or data brokers, or honoring Global Privacy Control was found.", "Arbitration / Class Action Waiver": "Not retrieved — no separate Terms of Use/Terms and Conditions document could be located for tsp.gov via search; the Website Privacy Policy that was fetched contains no arbitration, class-action-waiver, or jury-waiver language.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Not retrieved — no dedicated Terms of Use page was located; the Privacy Policy page fetched contains no unilateral-modification, liability-cap/indemnity, termination, or auto-renewal/fee language.", "Notes": "LEGAL ENTITY: Federal Retirement Thrift Investment Board (FRTIB)\nTERMS EFFECTIVE: Not stated | PRIVACY EFFECTIVE: July 14, 2022 (\"Last updated: July 14, 2022 at 08:15 PM\")\nENFORCEMENT / BREACH (one search, 2026-08-29): In May 2012, TSP publicly disclosed that a security breach at contractor Serco compromised personal information, including Social Security numbers, of approximately 123,000 TSP participants and beneficiaries. Source: Washington Post, \"TSP discloses hacking of accounts\" (https://www.washingtonpost.com/blogs/federal-eye/post/tsp-discloses-hacking-of-accounts/2012/05/25/gJQAsM4kpU_blog.html).\nPRIVACY CONTACT: Email: privacy@tsp.gov; Phone: 1-877-968-3778; Senior Agency Official for Privacy named as Dharmesh Vashee (General Counsel).\nRETENTION: As stated: \"We use and retain your personal information only for this purpose and only as long as is needed, as authorized by law\" (no specific timeframe given) | GPC honored: Not stated\nRESEARCHER NOTES: No dedicated \"Terms of Use\"/\"Terms and Conditions\" page for tsp.gov could be located via WebSearch; only the Website Privacy Policy and PDF participant-guidance publications (e.g., tspbk33.pdf, tspfs29.pdf) surfaced. The 2012 breach item was found via a general web search of news coverage, not from TSP's own site literature, and predates the privacy policy version actually fetched (2022) — a future researcher should check whether tsp.gov publishes any current breach-notification or incident-history statement.\nFETCH LOG (2026-08-29):\nhttps://www.tsp.gov/privacy-policy/ - 200 OK\nhttps://www.lawfaremedia.org/article/thrift-savings-plan-cyber-breach - 200 OK (background, not used as primary source due to internally inconsistent dates in fetch summary)", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Email: privacy@tsp.gov; Phone: 1-877-968-3778; Senior Agency Official for Privacy named as Dharmesh Vashee (General Counsel).", "Legal / Privacy Contact Email": "privacy@tsp.gov", "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Fetched - awaiting document verification", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Federal Retirement Thrift Investment Board (FRTIB)", "Years Referenced in Finding (heuristic)": "2012, 2022", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-24 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] TSP's 2012 contractor breach exposed Social Security numbers of ~123,000 participants\nWHAT THE TERMS SAY: In May 2012, TSP publicly disclosed that a security breach at contractor Serco compromised personal information, including Social Security numbers, of approximately 123,000 TSP participants and beneficiaries.\nWHY IT MATTERS: Federal retirement account holders' SSNs were exposed via a third-party contractor, and the currently published privacy policy contains no reference to breach-notification procedures.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[RETENTION_PERIOD · FL-2] TSP retains personal data only 'as long as needed... as authorized by law,' with no specific timeframe\nWHAT THE TERMS SAY: The Privacy Policy states: 'We use and retain your personal information only for this purpose and only as long as is needed, as authorized by law,' without giving a specific timeframe.\nWHY IT MATTERS: Participants cannot determine how long their financial and identity data is kept.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No Terms of Use / arbitration or fees document could be located for tsp.gov, so only the privacy-related breach and retention items are substantiated; a third distinct harm was not found in the retrieved text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No Terms of Use document could be located at all, and retention is stated only in vague, non-specific terms.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Thrift Savings Plan (TSP)  <-  Federal Retirement Thrift Investment Board (FRTIB)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Thrift Savings Plan (TSP) takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:21:29Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "The retention period stated is only the vague \"as long as is needed, as authorized by law\" with no specific timeframe given anywhere in the policy read, and the currently-published privacy policy (last updated July 2022) contains no reference to breach-notification procedures — notable given the agency's own 2012 contractor breach exposing ~123,000 participants' Social Security numbers.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 5, "_entity_id": 10, "_entity_slug": "thrift-savings-plan-tsp", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "DC Health Link", "Category": "State health insurance marketplace", "Terms & Conditions URL": "https://www.dchealthlink.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://www.dchealthlink.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The privacy page states: \"Your individual identifying information will not be shared, sold, or transferred to any third party without your prior consent, or unless it is required by law.\" It notes information is accessible to \"District web development employees only\" for portal maintenance. Credit card and similar payment data are encrypted (\"We encrypt credit card numbers and other data that must remain secure\"). Global Privacy Control is not mentioned anywhere on the page. Separate linked policies (\"Privacy and Security Policies for Exchange Websites\" and \"...for Exchange Operations\") were not fetched this session and may contain additional detail.", "Arbitration / Class Action Waiver": "No arbitration clause found in the terms fetched. The Terms and Conditions of Use page contains no mandatory-arbitration, class-action-waiver, or jury-waiver language, and no opt-out procedure of any kind.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Unilateral modification: \"HBX maintains the right, at any time and without notice, to modify these Terms and Conditions of Use and may do so by updating this posting or webpage.\" Liability limitation: \"In no event will HBX or the District, nor their employees, be liable for any incidental, indirect, special, punitive, exemplary, or consequential damages, arising out of your use of or inability to use the Site.\" Indemnity: users must \"defend, indemnify, and hold harmless HBX and the District and all of their employees, directors, officers, agents, affiliates, contractors, assigns, licensees, and successors in interest\" from claims. Termination: \"HBX may, in its sole discretion, terminate or suspend your access to and use of this Site without notice and for any reason.\" No auto-renewal or fee language found (site is not a paid-subscription service itself).", "Notes": "LEGAL ENTITY: DC Health Benefit Exchange Authority (HBX)\nTERMS EFFECTIVE: October 8, 2015 (\"Last Updated\") | PRIVACY EFFECTIVE: Not stated\nENFORCEMENT / BREACH (one search, 2026-08-29): District of Columbia Health Benefit Exchange Authority agreed to a $1.45 million class-action settlement over a 2023 data breach that exposed data including that of members of Congress. Source: https://www.hipaajournal.com/district-of-columbia-health-benefit-exchange-authority-data-breach-settlement/\nPRIVACY CONTACT: DC Health Benefit Exchange Authority, Privacy & Data Security Officer, 1225 Eye Street NW, Fourth Floor, Washington, DC 20005; phone 202-715-7576 (per terms page). Privacy page separately lists phone (855) 532-5465 / TTY 711 (Mon-Fri 8am-6pm) and a \"Send us a message\" secure-message option; no plain-text email address rendered in the fetched content.\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: Terms and Privacy are on two separate pages under the DC Health Link consumer site (dchealthlink.com), distinct from the hbx.dc.gov mirror found in search. DC Health Link also maintains separate 'Privacy and Security Policies for Exchange Websites' (dchealthlink.com/privacy-websites) and '...for Exchange Operations' (dchealthlink.com/privacy-operations) pages that were located via search but not fetched this session — a future researcher should pull those for the full HIPAA/GLBA-style operational privacy language.\nFETCH LOG (2026-08-29):\nhttps://www.dchealthlink.com/terms - 200 OK\nhttps://www.dchealthlink.com/privacy - 200 OK\nWebSearch: DC Health Link data breach OR settlement OR attorney general OR class action", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "DC Health Benefit Exchange Authority, Privacy & Data Security Officer, 1225 Eye Street NW, Fourth Floor, Washington, DC 20005; phone 202-715-7576 (per terms page). Privacy page separately lists phone (855) 532-5465 / TTY 711 (Mon-Fri 8am-6pm) and a \"Send us a message\" secure-message option; no plain-text email address rendered in the fetched content.", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Data breach + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Pending - severity 4/5, no source yet", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "DC Health Benefit Exchange Authority (HBX)", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-26 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] DC Health Link's 2023 breach exposed data including members of Congress; $1.45M class-action settlement\nWHAT THE TERMS SAY: District of Columbia Health Benefit Exchange Authority agreed to a $1.45 million class-action settlement over a 2023 data breach that exposed data including that of members of Congress.\nWHY IT MATTERS: The 2023 breach and $1.45 million settlement came despite the current privacy page's assurance that identifying information \"will not be shared, sold, or transferred to any third party without your prior consent.\"\n(evidence: Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[LIABILITY_CAP_INDEMNITY · FL-1] DC Health Link excludes indirect and consequential damages while users indemnify it and its contractors\nWHAT THE TERMS SAY: 'In no event will HBX or the District... be liable for any incidental, indirect, special, punitive, exemplary, or consequential damages,' and users must 'defend, indemnify, and hold harmless HBX and the District and all of their employees, directors, officers, agents, affiliates, contractors, assigns, licensees, and successors in interest.'\nWHY IT MATTERS: Consumers enrolling through the exchange must \"defend, indemnify, and hold harmless HBX and the District\" and their employees, agents, affiliates and contractors, while HBX and the District are \"in no event\" liable for incidental, indirect, special, punitive, exemplary, or consequential damages.\n(evidence: Fees; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[RETENTION_PERIOD · FL-2] No data retention period is stated anywhere in DC Health Link's fetched terms or privacy pages\nWHAT THE TERMS SAY: No data retention period is stated anywhere in the fetched pages, despite the site handling identifying and payment information for a health insurance marketplace.\nWHY IT MATTERS: Enrollees cannot determine how long their sensitive health-enrollment and payment data are kept, which is especially notable after the 2023 breach.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=N; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Terms and privacy pages are clear and specific, but the 2023 breach undercuts the sharing assurance and no retention period is given.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 14, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 14/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4) | Record 16/20 (severity4+14, litigation+2) | flags stated 11/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "DC Health Link  <-  DC Health Benefit Exchange Authority (HBX)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action; your right to a jury; your right to stop paying by inaction.\n\nNOT YET DETERMINED (5 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using DC Health Link you gave up your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 5 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 66.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A 2023 breach of DC Health Link's systems exposed personal data of members of Congress and thousands of consumers and led to a \"$1.45 million\" class-action settlement, despite the current privacy page's assurance that identifying information \"will not be shared, sold, or transferred to any third party without your prior consent.\" No data retention period is stated anywhere in the fetched pages.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 6, "_entity_id": 12, "_entity_slug": "dc-health-link", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Maryland Health Connection", "Category": "State health insurance marketplace", "Terms & Conditions URL": "Not retrieved — not found", "T&C Direct PDF?": "Not retrieved", "Privacy Policy URL": "https://www.marylandhealthconnection.gov/wp-content/uploads/2022/10/Privacy-Notice-October-2022.pdf", "Privacy Direct PDF?": "PDF", "Data Sharing/Selling Flags": "The Privacy Notice states: \"We do not sell your information or allow access to it for purposes such as testing or research without your consent and/or legal authority.\" It discloses PII to \"State and federal agencies, and other entities, to determine your eligibility,\" naming HHS, CMS, SSA, IRS, DHS, DoD, and VHA, plus the Maryland Department of Health, Medicaid, CHIP, MIA, Office of the Comptroller, DoIT, employers, \"consumer reporting agencies,\" and \"agents, brokers, issuers of health plans,\" as well as \"our contractors that are engaged to perform various functions of the Exchange such as consumer assistance services, information technology services.\" Global Privacy Control is not mentioned.", "Arbitration / Class Action Waiver": "No arbitration clause found in the pages fetched. Maryland Health Connection has no general consumer Terms of Use document distinct from its Privacy Notice; the only 'Terms and Conditions' document located is limited to SMS/text-alert opt-in language (https://www.marylandhealthconnection.gov/policies-accessibility/terms-and-conditions-for-text-alerts/) and contains no arbitration, class-waiver, or jury-waiver language, only an opt-out instruction: \"To stop delivery of text messages ... reply STOP from your mobile phone.\"", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Privacy Notice permits unilateral revision: \"At our discretion, and consistent with State and Federal law, we may update and revise this Privacy Notice from time-to-time.\" No liability cap, indemnity, arbitration, or auto-renewal/fee language was found in the documents fetched (this is a free public benefits-eligibility portal, not a paid subscription service).", "Notes": "LEGAL ENTITY: Maryland Health Benefit Exchange\nTERMS EFFECTIVE: Not stated | PRIVACY EFFECTIVE: October 2022\nENFORCEMENT / BREACH (one search, 2026-08-29): No enforcement/breach item specific to Maryland Health Connection or the Maryland Health Benefit Exchange found in one search (2026-08-29); results returned unrelated Maryland data-breach items (e.g., a law-firm data-breach settlement and a Frederick Health breach) with no connection to this entity.\nPRIVACY CONTACT: Maryland Health Connection, P.O. Box 857, Lanham, MD 20703; Privacy Officer phone 410-547-6862; general Consumer Support 1-855-642-8572. No email address provided.\nRETENTION: Not stated (see below) | GPC honored: Not stated\nRESEARCHER NOTES: Site has no single freestanding 'Terms of Use' — the /policies-accessibility/ hub page functions as the combined policy index, linking the Privacy Notice PDF and a separate SMS Terms and Conditions page. An older Privacy-Notice PDF URL from 2020 (referenced in initial search results) 404'd; the October 2022 version was located and fetched instead and may itself have been superseded — a future researcher should check for a newer version.\nFETCH LOG (2026-08-29):\nhttps://www.marylandhealthconnection.gov/policies-accessibility/ - 200 OK\nhttps://www.marylandhealthconnection.gov/wp-content/uploads/2020/10/MHC-Privacy-Notice.pdf - 404\nhttps://www.marylandhealthconnection.gov/policies-accessibility/terms-and-conditions-for-text-alerts/ - 200 OK\nhttps://www.marylandhealthconnection.gov/wp-content/uploads/2022/10/Privacy-Notice-October-2022.pdf - 200 OK\nWebSearch: Maryland Health Connection data breach OR settlement OR attorney general OR class action", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Maryland Health Connection, P.O. Box 857, Lanham, MD 20703; Privacy Officer phone 410-547-6862; general Consumer Support 1-855-642-8572. No email address provided.", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated (text 'STOP' to opt out of SMS alerts only, not an arbitration opt-out)", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Maryland Health Benefit Exchange", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-20 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Maryland Health Connection discloses sensitive personal data to a long list of agencies, contractors, and insurance brokers\nWHAT THE TERMS SAY: The Privacy Notice discloses PII including SSN, immigration documents, health insurance status, race, photo ID, driver's license number, military status, and approximate geographic location to state and federal agencies (HHS, CMS, SSA, IRS, DHS, DoD, VHA), the Maryland Department of Health, Medicaid, CHIP, consumer reporting agencies, and insurance 'agents, brokers, issuers of health plans,' plus outside contractors.\nWHY IT MATTERS: Applicants for health coverage have their sensitive personal and immigration data routed to a wide array of government and private-sector third parties as a condition of eligibility determination.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[RETENTION_PERIOD · FL-2] No concrete retention period given, only a vague reference to ACA-minimum record schedules\nWHAT THE TERMS SAY: Records are stated to be 'archived or destroyed in accordance with our records schedules which, at a minimum, reflect the Affordable Care Act data retention requirements' -- no concrete retention period is given, and no privacy-request email address is provided, only a phone number and PO box.\nWHY IT MATTERS: Consumers cannot determine an actual timeframe for how long their sensitive eligibility data (including SSN and immigration status) is kept, nor easily reach a privacy contact by email.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No general consumer Terms of Use exists distinct from the Privacy Notice (only SMS-alert terms), and no unilateral-modification/liability/termination language beyond a discretionary revision clause was found, leaving no third distinct company-specific harm.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=Y; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Privacy Notice is detailed about who receives data but gives no concrete retention timeframe and no dedicated privacy email.", "Exposure Score (0-100)": 15, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 5/20 (unilateral_modification+5) | Record 2/20 (severity2+2) | flags stated 10/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent", "Entity Type": "Company", "Ownership Path": "Maryland Health Connection  <-  Maryland Health Benefit Exchange", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action; your right to a jury; your right to stop paying by inaction.\n\nNOT YET DETERMINED (5 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to keep what you paid for; your right to meaningful compensation. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Maryland Health Connection you gave up your physical movements, your data shared corporate-wide, and your right to be consulted before terms change. 5 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 63.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The Privacy Notice discloses personal data (including SSN, immigration documents, health insurance status, race, photo ID, driver's license number, military status, and IP-based \"Approximate geographic location\") to a long list of state/federal agencies, contractors, consumer-reporting agencies, and insurance \"agents, brokers, issuers,\" while stating only that records are \"archived or destroyed in accordance with our records schedules which, at a minimum, reflect the Affordable Care Act data retention requirements\" — no concrete retention period is given, and no privacy-request email address is provided, only a phone number and PO box.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 7, "_entity_id": 14, "_entity_slug": "maryland-health-connection", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cover Virginia", "Category": "State Medicaid enrollment portal", "Terms & Conditions URL": "https://coverva.dmas.virginia.gov/terms-and-conditions/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://www.dmas.virginia.gov/media/2yloy1l5/dmas-updated-notice-of-privacy-practices-03-01-2024.pdf", "Privacy Direct PDF?": "PDF", "Data Sharing/Selling Flags": "The DMAS Notice of Privacy Practices states: \"In these cases we never share your information unless you give us written permission: Marketing purposes, Sale of your information.\" It does describe sharing with treatment providers, health plans (for billing), and public-health/research entities under legally permitted conditions, without needing separate written authorization for those categories. No affiliate or data-broker sale/sharing language and no Global Privacy Control mention were found.", "Arbitration / Class Action Waiver": "Not retrieved — the live 'Terms and Conditions' page at coverva.dmas.virginia.gov/terms-and-conditions/ contains only Lorem Ipsum placeholder text, so no genuine arbitration language could be read. The fetched Notice of Privacy Practices PDF likewise contains no arbitration clause.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Not retrieved — the coverva.dmas.virginia.gov Terms and Conditions page is a broken/placeholder page (Lorem Ipsum only), so unilateral-modification, liability-cap, indemnity, termination, and auto-renewal language could not be read from it. The Notice of Privacy Practices PDF only states a non-retaliation assurance: \"We will not retaliate against you for filing a complaint.\"", "Notes": "LEGAL ENTITY: Department of Medical Assistance Services (DMAS)\nTERMS EFFECTIVE: Not retrieved — the fetched page's body text consists entirely of generic Lorem Ipsum placeholder paragraphs (e.g. \"Aenean ultricies mi vitae est. Mauris placerat eleifend leo...\") with no real legal content or date rendered | PRIVACY EFFECTIVE: March 1, 2024 (per filename/document title \"DMAS Updated Notice of Privacy Practices 03-01-2024\")\nENFORCEMENT / BREACH (one search, 2026-08-29): No enforcement/breach item specific to Cover Virginia or DMAS found in one search (2026-08-29); results returned unrelated Virginia breach items (Blackbaud multistate settlement, Virginia Mason Medical Center, Virginia Health Services) with no connection to CoverVA/DMAS.\nPRIVACY CONTACT: Department of Medical Assistance Services, 600 East Broad Street, Richmond, Virginia 23219; phone 1-855-242-8282 (TTY 1-888-221-1590). Notice of Privacy Practices PDF also lists HHS Office for Civil Rights complaint address: 200 Independence Avenue, S.W., Washington, D.C. 20201. No dedicated privacy-request email address found.\nRETENTION: Not stated (accounting of disclosures covers \"six years prior to the date you ask\", but this is a disclosure-history window, not a data-retention period) | GPC honored: Not stated\nRESEARCHER NOTES: DMAS operates CoverVA under the parent dmas.virginia.gov domain; the CoverVA-hosted Privacy Practices page (coverva.dmas.virginia.gov/privacy-practices/) itself lacked embedded text and only linked out to the PDF Notice of Privacy Practices hosted at dmas.virginia.gov, which was fetched successfully. The Terms and Conditions page defect (Lorem Ipsum placeholder) should be re-checked by a future researcher in case it is a temporary CMS glitch.\nFETCH LOG (2026-08-29):\nhttps://coverva.dmas.virginia.gov/terms-and-conditions/ - 200 OK (placeholder content only, fetched twice to confirm)\nhttps://coverva.dmas.virginia.gov/privacy-practices/ - 200 OK (no embedded substantive text)\nhttps://www.dmas.virginia.gov/media/2yloy1l5/dmas-updated-notice-of-privacy-practices-03-01-2024.pdf - 200 OK\nWebSearch: Cover Virginia DMAS data breach OR settlement OR attorney general OR class action", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Department of Medical Assistance Services, 600 East Broad Street, Richmond, Virginia 23219; phone 1-855-242-8282 (TTY 1-888-221-1590). Notice of Privacy Practices PDF also lists HHS Office for Civil Rights complaint address: 200 Independence Avenue, S.W., Washington, D.C. 20201. No dedicated privacy-request email address found.", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Department of Medical Assistance Services (DMAS)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-20 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] CoverVA's published 'Terms and Conditions' page is broken, showing only Lorem Ipsum placeholder text\nWHAT THE TERMS SAY: The live 'Terms and Conditions' page at coverva.dmas.virginia.gov/terms-and-conditions/ contains only generic Lorem Ipsum placeholder paragraphs (e.g., 'Aenean ultricies mi vitae est. Mauris placerat eleifend leo...'), fetched twice to confirm, with no real legal content or date rendered.\nWHY IT MATTERS: Virginia's Medicaid/health-insurance marketplace is presenting the public with what is effectively a blank, unfinished legal agreement in place of actual governing terms.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one substantive, company-specific finding exists: the site's own Terms and Conditions page is a broken placeholder. The Notice of Privacy Practices does describe data-sharing categories but states no troubling practice beyond standard treatment/payment disclosures; no breach, arbitration, or fee item was found.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The site's actual Terms and Conditions page is a broken placeholder with no real content, and only the Notice of Privacy Practices could be substantively read.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Cover Virginia  <-  Department of Medical Assistance Services (DMAS)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Cover Virginia takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:21:33Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Notably ABSENT: CoverVA's own published \"Terms and Conditions\" page (coverva.dmas.virginia.gov/terms-and-conditions/) is not real content — it is a broken template rendering only generic Lorem Ipsum placeholder text, meaning the state is presenting the public with what is effectively a blank/unfinished legal agreement for the health-insurance marketplace's consumer-facing site.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 8, "_entity_id": 16, "_entity_slug": "cover-virginia", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Maryland unemployment BEACON", "Category": "State unemployment insurance portal", "Terms & Conditions URL": "Not retrieved — not found", "T&C Direct PDF?": "Not retrieved", "Privacy Policy URL": "https://labor.maryland.gov/aboutdllr/privacystatement.shtml", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The Maryland Department of Labor's site-wide Privacy Statement states: \"The Maryland Department of Labor does not release that information to other parties, except in the event we are required to do so by law or as necessary for online transactions [i.e.] secure credit card payments over the Internet.\" This statement does not specifically mention BEACON, unemployment-claim data, affiliates, data brokers, or Global Privacy Control.", "Arbitration / Class Action Waiver": "Not retrieved — no BEACON-specific Terms of Use document could be located via search or fetch (the beacon.labor.maryland.gov claimant portal renders as a general informational/login page with no visible legal-agreement text, and the only linked legal document from the BEACON overview page is the department-wide privacy statement). The department-wide privacy statement contains no arbitration clause.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Not retrieved — no BEACON-specific terms document was found covering unilateral modification, liability cap, indemnity, termination/account-confiscation, or fee language. The department-wide privacy statement contains no such contract-terms language; it addresses only web-server logging and e-mail handling.", "Notes": "LEGAL ENTITY: Maryland Department of Labor\nTERMS EFFECTIVE: Not stated | PRIVACY EFFECTIVE: Not stated\nENFORCEMENT / BREACH (one search, 2026-08-29): A class action was filed against the Maryland Secretary of Labor alleging \"gross and systemic failures\" in distributing unemployment insurance benefits (a benefits-administration failure, not a confirmed data breach); the Maryland labor department later settled and agreed to make changes. Source: https://www.classaction.org/news/maryland-dept.-of-labor-hit-with-class-action-over-alleged-failure-to-issue-unemployment-insurance-benefits (see also https://www.thebanner.com/politics-power/state-government/unemployment-claims-department-of-labor-LTHM4BEPFBD67LS4RBEVJT3XA4/).\nPRIVACY CONTACT: Office of Information Technology, Maryland Department of Labor, 100 S. Charles Street, Tower I, Baltimore, Maryland 21202. No email address given; retention note for correspondence only: \"We retain the content of your e-mail, e-mail address, and our response so that we can more efficiently handle any follow-up questions that you may have\" (no specific timeframe stated).\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: BEACON (beacon.labor.maryland.gov, employer.beacon.labor.md.gov, agent.beacon.labor.md.gov) is a login-gated Cúram/IBM benefits system; any BEACON-specific click-through Terms of Use, if one exists, is likely presented only inside the authenticated application flow and was not reachable by unauthenticated WebFetch this session. A future researcher with portal access should check for an in-app 'Terms and Conditions' acceptance screen during registration.\nFETCH LOG (2026-08-29):\nhttps://beacon.labor.maryland.gov - 200 OK (no legal-terms content found)\nhttps://labor.maryland.gov/employment/uibeaconoverview.shtml - 404\nhttps://labor.maryland.gov/aboutdllr/privacystatement.shtml - 200 OK\nWebSearch: Maryland BEACON unemployment data breach OR settlement OR attorney general OR class action\nWebSearch: classaction.org Maryland Department of Labor unemployment insurance benefits lawsuit summary", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Office of Information Technology, Maryland Department of Labor, 100 S. Charles Street, Tower I, Baltimore, Maryland 21202. No email address given; retention note for correspondence only: \"We retain the content of your e-mail, e-mail address, and our response so that we can more efficiently handle any follow-up questions that you may have\" (no specific timeframe stated).", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Data breach + Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Fetched - awaiting document verification", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Maryland Department of Labor", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-24 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] No BEACON-specific Terms of Use or Privacy Policy exists anywhere the system could locate\nWHAT THE TERMS SAY: Claimants entering Social Security numbers, bank account numbers, and employment history into the BEACON portal are covered, at most, by a generic department-wide privacy statement that does not mention BEACON, unemployment data, or any retention period at all.\nWHY IT MATTERS: Unemployment claimants submitting highly sensitive financial and identity data have no BEACON-specific document describing how that data is used, shared, or retained.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-1] Class action alleged 'gross and systemic failures' in Maryland unemployment benefits; department settled\nWHAT THE TERMS SAY: A class action alleged 'gross and systemic failures' in distributing unemployment insurance benefits; the Maryland labor department later settled and agreed to make changes.\nWHY IT MATTERS: A class action alleged \"gross and systemic failures\" in distributing unemployment insurance benefits; the Maryland labor department later settled and agreed to make changes.\n(evidence: Notes; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No BEACON-specific arbitration or fees/contract-terms document could be located, so only the no-disclosure and litigation items are substantiated; a third distinct company-specific harm was not found.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No BEACON-specific Terms of Use or Privacy Policy exists at all; only a generic department-wide privacy statement was located.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Maryland unemployment BEACON  <-  Maryland Department of Labor", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Maryland unemployment BEACON takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:21:33Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Notably ABSENT: no BEACON-specific Terms of Use or Privacy Policy exists anywhere the system could locate — claimants entering Social Security numbers, bank account numbers, and employment history into the BEACON portal are covered, at most, by a generic department-wide privacy statement (labor.maryland.gov/aboutdllr/privacystatement.shtml) that does not mention BEACON, unemployment data, or any retention period at all.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 9, "_entity_id": 18, "_entity_slug": "maryland-unemployment-beacon", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Maryland Tax Connect", "Category": "State tax filing/payment portal", "Terms & Conditions URL": "Not retrieved — not found", "T&C Direct PDF?": "Not retrieved", "Privacy Policy URL": "https://www.marylandcomptroller.gov/privacy-statement.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The Comptroller of Maryland's general Privacy Statement states: \"We do not and will not sell this information or distribute it to anyone outside the agency.\" It separately notes that tax data privacy is governed by \"Tax General Article of the Maryland Annotated Code, Section 13-202\" but does not explicitly state whether this statement covers the Maryland Tax Connect portal specifically. No mention of affiliates, data brokers, or Global Privacy Control.", "Arbitration / Class Action Waiver": "Not retrieved — no Maryland Tax Connect-specific Terms of Use could be located via search or fetch. The mdtaxconnect.gov homepage and a guest-return sub-page were fetched and contained no legal-terms links or text. The general Comptroller of Maryland privacy statement contains no arbitration clause.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Not retrieved — no dedicated Maryland Tax Connect Terms of Use/Terms and Conditions document was found covering unilateral modification, liability cap, indemnity, termination, or fee language. The general privacy statement does not address these topics.", "Notes": "LEGAL ENTITY: Comptroller of Maryland\nTERMS EFFECTIVE: Not stated | PRIVACY EFFECTIVE: Not stated\nENFORCEMENT / BREACH (one search, 2026-08-29): No enforcement/breach item specific to Maryland Tax Connect or the Comptroller's online tax portal found in one search (2026-08-29); results surfaced only general Maryland breach-notification-law background (Davis Wright Tremaine summary) and the Maryland AG's general security-breach-notice resource page (https://oag.maryland.gov/resources-info/Pages/security-breach-notices.aspx), with no incident tied to this entity.\nPRIVACY CONTACT: Revenue Administration Division, P.O. Box 549, Annapolis, MD 21411-0001; online contact form at https://services.marylandcomptroller.gov/taxes/en/contact-us. No dedicated privacy-request email address found.\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: Maryland Tax Connect is the Comptroller's newer online filing/payment portal (mdtaxconnect.gov, an IBM Cúram/RPTP-based system) replacing older bFile/iFile tools; it appears to rely on the parent marylandtaxes.gov / marylandcomptroller.gov general privacy statement rather than publishing its own. A future researcher with a registered account should check for an in-app Terms of Use acceptance screen during registration/login, which was not reachable via unauthenticated WebFetch this session.\nFETCH LOG (2026-08-29):\nhttps://marylandtaxes.gov/tax-security/privacy-statement.php - 302 redirect\nhttps://www.marylandcomptroller.gov/privacy-statement.html - 200 OK\nhttps://mdtaxconnect.gov/rptp/portal/home/md-guest-return/... - 404\nhttps://mdtaxconnect.gov/ - 200 OK (no legal-terms links found)\nWebSearch: Maryland Tax Connect Comptroller data breach OR settlement OR attorney general OR class action", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Revenue Administration Division, P.O. Box 549, Annapolis, MD 21411-0001; online contact form at https://services.marylandcomptroller.gov/taxes/en/contact-us. No dedicated privacy-request email address found.", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Fetched - awaiting document verification", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Comptroller of Maryland", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-20 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] No Terms of Use or Privacy Policy specific to the Maryland Tax Connect portal could be found anywhere\nWHAT THE TERMS SAY: No Terms of Use or Privacy Policy specific to the Maryland Tax Connect portal (mdtaxconnect.gov, where businesses file returns and make payments with bank routing/account numbers) could be located anywhere on the site; the closest document found, the Comptroller's general agency privacy statement, does not confirm it applies to the Tax Connect portal and states no retention period.\nWHY IT MATTERS: Businesses submitting bank routing and account numbers through Tax Connect have no confirmed governing document describing how that payment data is protected, shared, or retained.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fees fields are both explicitly 'not retrieved,' and the general privacy statement's only substantive content is a no-sale assurance, leaving a single distinct, company-specific harm.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=N; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No portal-specific Terms of Use or Privacy Policy could be located; only a general Comptroller privacy statement of unconfirmed applicability was found.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Maryland Tax Connect  <-  Comptroller of Maryland", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your data shared corporate-wide.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Maryland Tax Connect takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:21:33Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Notably ABSENT: no Terms of Use or Privacy Policy specific to the Maryland Tax Connect portal (mdtaxconnect.gov, where businesses file returns and make payments with bank routing/account numbers) could be located anywhere on the site — the closest document found, the Comptroller of Maryland's general agency privacy statement, does not confirm it applies to the Tax Connect portal and states no retention period for the tax and payment data submitted through it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 10, "_entity_id": 20, "_entity_slug": "maryland-tax-connect", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "E-ZPass Maryland", "Category": "Electronic toll account management", "Terms & Conditions URL": "https://driveezmd.com/terms-conditions/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://driveezmd.com/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The Terms state: \"Account information will not be disclosed to third parties without your consent except as permissible by law.\" The Privacy Policy is more explicit: \"The MDTA does not rent, sell or exchange information submitted to its websites.\" Disclosure otherwise occurs \"only as required by the Maryland Public Information Act or as necessary and permissible to carry out official duties,\" and any third party supporting MDTA must \"agree to safeguard personal information in the same manner.\" No Global Privacy Control language appears in either document.", "Arbitration / Class Action Waiver": "No arbitration clause found in the terms fetched. The document contains no mandatory-arbitration, class-action-waiver, or jury-waiver language, and therefore no opt-out procedure or address.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Unilateral modification: \"MDTA may change the DriveEzMD E-ZPass Maryland Terms and Conditions at any time by giving customers notice thereof. The terms and conditions shall become effective seven (7) days after such notice.\" Indemnification: \"You agree to indemnify, defend, and hold harmless MDTA from and against any and all damage, loss, cost, expense, or liability.\" Termination: account holders may close their account \"at any time by notifying E-ZPass Maryland in writing.\" Auto-renewal: \"E-ZPass Maryland will renew your Hatem Plan(s) automatically approximately thirty (30) days prior to the plan's expiration date.\"", "Notes": "LEGAL ENTITY: Maryland Transportation Authority (MDTA)\nTERMS EFFECTIVE: December 14, 2022 | PRIVACY EFFECTIVE: March 5, 2025\nENFORCEMENT / BREACH (one search, 2026-08-29): No enforcement/breach item specific to E-ZPass Maryland / DriveEzMD / MDTA found in one search (2026-08-29); results returned only unrelated general Maryland data-breach settlements (e.g., a law firm data-breach settlement, a 23andMe multistate settlement) with no MDTA/E-ZPass connection.\nPRIVACY CONTACT: mdta@mdta.maryland.gov; MDTA, P.O. Box 5060, Middle River, MD 21220-5060; Phone: 1-888-321-6824\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: Multiple dated PDF versions of the T&C exist on driveezmd.com (2021, Dec-2022, May-2023); the live HTML page at /terms-conditions/ was used as the primary source and reflects the Dec-2022 revision. Privacy Policy is a separate document (last updated March 5, 2025). Toll enforcement relies on camera/license-plate images described in the Terms; this is location-relevant data but not framed by the document as 'biometric' or formal 'geolocation' collection, so flagged cautiously.\nFETCH LOG (2026-08-29):\nhttps://driveezmd.com/terms-conditions/ - 200 OK\nhttps://driveezmd.com/privacy-policy/ - 200 OK", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "mdta@mdta.maryland.gov; MDTA, P.O. Box 5060, Middle River, MD 21220-5060; Phone: 1-888-321-6824", "Legal / Privacy Contact Email": "mdta@mdta.maryland.gov", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Maryland Transportation Authority (MDTA)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-20 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LIABILITY_CAP_INDEMNITY · FL-1] E-ZPass Maryland can change its terms with just seven days' notice while binding customers to broad indemnification\nWHAT THE TERMS SAY: 'MDTA may change the DriveEzMD E-ZPass Maryland Terms and Conditions at any time by giving customers notice thereof. The terms and conditions shall become effective seven (7) days after such notice,' and customers 'agree to indemnify, defend, and hold harmless MDTA from and against any and all damage, loss, cost, expense, or liability.'\nWHY IT MATTERS: A short seven-day change window paired with open-ended indemnification places most of the contractual and financial risk on the customer.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[RETENTION_PERIOD · FL-2] No stated retention period for the toll-camera images E-ZPass Maryland's system generates\nWHAT THE TERMS SAY: Toll enforcement relies on camera/license-plate images described in the Terms, and no retention period is stated for that data anywhere in the fetched documents.\nWHY IT MATTERS: Drivers cannot know how long location-revealing toll-camera images of their vehicle are kept.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[AUTO_RENEWAL_FEES · FL-1] E-ZPass Maryland automatically renews Hatem Plans about 30 days before the plan's expiration date\nWHAT THE TERMS SAY: 'E-ZPass Maryland will renew your Hatem Plan(s) automatically approximately thirty (30) days prior to the plan's expiration date.'\nWHY IT MATTERS: Hatem Plan holders are re-enrolled automatically unless they act before the renewal, which occurs approximately thirty (30) days prior to the plan's expiration date.\n(evidence: Fees; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=Y; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Terms and privacy documents are specific and dated, but no retention period is given for toll-camera location data.", "Exposure Score (0-100)": 23, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 17, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 17/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4, auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 11/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "E-ZPass Maryland  <-  Maryland Transportation Authority (MDTA)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action; your right to a jury.\n\nNOT YET DETERMINED (4 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using E-ZPass Maryland you gave up your physical movements, your right to keep what you paid for, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 4 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 66.7, "URL Last Validated": "2026-09-08T19:21:36Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "The Terms let MDTA change the agreement unilaterally with only \"notice\" that becomes binding after just \"seven (7) days,\" while the customer simultaneously agrees to broad, unconditional indemnification of MDTA (\"indemnify, defend, and hold harmless...from and against any and all damage, loss, cost, expense, or liability\") — a short change window paired with an open-ended indemnity obligation and no stated data-retention period for the toll-camera images the system generates.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 11, "_entity_id": 22, "_entity_slug": "e-zpass-maryland", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "E-ZPass Virginia", "Category": "Electronic toll account management", "Terms & Conditions URL": "https://www.ezpassva.com/media/ezpassva/content-assets/documents/agreement.pdf", "T&C Direct PDF?": "PDF", "Privacy Policy URL": "https://www.ezpassva.com/media/ezpassva/content-assets/documents/privacy.pdf", "Privacy Direct PDF?": "PDF", "Data Sharing/Selling Flags": "The Privacy Policy states: \"We do not sell data about our customers to marketing firms.\" Data is shared with other toll facilities (for unpaid-toll collection), with law enforcement pursuant to court orders, and with researchers in summary/aggregate form only. Travel times, dates, and locations through toll facilities are tracked and retained as part of transaction records, along with driver's license numbers, Social Security numbers, vehicle data, and financial account/card numbers. No Global Privacy Control language appears.", "Arbitration / Class Action Waiver": "No arbitration clause found in the terms fetched. The Customer Agreement contains no mandatory-arbitration, class-action-waiver, or jury-waiver provisions, so there is no opt-out procedure, window, or address to report.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Unilateral modification: \"The E-ZPass Service Center may change the terms of this Agreement at any time by providing electronic or written notice,\" with notice deemed received 10 days after mailing/emailing; continued use after that constitutes acceptance. Liability/indemnity: the user must \"indemnify and hold the E-ZPass Service Center, the Commonwealth of Virginia, and all other operating agencies...harmless from and against any and all damage, loss, cost, expense, injury or liability,\" and the Service Center \"shall not be liable for any incidental, indirect, special or consequential damages.\" Termination: either party may terminate at any time; on termination the user must return the transponder and receives any balance refund within 30 days minus amounts owed; accounts inactive 12 months may be terminated. Auto-renewal/fee: automatic account replenishment charges the customer's card/bank account \"average monthly usage or $35.00 per transponder, whichever is greater.\"", "Notes": "LEGAL ENTITY: Commonwealth of Virginia / E-ZPass Service Center (operating on behalf of VDOT and participating toll agencies)\nTERMS EFFECTIVE: July 1, 2020 | PRIVACY EFFECTIVE: Updated June 4, 2025\nENFORCEMENT / BREACH (one search, 2026-08-29): No enforcement/breach item specific to E-ZPass Virginia found in one search (2026-08-29); top results were unrelated Virginia AG settlements (Equifax, Blackbaud) with no E-ZPass connection.\nPRIVACY CONTACT: Not stated in the Privacy Policy document itself (no dedicated privacy address/email given); general customer-service address in the Customer Agreement: E-ZPass VA Customer Service Center, P.O. Box 1234, Clifton Forge, VA 24422-1234.\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: Both governing documents (Customer Agreement and Privacy Policy) are PDFs hosted on ezpassva.com and fetched successfully (not JS-only, no 403). Agreement dated 2020; Privacy Policy separately dated/updated 2025 — two documents of different vintage governing the same account relationship.\nFETCH LOG (2026-08-29):\nhttps://www.ezpassva.com/media/ezpassva/content-assets/documents/agreement.pdf - 200 OK\nhttps://www.ezpassva.com/media/ezpassva/content-assets/documents/privacy.pdf - 200 OK", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Not stated in the Privacy Policy document itself (no dedicated privacy address/email given); general customer-service address in the Customer Agreement: E-ZPass VA Customer Service Center, P.O. Box 1234, Clifton Forge, VA 24422-1234.", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Commonwealth of Virginia / E-ZPass Service Center (operating on behalf of VDOT and participating toll agencies)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-20 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] E-ZPass Virginia can auto-charge customers 'average monthly usage or $35.00 per transponder, whichever is greater' with no stated cap\nWHAT THE TERMS SAY: Automatic account replenishment charges the customer's card or bank account 'average monthly usage or $35.00 per transponder, whichever is greater,' with no cap specified in the Agreement.\nWHY IT MATTERS: Customers on automatic replenishment have no contractual ceiling on how much can be charged per replenishment event.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[LOCATION_TRACKING · FL-2] E-ZPass Virginia keeps detailed travel-time and location records tied to SSNs, with no stated retention period\nWHAT THE TERMS SAY: Travel times, dates, and locations through toll facilities are tracked and retained as part of transaction records, along with driver's license numbers, Social Security numbers, vehicle data, and financial account/card numbers; no retention period is stated anywhere in the fetched documents.\nWHY IT MATTERS: Drivers' detailed movement histories, linked to their SSNs, are kept indefinitely as far as the published terms disclose.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[LIABILITY_CAP_INDEMNITY · FL-1] E-ZPass Virginia disclaims consequential damages while requiring customers to indemnify the Commonwealth\nWHAT THE TERMS SAY: The user must 'indemnify and hold the E-ZPass Service Center, the Commonwealth of Virginia, and all other operating agencies... harmless from and against any and all damage, loss, cost, expense, injury or liability,' while the Service Center 'shall not be liable for any incidental, indirect, special or consequential damages.'\nWHY IT MATTERS: Financial and legal risk is shifted onto the customer while the state entity limits its own exposure.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=Y; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Both governing PDFs were fetched and are specific, but no retention period is stated for detailed location/SSN transaction records and no privacy contact address is given.", "Exposure Score (0-100)": 23, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 17, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 17/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4, auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 12/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "E-ZPass Virginia  <-  Commonwealth of Virginia / E-ZPass Service Center (operating on behalf of VDOT and participating toll agencies)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury.\n\nNOT YET DETERMINED (3 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using E-ZPass Virginia you gave up your physical movements, your right to keep what you paid for, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 3 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 70.0, "URL Last Validated": "2026-09-08T19:21:38Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Automatic replenishment charges the customer's payment method for \"average monthly usage or $35.00 per transponder, whichever is greater\" without a stated cap, and the same agreement disclaims liability for \"incidental, indirect, special or consequential damages\" while requiring the customer to indemnify the Commonwealth — combined with an undisclosed retention period for detailed travel-time/location records tied to SSNs and driver's license numbers.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 12, "_entity_id": 24, "_entity_slug": "e-zpass-virginia", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "MTA Maryland CharmPass", "Category": "Regional transit fare payment", "Terms & Conditions URL": "https://www.mta.maryland.gov/terms-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://www.mta.maryland.gov/terms-conditions", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The document's only explicit third-party disclosure is logistical: \"We will also share your shipping information with the delivery service (U.S. Postal Service).\" No commercial sale of data is mentioned. On location data specifically: \"we use GPS technology (or other similar technology) to determine your current location\" for real-time tracking features, and \"MTA will retain location data for internal analysis purposes. We will not share your current or historical location with other users or partners.\" No Global Privacy Control language appears.", "Arbitration / Class Action Waiver": "No arbitration clause found in the terms fetched. The combined Terms & Conditions / Privacy Policy page contains no mandatory-arbitration, class-action-waiver, or jury-waiver language.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Unilateral modification only: \"These terms of use/privacy policy are subject to change, the substance of which will be posted on the site\" — no notice period or method specified. No liability cap/indemnity clause, no termination/account-closure clause, and no auto-renewal or fee language were found anywhere in the document.", "Notes": "LEGAL ENTITY: Maryland Transit Administration (MTA)\nTERMS EFFECTIVE: Not stated | PRIVACY EFFECTIVE: Not stated\nENFORCEMENT / BREACH (one search, 2026-08-29): On September 22, 2025, MTA publicly announced unauthorized access to its systems with confirmed \"incident-related data loss,\" advising users to watch for phishing, update passwords, and enable multi-factor authentication; core transit services remained operational but real-time information systems and call centers were potentially affected. Source: https://www.mta.maryland.gov/articles/508. Note: this notice is MTA-system-wide and was not confirmed by the source page to specifically name the CharmPass app.\nPRIVACY CONTACT: Not stated — no dedicated privacy email or mailing address is printed; only a general Transit Information Contact Center is listed: 410.539.5000 / Toll Free 1.866.743.3682 / TTY 410.539.3497 (Mon-Fri, 6am-7pm).\nRETENTION: Not stated — states location data is retained \"for internal analysis purposes\" without a duration | GPC honored: Not stated\nRESEARCHER NOTES: A CharmPass-app-specific Terms & Conditions PDF exists in URL form (charmpass_termsconditions_06302018.pdf, dated 2018) but currently returns an \"under construction\" placeholder page rather than the document, so it could not be used; the live, generic mta.maryland.gov/terms-conditions page (which itself states it covers both \"Terms & Conditions and Privacy Policy\") was used instead and may not be fully CharmPass-specific. A future researcher should re-check whether the CharmPass-specific PDF has been restored, and should confirm whether the Sept 2025 cybersecurity incident specifically touched CharmPass account/payment data.\nFETCH LOG (2026-08-29):\nhttps://www.mta.maryland.gov/terms-conditions - 200 OK\nhttps://www.mta.maryland.gov/sites/default/files/charmpass/charmpass_termsconditions_06302018.pdf - not found (page under construction)\nhttps://www.mta.maryland.gov/articles/508 - 200 OK", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Not stated — no dedicated privacy email or mailing address is printed; only a general Transit Information Contact Center is listed: 410.539.5000 / Toll Free 1.866.743.3682 / TTY 410.539.3497 (Mon-Fri, 6am-7pm).", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Maryland Transit Administration (MTA)", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-24 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] MTA announced a Sept 2025 incident with 'incident-related data loss'; the notice does not name CharmPass\nWHAT THE TERMS SAY: On September 22, 2025, MTA publicly announced unauthorized access to its systems with confirmed 'incident-related data loss,' advising users to watch for phishing, update passwords, and enable multi-factor authentication; the notice is MTA-system-wide and was not confirmed to specifically name the CharmPass app.\nWHY IT MATTERS: CharmPass riders cannot tell from the public notice whether their fare-payment account data was affected by the breach.\n(evidence: Notes; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[UNILATERAL_CHANGES · FL-1] CharmPass's combined terms/privacy policy can change just by being posted, with no advance-notice period\nWHAT THE TERMS SAY: 'These terms of use/privacy policy are subject to change, the substance of which will be posted on the site' -- no notice period or method is specified, and no liability cap, termination clause, or auto-renewal language appears anywhere in the document.\nWHY IT MATTERS: Riders have no advance-notice guarantee before new terms take effect, and no defined limit on the agency's liability.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[RETENTION_PERIOD · FL-2] MTA retains GPS location data 'for internal analysis purposes' with no stated duration\nWHAT THE TERMS SAY: 'MTA will retain location data for internal analysis purposes,' without stating for how long, though it adds 'We will not share your current or historical location with other users or partners.'\nWHY IT MATTERS: Riders cannot know how long their real-time GPS location history is kept by the transit agency.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=N; contentlic=?; confiscation=N; autorenew=N; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "CharmPass-specific terms PDF is broken/under-construction; only a generic, easily-changed MTA-wide policy could be used, with no CharmPass-specific breach confirmation.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 5/20 (unilateral_modification+5) | Record 11/20 (severity3+8, breach+3) | flags stated 12/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "MTA Maryland CharmPass  <-  Maryland Transit Administration (MTA)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction.\n\nNOT YET DETERMINED (3 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using MTA Maryland CharmPass you gave up your physical movements and your right to be consulted before terms change. 3 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 70.0, "URL Last Validated": "2026-09-08T19:21:41Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "The governing document is a combined, generic \"Terms of use/privacy policy\" that can change with nothing more than being \"posted on the site\" (no advance-notice period, unlike the other four entities researched), it states no liability cap, no termination clause, and no data-retention duration for the GPS location data it collects — and this same agency confirmed a September 2025 cybersecurity incident with \"incident-related data loss.\"", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 13, "_entity_id": 26, "_entity_slug": "mta-maryland-charmpass", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "VRE Mobile", "Category": "Regional commuter rail app", "Terms & Conditions URL": "https://www.vre.org/about/vre-mobile-terms-and-conditions/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://www.vre.org/about/privacy-statement/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The Privacy Statement states: \"VRE does not sell, rent, or lease its customer lists to third parties.\" It also says VRE \"may...contact you on behalf of external business partners\" while asserting \"your personally identifiable information...is not transferred to the third party.\" Other third parties assist with statistical analysis, mail, support, and deliveries \"under confidentiality requirements.\" On sensitive categories: \"VRE does not use or disclose sensitive personal information, such as race, religion, or political affiliations, without your explicit consent.\" Mobile device \"location\" is collected for app usage statistics. No Global Privacy Control language appears.", "Arbitration / Class Action Waiver": "No arbitration clause found in the terms fetched. The VRE Mobile Service Terms contain no mandatory-arbitration, class-action-waiver, or jury-waiver language.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Unilateral modification: \"VRE reserves the right to change or modify these Service Terms at any time and in its sole discretion, upon ten (10) days notice by email.\" Liability cap: \"The maximum liability of VRE and its licensors...for all damages, losses suffered by you...shall be One Hundred Dollars ($100.00).\" Indemnification: the user must \"indemnify, defend and hold VRE...harmless from and against any and all claims, damages, losses, costs (including reasonable attorney's fees)...arising...out of (a) your breach of these Service Terms.\" Termination: \"We reserve the right to immediately terminate these Service Terms, and/or your access to and use of the Services...at any time and for any reason, with or without cause.\" No auto-renewal/fee language applies (fare-payment app, not subscription).", "Notes": "LEGAL ENTITY: Virginia Railway Express (\"VRE\")\nTERMS EFFECTIVE: January 10, 2021 | PRIVACY EFFECTIVE: Not stated\nENFORCEMENT / BREACH (one search, 2026-08-29): No enforcement/breach item specific to VRE or VRE Mobile found in one search (2026-08-29); results were unrelated Virginia AG settlements (Anthem, Blackbaud) with no VRE connection.\nPRIVACY CONTACT: Address: 1500 King Street, Suite 202, Alexandria, Virginia 22314; Phone: 800-743-3873. (An email address is listed in both documents but was rendered by the fetch tool only as a generic \"[email protected]\" placeholder; the literal email string could not be confirmed from the fetched output.)\nRETENTION: \"VRE retains your personal information for as long as necessary to fulfill the original purposes,\" with an example of retaining customer-support data \"for up to 7 years after the issue has been resolved.\" | GPC honored: Not stated\nRESEARCHER NOTES: Two separate governing documents: VRE Mobile Terms and Conditions (app-specific, dated Jan 10, 2021) and a general VRE Privacy Statement (no effective date printed, applies site- and system-wide, not app-specific). Contact email addresses appear to have been redacted/obscured by the fetch tool's rendering rather than genuinely absent from the source pages — a future researcher should re-fetch or view-source to recover the literal address.\nFETCH LOG (2026-08-29):\nhttps://www.vre.org/about/vre-mobile-terms-and-conditions/ - 200 OK\nhttps://www.vre.org/about/privacy-statement/ - 200 OK", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Address: 1500 King Street, Suite 202, Alexandria, Virginia 22314; Phone: 800-743-3873. (An email address is listed in both documents but was rendered by the fetch tool only as a generic \"[email protected]\" placeholder; the literal email string could not be confirmed from the fetched output.)", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Virginia Railway Express (\"VRE\")", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-20 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LIABILITY_CAP_INDEMNITY · FL-1] VRE Mobile caps its own liability at a flat $100 while reserving the right to terminate service at any time for any reason\nWHAT THE TERMS SAY: 'The maximum liability of VRE and its licensors...for all damages, losses suffered by you...shall be One Hundred Dollars ($100.00),' and 'We reserve the right to immediately terminate these Service Terms, and/or your access to and use of the Services...at any time and for any reason, with or without cause.'\nWHY IT MATTERS: Riders who suffer a loss from the fare-payment app have essentially no meaningful financial recourse, capped at $100, while VRE can cut off access at will.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[UNILATERAL_CHANGES · FL-1] VRE can modify the Service Terms at its sole discretion on just ten days' email notice\nWHAT THE TERMS SAY: 'VRE reserves the right to change or modify these Service Terms at any time and in its sole discretion, upon ten (10) days notice by email.'\nWHY IT MATTERS: Riders have a short window to notice and react to changed terms before they take effect.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data-sharing practices are described favorably (no sale of customer lists, consent required for sensitive categories) and no breach/arbitration item exists, leaving only the liability-cap and unilateral-change items as distinct, substantive harms.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Two clear documents were fetched, but a stated $100 liability cap and at-will termination sit within otherwise standard consumer-facing terms.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 14, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 14/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4) | Record 2/20 (severity2+2) | flags stated 11/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent", "Entity Type": "App / Service", "Ownership Path": "VRE Mobile  <-  Virginia Railway Express (\"VRE\")", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action; your right to a jury.\n\nNOT YET DETERMINED (4 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using VRE Mobile you gave up your physical movements, your data shared corporate-wide, your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 4 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 66.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "VRE caps its own liability at a flat \"One Hundred Dollars ($100.00)\" for any and all damages while reserving the right to \"immediately terminate...at any time and for any reason, with or without cause,\" and can amend the governing terms itself on just \"ten (10) days notice by email\" — a strongly one-sided set of terms for an app that processes commuter-rail fare payments.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 14, "_entity_id": 28, "_entity_slug": "vre-mobile", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Maryland529", "Category": "State college savings plan account portal", "Terms & Conditions URL": "Not retrieved — not found", "T&C Direct PDF?": "Not retrieved", "Privacy Policy URL": "https://maryland529.com/home/privacy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The Privacy Policy states: \"We do not sell information about current or former account owner, custodians, and/or beneficiaries to any third parties.\" Information is shared with \"companies that perform administrative or marketing services for us or with a research firm,\" under contracts that \"restrict third-party use to specified purposes only.\" No Global Privacy Control language appears.", "Arbitration / Class Action Waiver": "Not retrieved — no Terms of Use / Terms of Service / Account Agreement page could be located or fetched for maryland529.com after multiple search attempts and direct-URL guesses (several candidate paths were blocked by the site's robots.txt); only the Privacy Policy was successfully retrieved, and it contains no arbitration language.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Not retrieved — a Terms of Use / Service Agreement page for maryland529.com could not be located or fetched (candidate URLs returned ROBOTS_DISALLOWED errors or were not found in search results), so no data on unilateral modification, liability cap/indemnity, termination, or auto-renewal/fee language could be read for this entity.", "Notes": "LEGAL ENTITY: Not retrieved — the Privacy Policy document does not explicitly name the legal entity (it refers only to the \"Program Manager\" and \"State Treasurer\"), and no Terms of Use page could be located to confirm it.\nTERMS EFFECTIVE: Not stated | PRIVACY EFFECTIVE: Not stated\nENFORCEMENT / BREACH (one search, 2026-08-29): No enforcement/breach item specific to Maryland529 found in one search (2026-08-29); results were unrelated Maryland AG/data-breach items (a law-firm breach settlement, a 23andMe multistate settlement) with no Maryland529 connection.\nPRIVACY CONTACT: Phone: 888.4MD.GRAD (463.4723). No specific privacy email or mailing address is printed in the fetched document.\nRETENTION: Electronic documents are \"archived online for a certain number of years\" (duration unspecified); account statements/confirmations are retained \"up to six years following the date.\" | GPC honored: Not stated\nRESEARCHER NOTES: Maryland529 is a state-administered 529 college-savings program, not a typical consumer app; account-level legal terms for this type of program are usually found in plan-specific Disclosure Statement / Participation (Enrollment) Agreement documents (e.g., the Maryland Prepaid College Trust Disclosure Statement PDF at cdn.unite529.com, located via search but not fetched this session) rather than a single site-wide \"Terms of Use\" page. A future researcher should fetch that plan-specific Disclosure Statement/Participation Agreement PDF (and the equivalent for the Maryland College Investment Plan) directly for the arbitration/liability/termination fields left \"Not retrieved\" here, and should retry the maryland529.com Terms/robots.txt issue, since /home/privacy.html itself fetched successfully while several sibling paths (/home/terms.html, /home/terms-of-use.html, /terms, /Privacy-Statement) all failed with ROBOTS_DISALLOWED.\nFETCH LOG (2026-08-29):\nhttps://maryland529.com/home/privacy.html - 200 OK\nhttps://maryland529.com/home/terms.html - ROBOTS_DISALLOWED (fetch failed)\nhttps://maryland529.com/home/terms-of-use.html - ROBOTS_DISALLOWED (fetch failed)\nhttps://maryland529.com/terms - ROBOTS_DISALLOWED (fetch failed)\nhttps://maryland529.com/Privacy-Statement - ROBOTS_DISALLOWED (fetch failed)\nhttps://maryland529.com/ - 200 OK (homepage checked for legal-page links; none found in excerpt)", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Phone: 888.4MD.GRAD (463.4723). No specific privacy email or mailing address is printed in the fetched document.", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Fetched - awaiting document verification", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Not retrieved — the Privacy Policy document does not explicitly name the legal entity (it refers only to the \"Program Manager\" and \"State Treasurer\"), and no Terms of Use page could be located to conf", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-20 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] No Terms of Use page could be located on maryland529.com, which collects Social Security/tax ID numbers\nWHAT THE TERMS SAY: No dedicated Terms of Use/Service Agreement page could be located anywhere on maryland529.com despite repeated targeted searches and direct-URL attempts, several of which returned robots.txt-blocked errors; the Privacy Policy that was retrieved states no effective/last-updated date and provides only a general customer-service phone number -- no privacy-specific email or mailing address.\nWHY IT MATTERS: Families investing in a state college-savings program handing over Social Security/tax ID numbers have no findable governing contract terms and only a bare phone number to reach with privacy concerns.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No Terms of Use could be located at all (blocked by robots.txt), so arbitration, liability, and termination fields are all 'not retrieved'; only the missing-terms finding itself is substantiated.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No Terms of Use page could be located at all (robots.txt blocked), and the Privacy Policy carries no effective date or dedicated privacy contact.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Maryland529  <-  Not retrieved — the Privacy Policy document does not explicitly name the legal entity (it refers only to the \"Program Manager\" and \"State Treasurer\"), and no Terms of Use page could be located to conf", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Maryland529 you gave up your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:21:44Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Notably absent: no dedicated Terms of Use / Service Agreement page could be located anywhere on maryland529.com despite repeated targeted searches and direct-URL attempts (several returned robots.txt-blocked errors), and the Privacy Policy that was retrieved states no effective/last-updated date and provides only a general customer-service phone number — no privacy-specific email or mailing address — for a program that collects Social Security/tax ID numbers.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 15, "_entity_id": 29, "_entity_slug": "maryland529", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Johns Hopkins Medicine (MyChart)", "Category": "Hospital system patient portal app (MyChart-based)", "Terms & Conditions URL": "https://www.hopkinsmedicine.org/terms-and-conditions-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://www.hopkinsmedicine.org/-/media/privacy/notice-of-privacy-practices-providers.pdf", "Privacy Direct PDF?": "PDF", "Data Sharing/Selling Flags": "The Notice of Privacy Practices states Johns Hopkins is \"not allowed to sell or receive anything of value in exchange for your medical information without your written authorization\" (with limited legal exceptions). It discloses participation in Health Information Exchanges, stating it \"may share information we obtain or create about you through our participation with Health Information Exchanges (HIEs) as permitted by law,\" naming CRISP (Chesapeake Regional Information System) and the Florida HIE, with an opt-out available. Uses/shares are also permitted for treatment, payment, healthcare operations (\"administrative, financial, legal, and quality improvement activities\"), research with IRB approval, fundraising, and a hospital directory (with opt-out). No Global Privacy Control language was found.", "Arbitration / Class Action Waiver": "No arbitration clause was found in either the general hopkinsmedicine.org Terms & Conditions of Use or the MyChart-specific Terms of Use fetched. Neither document mentions mandatory arbitration, a class-action waiver, or a jury waiver.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): General terms state amendments are \"effective immediately upon notice, which we may give by any means, including but not limited to posting notice of the revision on the Online Services homepage.\" Liability is capped: \"JOHNS HOPKINS SHALL NOT BE HELD LIABLE UNDER THIS AGREEMENT OR OTHERWISE IN CONNECTION WITH ONLINE SERVICES FOR AN AMOUNT MORE THAN $500,\" and users must indemnify Johns Hopkins and a long list of affiliates/agents/licensees. Johns Hopkins \"reserves the right to take whatever lawful actions it may deem appropriate ... including without limitation, suspending or terminating any account.\" The separate MyChart Terms of Use state MyChart \"is being provided to you without charge\" and that Johns Hopkins \"may revise the information on this website or otherwise change or update the website, including these Terms of Use, without notice to you,\" and \"reserves the right to terminate your access to MyChart at any time, with or without cause.\"", "Notes": "LEGAL ENTITY: The Johns Hopkins University, The Johns Hopkins Hospital, and Johns Hopkins Health System (collectively \"Johns Hopkins\" / \"Johns Hopkins Medicine\")\nTERMS EFFECTIVE: Not stated | PRIVACY EFFECTIVE: November 20, 2025\nENFORCEMENT / BREACH (one search, 2026-08-29): Johns Hopkins Health System reached a roughly $2.9M class-action settlement (Turner et al. v. Johns Hopkins Health System Corporation, jhsettlement.com) over a 2023 data breach tied to the vendor MOVEit file-transfer software incident. Source: https://www.cybersecuritydive.com/news/johns-hopkins-class-action-moveit/686669/\nPRIVACY CONTACT: Johns Hopkins Privacy Office, 733 N. Broadway, MRB Suite 102B, Baltimore, MD 21205. Phone: 410-614-9900. Fax: 443-529-1548. Email: hipaa@jhmi.edu. (Individual facility Health Information Management departments also listed, e.g. Johns Hopkins Hospital: 410-955-6044.)\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: Two separate governing documents exist: the general hopkinsmedicine.org Terms & Conditions of Use (website-wide) and a distinct MyChart Terms of Use served from the mychart.hopkinsmedicine.org login page — they have different modification/liability language and neither carries a visible effective date. The Notice of Privacy Practices (HIPAA) is a separate PDF from the patient-facing 'Patient Privacy Information' web page; the web page itself did not state a retention period or effective date. MyChart Bedside data is stated to be 'erased once you are discharged'; deceased-patient proxy access is 'valid for a maximum of one year.'\nFETCH LOG (2026-08-29):\nhttps://www.hopkinsmedicine.org/terms-and-conditions-of-use - 200 OK\nhttps://mychart.hopkinsmedicine.org/mychart/Authentication/Login?mode=stdfile&option=termsandconditions - 200 OK\nhttps://www.hopkinsmedicine.org/Privacy/patients.html - 200 OK\nhttps://www.hopkinsmedicine.org/-/media/privacy/notice-of-privacy-practices-providers.pdf - 200 OK", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Johns Hopkins Privacy Office, 733 N. Broadway, MRB Suite 102B, Baltimore, MD 21205. Phone: 410-614-9900. Fax: 443-529-1548. Email: hipaa@jhmi.edu. (Individual facility Health Information Management departments also listed, e.g. Johns Hopkins Hospital: 410-955-6044.)", "Legal / Privacy Contact Email": "hipaa@jhmi.edu.", "Finding Type": "Data breach + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Pending - severity 4/5, no source yet", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "The Johns Hopkins University, The Johns Hopkins Hospital, and Johns Hopkins Health System (collectively \"Johns Hopkins\" / \"Johns Hopkins Medicine\")", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-26 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Johns Hopkins reached a ~$2.9M settlement over a 2023 MOVEit vendor data breach\nWHAT THE TERMS SAY: Johns Hopkins Health System reached a roughly $2.9M class-action settlement (Turner et al. v. Johns Hopkins Health System Corporation) over a 2023 data breach tied to the vendor MOVEit file-transfer software incident.\nWHY IT MATTERS: Patient data was compromised through a third-party vendor, resulting in litigation and a multimillion-dollar settlement.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[LIABILITY_CAP_INDEMNITY · FL-1] Johns Hopkins caps its own online-services liability at just $500, regardless of the sensitivity of health data involved\nWHAT THE TERMS SAY: 'JOHNS HOPKINS SHALL NOT BE HELD LIABLE UNDER THIS AGREEMENT OR OTHERWISE IN CONNECTION WITH ONLINE SERVICES FOR AN AMOUNT MORE THAN $500,' and users must indemnify Johns Hopkins and a long list of affiliates, agents, and licensees.\nWHY IT MATTERS: A $500 cap is strikingly low relative to the sensitivity of the health data handled through the same online services.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[UNILATERAL_CHANGES · FL-1] MyChart terms can be changed by Johns Hopkins without notice to patients\nWHAT THE TERMS SAY: The MyChart Terms of Use state Johns Hopkins 'may revise the information on this website or otherwise change or update the website, including these Terms of Use, without notice to you,' and 'reserves the right to terminate your access to MyChart at any time, with or without cause.'\nWHY IT MATTERS: Patients using the portal to access their medical records have no guarantee they'll be notified before the terms governing that access change.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=N; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Multiple governing documents were fetched and are specific, but neither carries a visible effective date and the two documents (general vs. MyChart) have different liability/modification terms.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 14, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 14/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4) | Record 16/20 (severity4+14, litigation+2) | flags stated 12/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "App / Service", "Ownership Path": "Johns Hopkins Medicine (MyChart)  <-  The Johns Hopkins University, The Johns Hopkins Hospital, and Johns Hopkins Health System (collectively \"Johns Hopkins\" / \"Johns Hopkins Medicine\")", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action; your right to a jury; your right to stop paying by inaction.\n\nNOT YET DETERMINED (4 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Johns Hopkins Medicine (MyChart) you gave up your data shared corporate-wide, your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 4 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 70.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The general online-services liability cap of $500 (\"JOHNS HOPKINS SHALL NOT BE HELD LIABLE ... FOR AN AMOUNT MORE THAN $500\") is strikingly low relative to the sensitivity of health data handled through the same domain family, and it sits alongside a right to change the terms \"without notice to you\" for MyChart specifically.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 16, "_entity_id": 31, "_entity_slug": "johns-hopkins-medicine-mychart", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sentara Health (MyChart)", "Category": "Hospital system patient portal app (MyChart-based)", "Terms & Conditions URL": "https://www.sentara.com/patientguide/medical-records/sentara-mychart/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://www.sentara.com/Policies-and-Agreements/Sentara-Privacy-Statement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The Sentara Privacy Statement states: \"Sentara does not sell, trade, rent or share your personal information to organizations outside Sentara Healthcare and its affiliate companies unless required to do by legal, judicial or governmental proceedings.\" It notes the website collects name, address, phone number, and IP addresses, and uses cookies \"for browsing experience customization\" while stating no personal/health data is retained in cookies. No Global Privacy Control language was found. Separately, the MyChart terms state emails sent to Sentara \"may be shared with your clinical care team, billing teams, or other Sentara workforce members or service providers,\" and proxy access permits sharing medical information with the designated proxy.", "Arbitration / Class Action Waiver": "No arbitration clause, class-action waiver, or jury waiver was found in the Sentara MyChart Terms and Conditions fetched.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): The MyChart Terms and Conditions state: \"These terms and conditions are subject to change without prior written notice at any time at Sentara's sole discretion,\" and require users to accept updated terms at next login or face account deactivation. No liability cap language was found in the MyChart terms beyond a general disclaimer: \"We are not to blame for any problems that may arise from being unable to see your information via MyChart.\" Termination: \"We reserve the right to revoke (remove) access to MyChart at any time,\" with deactivation triggers listed including non-acceptance of updated terms, turning 14 (loss of parental proxy access), inappropriate messaging, proxy abuse, legal issues, incarceration, and poor training response. No auto-renewal/fee language found (MyChart is a free patient portal).", "Notes": "LEGAL ENTITY: Sentara Health (also referred to as \"Sentara Healthcare\" in the website privacy statement)\nTERMS EFFECTIVE: March 26, 2025 (last updated) | PRIVACY EFFECTIVE: Not stated\nENFORCEMENT / BREACH (one search, 2026-08-29): Sentara Hospitals paid a $2.175 million HHS OCR settlement in 2019 for \"refusal to properly report\" two data breaches (misdirected electronic health record access) to federal regulators, per a HIPAA corrective action plan. Source: https://www.healthcaredive.com/news/refusal-to-properly-report-data-breach-spurs-2175m-fine-for-sentara-hos/568215/\nPRIVACY CONTACT: Sentara Health Notice of Privacy Practices page: PO Box 2200, Norfolk, VA 23502; Phone 1-833-723-0582; Email privacy@sentara.com. MyChart support: MyChart_Support@sentara.com, 1-833-351-4357 (M–F, 8am–6pm EST).\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: Sentara maintains at least three separate documents: the MyChart-specific 'Terms and Conditions' (dated March 26, 2025), the general 'Sentara Privacy Statement' (website data practices, no date shown), and the 'Sentara Integrated Notice of Privacy Practices' (HIPAA NPP, referenced filename suggests a February 2026 version but the linked landing page did not display the substantive text). The NPP landing page itself only surfaced contact information, not the clause language a full HIPAA analysis would need — a future researcher should fetch the underlying PDF directly.\nFETCH LOG (2026-08-29):\nhttps://www.sentara.com/patientguide/medical-records/sentara-mychart/terms-and-conditions - 200 OK\nhttps://www.sentara.com/Policies-and-Agreements/Privacy-Policy - 200 OK (index/landing page only)\nhttps://www.sentara.com/Policies-and-Agreements/Sentara-Integrated-Notice-of-Privacy-Practices - 200 OK (index/landing page only, substantive PDF not reached)\nhttps://www.sentara.com/Policies-and-Agreements/Sentara-Privacy-Statement - 200 OK", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Sentara Health Notice of Privacy Practices page: PO Box 2200, Norfolk, VA 23502; Phone 1-833-723-0582; Email privacy@sentara.com. MyChart support: MyChart_Support@sentara.com, 1-833-351-4357 (M–F, 8am–6pm EST).", "Legal / Privacy Contact Email": "privacy@sentara.com.", "Finding Type": "Data breach + Regulatory action + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Pending - severity 4/5, no source yet", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Sentara Health (also referred to as \"Sentara Healthcare\" in the website privacy statement)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-26 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] Sentara paid a $2.175M HHS OCR settlement over 'refusal to properly report' two data breaches\nWHAT THE TERMS SAY: Sentara Hospitals paid a $2.175 million HHS OCR settlement in 2019 for 'refusal to properly report' two data breaches (misdirected electronic health record access) to federal regulators, per a HIPAA corrective action plan.\nWHY IT MATTERS: The 2019 penalty concerns Sentara's \"refusal to properly report\" two data breaches to federal regulators, resolved under a HIPAA corrective action plan -- a trust failure around breach transparency.\n(evidence: Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[TERMINATION_CONFISCATION · FL-4] Sentara can cut off MyChart access for reasons including turning 14 or incarceration, after unilateral no-notice term changes\nWHAT THE TERMS SAY: 'These terms and conditions are subject to change without prior written notice at any time at Sentara's sole discretion,' requiring users to accept updates at next login or face deactivation; deactivation triggers include non-acceptance of updated terms, turning 14 (loss of parental proxy access), inappropriate messaging, proxy abuse, legal issues, incarceration, and poor training response.\nWHY IT MATTERS: Patients can lose access to their own health records portal under broad, unilaterally-changeable conditions, some unrelated to any misuse of the portal itself (e.g., incarceration, turning 14).\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data sharing is described as not sold/traded/rented except by legal process, and no arbitration clause or class/jury waiver exists, leaving the OCR penalty and the deactivation-trigger/unilateral-change item as the two distinct, substantive harms.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=N; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "MyChart terms are specific and dated, but the NPP landing page did not surface substantive HIPAA text, and unilateral no-notice changes are explicit.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 14, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 14/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4) | Record 16/20 (severity4+14, litigation+2) | flags stated 13/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "App / Service", "Ownership Path": "Sentara Health (MyChart)  <-  Sentara Health (also referred to as \"Sentara Healthcare\" in the website privacy statement)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action; your right to a jury; your right to stop paying by inaction.\n\nNOT YET DETERMINED (4 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Sentara Health (MyChart) you gave up your data shared corporate-wide, your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 4 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 73.3, "URL Last Validated": "2026-09-08T19:21:52Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "The MyChart terms give Sentara unilateral, no-notice authority to change the agreement (\"subject to change without prior written notice at any time at Sentara's sole discretion\") while simultaneously listing broad, patient-triggered deactivation conditions (e.g., incarceration, turning 14) that can cut off portal access to one's own health records.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 17, "_entity_id": 33, "_entity_slug": "sentara-health-mychart", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Children's National Hospital (MyChart)", "Category": "Pediatric hospital system patient portal app (MyChart-based)", "Terms & Conditions URL": "https://childrensnational.iqhealth.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://www.childrensnational.org/about-us/legal-and-compliance/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The portal Terms of Use state: \"We will not disclose any information to third parties for any other purpose, and we will not sell mailing lists,\" but add \"This information may be shared with Children's National's business associates.\" The website privacy policy repeats the no-sale-of-mailing-lists language and separately states \"We do not collect or share users' health record data of any kind\" on the general website (distinct from the patient portal, which does handle PHI). The privacy policy also describes collecting fitness/activity data (workout types, durations, steps, distance) from connected devices. No Global Privacy Control language was found; Maryland residents are offered rights to access, delete, correct, port, and withdraw consent for sensitive data, with a 45-day (60-day on appeal) response window.", "Arbitration / Class Action Waiver": "No arbitration clause, class-action waiver, or jury waiver was found in the MyChildrensPortal Terms of Use fetched.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): \"Children's National may revise these Terms and Notice of Privacy Practices at any time... A revised Terms of Use and Privacy Policy are effective upon posting, and your continued use of the Patient Portal indicates your acceptance.\" Liability: \"in no event shall Children's National be liable for any direct, indirect, incidental, consequential, special, exemplary, punitive, or any other monetary or other damages,\" and users must indemnify the organization \"against any damages, losses, injuries, liabilities, judgments, costs or expenses (including reasonable attorneys' fees and costs).\" Termination: \"Children's National reserves the right to change, suspend or discontinue all or any aspects of the Patient Portal at any time without prior notice, unless noted otherwise.\" No auto-renewal/fee language found (free patient portal).", "Notes": "LEGAL ENTITY: Children's National Medical Center (also \"Children's National\")\nTERMS EFFECTIVE: Not stated | PRIVACY EFFECTIVE: Not stated\nENFORCEMENT / BREACH (one search, 2026-08-29): A phishing-driven data breach at Children's National Health System exposed roughly 18,000 patients' information (employee email accounts compromised in Dec. 2014, patients notified Feb. 2015); a resulting class-action lawsuit was moved to federal court by mid-2015 (Social Security numbers involved 'only in a small number of instances'; medical records reportedly not compromised). Source: https://www.beckershospitalreview.com/healthcare-information-technology/data-hack-lawsuit-filed-against-children-s-national-medical-center-has-moved-to-federal-court.html\nPRIVACY CONTACT: MyChildrensPortal: privacyofficer@childrensnational.org, phone 301-572-6348, support 1-877-621-8014, 111 Michigan Ave., NW, Washington, DC 20010. Website privacy policy: general phone 202-476-5000; Maryland rights request form at https://childrensnational.formstack.com/forms/modpa; same 111 Michigan Avenue NW address.\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: The patient portal for Children's National Hospital (Washington, DC) is branded 'MyChildrensPortal' (built on the IQHealth platform), NOT Epic MyChart — despite the input list labeling this entity '(MyChart)'. Two attempts to fetch the HIPAA Notice of Privacy Practices PDFs (childrensnational.org/-/media/cnhs-site/files/about/nppprivacypractices2.pdf and the international.childrensnational.org mirror) both failed with server 502 errors; NPP-specific fields (sale-of-PHI language, HIE participation, retention period, NPP effective date) are 'Not retrieved' as a result and should be retried by a future researcher. An older, separately dated NPP PDF (effective March 31, 2016) was found via search but not fetched.\nFETCH LOG (2026-08-29):\nhttps://childrensnational.iqhealth.com/terms - 200 OK\nhttps://www.childrensnational.org/about-us/legal-and-compliance/privacy-policy - 200 OK\nhttps://childrensnational.org/-/media/cnhs-site/files/about/nppprivacypractices2.pdf?la=en - 502 server error (PDF failed)\nhttps://international.childrensnational.org/-/media/cnhs-site/files/about/notice-of-privacy.pdf?la=en - 502 server error (PDF failed)\nhttps://childrensnational.org/-/media/cnhs-site/files/healthcare-providers/refer-a-patient/corona-virus/privacy.pdf?la=en&hash=0228B2051D7357B51A7BEF5DDBD90D8ACFAE8E36 - 502 server error (PDF failed)", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "MyChildrensPortal: privacyofficer@childrensnational.org, phone 301-572-6348, support 1-877-621-8014, 111 Michigan Ave., NW, Washington, DC 20010. Website privacy policy: general phone 202-476-5000; Maryland rights request form at https://childrensnational.formstack.com/forms/modpa; same 111 Michigan Avenue NW address.", "Legal / Privacy Contact Email": "privacyofficer@childrensnational.org", "Finding Type": "Data breach + Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Children's National Medical Center (also \"Children's National\")", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-24 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] Children's National's main privacy policy could mislead readers into thinking no health data is collected at all\nWHAT THE TERMS SAY: The website privacy policy states 'We do not collect or share users' health record data of any kind' about the general childrensnational.org site, distinct from the actual patient portal / PHI handling covered by a separate HIPAA Notice of Privacy Practices.\nWHY IT MATTERS: A consumer reading only the main privacy policy could reasonably but wrongly conclude no health data is collected at all, when the portal itself does handle protected health information.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] A 2014-2015 phishing breach exposed ~18,000 patients' data and drew a class-action lawsuit\nWHAT THE TERMS SAY: A phishing-driven data breach at Children's National Health System exposed roughly 18,000 patients' information (employee email accounts compromised Dec. 2014, patients notified Feb. 2015); Social Security numbers were involved 'only in a small number of instances,' and a resulting class-action lawsuit was moved to federal court by mid-2015.\nWHY IT MATTERS: The hospital's patient data was compromised via a phishing attack, leading to litigation over the incident.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[UNILATERAL_CHANGES · FL-1] Children's National can suspend or discontinue the patient portal at any time without prior notice\nWHAT THE TERMS SAY: 'Children's National reserves the right to change, suspend or discontinue all or any aspects of the Patient Portal at any time without prior notice, unless noted otherwise,' alongside a broad damages disclaimer and a requirement that users indemnify the organization.\nWHY IT MATTERS: Patients relying on the portal for medical record access can lose that access without warning.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=N; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Portal terms were fetched and specific, but the HIPAA Notice of Privacy Practices PDFs all failed to load (502 errors), leaving retention and further PHI-sharing details unconfirmed.", "Exposure Score (0-100)": 31, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 14, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 14/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 12/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "App / Service", "Ownership Path": "Children's National Hospital (MyChart)  <-  Children's National Medical Center (also \"Children's National\")", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action; your right to a jury; your right to stop paying by inaction.\n\nNOT YET DETERMINED (4 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Children's National Hospital (MyChart) you gave up your data shared corporate-wide, your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 4 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 70.0, "URL Last Validated": "2026-09-08T19:21:53Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "The website privacy policy draws a sharp, easy-to-miss distinction between the general childrensnational.org site (\"We do not collect or share users' health record data of any kind\") and the actual patient portal / PHI handling covered by a separate HIPAA Notice of Privacy Practices — a consumer reading only the main privacy policy could reasonably but wrongly conclude no health data is collected at all.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 18, "_entity_id": 35, "_entity_slug": "children-s-national-hospital-mychart", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Patient First", "Category": "Regional urgent care chain", "Terms & Conditions URL": "https://www.patientfirst.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://www.patientfirst.com/privacy-statement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The Privacy Statement states: \"Patient First does not sell, rent or lease its customer lists to third parties,\" but adds \"Patient First may share data with trusted partners to help us perform statistical analysis, send you email or postal mail, provide customer support, or arrange for deliveries,\" and information may be shared \"on behalf of external business partners about a particular offering that may be of interest to you\" (stated without transferring personally identifiable information to those partners). The separate Patient First Privacy Practices page states \"Patient First does not use or disclose sensitive personal information, such as race, religion, or political affiliations, without your explicit consent.\" No Global Privacy Control language was found. reCAPTCHA is used and described as analyzing \"user behavior (such as mouse movements and IP address) to determine whether interactions are human.\"", "Arbitration / Class Action Waiver": "No arbitration clause was found in the Terms of Use fetched. The document instead specifies: governed by Washington State law with \"exclusive jurisdiction\" of King County, Washington courts for disputes — no mention of mandatory arbitration, class-action waiver, or jury waiver.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): \"Patient First reserves the right to change the terms, conditions, and notices under which the Patient First Web Site is offered.\" Liability: \"IN NO EVENT SHALL PATIENT FIRST AND/OR ITS SUPPLIERS BE LIABLE FOR ANY DIRECT, INDIRECT, PUNITIVE, INCIDENTAL, SPECIAL, CONSEQUENTIAL DAMAGES.\" Termination: \"Patient First reserves the right, in its sole discretion, to terminate your access to the Patient First Web Site ... at any time, without notice.\" No auto-renewal/fee language found (informational site, no subscription).", "Notes": "LEGAL ENTITY: Patient First\nTERMS EFFECTIVE: October 6, 2025 (last updated) | PRIVACY EFFECTIVE: June 15, 2026 (last updated)\nENFORCEMENT / BREACH (one search, 2026-08-29): No enforcement/breach item found in one search (2026-08-29) — search results returned data-breach settlements for other, unrelated healthcare providers (e.g., General Physician, P.C.) but nothing specific to Patient First.\nPRIVACY CONTACT: Email: notify@patientfirst.com. Mailing address: 5000 Cox Road, Richmond, VA 23060. Phone: 804-968-5700 (Richmond) / 800-447-8588 (toll free); Fax: 804-968-5725. Patient-privacy-specific contact form referenced at https://www.patientfirst.com/contact-us/patient-privacy.\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: Two related but separate documents exist: the general 'Terms of Use' (website conduct, updated Oct 6, 2025) and the 'Privacy Statement' (website data practices, updated June 15, 2026) — plus a third, distinct 'Patient First Privacy Practices' page pointing to state-specific HIPAA Notice of Privacy Practices PDFs (VA, MD, PA, NJ) that were not individually fetched in this pass; a future researcher should pull each state's NPP PDF separately since they may differ by state law.\nFETCH LOG (2026-08-29):\nhttps://www.patientfirst.com/terms-of-use - 200 OK\nhttps://www.patientfirst.com/privacy-statement - 200 OK\nhttps://www.patientfirst.com/patient-first-privacy-practices - 200 OK", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Email: notify@patientfirst.com. Mailing address: 5000 Cox Road, Richmond, VA 23060. Phone: 804-968-5700 (Richmond) / 800-447-8588 (toll free); Fax: 804-968-5725. Patient-privacy-specific contact form referenced at https://www.patientfirst.com/contact-us/patient-privacy.", "Legal / Privacy Contact Email": "notify@patientfirst.com.", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: national vendor serving Mid-Atlantic users (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Patient First", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-20 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-3] Patient First's Terms pick Washington State law and King County venue for a company operating clinics in VA, MD, PA, and NJ\nWHAT THE TERMS SAY: The Terms of Use choose Washington State law and King County, Washington courts for 'exclusive jurisdiction' over disputes, despite Patient First being headquartered and operating clinics in Virginia, Maryland, Pennsylvania, and New Jersey.\nWHY IT MATTERS: An out-of-region forum clause raises the practical cost and difficulty of any dispute for a typical local patient, who would not expect to litigate across the country.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[LIABILITY_CAP_INDEMNITY · FL-1] Patient First disclaims broad categories of damages and can terminate site access at any time without notice\nWHAT THE TERMS SAY: 'IN NO EVENT SHALL PATIENT FIRST AND/OR ITS SUPPLIERS BE LIABLE FOR ANY DIRECT, INDIRECT, PUNITIVE, INCIDENTAL, SPECIAL, CONSEQUENTIAL DAMAGES,' and 'Patient First reserves the right, in its sole discretion, to terminate your access to the Patient First Web Site... at any time, without notice.'\nWHY IT MATTERS: Site users have essentially no contractual recourse for harm and no guaranteed continued access.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data-sharing practices are relatively standard (no sale of customer lists, consent required for sensitive categories) and no breach/enforcement item was found, leaving the forum-selection and liability/termination clauses as the two distinct, substantive harms.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=N; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Three separate documents were fetched and are dated/specific, but state-specific HIPAA NPP PDFs referenced were not individually pulled.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 14, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 14/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4) | Record 2/20 (severity2+2) | flags stated 11/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Patient First  <-  Patient First", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action; your right to a jury; your right to stop paying by inaction.\n\nNOT YET DETERMINED (4 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Patient First you gave up your data shared corporate-wide, your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 4 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 66.7, "URL Last Validated": "2026-09-08T19:22:00Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "The Terms of Use choose Washington State law and King County, Washington venue for a company headquartered and operating clinics in Virginia, Maryland, Pennsylvania, and New Jersey — an out-of-region forum clause a typical patient/consumer would not expect and that raises the practical cost of any dispute.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 19, "_entity_id": 36, "_entity_slug": "patient-first", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Righttime Medical Care", "Category": "Regional urgent care chain", "Terms & Conditions URL": "Not retrieved — not found", "T&C Direct PDF?": "Not retrieved", "Privacy Policy URL": "Not retrieved — not found", "Privacy Direct PDF?": "Not retrieved", "Data Sharing/Selling Flags": "Not retrieved — no Privacy Policy page for Righttime Medical Care could be located or fetched this session.", "Arbitration / Class Action Waiver": "Not retrieved — no Terms of Use page for Righttime Medical Care could be located or fetched this session.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Not retrieved — no Terms of Use page for Righttime Medical Care could be located or fetched this session.", "Notes": "LEGAL ENTITY: Not retrieved — no independent official website could be located or fetched\nTERMS EFFECTIVE: Not retrieved — page not found | PRIVACY EFFECTIVE: Not retrieved — page not found\nENFORCEMENT / BREACH (one search, 2026-08-29): No enforcement/breach item found in one search (2026-08-29) — results returned unrelated healthcare-provider data-breach settlements (e.g., General Physician, P.C.), nothing specific to Righttime Medical Care.\nPRIVACY CONTACT: Not stated\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: MedStar Health acquired Righttime Medical Care in December 2020 (sources: WTOP, Fox Baltimore, The Daily Record, Dec. 2020) and has since been rebranding former Righttime clinics as 'MedStar Health Urgent Care' (e.g., 'Towson Urgent Care Center Re-Opens as MedStar Health Urgent Care,' medstarhealth.org). righttimemedicalcare.com could not be resolved/fetched (WebFetch returned 'Name or service not known' / robots.txt fetch failure on both https and http). A domain named rightmd.health was checked and confirmed via fetch to be an unrelated telemedicine company, not Righttime Medical Care. A future researcher should check whether any Righttime-branded terms/privacy pages still exist under medstarhealth.org, or treat Righttime as functionally absorbed into MedStar Health's own policies.\nFETCH LOG (2026-08-29):\nhttps://righttimemedicalcare.com/ - ROBOTS_DISALLOWED / DNS resolution failed\nhttp://www.righttimemedicalcare.com - ROBOTS_DISALLOWED / robots.txt fetch failed\nhttps://www.rightmd.health/privacy-notice - 200 OK (fetched to confirm unrelated entity, not used as source)\nhttps://www.bbb.org/us/md/annapolis/profile/urgent-care-clinic/righttime-medical-care-0011-90027162 - 200 OK (business directory listing only, no policy content)\nhttps://www.medstarhealth.org/services/urgent-care - 200 OK (no Righttime-specific content found)\nhttps://www.solvhealth.com/company/righttime-medical-care - 200 OK (no Righttime-specific content found)", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Not stated", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "No URL recorded", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Not retrieved — no independent official website could be located or fetched", "Years Referenced in Finding (heuristic)": "2020", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-20 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] Righttime Medical Care appears to no longer maintain a reachable website or locatable terms/privacy docs\nWHAT THE TERMS SAY: Multiple attempts to fetch righttimemedicalcare.com returned DNS/robots.txt resolution failures; several individual Righttime clinic listings are marked 'CLOSED,' and search results confirm at least one former Righttime location (Towson) 're-opens as MedStar Health Urgent Care,' consistent with MedStar Health's December 2020 acquisition of Righttime.\nWHY IT MATTERS: A consumer searching for Righttime's terms or privacy policy today may find no live, entity-specific document at all.\n(evidence: SCARY; Tracker says unconfirmed (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No Privacy Policy, Terms of Use, or enforcement item could be located for this entity at all -- Righttime appears to have been absorbed into MedStar Health and no longer operates an independent site, leaving only the absence-of-terms finding itself as a reportable item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No website, terms, or privacy policy could be located for this entity at all; it appears to have been absorbed into MedStar Health.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Righttime Medical Care  <-  Not retrieved — no independent official website could be located or fetched", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Righttime Medical Care takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Notably ABSENT: Righttime Medical Care appears to no longer maintain an independently reachable website. Multiple attempts to fetch righttimemedicalcare.com returned DNS/robots.txt resolution failures, several individual Righttime clinic listings on Yelp/Healthgrades are marked 'CLOSED,' and search results confirm at least one former Righttime location (Towson) 're-opens as MedStar Health Urgent Care' — consistent with MedStar Health's December 2020 acquisition of Righttime and an apparent ongoing rebrand. A consumer searching for Righttime's terms/privacy today may find no live, entity-specific document at all.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 20, "_entity_id": 37, "_entity_slug": "righttime-medical-care", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sandy Spring Bank", "Category": "Regional bank", "Terms & Conditions URL": "https://www.atlanticunionbank.com/getmedia/e0dcffd3-1ccf-4841-a00b-0a650c9a343e/consumer-deposit-account-agreement.pdf", "T&C Direct PDF?": "PDF", "Privacy Policy URL": "https://www.atlanticunionbank.com/about/helpful-links/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The GLBA disclosure chart on the privacy page states AUB shares: \"For our everyday business purposes\" = Yes/cannot limit; \"For our marketing purposes\" = Yes/cannot limit; \"For joint marketing with other financial companies\" = Yes/cannot limit; \"For our affiliates' everyday business purposes\" (transactions/experience) = Yes/cannot limit; affiliates' creditworthiness info = Yes/can limit; affiliates to market to you = Yes/can limit; \"For nonaffiliates to market to you\" = \"No\" / \"We do not share.\" Biometric login: \"your biometrics are not shared with us.\" Precise geolocation is collected \"if you consent... such as to find nearby branches.\" No mention of Global Privacy Control.", "Arbitration / Class Action Waiver": "Not retrieved — the Consumer Deposit Account Agreement's table of contents lists a section titled \"Resolving Disputes, Waiver of Jury Trial and Class and Representative Actions\" on page 32, confirming such a clause exists, but the PDF fetch was truncated before that section and its text was not read. The separately fetched Consumer Online Banking Agreement (COLB) contains a jury-trial waiver only, Section 25: \"YOU AND WE KNOWINGLY, VOLUNTARILY AND INTENTIONALLY WAIVE OUR RESPECTIVE RIGHTS TO A TRIAL BY JURY IN ANY PROCEEDING, WHETHER SOUNDING IN CONTRACT, TORT, OR OTHERWISE, ARISING OUT OF OR RELATING TO THIS ONLINE BANKING AGREEMENT.\" That document contains no arbitration clause, no class-action waiver, and no opt-out language.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Unilateral modification: \"Please be aware that we regularly update this Agreement\"; continued use after posting = acceptance, and overdraft practices may change \"without notice to you.\" Liability/indemnity: multiple indemnification clauses (fiduciary/UTMA custodians, ACH stop-payment requesters) and a disclaimer that \"ordinary care does not require us to exam[ine] the item\" for automated processing. Termination: overdrawn accounts are generally \"close[d] and charge[d] off... sixty (60) days after it first becomes overdrawn,\" and accounts may be restricted for KYC non-compliance. Fees: no auto-renewal clause found, but extensive discretionary fee language (e.g., \"may charge an overdraft fee for each paid transaction\"; new stop-payment fee \"for each new stop payment order\" on renewal).", "Notes": "LEGAL ENTITY: Atlantic Union Bank (\"a Virginia banking corporation\") — Sandy Spring Bank merged into Atlantic Union Bank effective April 1, 2025, with full systems conversion completed October 13, 2025; sandyspringbank.com now 302-redirects to atlanticunionbank.com and Sandy Spring's own terms/privacy documents are no longer published\nTERMS EFFECTIVE: August 11, 2025 (Consumer Deposit Account Agreement, doc code \"CDAA2024-8/11/2025\") | PRIVACY EFFECTIVE: Online Privacy Notice: \"Last Updated: April 5, 2024\"; Consumer Privacy Notice (GLBA chart): \"Last Updated: May 2022\"\nENFORCEMENT / BREACH (one search, 2026-08-29): On December 7, 2023 the CFPB ordered Atlantic Union Bank — the entity Sandy Spring Bank has since merged into — to pay $6.2 million in redress and penalties for Regulation E violations and deceptive practices tied to overdraft-fee enrollment (predates the merger but the same legal entity now governs former Sandy Spring accounts). Source: https://www.consumerfinance.gov/enforcement/actions/atlantic-union-bank/\nPRIVACY CONTACT: Phone: 800-990-4828 (\"our menu will prompt you through your choice(s)\"). No mailing address for privacy requests was found in the pages fetched.\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: Sandy Spring Bank merged into Atlantic Union Bank (effective 4/1/2025; systems conversion 10/13/2025); sandyspringbank.com 302-redirects to atlanticunionbank.com. Multiple governing documents exist for the successor: a general website \"Terms of Use\" page (thin content), a Consumer Deposit Account Agreement PDF (effective 8/11/2025, ~32+ pages, arbitration section on p.32 not retrieved due to PDF truncation by the fetch tool), and a Consumer Online Banking Agreement (COLB) PDF (jury waiver only, no arbitration clause, no effective date stated). A future researcher should re-fetch the Consumer Deposit Account Agreement in smaller page ranges or via a different tool to capture the full \"Resolving Disputes\" section (arbitration/class-action/opt-out terms). Two separate privacy documents exist with different \"last updated\" dates (Online Privacy Notice 4/5/2024 vs. Consumer Privacy Notice/GLBA chart 5/2022).\nFETCH LOG (2026-08-29):\nhttps://www.sandyspringbank.com/sites/default/files/Employee/SSB-1671%20Personal%20Account%20Agreement%20July%202020.pdf — 404\nhttps://www.sandyspringbank.com/resource-center — 200 OK (no relevant links found)\nhttps://www.sandyspringbank.com/ — 302 redirect to https://www.atlanticunionbank.com/\nhttps://www.atlanticunionbank.com/ — 200 OK (redirect target; confirmed merger notice)\nhttps://www.atlanticunionbank.com/welcome1 — 200 OK\nhttps://www.atlanticunionbank.com/about/helpful-links/terms-of-use — 200 OK\nhttps://www.atlanticunionbank.com/about/helpful-links/privacy — 200 OK (fetched twice, second time targeting GLBA chart)\nhttps://www.atlanticunionbank.com/getmedia/e0dcffd3-1ccf-4841-a00b-0a650c9a343e/consumer-deposit-account-agreement.pdf — 200 OK, truncated before arbitration section\nhttps://www.atlanticunionbank.com/getmedia/337a7e2c-1772-4bd6-8f09-0dbe082cb6ae/COLB_Agreement.pdf — 200 OK\nhttps://www.consumerfinance.gov/enforcement/actions/atlantic-union-bank/ — 200 OK", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Phone: 800-990-4828 (\"our menu will prompt you through your choice(s)\"). No mailing address for privacy requests was found in the pages fetched.", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Pending - severity 4/5, no source yet", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Atlantic Union Bank (\"a Virginia banking corporation\") — Sandy Spring Bank merged into Atlantic Union Bank effective April 1, 2025, with full systems conversion completed October 13, 2025; sandyspring", "Years Referenced in Finding (heuristic)": "2023, 2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-26 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] The bank that absorbed Sandy Spring paid a $6.2M CFPB penalty for deceptive overdraft-fee practices\nWHAT THE TERMS SAY: On December 7, 2023 the CFPB ordered Atlantic Union Bank -- the entity Sandy Spring Bank has since merged into -- to pay $6.2 million in redress and penalties for Regulation E violations and deceptive practices tied to overdraft-fee enrollment.\nWHY IT MATTERS: Former Sandy Spring customers are now governed by a bank with a recent, substantial federal penalty for deceptive overdraft practices.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[UNILATERAL_CHANGES · FL-4] Sandy Spring customers are now bound by Atlantic Union Bank's agreements without having separately agreed to them\nWHAT THE TERMS SAY: Sandy Spring Bank no longer exists as an independent legal entity or terms-publisher: its website now hard-redirects to Atlantic Union Bank, meaning former Sandy Spring customers are now bound by a different bank's Consumer Deposit Account Agreement (effective Aug 11, 2025) and Online Banking Agreement, including a jury-trial waiver, without the customer having separately agreed to the successor's terms as 'Sandy Spring Bank.'\nWHY IT MATTERS: Customers who opened accounts under one bank's terms find themselves bound to a different institution's contract, including a jury-trial waiver, through a merger they had no say in.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[JURY_WAIVER · FL-3] The successor bank's Online Banking Agreement includes an unconditional jury-trial waiver\nWHAT THE TERMS SAY: Section 25 of the Consumer Online Banking Agreement states: 'YOU AND WE KNOWINGLY, VOLUNTARILY AND INTENTIONALLY WAIVE OUR RESPECTIVE RIGHTS TO A TRIAL BY JURY IN ANY PROCEEDING, WHETHER SOUNDING IN CONTRACT, TORT, OR OTHERWISE, ARISING OUT OF OR RELATING TO THIS ONLINE BANKING AGREEMENT.'\nWHY IT MATTERS: Online banking customers give up their right to a jury trial for any dispute related to the agreement.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=Y; optout=?; datasale=N; affiliates=Y; biometric=Y; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=Y; breach=?; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The bank itself has ceased to exist as an independent entity and its terms/privacy pages have been replaced by the successor's, with the key arbitration section left unread due to a truncated PDF fetch.", "Exposure Score (0-100)": 48, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 3, "Sub: Data Practices /30": 14, "Sub: Contract Asymmetry /20": 17, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 3/30 (jury_trial_waiver+3) | Data 14/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, precise_location_tracking+4) | Contract 17/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4, auto_renewal_or_fee_trap+3) | Record 14/20 (severity4+14) | flags stated 10/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Sandy Spring Bank  <-  Atlantic Union Bank (\"a Virginia banking corporation\") — Sandy Spring Bank merged into Atlantic Union Bank effective April 1, 2025, with full systems conversion completed October 13, 2025; sandyspring", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to a jury.\n  5. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  8. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (4 of 13): your content used as AI training data; a broad licence to your own content; your right to sue; your right to join a class action. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Sandy Spring Bank you gave up your biometric identifiers, your physical movements, your data shared corporate-wide, your right to a jury, your right to keep what you paid for, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 4 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 63.3, "URL Last Validated": "2026-09-08T19:22:03Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Sandy Spring Bank no longer exists as an independent legal entity or terms-publisher: its website now hard-redirects to Atlantic Union Bank, meaning former Sandy Spring customers are now bound by a different bank's Consumer Deposit Account Agreement (effective Aug 11, 2025) and Online Banking Agreement, including a jury-trial waiver (\"YOU AND WE KNOWINGLY, VOLUNTARILY AND INTENTIONALLY WAIVE... RIGHTS TO A TRIAL BY JURY\"), without the customer having separately agreed to the successor's terms as \"Sandy Spring Bank.\" Separately, the successor entity paid a $6.2M CFPB penalty in 2023 for deceptive overdraft-fee practices.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 21, "_entity_id": 39, "_entity_slug": "sandy-spring-bank", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "EagleBank", "Category": "Regional bank", "Terms & Conditions URL": "https://www.eaglebankcorp.com/media/filer_public/f0/d9/f0d92066-f773-4035-bf2e-99fba156413c/terms_and__conditions_agreement_with_bill_pay_08_22.pdf", "T&C Direct PDF?": "PDF", "Privacy Policy URL": "https://www.eaglebankcorp.com/media/filer_public/7d/51/7d5114c9-0c7e-4797-adfb-db2d76756461/eaglebank_privacy_policy_rev_06-24_v2.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "GLBA chart (Rev. 06/2024): affiliates' everyday business purposes (creditworthiness info) = Yes share/Yes can limit; affiliates to market to you = Yes/Yes can limit; joint marketing with other financial companies = Yes/No cannot limit; nonaffiliates to market to you = \"NO\" / \"We don't share.\" Everyday-business and marketing-purpose rows are also disclosed as \"NO\" limitation options. The customer-privacy security page separately states: \"We restrict employee access to nonpublic customer information to only those employees who have a business reason to know such information.\" No mention of data sale, brokers, or Global Privacy Control.", "Arbitration / Class Action Waiver": "No arbitration clause found in the Online Service Agreement and Electronic Fund Transfer/Bill Pay terms fetched. No class-action waiver or jury-trial waiver language was found either.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Unilateral modification: \"We will mail or deliver a written notice to you at least 30 days before the effective date of any change in a term or condition disclosed in this Agreement\" (Section U), or by branch posting / other legal means. Liability cap: \"EagleBank will not be liable for any special, consequential, incidental, or punitive losses, damages, or expenses in connection with this Agreement or the Service, even if EagleBank has knowledge of the possibility of them.\" No explicit indemnity clause was found. Termination: EagleBank may terminate Online Banking privileges \"without notice\" for nonpayment of fees or non-compliance (Section T); customer may terminate by written notice. Fees: Bill Pay service listed at \"$0.00 per month, for an unlimited number of monthly payments\"; no auto-renewal language found.", "Notes": "LEGAL ENTITY: Eagle Bancorp, Inc. (NMLS #440513), d/b/a EagleBank — confirmed as the Washington, DC/Maryland/Virginia bank (eaglebankcorp.com), distinct from unrelated \"Eagle Bank & Trust\" (Louisiana, eaglebank.com), \"First Eagle Bank\" (Illinois), and \"Eagle Bank\" (Montana, bankeagle.com)\nTERMS EFFECTIVE: Not stated in document text (filename suggests August 2022 — \"08_22\") | PRIVACY EFFECTIVE: \"Revised 06/2024\"\nENFORCEMENT / BREACH (one search, 2026-08-29): Two items found in one search: (1) EagleBank reported a data breach discovered around November 2022 compromising \"names, financial account numbers, Social Security numbers and driver's license numbers,\" with approximately 476 affected Massachusetts residents per a filing with that state's Attorney General (source: https://topclassactions.com/lawsuit-settlements/privacy/data-breach/eagle-bank-data-breach-compromises-social-security-numbers-financial-account-numbers-more/); (2) per DOJ/Banking Dive search results, \"EagleBank Agrees to Pay More than $9.7 Million to Resolve Bank Secrecy Act Investigation\" (source: https://www.justice.gov/opa/pr/eaglebank-agrees-pay-more-97-million-resolve-bank-secrecy-act-investigation — headline/snippet only, page itself not fetched).\nPRIVACY CONTACT: Phone: 301-986-1800, or 800-364-8313 (\"select option #7\") for opt-out; Email: support@eaglebankcorp.com / ContactMe@EagleBankCorp.com; online opt-out via Secure Messaging portal. No mailing address found in pages fetched.\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: Confirmed correct EagleBank via \"Personal Online Mobile Banking in Washington, DC, Maryland and Virginia\" page — several unrelated banks share the \"Eagle Bank\" name nationally; a future researcher should double-check any cited breach/enforcement item is not conflated with those other entities. jdsupra.com article on the breach could not be fetched (robots.txt disallowed); topclassactions.com used instead.\nFETCH LOG (2026-08-29):\nhttps://www.eaglebankcorp.com/customer-privacy/ — 200 OK\nhttps://www.eaglebankcorp.com/media/filer_public/f0/d9/f0d92066-f773-4035-bf2e-99fba156413c/terms_and__conditions_agreement_with_bill_pay_08_22.pdf — 200 OK\nhttps://www.jdsupra.com/legalnews/eagle-bank-reports-that-recent-data-1912935/ — ROBOTS_DISALLOWED (fetch refused)\nhttps://topclassactions.com/lawsuit-settlements/privacy/data-breach/eagle-bank-data-breach-compromises-social-security-numbers-financial-account-numbers-more/ — 200 OK\nhttps://www.eaglebankcorp.com/media/filer_public/7d/51/7d5114c9-0c7e-4797-adfb-db2d76756461/eaglebank_privacy_policy_rev_06-24_v2.html — 200 OK", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Phone: 301-986-1800, or 800-364-8313 (\"select option #7\") for opt-out; Email: support@eaglebankcorp.com / ContactMe@EagleBankCorp.com; online opt-out via Secure Messaging portal. No mailing address found in pages fetched.", "Legal / Privacy Contact Email": "support@eaglebankcorp.com", "Finding Type": "Data breach + Regulatory action + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Pending - severity 4/5, no source yet", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Eagle Bancorp, Inc. (NMLS #440513), d/b/a EagleBank — confirmed as the Washington, DC/Maryland/Virginia bank (eaglebankcorp.com), distinct from unrelated \"Eagle Bank & Trust\" (Louisiana, eaglebank.com", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-26 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] EagleBank agreed to pay over $9.7 million to resolve a federal Bank Secrecy Act investigation\nWHAT THE TERMS SAY: Per DOJ/Banking Dive search results, 'EagleBank Agrees to Pay More than $9.7 Million to Resolve Bank Secrecy Act Investigation.'\nWHY IT MATTERS: The reported payment resolves a federal Bank Secrecy Act investigation at the institution holding customers' financial accounts; the tracker records this from a DOJ/Banking Dive headline/snippet, with the page itself not fetched.\n(evidence: Notes; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] EagleBank disclosed a 2022 breach compromising Social Security and driver's license numbers of hundreds of customers\nWHAT THE TERMS SAY: EagleBank reported a data breach discovered around November 2022 compromising 'names, financial account numbers, Social Security numbers and driver's license numbers,' with approximately 476 affected Massachusetts residents per a filing with that state's Attorney General.\nWHY IT MATTERS: Sensitive identity and financial data was exposed, and the bank's fetched Terms/Privacy documents state no retention period for such data.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data sharing is largely GLBA-standard with nonaffiliate marketing sharing disclosed as 'No,' leaving the breach and BSA penalty as the two distinct, substantive company-specific harms.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=N; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "GLBA chart and online agreement are specific and dated, but the BSA penalty was confirmed only via headline/snippet, not a fetched source page.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 14, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 14/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4) | Record 16/20 (severity4+14, litigation+2) | flags stated 13/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "EagleBank  <-  Eagle Bancorp, Inc. (NMLS #440513), d/b/a EagleBank — confirmed as the Washington, DC/Maryland/Virginia bank (eaglebankcorp.com), distinct from unrelated \"Eagle Bank & Trust\" (Louisiana, eaglebank.com", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action; your right to a jury; your right to stop paying by inaction.\n\nNOT YET DETERMINED (4 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using EagleBank you gave up your data shared corporate-wide, your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 4 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 73.3, "URL Last Validated": "2026-09-08T19:22:05Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "EagleBank disclosed a breach exposing Social Security numbers and driver's license numbers (~476 Massachusetts residents per state AG filing), and separately agreed to pay over $9.7 million to resolve a federal Bank Secrecy Act investigation — both concern the safety of sensitive customer financial data, yet the fetched Terms/Privacy documents state no retention period and no data-sale disclosure either way.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 22, "_entity_id": 41, "_entity_slug": "eaglebank", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Apple Federal Credit Union", "Category": "Credit union", "Terms & Conditions URL": "https://www.applefcu.org/Content/docs/disclosures/Online_and_Mobile_Service_Agreement.pdf", "T&C Direct PDF?": "PDF", "Privacy Policy URL": "https://www.applefcu.org/security-privacy/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "GLBA chart: everyday business purposes (transactions, account maintenance, court orders, credit reporting) = Yes share/No limit; marketing our products/services = Yes/No limit; joint marketing with other financial companies = Yes/Yes can limit; affiliates' everyday business (transactions/experiences) = Yes/Yes can limit; affiliates' creditworthiness = Yes/Yes can limit; affiliates' marketing to you = Yes/Yes can limit; nonaffiliates' marketing to you = \"No\" / \"We don't share.\" No explicit data-sale or data-broker language found; no Global Privacy Control mention.", "Arbitration / Class Action Waiver": "No arbitration clause, class-action waiver, jury-trial waiver, or opt-out procedure was found in the Online and Mobile Services Agreement fetched.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Unilateral modification: \"We may amend or change this Agreement from time to time. Your use of the Services after we have made such changes available will be considered your agreement to the change.\" Liability/indemnity: \"WE SHALL NOT BE RESPONSIBLE FOR ANY LOSS, DAMAGE OR INJURY OR FOR ANY DIRECT, INDIRECT, SPECIAL, INCIDENTAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES,\" and members must \"defend, indemnify and hold us harmless from and against any loss, damage, liability, cost or expense\" from their use of the service. Termination: \"Apple FCU reserves the right to terminate, limit or suspend access to any Online or Mobile Service made available to you without notice and for any reason, unless prohibited by applicable law.\" Fees: online/mobile access is \"currently provided to you at no additional cost,\" though other products/services may incur fees; no auto-renewal clause found.", "Notes": "LEGAL ENTITY: Apple Federal Credit Union\nTERMS EFFECTIVE: \"202405\" (document date code, i.e. May 2024) | PRIVACY EFFECTIVE: Not stated in content retrieved\nENFORCEMENT / BREACH (one search, 2026-08-29): Apple Federal Credit Union settled a class action lawsuit over allegedly improper debit-payment overdraft charges; cutimes.com reports a $2.5 million settlement approved March 14, 2025 (\"current and former members\" to receive refunds), while a separate search result (Hedin LLP) headlines a \"$2.7 Million Settlement\" in a related/same case — the discrepancy was not resolved as neither figure was independently re-verified beyond the search snippets. Source: https://www.cutimes.com/2025/03/14/apple-federal-credit-union-settles-od-class-action-lawsuit-for-25-million/\nPRIVACY CONTACT: Phone: 703-788-4800; Mailing address: \"P.O. Box 1200, Fairfax, Virginia 22038-1200.\"\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: Two different settlement dollar figures ($2.5M vs $2.7M) appeared across search results for what may be the same overdraft-fee litigation; not reconciled this session — flag for a future researcher to fetch both source articles directly.\nFETCH LOG (2026-08-29):\nhttps://www.applefcu.org/Content/docs/disclosures/Online_and_Mobile_Service_Agreement.pdf — 200 OK\nhttps://www.applefcu.org/security-privacy/privacy-policy — 200 OK\nhttps://www.cutimes.com/2025/03/14/apple-federal-credit-union-settles-od-class-action-lawsuit-for-25-million/ — 200 OK", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Phone: 703-788-4800; Mailing address: \"P.O. Box 1200, Fairfax, Virginia 22038-1200.\"", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Pending - severity 4/5, no source yet", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Apple Federal Credit Union", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-26 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-1] Apple FCU settled a class action over allegedly improper overdraft charges for $2.5M (one source: $2.7M)\nWHAT THE TERMS SAY: Apple Federal Credit Union settled a class action lawsuit over allegedly improper debit-payment overdraft charges; cutimes.com reports a $2.5 million settlement approved March 14, 2025, while a separate search result headlines a '$2.7 Million Settlement' in a related/same case -- the discrepancy was not independently resolved.\nWHY IT MATTERS: Members were allegedly overcharged on overdraft fees, and the credit union paid millions to resolve the resulting litigation.\n(evidence: Notes; Tracker says unconfirmed (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[LIABILITY_CAP_INDEMNITY · FL-1] Apple FCU can cut off online/mobile access at will while disclaiming nearly all liability and requiring member indemnification\nWHAT THE TERMS SAY: 'Apple FCU reserves the right to terminate, limit or suspend access to any Online or Mobile Service made available to you without notice and for any reason, unless prohibited by applicable law,' while disclaiming 'ANY DIRECT, INDIRECT, SPECIAL, INCIDENTAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES' and requiring members to 'defend, indemnify and hold us harmless.'\nWHY IT MATTERS: Members bear most of the legal and financial risk of using online banking, with the credit union able to end access at any time.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — GLBA data-sharing practices are standard with nonaffiliate marketing sharing disclosed as 'No,' and no arbitration or breach item was found, leaving the overdraft-settlement and liability/termination items as the two distinct harms.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=N; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "GLBA chart and service agreement are specific, but the settlement dollar figure is unresolved between two conflicting source snippets.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 14, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 14/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4) | Record 16/20 (severity4+14, litigation+2) | flags stated 12/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Apple Federal Credit Union  <-  Apple Federal Credit Union", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action; your right to a jury; your right to stop paying by inaction.\n\nNOT YET DETERMINED (4 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Apple Federal Credit Union you gave up your data shared corporate-wide, your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 4 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 70.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Apple FCU can \"terminate, limit or suspend access to any Online or Mobile Service made available to you without notice and for any reason, unless prohibited by applicable law\" while simultaneously disclaiming almost all liability and requiring the member to indemnify the credit union — combined with the reported $2.5M (or $2.7M, per a second source) overdraft-fee class action settlement concluded in March 2025.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 23, "_entity_id": 42, "_entity_slug": "apple-federal-credit-union", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "SECU Maryland (State Employees Credit Union of Maryland)", "Category": "Credit union", "Terms & Conditions URL": "https://docs.secumd.org/account-opening/AandDBooklet.pdf", "T&C Direct PDF?": "PDF", "Privacy Policy URL": "https://www.secumd.org/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The fetched secumd.org/privacy-policy page (an online-privacy policy, dated Feb 28, 2025) does not contain the standard GLBA \"what we do with your information\" Yes/No chart; it references a separate Privacy Notice for that detail, which was not located/fetched this session. It states: \"We may share information with service providers with whom we work, such as data processors and companies that help us market products and services to you.\" It mentions \"biometric/behavioral data\" as a category of information collected from user activity, and geolocation via Google Maps integration that users can disable, adding \"Location data is not stored by SECU.\" No mention of data sale, brokers by name, or Global Privacy Control.", "Arbitration / Class Action Waiver": "Mandatory, with an opt-out: \"ANY ARBITRATION OF A CLAIM WILL BE ON AN INDIVIDUAL BASIS. FURTHER, YOU UNDERSTAND AND AGREE THAT YOU ARE WAIVING THE RIGHT TO PARTICIPATE AS A CLASS REPRESENTATIVE OR CLASS MEMBER IN A CLASS ACTION LAWSUIT.\" Jury waiver: \"your rights will be determined by a neutral arbitrator and NOT a judge or jury.\" Opt-out requires written notification within 60 days, mailed to \"SECU, PO Box 23896, Attn: Operations, Glen Burnie, MD 21298.\"", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Unilateral modification: \"Except as prohibited by applicable law, we may amend this Agreement by adding, removing, or changing terms at any time. We will notify you, in a manner we deem appropriate under the circumstances, of any changes.\" Liability cap: for improperly completed transactions, SECU's liability is capped at \"the amount of the transaction, except as otherwise provided by law\"; members must \"indemnify and hold the SECU harmless from all costs, including attorney's fees and all damages or claims.\" Termination: SECU \"may terminate your account at any time without notice to you\" for reasons including fraud, excessive returned items, misrepresentation, or loss prevention. Fees: \"We may change the rate sheet or Fee Schedule at any time and will notify you as required by law\"; no distinct auto-renewal clause found.", "Notes": "LEGAL ENTITY: \"State Employees Credit Union of Maryland, Incorporated\" (abbreviated \"SECU\")\nTERMS EFFECTIVE: Not explicitly stated in the excerpt retrieved; the arbitration agreement itself states it becomes effective \"upon the 61st day after we provide this Arbitration Agreement to you\" | PRIVACY EFFECTIVE: \"February 28, 2025\" (Last Updated)\nENFORCEMENT / BREACH (one search, 2026-08-29): Per breachsense.com, SECU Maryland (\"Maryland's Largest Credit Union\") suffered a breach discovered October 17, 2023, claimed by the ALPHV ransomware group; exact number of records affected is listed as \"Unknown,\" though the source separately notes 5 @secumd.org accounts and 397 additional secumd.org-linked credentials found in unrelated breach/infostealer data as of an August 2026 check (not necessarily connected to the ransomware incident). Source: https://www.breachsense.com/breaches/secu-credit-union-data-breach/\nPRIVACY CONTACT: Mailing: \"SECU, PO Box 13025, Baltimore, MD 21203\"; Phone: 410-487-7328 or 800-879-7328. No email address listed.\nRETENTION: As stated: \"We keep your Personal Information for as long as needed or permitted in light of the purpose(s) for which it was obtained,\" tied to ongoing relationship status, legal obligations, or litigation/regulatory considerations — no fixed duration given | GPC honored: Not stated\nRESEARCHER NOTES: The secumd.org/privacy-policy page fetched is an online/website privacy policy, not the full GLBA-format Privacy Notice with the standard Yes/No/can-you-limit chart — that document is referenced but was not located this session; a future researcher should search for SECU's standalone \"Privacy Notice\" (often a short PDF distinct from the website policy) to complete the data_flags for sale/affiliate sharing.\nFETCH LOG (2026-08-29):\nhttps://www.breachsense.com/breaches/secu-credit-union-data-breach/ — 200 OK\nhttps://www.secumd.org/privacy-policy/ — 200 OK\nhttps://docs.secumd.org/account-opening/AandDBooklet.pdf — 200 OK", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Mailing: \"SECU, PO Box 13025, Baltimore, MD 21203\"; Phone: 410-487-7328 or 800-879-7328. No email address listed.", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "60", "Corporate Legal Notice Address (public cos.)": "SECU, PO Box 23896, Attn: Operations, Glen Burnie, MD 21298", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "\"State Employees Credit Union of Maryland, Incorporated\" (abbreviated \"SECU\")", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-24 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] SECU imposes mandatory individual arbitration with class-action and jury waivers by default, requiring a mailed opt-out within 60 days\nWHAT THE TERMS SAY: 'ANY ARBITRATION OF A CLAIM WILL BE ON AN INDIVIDUAL BASIS... YOU ARE WAIVING THE RIGHT TO PARTICIPATE AS A CLASS REPRESENTATIVE OR CLASS MEMBER IN A CLASS ACTION LAWSUIT,' and 'your rights will be determined by a neutral arbitrator and NOT a judge or jury.' Opt-out requires written notification mailed within 60 days to a Glen Burnie, MD PO box.\nWHY IT MATTERS: Most members will never act on the 60-day mailed opt-out window, making individual arbitration -- with no class action or jury trial -- the default for Maryland's largest credit union.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] SECU suffered an October 2023 ransomware breach claimed by the ALPHV group, with scope listed as unknown\nWHAT THE TERMS SAY: SECU Maryland suffered a breach discovered October 17, 2023, claimed by the ALPHV ransomware group; the exact number of records affected is listed as 'Unknown.'\nWHY IT MATTERS: Members have no confirmed scope of what personal data was exposed in a ransomware incident at their credit union.\n(evidence: Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[BIOMETRICS · FL-2] SECU's online privacy policy lists biometric/behavioral data among information collected from user activity\nWHAT THE TERMS SAY: The privacy policy mentions 'biometric/behavioral data' as a category of information collected from user activity, without further detail on how it's used, shared, or retained.\nWHY IT MATTERS: Members' biometric or behavioral data is collected with no further disclosure on its handling.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and breach details are specific, but SECU's standard GLBA-format Privacy Notice (with the yes/no sharing chart) was not located this session.", "Exposure Score (0-100)": 64, "Exposure Band": "High", "Sub: Dispute Rights /30": 25, "Sub: Data Practices /30": 14, "Sub: Contract Asymmetry /20": 14, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 25/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_60d+1) | Data 14/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, precise_location_tracking+4) | Contract 14/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4) | Record 11/20 (severity3+8, breach+3) | flags stated 11/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "SECU Maryland (State Employees Credit Union of Maryland)  <-  \"State Employees Credit Union of Maryland, Incorporated\" (abbreviated \"SECU\")", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n  6. Your right to a jury.\n  7. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  8. Your right to be made whole. Their liability is capped, often at what you paid.\n  9. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (4 of 13): your personal data sold onward; your content used as AI training data; a broad licence to your own content; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using SECU Maryland (State Employees Credit Union of Maryland) you gave up your biometric identifiers, your physical movements, your data shared corporate-wide, your right to sue, your right to join a class action, your right to a jury, your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 4 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 66.7, "URL Last Validated": "2026-09-08T19:22:09Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "SECU imposes mandatory, individual-only arbitration with an explicit class-action and jury-trial waiver on all members by default (\"YOU ARE WAIVING THE RIGHT TO PARTICIPATE AS A CLASS REPRESENTATIVE OR CLASS MEMBER IN A CLASS ACTION LAWSUIT\"), requiring an affirmative, mailed, written opt-out within 60 days to preserve court rights — for Maryland's largest credit union, this is a default that most members will never act on. This sits alongside an October 2023 ransomware-group breach claim of undisclosed scope.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 24, "_entity_id": 44, "_entity_slug": "secu-maryland-state-employees-credit-union-of-maryland", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Andrews Federal Credit Union", "Category": "Credit union", "Terms & Conditions URL": "https://www.andrewsfcu.org/getContentAsset/7d8db63f-031d-44ac-a8de-1900c5d3d7bd/73aabf56-e6e5-4330-95a3-5f2a270a1d2b/Terms-and-Conditions.pdf?language=en", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://www.andrewsfcu.org/Privacy-Center/United-States-Privacy-Notice", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "GLBA chart on the US Privacy Notice: everyday business purposes = Yes share/No limit; marketing purposes = Yes/No limit; joint marketing = Yes/No limit; affiliates' everyday business = \"No\" share; affiliates' creditworthiness = \"No\" share; affiliates' marketing = \"No\" share; nonaffiliates' marketing = \"Yes\" share/\"Yes\" can limit. No data-broker language or Global Privacy Control mention found. Mobile app geolocation: \"we may collect and process information about your actual location,\" disableable via device settings.", "Arbitration / Class Action Waiver": "Mandatory: the terms state disputes go to individual arbitration with \"NO CLASS ACTION, CLASSWIDE ARBITRATION, PRIVATE ATTORNEY GENERAL ACTION\" permitted. Jury waiver: \"ARBITRATION REPLACES THE RIGHT TO GO TO COURT, INCLUDING THE RIGHT TO A JURY TRIAL.\" Opt-out window is 30 days from account opening or from the mailing of notice, whichever is sooner, by written notice to \"Andrews Federal Credit Union ATTN: Legal Department, P.O. Box 4000, Clinton, MD 20735-8000.\"", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Unilateral modification: \"From time to time...we will update our policies and disclosures. We will provide prior notice of changes to you as required by law; otherwise all updated documents...are posted to the Terms and Conditions section of our website.\" Liability caps: wire-transfer liability limited to \"direct loss, and not to any consequential or special loss or damages\"; substitute-check refunds limited to \"the amount of your loss or the amount of the substitute check, whichever is less.\" Members indemnify the credit union for unauthorized forms, damaged deposits, and dispute-related legal costs. Termination: either party \"may close your account at any time.\" Fees: an inactivity fee applies after 12 months without activity, dormant status after 18 months, and multiple NSF fees are permitted for resubmitted items.", "Notes": "LEGAL ENTITY: Andrews Federal Credit Union\nTERMS EFFECTIVE: Not explicitly stated in the excerpt retrieved | PRIVACY EFFECTIVE: \"Updated 07/2026; Reviewed 07/2026\"\nENFORCEMENT / BREACH (one search, 2026-08-29): No enforcement/breach item found in one search (2026-08-29) — search results returned data-breach settlements for other, unrelated credit unions (AOD Federal Credit Union, First Commonwealth Federal Credit Union, USAA, CFCU) but nothing specific to Andrews Federal Credit Union.\nPRIVACY CONTACT: Phone: 1-800-487-5500 (US) or 00.800.487.56267 (outside US); Web opt-out: www.andrewsfcu.org/optout; Mailing address: \"5711 Allentown Road, Suitland, MD 20746.\" No email listed.\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: Andrews FCU also publishes a separate \"European Union Privacy Notice\" (GDPR-oriented), consistent with its historical base of serving members near U.S. military installations in Europe; that document was not fetched this session and may contain additional relevant disclosures (e.g. different retention/AI language) for members covered by it.\nFETCH LOG (2026-08-29):\nhttps://www.andrewsfcu.org/getContentAsset/7d8db63f-031d-44ac-a8de-1900c5d3d7bd/73aabf56-e6e5-4330-95a3-5f2a270a1d2b/Terms-and-Conditions.pdf?language=en — 200 OK\nhttps://www.andrewsfcu.org/Privacy-Center/United-States-Privacy-Notice — 200 OK", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Phone: 1-800-487-5500 (US) or 00.800.487.56267 (outside US); Web opt-out: www.andrewsfcu.org/optout; Mailing address: \"5711 Allentown Road, Suitland, MD 20746.\" No email listed.", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "30", "Corporate Legal Notice Address (public cos.)": "Andrews Federal Credit Union ATTN: Legal Department, P.O. Box 4000, Clinton, MD 20735-8000", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Andrews Federal Credit Union", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-20 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Andrews FCU's mandatory arbitration forecloses class actions and even private attorney general actions, with just a 30-day opt-out\nWHAT THE TERMS SAY: Disputes go to individual arbitration with 'NO CLASS ACTION, CLASSWIDE ARBITRATION, PRIVATE ATTORNEY GENERAL ACTION' permitted, and 'ARBITRATION REPLACES THE RIGHT TO GO TO COURT, INCLUDING THE RIGHT TO A JURY TRIAL.' The opt-out window is 30 days from account opening or notice mailing, whichever is sooner, via written notice to a Clinton, MD PO box.\nWHY IT MATTERS: Members who don't act within 30 days lose access to class actions, private attorney general actions, and jury trials for any dispute with the credit union.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SALE · FL-2] Andrews FCU's own GLBA chart discloses it shares personal information with nonaffiliated third parties for marketing\nWHAT THE TERMS SAY: The GLBA chart shows 'For nonaffiliates to market to you' = 'Yes' share / 'Yes' can limit -- meaning members must affirmatively opt out to stop this sharing.\nWHY IT MATTERS: By default, members' information is shared with outside companies for marketing purposes unless they take action to opt out.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No breach or enforcement item was found for this entity, and liability/termination/fee language is largely standard credit-union boilerplate, leaving the arbitration and nonaffiliate-marketing-sharing items as the two distinct, substantive harms.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=Y; affiliates=N; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=Y; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Both governing documents were fetched successfully and contain specific, complete GLBA and arbitration-opt-out language.", "Exposure Score (0-100)": 58, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 17, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_30d+3) | Data 12/30 (data_sold_or_shared_for_value+8, precise_location_tracking+4) | Contract 17/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4, auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 12/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Andrews Federal Credit Union  <-  Andrews Federal Credit Union", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to a jury.\n  6. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  7. Your right to be made whole. Their liability is capped, often at what you paid.\n  8. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  9. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your data shared corporate-wide.\n\nNOT YET DETERMINED (3 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Andrews Federal Credit Union you gave up your personal data sold onward, your physical movements, your right to sue, your right to join a class action, your right to a jury, your right to keep what you paid for, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 3 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 70.0, "URL Last Validated": "2026-09-08T19:22:21Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Andrews FCU's own GLBA chart discloses it DOES share personal information with nonaffiliated third parties for marketing (\"For nonaffiliates to market to you\" = Yes), which members can only stop by opting out — combined with mandatory arbitration that forecloses class actions and even \"PRIVATE ATTORNEY GENERAL ACTION,\" with only a 30-day window (mailed written notice to a PO box) to preserve court/class rights.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 25, "_entity_id": 45, "_entity_slug": "andrews-federal-credit-union", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "PowerSchool", "Category": "Student Information System (SIS)", "Terms & Conditions URL": "https://support.powerschool.com/tos.action", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://support.powerschool.com/psu/privacy.action", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The PowerSchool University Privacy Policy states: \"Information collected through this site may be supplied to affiliates of PowerSchool.com, and other companies and organizations who perform work for us under contract or sell products or services that complement our products and services.\" It also permits disclosure \"in connection with a sale, joint venture or other transfer to some or all of the assets of PowerSchool Group LLC.\" No mention of Global Privacy Control, no CCPA-style 'we do/do not sell' statement, and no mention of data brokers by name.", "Arbitration / Class Action Waiver": "No arbitration clause found in the terms fetched. The PowerSource Terms of Use contain no mandatory-arbitration provision, class-action waiver, jury-trial waiver, or opt-out procedure of any kind.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): PowerSource ToS: unilateral modification — \"PowerSchool may, at its sole discretion, update, modify, change, add or remove the Terms\" with or without notice. Liability cap — \"IN NO EVENT SHALL POWERSCHOOL BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL OR CONSEQUENTIAL DAMAGES.\" Indemnity — users must \"indemnify and hold harmless PowerSchool from and against any and all claims, charges, demands, damages\" from breach of the terms. Termination — PowerSchool may \"change[d], terminate[d], suspend[d] or discontin[ued]\" portal access without notice. No auto-renewal or fee language appears (this is a free support portal, not a paid subscription).", "Notes": "LEGAL ENTITY: PowerSchool Group LLC (PowerSource ToS); \"PowerSchool Group LLC and/or its affiliate(s)\" (PowerSchool University Privacy Policy)\nTERMS EFFECTIVE: Last updated August 1, 2015 | PRIVACY EFFECTIVE: Not stated\nENFORCEMENT / BREACH (one search, 2026-08-29): In December 2024, PowerSchool Holdings Inc. suffered a breach compromising data of roughly 60 million students, families, and school personnel (names, contact info, DOB, SSNs, medical records), and Texas Attorney General Ken Paxton sued PowerSchool over the breach's impact on more than 880,000 Texas school-aged children and teachers; a related $17.25M class-action settlement was also reported over alleged interception of confidential student communications. Sources: https://www.hbsslaw.com/cases/powerschool-data-breach ; https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-sues-big-tech-company-catastrophic-data-breach-compromised-personal ; https://www.classaction.org/news/17.25m-powerschool-settlement-resolves-class-action-over-alleged-interception-of-confidential-student-communications\nPRIVACY CONTACT: Not stated as a dedicated privacy email/address in the fetched Privacy Policy. The fetched Terms of Use lists a general company address: 150 Parkshore Dr, Folsom, CA 95630. No privacy-specific email was found in either document.\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: The flagship consumer/parent-facing Terms at www.powerschool.com/terms/ and the current company Privacy Statement (www.powerschool.com/legal/privacy-2023/ and any successor page) are behind Incapsula bot-protection and could NOT be fetched this session — every attempt returned only a security-challenge resource string, not page content. What was fetched instead were the closest same-family legal documents the fetch tool could reach: (1) support.powerschool.com/tos.action, the 'PowerSource' support-portal Terms of Use (dated 2015), and (2) support.powerschool.com/psu/privacy.action, the 'PowerSchool University' training-portal Privacy Policy. Neither is confirmed to be the operative document for the parent/student PowerSchool SIS/portal that most consumers interact with. A future researcher with a fetch path not blocked by Incapsula should re-pull www.powerschool.com/terms/ and the current (non-archived) privacy statement for authoritative text. The December 2024 nationwide SIS breach and the Texas AG suit are well documented in news/legal sources but are NOT described in the two documents actually fetched here.\nFETCH LOG (2026-08-29):\nhttps://www.powerschool.com/terms/ — FAILED (Incapsula bot-protection challenge, no content, attempted twice)\nhttps://www.powerschool.com/legal/privacy-2023/ — FAILED (Incapsula bot-protection challenge, no content)\nhttps://support.powerschool.com/tos.action — 200 OK\nhttps://support.powerschool.com/psu/privacy.action — 200 OK\nhttps://www.hbsslaw.com/cases/powerschool-data-breach — 200 OK (breach/enforcement search)\nhttps://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-sues-big-tech-company-catastrophic-data-breach-compromised-personal — found via WebSearch, not separately fetched\nhttps://www.classaction.org/news/17.25m-powerschool-settlement-resolves-class-action-over-alleged-interception-of-confidential-student-communications — found via WebSearch, not separately fetched", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Not stated as a dedicated privacy email/address in the fetched Privacy Policy. The fetched Terms of Use lists a general company address: 150 Parkshore Dr, Folsom, CA 95630. No privacy-specific email was found in either document.", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Data breach + Regulatory action + Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Pending - severity 4/5, no source yet", "Region Basis": "v58 tranche: national vendor serving Mid-Atlantic users (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "PowerSchool Group LLC (PowerSource ToS); \"PowerSchool Group LLC and/or its affiliate(s)\" (PowerSchool University Privacy Policy)", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-25 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] PowerSchool's December 2024 breach compromised data of roughly 60 million students, families, and staff\nWHAT THE TERMS SAY: In December 2024, PowerSchool Holdings Inc. suffered a breach compromising data of roughly 60 million students, families, and school personnel (names, contact info, DOB, SSNs, medical records).\nWHY IT MATTERS: Names, contact information, dates of birth, Social Security numbers, and medical records of roughly 60 million students, families, and school personnel were compromised.\n(evidence: Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[PENDING_LITIGATION · FL-2] Texas Attorney General sued PowerSchool over the breach's impact on more than 880,000 Texas schoolchildren and teachers\nWHAT THE TERMS SAY: Texas Attorney General Ken Paxton sued PowerSchool over the breach's impact on more than 880,000 Texas school-aged children and teachers.\nWHY IT MATTERS: A state attorney general pursued legal action specifically over the scale of harm to children's data in that state.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] PowerSchool's privacy policy lets user information go to affiliates and transfer in a company sale\nWHAT THE TERMS SAY: The Privacy Policy states information 'may be supplied to affiliates... and other companies and organizations who perform work for us under contract or sell products or services that complement our products and services,' and permits disclosure 'in connection with a sale, joint venture or other transfer' of PowerSchool Group LLC's assets.\nWHY IT MATTERS: Information collected through the site can move to affiliated companies, contractors, or a buyer of PowerSchool Group LLC's assets, with no stated retention period, no Global Privacy Control commitment, and no dedicated privacy-request contact.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=N; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The consumer-facing PowerSchool.com Terms/Privacy pages were blocked by bot protection; only closely-related PowerSource support-portal documents (dated 2015) could be fetched, and they don't describe the 2024 breach at all.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 14, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 14/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4) | Record 20/20 (severity5+20, litigation+2) | flags stated 12/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "PowerSchool  <-  PowerSchool Group LLC (PowerSource ToS); \"PowerSchool Group LLC and/or its affiliate(s)\" (PowerSchool University Privacy Policy)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action; your right to a jury; your right to stop paying by inaction.\n\nNOT YET DETERMINED (5 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using PowerSchool you gave up your data shared corporate-wide, your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 5 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 70.0, "URL Last Validated": "2026-09-08T19:22:23Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "PowerSchool's privacy policy allows user information to be \"supplied to affiliates... and other companies and organizations who perform work for us under contract or sell products or services that complement our products and services,\" and to be transferred \"in connection with a sale, joint venture or other transfer\" of company assets — with no stated retention period, no Global Privacy Control commitment, and no dedicated privacy-request contact — despite PowerSchool being the subject of a 2024 breach affecting roughly 60 million students/families/staff and a Texas AG lawsuit covering over 880,000 children.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 26, "_entity_id": 47, "_entity_slug": "powerschool", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "ParentVUE / StudentVUE (Edupoint Synergy)", "Category": "Mid-Atlantic service", "Terms & Conditions URL": "Not retrieved — not found", "T&C Direct PDF?": "Not retrieved", "Privacy Policy URL": "https://md-hcpss-psv.edupoint.com/PXP2_Privacy.aspx", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The fetched HCPSS ParentVUE privacy page contains no explicit language about selling data, sharing with brokers, or honoring Global Privacy Control in the portion retrieved. It states only that \"the data accessible through Synergy is specific to your individual account credentials (username and password) and intended for your use only,\" i.e. it describes account-level access control rather than third-party data-sharing practices.", "Arbitration / Class Action Waiver": "Not retrieved — no separate Terms of Use / EULA page distinct from the Privacy page could be located for the HCPSS ParentVUE instance; a second attempt to fetch the account-activation/consent page (https://md-hcpss-psv.edupoint.com/PXP2_Activate_Account_Privacy_Parent.aspx) timed out twice and was not read.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Not retrieved — no Terms of Use / EULA text was found or fetched for this district instance in this session; the only document read was a short privacy notice focused on account-credential confidentiality.", "Notes": "LEGAL ENTITY: Edupoint, LLC (vendor); the applicable data controller is the individual school district instance — the page fetched this session was the Howard County Public School System (HCPSS), Maryland instance\nTERMS EFFECTIVE: Not stated | PRIVACY EFFECTIVE: Not stated — footer shows \"2026 Edupoint, LLC\" copyright line only, which is a copyright year, not a document effective/last-updated date\nENFORCEMENT / BREACH (one search, 2026-08-29): No enforcement/breach item found in one search (2026-08-29) — the top result for this query was a $5.1 million multistate-AG settlement over a December 2021 student-data breach, but on verification via oag.ca.gov the settling company was confirmed to be Illuminate Education, Inc., an unrelated ed-tech vendor, not Edupoint/ParentVUE/StudentVUE.\nPRIVACY CONTACT: Not stated in the fetched text — a \"Contact\" link (https://md-hcpss-psv.edupoint.com/PXP2_Contact.aspx) is present in the interface, but no direct email address or mailing address was printed on the privacy page itself.\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: Edupoint Synergy (ParentVUE/StudentVUE) is deployed per-school-district on district-specific subdomains (e.g. md-hcpss-psv.edupoint.com, or-cen-psv.edupoint.com, az-cfsd16.edupoint.com), so there is no single central consumer-facing Terms/Privacy URL for the product as a whole — each district's instance may host its own or a district-customized version, and terms/policies could differ by district. This entry used the Howard County, MD (HCPSS) instance as a representative sample since the input list did not specify a district. The activation/consent page that likely contains fuller license/consent language repeatedly timed out on fetch and was never actually read — do NOT treat any statement here about its content as retrieved; it is correctly marked 'Not retrieved.' A future researcher should retry that page or pick a specific target district and check for a distinct Terms of Use / EULA document, which was not located in this session.\nFETCH LOG (2026-08-29):\nhttps://md-hcpss-psv.edupoint.com/PXP2_Privacy.aspx — 200 OK\nhttps://md-hcpss-psv.edupoint.com/PXP2_Activate_Account_Privacy_Parent.aspx — FAILED (read timeout, attempted twice, no content read)", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Not stated in the fetched text — a \"Contact\" link (https://md-hcpss-psv.edupoint.com/PXP2_Contact.aspx) is present in the interface, but no direct email address or mailing address was printed on the privacy page itself.", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Fetched - awaiting document verification", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Edupoint, LLC (vendor); the applicable data controller is the individual school district instance — the page fetched this session was the Howard County Public School System (HCPSS), Maryland instance", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-20 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] No Terms of Use or substantive privacy disclosure found for the district instance checked\nWHAT THE TERMS SAY: No retention period, no data-sale/sharing/broker disclosure, no AI or automated-processing language, and no discoverable Terms of Use/EULA at all were found for the district instance checked; the only document surfaced was a two-line privacy statement about account-credential confidentiality.\nWHY IT MATTERS: This is a thin disclosure footprint for a product handling K-12 student academic and, via linked modules, attendance/grade/discipline data.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No Terms of Use/EULA document could be fetched (the likely consent page timed out twice), so arbitration and fees fields are both 'not retrieved,' leaving only the missing-disclosure finding itself.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Only a two-line account-credential privacy statement was located; no Terms of Use/EULA exists for the district instance checked, and the likely consent page timed out on fetch.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "ParentVUE / StudentVUE (Edupoint Synergy)  <-  Edupoint, LLC (vendor); the applicable data controller is the individual school district instance — the page fetched this session was the Howard County Public School System (HCPSS), Maryland instance", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, ParentVUE / StudentVUE (Edupoint Synergy) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "2026-09-08T19:22:25Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "What is notably ABSENT: no retention period, no data-sale/sharing/broker disclosure, no AI or automated-processing language, and no discoverable Terms of Use/EULA at all for the district instance checked — the only document surfaced was a two-line privacy statement about account-credential confidentiality, which is a thin disclosure footprint for a product handling K-12 student academic and (via linked modules) attendance/grade/discipline data.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 27, "_entity_id": 49, "_entity_slug": "parentvue-studentvue-edupoint-synergy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "WTOP", "Category": "All-news local radio app", "Terms & Conditions URL": "https://hubbardconnects.com/terms-of-use/ (redirect target of corporate.hubbardradio.com/terms-of-use/)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://hubbardconnects.com/privacy-policy/ (redirect target of corporate.hubbardradio.com/hbi-radio-llc-privacy-policy/ and corporate.hubbardradio.com/terms-of-use/'s referenced privacy policy)", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The Hubbard Radio, LLC Privacy Policy states the company \"may provide personal information to vendors...advertising partners or other marketing partners\" and that \"Ad partners and advertising technology companies\" receive shared data for targeted advertising; \"Affiliates for purposes of business operations and support\" also receive identifiers, demographic data, and network-activity information. It explicitly states: \"We also honor the Global Privacy Control, a browser-based opt-out signal,\" with an opt-out portal at corporate.hubbardradio.com/data-request/ or via datarequests@hubbardradio.com / 877-646-8255. It also discloses collection of \"geolocation data (including your precise location)\" from mobile devices, and uses inference language: \"We may use data about your activity to understand and infer your preferences.\"", "Arbitration / Class Action Waiver": "No arbitration clause found in the terms fetched. The Hubbard Radio, LLC Terms of Use contain no mandatory-arbitration clause, class-action waiver, or jury-trial waiver; disputes are instead subject to \"Minnesota state and federal courts in Hennepin County\" per the jurisdiction clause.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Unilateral modification: \"Operator may change any of the Terms of Use at any time by posting revisions to the Site. Your continued use of the Site constitutes your acceptance of the revised Terms of Use.\" Liability cap: \"OPERATOR...BE LIABLE FOR ANY DAMAGES OF ANY KIND OR NATURE WHATSOEVER\" with broad exclusions. Indemnity: \"You agree to defend, indemnify, reimburse and hold harmless the Released Parties from all liabilities, claims and expenses.\" Termination: \"Operator reserves the right...to terminate your access to all or part of the Site at any time and for any or no reason.\" Also notable: text-message marketing consent language — \"you authorize Hubbard Radio to send you autodialed marketing text messages.\" No auto-renewal/subscription-fee language found (WTOP is ad-supported free content).", "Notes": "LEGAL ENTITY: Hubbard Radio, LLC (and subsidiaries, including a Washington, D.C. operating entity) — the Terms of Use and Privacy Policy actually fetched are Hubbard Radio's corporate/network-wide documents, not a WTOP-specific standalone document\nTERMS EFFECTIVE: September 2024 | PRIVACY EFFECTIVE: September 23, 2024\nENFORCEMENT / BREACH (one search, 2026-08-29): A consumer digital-privacy lawsuit alleges Hubbard Radio's WTOP shared subscribers' personal information with Facebook without proper consent in violation of the Video Privacy Protection Act; as of February 2023 Hubbard Radio had moved to dismiss on jurisdictional grounds. Source: https://capitolcommunicator.com/hubbard-radio-seeks-dismissal-of-lawsuit-against-wtop/\nPRIVACY CONTACT: Email: datarequests@hubbardradio.com. Phone: 877-646-8255. Mailing address: Hubbard Radio, LLC / Hubbard Broadcasting, 3415 University Avenue, St. Paul, MN 55141, Attn: Legal.\nRETENTION: Not stated | GPC honored: Yes\nRESEARCHER NOTES: wtop.com/terms-of-use/ and wtop.com/privacy-policy/ block automated fetching via robots.txt, so the exact WTOP.com-hosted page text could not be read directly this session. Instead, the parent company's (Hubbard Radio, LLC) corporate Terms of Use and Privacy Policy were fetched via corporate.hubbardradio.com, which 302-redirected to hubbardconnects.com — these documents list a Washington, D.C. subsidiary among Hubbard Radio's stations and are presumed to be the operative network-wide legal documents WTOP.com's own pages link to or mirror, but this is an inference, not a direct confirmation from a WTOP.com-hosted page. A separate, similarly-named entity, Hubbard Broadcasting Inc. (TV division, St. Paul MN, privacy policy effective April 25, 2024, at hubbardbroadcasting.com/privacy-policy/), was also found and fetched but determined to be a DIFFERENT, related-but-distinct corporate entity from Hubbard Radio, LLC and was NOT used as the primary source for this record — noted here to prevent confusion for a future researcher.\nFETCH LOG (2026-08-29):\nhttps://wtop.com/terms-of-use/ — FAILED (ROBOTS_DISALLOWED)\nhttps://wtop.com/privacy-policy/ — FAILED (ROBOTS_DISALLOWED)\nhttps://corporate.hubbardradio.com/terms-of-use/ — 302 redirect to https://hubbardconnects.com/terms-of-use/\nhttps://hubbardconnects.com/terms-of-use/ — 200 OK\nhttps://corporate.hubbardradio.com/hbi-radio-llc-privacy-policy/ — 302 redirect to https://hubbardconnects.com/ (generic, not privacy page)\nhttps://hubbardconnects.com/privacy-policy/ — 200 OK\nhttps://hubbardbroadcasting.com/privacy-policy/ — 200 OK (different corporate entity, Hubbard Broadcasting Inc.; consulted but not used as primary source — see notes)\nhttps://capitolcommunicator.com/hubbard-radio-seeks-dismissal-of-lawsuit-against-wtop/ — 200 OK (breach/enforcement search)", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Email: datarequests@hubbardradio.com. Phone: 877-646-8255. Mailing address: Hubbard Radio, LLC / Hubbard Broadcasting, 3415 University Avenue, St. Paul, MN 55141, Attn: Legal.", "Legal / Privacy Contact Email": "datarequests@hubbardradio.com.", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Hubbard Radio, LLC (and subsidiaries, including a Washington, D.C. operating entity) — the Terms of Use and Privacy Policy actually fetched are Hubbard Radio's corporate/network-wide documents, not a ", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-24 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-2] WTOP is defending a lawsuit alleging it shared subscriber data with Facebook in violation of the Video Privacy Protection Act\nWHAT THE TERMS SAY: A consumer digital-privacy lawsuit alleges Hubbard Radio's WTOP shared subscribers' personal information with Facebook without proper consent in violation of the Video Privacy Protection Act; as of February 2023 Hubbard Radio had moved to dismiss on jurisdictional grounds.\nWHY IT MATTERS: This is a live allegation that the general corporate privacy policy, last updated after the suit was filed, does not appear to specifically address or resolve.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] WTOP's parent shares data with ad-tech partners for targeted ads and collects precise geolocation\nWHAT THE TERMS SAY: The Privacy Policy states the company 'may provide personal information to vendors...advertising partners or other marketing partners,' with 'Ad partners and advertising technology companies' receiving shared data for targeted advertising, and discloses collection of 'geolocation data (including your precise location)' from mobile devices.\nWHY IT MATTERS: Personal information is provided to vendors, advertising partners and other marketing partners for targeted advertising, and the policy separately discloses collection of \"geolocation data (including your precise location)\" from mobile devices.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[DARK_PATTERN_CONSENT · FL-3] WTOP's Terms authorize sending autodialed marketing text messages\nWHAT THE TERMS SAY: 'You authorize Hubbard Radio to send you autodialed marketing text messages' as part of accepting the Terms of Use.\nWHY IT MATTERS: The authorization sits inside the general Terms of Use, which state that \"continued use of the Site constitutes your acceptance of the revised Terms of Use.\"\n(evidence: Fees; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=?; affiliates=Y; biometric=N; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=N; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "WTOP's own pages are robots-blocked, so parent-company Hubbard Radio's network-wide documents were used as an inferred proxy, and a live VPPA lawsuit is not addressed in the current privacy policy.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 14, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 14/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4) | Record 10/20 (severity3+8, litigation+2) | flags stated 13/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent", "Entity Type": "App / Service", "Ownership Path": "WTOP  <-  Hubbard Radio, LLC (and subsidiaries, including a Washington, D.C. operating entity) — the Terms of Use and Privacy Policy actually fetched are Hubbard Radio's corporate/network-wide documents, not a", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to stop paying by inaction.\n\nNOT YET DETERMINED (3 of 13): your personal data sold onward; your content used as AI training data; a broad licence to your own content. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using WTOP you gave up your physical movements, your data shared corporate-wide, your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 3 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 73.3, "URL Last Validated": "2026-09-08T19:22:27Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "The Terms of Use include an authorization for \"autodialed marketing text messages,\" and while the privacy policy affirmatively states it honors Global Privacy Control and discloses collection of \"geolocation data (including your precise location),\" WTOP itself is currently defending a lawsuit alleging it shared subscriber data with Facebook in violation of the Video Privacy Protection Act — a live allegation that the general corporate privacy policy (last updated Sept. 2024, after the suit was filed) does not appear to specifically address or resolve.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 28, "_entity_id": 51, "_entity_slug": "wtop", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Baltimore Banner", "Category": "Nonprofit local newspaper app", "Terms & Conditions URL": "https://www.thebanner.com/terms-service/ (redirect target of thebaltimorebanner.com/terms-service/)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://www.thebanner.com/privacy/ (redirect target of thebaltimorebanner.com/privacy/)", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The Privacy Policy states the Company \"may share your name, email address, other contact information, and information about your subscriptions, listening and usage activity, donations and interests with the affiliate stations,\" and \"may share any information we collect with service providers or vendors who provide us with specialized services.\" On sale under CCPA it states: \"Company does not sell personal information of its readers as the term 'sell' is traditionally understood. But 'sell' under the CCPA is broadly defined.\" It explicitly disclaims honoring browser-based signals: \"We do not currently respond to browser do-not-track signals,\" and Global Privacy Control is not mentioned as honored.", "Arbitration / Class Action Waiver": "No arbitration clause found in the terms fetched. Instead, the Terms of Service state: \"any disputes under these Terms or relating to Company Services shall be litigated in the local or federal courts located in the State of Maryland.\" No class-action waiver or jury-trial waiver was found.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Unilateral modification: \"We may modify, add, or delete portions of these Terms at any time by notifying you of the change in writing (including by email or by posting the modified Terms.\" Liability cap: \"IN NO EVENT WILL COMPANY...BE LIABLE FOR ANY AMOUNT IN EXCESS OF $100.\" Termination: \"Company has the right to limit or terminate your, or any other person's, access to or registration in Company Services for any reason.\" No detailed auto-renewal/subscription-fee terms appear within the Terms of Service document itself (a separate 'Terms of Sale for Digital Products' page exists at thebanner.com/terms-sale/ and was not fetched this session).", "Notes": "LEGAL ENTITY: The Venetoulis Institute for Local Journalism, a Delaware charitable nonstock corporation, doing business as The Baltimore Banner and The Banner\nTERMS EFFECTIVE: Updated September 15, 2025 | PRIVACY EFFECTIVE: September 15, 2025\nENFORCEMENT / BREACH (one search, 2026-08-29): No enforcement/breach item found in one search (2026-08-29) — top results for \"Baltimore Banner data breach OR settlement OR attorney general OR class action\" returned unrelated litigation involving a different organization (Banner Health, an Arizona hospital system) and an unrelated Baltimore Medical System breach; nothing tying an enforcement action or breach to The Baltimore Banner itself was found.\nPRIVACY CONTACT: Email: privacy@thebaltimorebanner.com. General contact: https://www.thebanner.com/customer-care or customercare@thebaltimorebanner.com. Phone: 443-843-0043. Mailing address: 621 E. Pratt St, Suite 401, Baltimore, MD 21202.\nRETENTION: Yes | GPC honored: No\nRESEARCHER NOTES: Both thebaltimorebanner.com/terms-service/ and thebaltimorebanner.com/privacy/ 302-redirect to the sibling domain thebanner.com, which appears to host the master/shared legal documents for the same publisher (branded 'The Baltimore Banner' and 'The Banner'). A separate 'Terms of Sale for Digital Products' page (thebanner.com/terms-sale/) was identified via search but not fetched — it may contain auto-renewal/subscription-fee terms not covered in the master Terms of Service fetched here.\nFETCH LOG (2026-08-29):\nhttps://www.thebaltimorebanner.com/terms-service/ — 302 redirect to https://www.thebanner.com/terms-service/\nhttps://www.thebanner.com/terms-service/ — 200 OK\nhttps://www.thebaltimorebanner.com/privacy/ — 302 redirect to https://www.thebanner.com/privacy/\nhttps://www.thebanner.com/privacy/ — 200 OK", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Email: privacy@thebaltimorebanner.com. General contact: https://www.thebanner.com/customer-care or customercare@thebaltimorebanner.com. Phone: 443-843-0043. Mailing address: 621 E. Pratt St, Suite 401, Baltimore, MD 21202.", "Legal / Privacy Contact Email": "privacy@thebaltimorebanner.com.", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "Verified - fetched OK", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "The Venetoulis Institute for Local Journalism, a Delaware charitable nonstock corporation, doing business as The Baltimore Banner and The Banner", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-20 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LIABILITY_CAP_INDEMNITY · FL-1] The Baltimore Banner caps its own liability at a flat $100 regardless of harm\nWHAT THE TERMS SAY: 'IN NO EVENT WILL COMPANY...BE LIABLE FOR ANY AMOUNT IN EXCESS OF $100.'\nWHY IT MATTERS: Readers/subscribers have essentially no meaningful financial recourse for any harm caused by the service, capped at $100.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SALE · FL-2] Baltimore Banner hedges its CCPA 'sell' disclaimer and does not honor Global Privacy Control\nWHAT THE TERMS SAY: 'Company does not sell personal information of its readers as the term 'sell' is traditionally understood. But 'sell' under the CCPA is broadly defined.' The policy also states: 'We do not currently respond to browser do-not-track signals,' with no mention of honoring Global Privacy Control.\nWHY IT MATTERS: The hedged \"sell\" language, combined with \"We do not currently respond to browser do-not-track signals\" and no mention of honoring Global Privacy Control, leaves readers a comparatively weak opt-out posture over sharing with the affiliate stations and with service providers or vendors.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No breach or enforcement item was found, and the entity affirmatively describes some privacy practices (e.g., stating a retention policy), leaving the flat $100 liability cap and the hedged CCPA-sale/no-GPC posture as the two distinct harms.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Terms and privacy policy are specific and dated, but the company does not honor Global Privacy Control and hedges its CCPA 'sell' characterization.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 14, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 14/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4) | Record 2/20 (severity2+2) | flags stated 10/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent", "Entity Type": "App / Service", "Ownership Path": "Baltimore Banner  <-  The Venetoulis Institute for Local Journalism, a Delaware charitable nonstock corporation, doing business as The Baltimore Banner and The Banner", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action; your right to a jury.\n\nNOT YET DETERMINED (5 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Baltimore Banner you gave up your physical movements, your data shared corporate-wide, your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 5 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 63.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The Terms of Service cap Company liability at a flat \"$100\" regardless of the harm alleged, and the Privacy Policy expressly states \"We do not currently respond to browser do-not-track signals\" with no mention of honoring Global Privacy Control — a comparatively weak opt-out posture for an organization that separately claims it does not 'sell' data 'as the term is traditionally understood' while acknowledging CCPA defines 'sell' more broadly than that claim addresses.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 29, "_entity_id": 53, "_entity_slug": "baltimore-banner", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "MGM National Harbor", "Category": "Regional casino/gaming app", "Terms & Conditions URL": "Not retrieved — not found — mgmnationalharbor.com and mgmresorts.com are blocked at the fetch-tool/proxy level (\"Domain is blocklisted\" / HTTP 403 on every attempt), so no terms page of any kind could be retrieved", "T&C Direct PDF?": "Not retrieved", "Privacy Policy URL": "Not retrieved — not found — same domain-level block as terms", "Privacy Direct PDF?": "Not retrieved", "Data Sharing/Selling Flags": "Not retrieved — no privacy policy could be fetched this session due to the domain block described above.", "Arbitration / Class Action Waiver": "Not retrieved — mgmnationalharbor.com and mgmresorts.com could not be fetched this session due to a domain-level block returned by the fetch tool/proxy (\"Domain is blocklisted\" and separately \"PROXY_REJECTED\" HTTP 403 on repeated attempts across multiple URLs on both domains). No terms document was read, so no arbitration language can be reported.", "Fees / Billing Flags": "CONTRACT TERMS (unilateral change / liability / termination / fees): Not retrieved — no terms document could be fetched this session due to the domain block described above.", "Notes": "LEGAL ENTITY: Not retrieved — the corporate/website terms and privacy documents could not be fetched this session (see notes); news/legal-settlement coverage refers to the parent company as \"MGM Resorts International\"\nTERMS EFFECTIVE: Not retrieved — domain blocked, page never read | PRIVACY EFFECTIVE: Not retrieved — domain blocked, page never read\nENFORCEMENT / BREACH (one search, 2026-08-29): A federal judge approved a $45 million class-action settlement on June 18, 2025, covering MGM Resorts International guests whose personal information (\"names, addresses, phone numbers, and other personally identifiable information\") was compromised in cybersecurity incidents in 2019 and 2023. Source: https://www.forthepeople.com/blog/45-million-class-action-settlement-approved-mgm-resorts-data-breach-case/\nPRIVACY CONTACT: Not stated — not retrieved.\nRETENTION: Not stated | GPC honored: Not stated\nRESEARCHER NOTES: Every WebFetch attempt against mgmnationalharbor.com and mgmresorts.com failed at the tool/proxy level before any page content was returned — errors were \"Domain is blocklisted\" (robots.txt fetch stage) and \"PROXY_REJECTED\" (HTTP 403), consistent with a categorical block on gambling/casino domains rather than a per-page issue. This is a hard block, not a content problem, and was confirmed across four separate URLs (mgmnationalharbor.com root, an mgmresorts.com privacy-policy path, the mgmresorts.com root, and a WebSearch-suggested mgmresorts.com terms path never even reachable). A future researcher using a different fetch tool/proxy without this domain restriction should be able to retrieve these documents directly. The breach/settlement finding above (via forthepeople.com, a non-blocked third-party legal-news domain) is the only real, fetched information obtained for this entity this session.\nFETCH LOG (2026-08-29):\nhttps://www.mgmnationalharbor.com/ — FAILED (\"Domain is blocklisted\")\nhttps://www.mgmresorts.com/en/legal/privacy-policy.html — FAILED (PROXY_REJECTED, HTTP 403)\nhttps://www.mgmresorts.com/ — FAILED (PROXY_REJECTED, HTTP 403)\nhttps://www.forthepeople.com/blog/45-million-class-action-settlement-approved-mgm-resorts-data-breach-case/ — 200 OK (breach/enforcement search)", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Not stated — not retrieved.", "Legal / Privacy Contact Email": "Not stated", "Finding Type": "Data breach + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-29", "Provenance (who determined this)": "REAL-FETCH RESEARCH 2026-08-29: WebSearch + WebFetch by Claude subagent under RESEARCH_INSTRUCTIONS.md; every URL read is in the Notes fetch log; fields marked 'Not retrieved' were not read. Severity/Finding Type derived heuristically from the one-search enforcement sentence (v58).", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not stated", "URL Status": "No URL recorded", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Pending - severity 4/5, no source yet", "Region Basis": "v58 tranche: entity operates primarily in DC/MD/VA (set at ingest, not from HQ columns)", "Parent / Ultimate Owner": "Not retrieved — the corporate/website terms and privacy documents could not be fetched this session (see notes); news/legal-settlement coverage refers to the parent company as \"MGM Resorts Internation", "Years Referenced in Finding (heuristic)": "2019, 2023, 2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up", "Registered Agent Address / Service Notes": "Not yet looked up", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-26 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] MGM Resorts International, parent of MGM National Harbor, paid $45M over 2019 and 2023 guest-data breaches\nWHAT THE TERMS SAY: A federal judge approved a $45 million class-action settlement on June 18, 2025, covering MGM Resorts International guests whose personal information ('names, addresses, phone numbers, and other personally identifiable information') was compromised in cybersecurity incidents in 2019 and 2023.\nWHY IT MATTERS: MGM Resorts International, the corporate parent of MGM National Harbor, paid a $45 million class-action settlement, approved June 18, 2025, over guest personal information compromised in cybersecurity incidents in 2019 and 2023.\n(evidence: Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-4] No Terms of Use or Privacy Policy could be retrieved at all for MGM National Harbor or its parent\nWHAT THE TERMS SAY: This session could not retrieve any terms-of-use or privacy-policy text for MGM National Harbor or its parent MGM Resorts International -- both domains were blocked outright by the fetch tool/proxy on every attempted URL, so no arbitration, data-sharing, or contract-term language can be reported for this entity at all.\nWHY IT MATTERS: No governing consumer terms could be independently verified for a casino/gaming operator that has already had two guest-data breaches.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No terms or privacy text of any kind could be fetched for this entity (hard domain block), so beyond the parent-company breach settlement, no additional company-specific clause language exists to support a third item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Both mgmnationalharbor.com and mgmresorts.com were blocked at the domain/proxy level on every attempt, so no terms or privacy text could be retrieved at all.", "Exposure Score (0-100)": 16, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "App / Service", "Ownership Path": "MGM National Harbor  <-  Not retrieved — the corporate/website terms and privacy documents could not be fetched this session (see notes); news/legal-settlement coverage refers to the parent company as \"MGM Resorts Internation", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, MGM National Harbor takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "What is notably ABSENT: this session could not retrieve ANY terms-of-use or privacy-policy text for MGM National Harbor or its parent MGM Resorts International — both mgmnationalharbor.com and mgmresorts.com were blocked outright by the fetch tool/proxy on every attempted URL (root domain and specific legal-page paths alike), so no arbitration, data-sharing, or contract-term language can be reported for this entity at all. Separately, and confirmed via a working third-party source, MGM Resorts International (the corporate parent of MGM National Harbor) paid a $45 million settlement for two large guest-data breaches (2019 and 2023), approved June 18, 2025.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Tranche 1 (v58)", "_row_id": 30, "_entity_id": 54, "_entity_slug": "mgm-national-harbor", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Verizon Wireless", "Category": "Carrier", "Terms & Conditions URL": "verizon.com/support/customer-agreement/", "T&C Direct PDF?": "https://ss7.vzw.com/is/content/VerizonWireless/Footer/cap/customer-agreement-policy-current-en.pdf", "Privacy Policy URL": "verizon.com/about/privacy/full-privacy-policy", "Privacy Direct PDF?": "NO (HTML only — no single official PDF found; page has a Print option)", "Data Sharing/Selling Flags": "Collects cell tower/GPS/Wi-Fi location; shares demographic & interest data from third-party data providers; social media partner data; 'Verizon Value' prepaid brands (Total Wireless, Straight Talk, Tracfone, etc.) share identity data with partner 'Prove' for bank credit decisions unless customer opts out.", "Arbitration / Class Action Waiver": "Binding arbitration + class/collective action waiver + jury-trial waiver; Verizon pays AAA/BBB filing fee if customer can't; offers a free voluntary internal mediation program before arbitration.\n\nAUG 2026 CLARIFICATION — DO NOT CONFUSE TWO DIFFERENT CLOCKS: Verizon's own arbitration FAQ describes a 60-day PRE-ARBITRATION NOTICE requirement — you must file a Notice of Dispute and wait 60 days before you may commence AAA arbitration. That is a hurdle before arbitrating, NOT an opt-out window that would let you keep your right to sue in court. No consumer opt-out window was confirmed for the Verizon Customer Agreement this pass. Conflating the two is an easy and costly error: acting on the 60-day figure would not preserve court access.", "Fees / Billing Flags": "Activation/upgrade fee up to $35/line; early termination fee up to $175 (or $350 for advanced devices); surcharges can add 15–50% to bill (incl. 38.1% federal USF pass-through on interstate charges, varies quarterly); no prepaid refunds after 30 days.", "Notes": "Privacy Office located in Washington, DC. Business customers have separate contract privacy terms.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$138.2B", "Market Cap": "$184.9B", "Employees": "99,600", "HQ City": "New York", "HQ State": "New York", "CEO": "Hans Vestberg", "Ticker": "VZ", "Website (Corporate)": "verizon.com", "Main Mailing Address (legal/privacy notices)": "Verizon Privacy Office, 1300 I Street NW, Suite 500 East, Washington, DC 20005, USA (International: Verizon Legal Dept, Reading International Business Park, Basingstoke Road, Reading, Berkshire RG2 6DA, UK)", "Legal / Privacy Contact Email": "No published privacy email; Verizon routes requests through its online privacy form", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (VZ). Service route: c/o General Counsel / Corporate Secretary, New York, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Verizon's prepaid brands share your identity data with 'Prove' for bank credit decisions unless you opt out.\nWHAT THE TERMS SAY: Verizon's prepaid brands (Total Wireless, Straight Talk, Tracfone, etc.) share customer identity data with partner 'Prove' for use in bank/lender credit decisions, unless the customer opts out.\nWHY IT MATTERS: A prepaid phone customer's data can quietly influence whether they're approved for a loan or credit card unless they know to opt out.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Verizon requires binding arbitration and waives class actions and jury trials, with no confirmed opt-out window.\nWHAT THE TERMS SAY: Verizon requires binding arbitration plus a class/collective action waiver and jury-trial waiver; Verizon covers the AAA/BBB filing fee if the customer can't pay and offers a free voluntary internal mediation step before arbitration. A 60-day pre-arbitration notice requirement exists, but the tracker states this is a filing hurdle, not a consumer opt-out window, and no opt-out window was confirmed.\nWHY IT MATTERS: A customer who mistakes the 60-day notice period for a chance to preserve their right to sue in court would be wrong, per the tracker's own clarification.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[AUTO_RENEWAL_FEES · FL-1] Verizon charges up to $175-$350 to cancel a device plan early and won't refund prepaid balances after 30 days.\nWHAT THE TERMS SAY: Fees include activation/upgrade charges up to $35/line, an early termination fee up to $175 (or $350 for advanced devices), surcharges adding 15-50% to the bill (including a 38.1% federal USF pass-through that varies quarterly), and no prepaid refunds after 30 days.\nWHY IT MATTERS: Customers who cancel service or switch devices can face steep, compounding charges beyond the advertised plan price.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration and fee terms are specifically detailed, but the tracker flags that the 60-day pre-arbitration notice is easily confused with an opt-out window, and no true opt-out window is confirmed.", "Exposure Score (0-100)": 51, "Exposure Band": "High", "Sub: Dispute Rights /30": 30, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 30/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, no_or_unstated_optout+6) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Verizon Wireless  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n  6. Your right to a jury.\n  7. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (6 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Verizon Wireless you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, your right to join a class action, your right to a jury, and your right to stop paying by inaction. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "2026-09-08T19:22:34Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Verizon's own PREPAID BRANDS (Total Wireless, Straight Talk, Tracfone) share your IDENTITY DATA with a third party called 'Prove' specifically so BANKS AND LENDERS can use it in CREDIT DECISIONS about you — unless you actively find and use the opt-out. Meaning: your prepaid phone carrier can quietly feed a company data that shapes whether you get approved for a loan or credit card, and this only stops if you know to say no.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Carriers", "_row_id": 31, "_entity_id": 55, "_entity_slug": "verizon-wireless", "_issuer": "Verizon Wireless", "_issuer_slug": "verizon-wireless", "_ticker": "VZ", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "AT&T", "Category": "Carrier", "Terms & Conditions URL": "att.com/legal/terms.consumerServiceAgreement.html", "T&C Direct PDF?": "https://www.att.com/scmsassets/support/other/attconsumerarbitrationagreement.pdf (arbitration section only; full CSA is HTML)", "Privacy Policy URL": "about.att.com/privacy/privacy-notice.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Shares account/device info with affiliates & vendors; credit checks authorized at will; location-data disclosure practices were the subject of a 2019 EFF/Hagens Berman lawsuit (Scott v. AT&T) alleging unlawful location-data sharing.", "Arbitration / Class Action Waiver": "Binding individual arbitration via AAA; class action AND jury trial waiver; AT&T pays arbitration costs for non-frivolous claims ≤$75,000; 30-day opt-out window from signup; EFF reports courts have used this clause to block a location-privacy class action.", "Fees / Billing Flags": "Installment plan acceleration if service is cancelled with an active device plan; discretionary fees separate from taxes (see 'AT&T discretionary fees' list); bundled-service cancellation can affect other discounted services.", "Notes": "AT&T's public arbitration/opt-out address: Legal Dept., 208 S. Akard, Dallas, TX.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$125.6B", "Market Cap": "$160.1B", "Employees": "140,990", "HQ City": "Dallas", "HQ State": "Texas", "CEO": "John Stankey", "Ticker": "T", "Website (Corporate)": "att.com", "Main Mailing Address (legal/privacy notices)": "AT&T Chief Privacy Office, 208 S. Akard St., Room 2901, Dallas, TX 75202, USA (AT&T also operates a Data Request Center and a Global Legal Demand Center for law-enforcement demands)", "Legal / Privacy Contact Email": "privacypolicy@att.com", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (T). Service route: c/o General Counsel / Corporate Secretary, Dallas, Texas — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] AT&T's arbitration clause reportedly (per EFF) was used in court to block a class action over alleged location\nWHAT THE TERMS SAY: AT&T requires binding individual arbitration via AAA plus a class action and jury trial waiver; AT&T covers arbitration costs for non-frivolous claims up to $75,000, and customers get a 30-day opt-out window from signup. EFF reports courts have used this clause to block a location-privacy class action.\nWHY IT MATTERS: Even with a privacy watchdog backing the case, the arbitration clause reportedly prevented customers from pursuing the location-data claims in open court.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity pass 1: Hedge lost corrected))", "Top Troubling #2": "[LOCATION_TRACKING · FL-2] AT&T faced a 2019 lawsuit alleging it unlawfully shared customers' location data.\nWHAT THE TERMS SAY: AT&T shares account/device info with affiliates and vendors, and its location-data disclosure practices were the subject of a 2019 EFF/Hagens Berman lawsuit (Scott v. AT&T) alleging unlawful location-data sharing.\nWHY IT MATTERS: The allegation, if true, means real-time location data about customers reached third parties without adequate consumer control -- though this is an allegation, not a confirmed finding.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[AUTO_RENEWAL_FEES · FL-1] Cancelling AT&T service with an active device plan can trigger full acceleration of remaining installments.\nWHAT THE TERMS SAY: AT&T's installment plan balance can be accelerated if service is cancelled while a device plan is active; AT&T also charges discretionary fees separate from taxes, and cancelling a bundled service can affect other discounted services.\nWHY IT MATTERS: A customer cancelling service could owe the full remaining device balance immediately, not just future monthly payments.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Arbitration terms, the opt-out window, and a specific litigation outcome are all clearly documented with figures and a case name.", "Exposure Score (0-100)": 46, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_30d+3) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "AT&T  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to a jury.\n  6. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using AT&T you gave up your physical movements, your data shared corporate-wide, your right to sue, your right to join a class action, your right to a jury, and your right to stop paying by inaction. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "2026-09-08T19:22:36Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "AT&T's own mandatory arbitration clause was successfully used IN COURT to BLOCK a class-action lawsuit (Scott v. AT&T) that accused the company of unlawfully selling customers' real-time LOCATION DATA. In other words: the very contract clause buried in your phone bill terms can prevent you from ever holding AT&T accountable in open court for tracking where you physically go — even when a federal privacy watchdog (EFF) was backing the case.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Carriers", "_row_id": 32, "_entity_id": 56, "_entity_slug": "at-t", "_issuer": "AT&T", "_issuer_slug": "at-t", "_ticker": "T", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "T-Mobile", "Category": "Carrier", "Terms & Conditions URL": "t-mobile.com/responsibility/legal/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only — no official PDF export found)", "Privacy Policy URL": "t-mobile.com/privacy-center/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Privacy Notice + 'Privacy Dashboard' for choices; separate B2B privacy notice for business accounts; data may remain on SIM/device after removal.", "Arbitration / Class Action Waiver": "Mandatory individual binding arbitration explicitly covers privacy/data-security disputes, not just billing — broader scope than some peers. Named in a class action (location-data case) arguing the 71-page/20,116-word T&Cs are unconscionable due to length + buried arbitration clause; T-Mobile does offer a documented opt-out process (30 days from activation).", "Fees / Billing Flags": "Historical AAA claim fee schedule shows small-claim ($25–$1,000) customer share capped at $25.", "Notes": "As of Aug 1 2025, T-Mobile acquired US Cellular's wireless operations — former US Cellular customers are transitioning to T-Mobile's terms/privacy practices.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$88.3B", "Market Cap": "$206.6B", "Employees": "75,000", "HQ City": "Bellevue", "HQ State": "Washington", "CEO": "Srini Gopalan", "Ticker": "TMUS", "Website (Corporate)": "t-mobile.com", "Main Mailing Address (legal/privacy notices)": "T-Mobile USA, Inc., Attn: Chief Privacy Officer, 12920 SE 38th Street, Bellevue, WA 98006, USA", "Legal / Privacy Contact Email": "privacy@t-mobile.com (privacy line 1-877-937-8997)", "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (TMUS). Service route: c/o General Counsel / Corporate Secretary, Bellevue, Washington — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] T-Mobile's arbitration clause explicitly covers privacy and data-security disputes, not just billing.\nWHAT THE TERMS SAY: T-Mobile's mandatory individual binding arbitration explicitly covers privacy/data-security disputes, a broader scope than some peers; the clause and a 71-page, 20,116-word T&C document are the subject of a class action arguing the length makes the buried clause unconscionable. T-Mobile does offer a documented opt-out process (30 days from activation).\nWHY IT MATTERS: A customer would have to read roughly 20,000 words to discover they've waived their right to sue over something like a data breach.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] T-Mobile is named in a class action alleging its 71-page terms unconscionably bury the arbitration clause.\nWHAT THE TERMS SAY: T-Mobile was named in a class action (a location-data case) arguing that the 71-page/20,116-word T&Cs are unconscionable due to their length and the buried arbitration clause.\nWHY IT MATTERS: If successful, such a claim could affect whether the arbitration clause is enforceable against affected customers; the tracker does not state an outcome.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[RETENTION_PERIOD · FL-2] T-Mobile discloses that customer data may remain on a SIM or device even after it's removed.\nWHAT THE TERMS SAY: The tracker notes data may remain on a SIM/device after removal, per T-Mobile's Privacy Notice.\nWHY IT MATTERS: A customer who removes a SIM or hands off a device may still be carrying residual personal data they assume is gone.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration scope and opt-out are specifically documented, but the Finding Type references a data breach with no supporting detail elsewhere in the row.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "T-Mobile  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using T-Mobile you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "T-Mobile's Terms & Conditions run 71 PAGES and 20,116 WORDS — longer than many short novels — and a court filing argues this length itself is part of why the buried arbitration clause is 'unconscionable.' That same clause is ALSO broader than most competitors': it explicitly covers PRIVACY AND DATA-SECURITY disputes, not just billing fights, meaning a customer would have to read roughly 20,000 words to discover they've waived their right to sue over a data breach.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Carriers", "_row_id": 33, "_entity_id": 57, "_entity_slug": "t-mobile", "_issuer": "T-Mobile", "_issuer_slug": "t-mobile", "_ticker": "TMUS", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "US Cellular (UScellular)", "Category": "Carrier", "Terms & Conditions URL": "uscellular.com – Terms & Conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "uscellular.com/content/dam/uscc-static/assets/pdfs/USCC_External_Privacy_Policy_updated_8_1_2025.pdf", "Privacy Direct PDF?": "YES", "Data Sharing/Selling Flags": "Shares data with parent Telephone and Data Systems (TDS) affiliates and 'Service Providers'; uses cookies/location data for ad personalization; not responsible for third-party app/Wi-Fi privacy practices.", "Arbitration / Class Action Waiver": "Binding arbitration under Wireless Industry Arbitration Rules (AAA); explicit rejection of any class-action consolidation ('USCellular expressly rejects and does not consent to any consolidation of claims or class action'); company pays filing/admin/arbitrator fees.", "Fees / Billing Flags": "Standard postpaid/prepaid fee structure; note company status change below.", "Notes": "IMPORTANT: As of Aug 1, 2025, T-Mobile now owns/operates UScellular's wireless business — existing customers keep prior privacy opt-outs but are effectively under T-Mobile going forward. Re-verify current entity before using in customer-facing materials.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CLASS_ACTION_WAIVER · FL-3] US Cellular bluntly states it 'expressly rejects' any class-action consolidation of claims.\nWHAT THE TERMS SAY: US Cellular's arbitration terms include an explicit rejection of any class-action consolidation: 'USCellular expressly rejects and does not consent to any consolidation of claims or class action.'\nWHY IT MATTERS: Customers with small individual claims lose the practical ability to band together, since the company will not consent to consolidating them.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] T-Mobile now owns US Cellular's wireless business, binding former customers to different practices.\nWHAT THE TERMS SAY: As of Aug 1, 2025, T-Mobile owns/operates US Cellular's wireless operations; existing customers keep prior privacy opt-outs but are effectively under T-Mobile going forward.\nWHY IT MATTERS: Customers who signed up under US Cellular are now governed by a different company's practices without having agreed to switch.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] US Cellular shares data with parent TDS affiliates and uses cookies/location data for ad personalization.\nWHAT THE TERMS SAY: US Cellular shares data with parent Telephone and Data Systems (TDS) affiliates and 'Service Providers,' and uses cookies/location data for ad personalization; it disclaims responsibility for third-party app/Wi-Fi privacy practices.\nWHY IT MATTERS: Customer data flows to a defined set of corporate affiliates and vendors for advertising purposes beyond the direct carrier relationship.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration and data-sharing terms are described, but the opt-out window is not stated and practices are in flux amid the T-Mobile transition.", "Exposure Score (0-100)": 43, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "US Cellular (UScellular)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using US Cellular (UScellular) you gave up your physical movements, your data shared corporate-wide, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "USCellular's contract contains a blunt, all-caps-style refusal built right into the legal language: the company 'EXPRESSLY REJECTS AND DOES NOT CONSENT to any consolidation of claims or class action' — a company preemptively declaring it won't even ENTERTAIN customers banding together, no matter what happens. And as of August 2025, T-Mobile now owns USCellular's wireless business — meaning customers who signed up under USCellular's name are now effectively bound to an entirely different company's practices, without ever having chosen T-Mobile themselves.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Carriers", "_row_id": 34, "_entity_id": 58, "_entity_slug": "us-cellular-uscellular", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Xfinity Mobile (Comcast)", "Category": "Carrier", "Terms & Conditions URL": "xfinity.com/mobile/policies/customer-agreement", "T&C Direct PDF?": "NO (HTML only for consumer Mobile T&Cs; Business Mobile version is a PDF: xfinity.com/mobile-static/Legal/Business/t&C.pdf)", "Privacy Policy URL": "xfinity.com/privacy/policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Single Comcast-wide privacy policy covers Xfinity Mobile, TV, Internet, Xumo, and 'Our Related Businesses' (NBCU, Sky); uses cookies/tracking for ad targeting across services; account-based opt-outs available via cookie/ad preference center.", "Arbitration / Class Action Waiver": "Binding arbitration + class/collective/representative action waiver + jury trial waiver explicitly survive termination of service; 30-day written opt-out available (mail or xfinity.com/webarbopt-out-style link); a 2019 federal case (O'Neil v. Comcast) upheld forcing a data-privacy/fraud class claim into arbitration despite alleged unauthorized account creation.", "Fees / Billing Flags": "120-day window to dispute a billing charge or you waive the right to a credit, small-claims action, or arbitration over it; reactivation fees after suspension/disconnection.", "Notes": "Terms differ by product line (Mobile vs Internet/TV vs Business) — make sure the audit uses the Mobile-specific customer agreement, not the general Xfinity Residential Subscriber Agreement.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Comcast Corporation", "Years Referenced in Finding (heuristic)": "2019", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] A federal case shows Comcast's arbitration clause can apply even to an alleged unauthorized account.\nWHAT THE TERMS SAY: Xfinity Mobile requires binding arbitration plus a class/collective/representative action waiver and jury trial waiver that explicitly survive termination of service, with a 30-day written opt-out. In O'Neil v. Comcast (2019), a federal case upheld forcing a data-privacy/fraud class claim into arbitration despite an allegation of unauthorized account creation.\nWHY IT MATTERS: Even a claim that a customer never agreed to have an account at all was still routed to arbitration rather than open court.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] One Comcast privacy policy covers Xfinity Mobile, TV, Internet, Xumo, NBCU, and Sky for ad targeting.\nWHAT THE TERMS SAY: A single Comcast-wide privacy policy covers Xfinity Mobile, TV, Internet, Xumo, and 'Our Related Businesses' (NBCU, Sky), using cookies/tracking for ad targeting across services, with opt-outs available via a cookie/ad preference center.\nWHY IT MATTERS: Data collected through a mobile line can be used for ad targeting across a wide family of Comcast-related media and entertainment businesses.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[AUTO_RENEWAL_FEES · FL-1] Xfinity Mobile customers have only 120 days to dispute a billing charge or lose the right to a credit.\nWHAT THE TERMS SAY: Customers have a 120-day window to dispute a billing charge or waive the right to a credit, small-claims action, or arbitration over it; reactivation fees apply after suspension/disconnection.\nWHY IT MATTERS: A billing error not caught within 120 days becomes permanently uncontestable, per the terms.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Arbitration scope, the opt-out window, and a specific case outcome are all clearly documented.", "Exposure Score (0-100)": 42, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Xfinity Mobile (Comcast)  <-  Comcast Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to a jury.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Xfinity Mobile (Comcast) you gave up your data shared corporate-wide, your right to sue, your right to join a class action, your right to a jury, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "In O'Neil v. Comcast (2019), a customer alleged Comcast created an account in their name WITHOUT AUTHORIZATION — essentially alleging fraud — and a federal court still forced that claim into ARBITRATION rather than letting it be heard in open court. Meaning: even when the customer's core argument is 'I never agreed to have an account with you in the first place,' the arbitration clause can still apply and block the courthouse door.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Carriers", "_row_id": 35, "_entity_id": 60, "_entity_slug": "xfinity-mobile-comcast", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Capital One", "Category": "Bank", "Terms & Conditions URL": "capitalone.com/digital/corporate-terms/ (Online Banking T&Cs)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "capitalone.com/privacy/online-privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Combines info from phone/email contacts, third-party data brokers (fraud/ID verification/marketing), co-brand card partners, and public sources; collects biometric data for authentication/fraud prevention; separate 'Datasharing' program lets you authorize sharing account data with named third-party apps, after which Capital One says the data is 'in their control' and no longer covered by CapOne's own policy.", "Arbitration / Class Action Waiver": "Historically one of only 3 major card issuers (with BofA, TD) WITHOUT forced arbitration in card terms (per Public Citizen 2024 review) — verify current deposit-account agreement to confirm this still holds, since BofA (a peer 'no-arbitration' bank) added arbitration in 2026 (see below).\n\nAUG 2026 FINDING (verify against your current cardmember agreement before relying on it): Capital One and Bank of America gave up credit-card arbitration clauses as part of a 2010 antitrust settlement, and reporting citing CFPB work indicates both CONTINUED to leave the clause out after the settlement period expired in 2013 — meaning there is no arbitration clause to opt out of, and no deadline to miss. Chase went the other way, reintroducing forced arbitration on many cards from Aug 11 2019 with a one-time opt-out that closed Aug 10 2019. This is a real and actionable difference between issuers, and it is exactly the kind of fact a cardholder would never find unaided. The source is 2020 reporting, so CONFIRM against the current agreement — issuers reintroduce these clauses, as Chase did.", "Fees / Billing Flags": "Standard card/deposit fee schedules; largest bank by deposits in the DC metro (~19% share, ~$58B in D.C.-area deposits) so its terms affect an outsized share of DMV customers.", "Notes": "HQ in Tysons, VA — the single most relevant bank for a DMV-focused audit given its #1 local deposit share.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$53.4B", "Market Cap": "$124.0B", "Employees": "52,600", "HQ City": "McLean", "HQ State": "Virginia", "CEO": "Richard Fairbank", "Ticker": "COF", "Website (Corporate)": "capitalone.com", "Main Mailing Address (legal/privacy notices)": "PRIVACY NOTICE ADDRESS (use this, not the HQ): Capital One, P.O. Box 30285, Salt Lake City, UT 84130-0285, USA. Corporate HQ is Capital One Financial Corp, 1680 Capital One Drive, McLean, VA 22102-3491 — the two differ, and the P.O. box is the one stated in the consumer privacy notice.", "Legal / Privacy Contact Email": "webinfo@capitalone.com (Do Not Call list: 1-888-817-2970)", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (COF). Service route: c/o General Counsel / Corporate Secretary, McLean, Virginia — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "DMV", "Primary Source URL": "https://www.security.org/identity-theft/breach/capital-one/", "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Virginia' is DC/MD/VA", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Corporation Service Company (CSC) — Virginia registered agent", "Registered Agent Address / Service Notes": "Registered Office: 100 Shockoe Slip, Fl 2, Richmond, VA 23219-4100. Principal Office: 1680 Capital One Dr, McLean, VA 22102-3407. VERIFIED against the Virginia SCC Clerk's Information System entity record for CAPITAL ONE FINANCIAL CORPORATION. CRITICAL SERVICE CAVEAT: Capital One Financial Corporation (the Delaware holding company) and Capital One, National Association (the OCC-chartered bank, FDIC Cert. 4297, Fed RSSD 112837) are SEPARATE legal entities. Service on the holding company's registered agent does NOT bind the bank. Each entity requires its own service event against its own agent. Legacy Discover claims may involve yet another entity — some Discover entities were dissolved post-merger, and service on a dissolved entity neither starts the clock nor tolls the statute of limitations.", "Company Brief": "Capital One Financial Corporation is a Delaware-incorporated bank holding company headquartered in the Capital One Tower, Tysons/McLean, Virginia. Founded 1994 in Richmond by Richard Fairbank and Nigel Morris. It is the largest credit-card issuer in the United States and one of the largest auto lenders, operating across the US, Canada, and the UK through three segments: credit cards, consumer banking, and commercial banking. Following the Discover acquisition it also owns the Discover, Diners Club, and Pulse payment networks — making it one of very few US institutions that both issues cards and operates a card network.", "Investor Overview": "NYSE: COF. S&P 100 and S&P 500 component. Revenue $53.4B (2025). Total assets $669.0B (2025). Total equity $94.6B (2025). Operating income $5.91B (2024). Net income before tax $4.747B (2024). Employees 76,300 (2025). Capital ratio 12.9% (2023). Chairman/President/CEO: Richard Fairbank (founder). CFO: Andrew Young. Brands: Capital One, CreditWise, Discover, Diners Club, Pulse. INVESTOR-RELEVANT RISK: the Discover integration adds network economics but also consolidates two consumer-complaint and regulatory surfaces; the 2019 breach cost ~$270M+ in combined penalties and settlement.", "Major Issues Record": "2019-07: Breach disclosed — ~106M US and Canadian credit-card applicants. Root cause was a misconfigured web application firewall in Capital One's AWS environment exploited via SSRF by Paige Thompson, a former AWS employee. Data included names, addresses, credit scores, and ~140K SSNs / ~80K linked bank account numbers. | 2020-08: OCC assessed an $80M civil money penalty for risk-management deficiencies tied to the cloud migration. | 2022: $190M class settlement receives final approval (Edmonson v. Capital One, E.D. Va., 1:21-cv-00332). The class action SURVIVED Capital One's arbitration clause because the claims sounded in negligence and data security rather than in contract. | 2024-02: Discover acquisition announced; subsequently completed, bringing the Discover/Diners Club/Pulse networks in-house. | Ongoing: Capital One Shopping (fmr. Wikibuy, acquired 2018) operates a browser extension that observes shopping behavior across third-party e-commerce sites, not only Capital One properties.", "T&C Key Provisions (paraphrased)": "PARAPHRASED, not quoted. Capital One's Customer Agreement provides for mandatory individual arbitration and waives class actions, with a 30-day window to reject the arbitration provision by written notice. Governing law is Virginia. The agreement covers credit card, deposit, and auto-loan relationships. Separate agreements govern Capital One Shopping and the mobile app. CONSUMER ACTION: rejection notice goes to Capital One, Attn: Legal Operations, 15000 Capital One Drive, Richmond VA 23238 — send within 30 days of account opening and keep proof of mailing.", "Re-verify By": "2027-02-13 (re-check Discover integration status and any new CFPB/OCC actions)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Capital One's 2019 breach exposed ~106M applicants' data, including ~140K Social Security numbers.\nWHAT THE TERMS SAY: The Major Issues Record states a 2019 breach disclosed roughly 106M US/Canadian credit-card applicants' data (names, addresses, credit scores, ~140K SSNs, ~80K linked bank accounts), caused by a misconfigured web application firewall in Capital One's AWS environment exploited via SSRF by a former AWS employee.\nWHY IT MATTERS: The OCC assessed an $80M penalty for related risk-management deficiencies, and a $190M class settlement followed -- concrete evidence the exposure caused real financial and legal fallout, though the tracker notes that settlement survived Capital One's arbitration clause because the claims sounded in negligence and data security rather than contract.\n(evidence: Major Issues Record; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Capital One's 'Datasharing' feature removes your data from its own privacy policy once you use it.\nWHAT THE TERMS SAY: Capital One lets customers connect accounts to third-party apps via a 'Datasharing' feature; once enabled, the fine print states account data is 'in the third party's control' and no longer covered by Capital One's own privacy policy.\nWHY IT MATTERS: A feature Capital One builds and encourages customers to use shifts responsibility for the data's protection to a third party the moment it's actually used.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Whether Capital One's card agreement has arbitration is inconsistent in the tracker and unverified.\nWHAT THE TERMS SAY: The tracker flags conflicting signals: historically Capital One was one of only 3 major card issuers without forced arbitration (unconfirmed for 2026, and reporting suggests it never reinstated the clause after a 2013 settlement deadline), yet a separate paraphrase of the Customer Agreement describes mandatory individual arbitration with a 30-day window to reject it, covering card, deposit, and auto-loan relationships.\nWHY IT MATTERS: A customer relying on the wrong version could either wrongly assume they've waived court access or miss a real 30-day window to opt out, if one exists.\n(evidence: Arbitration / Class Action Waiver | T&C Key Provisions; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Breach and data-sharing details are well documented, but the row's own arbitration facts are internally inconsistent and explicitly flagged for verification.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 18, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 18/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 8/20 (severity2+2, breach+3, penalty+3) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Capital One  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (10 of 13): your content used as AI training data; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Capital One you gave up your personal data sold onward, your biometric identifiers, and your data shared corporate-wide. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 63.3, "URL Last Validated": "2026-09-08T19:22:44Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Capital One lets you turn on a 'Datasharing' feature to connect your account to third-party apps — but the fine print says that once you do, YOUR OWN ACCOUNT DATA is now 'in the third party's control' and NO LONGER covered by Capital One's own privacy policy. Capital One built the feature, encourages you to use it, and then walks away from responsibility for what happens to your data the moment you actually use it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 36, "_entity_id": 61, "_entity_slug": "capital-one", "_issuer": "Capital One", "_issuer_slug": "capital-one", "_ticker": "COF", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Bank of America", "Category": "Bank", "Terms & Conditions URL": "bankofamerica.com/salesservices/deposits/resources/deposit-agreements/", "T&C Direct PDF?": "YES (info.bankofamerica.com/.../deposit-agreement-disclosures_alt_text_ada.pdf)", "Privacy Policy URL": "bankofamerica.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Shares customer info among 'Bank of America Affiliates' and 'selected third parties' for credit/insurance eligibility by default; opt-out requires a phone call or website form rather than being off by default.", "Arbitration / Class Action Waiver": "MAJOR RECENT CHANGE: in early 2026 BofA added mandatory binding arbitration + a class-action waiver to its Deposit Agreement for the first time — previously one of the few large banks without it. There is a time-limited opt-out window tied to the update; confirm current opt-out deadline directly with BofA before advising customers, since this is a live, recent change (per ConductAtlas policy-monitoring, May 2026).\n\nAUG 2026 FINDING (verify before relying): see the Capital One row — Bank of America likewise dropped credit-card arbitration under the 2010 antitrust settlement and reporting indicates it did not reinstate the clause after the period expired in 2013. No clause means no opt-out deadline. Confirm against the current cardmember agreement, since issuers do reintroduce arbitration (Chase did in 2019).", "Fees / Billing Flags": "Standard checking/savings fee schedule; automatic 'Standard Overdraft Setting' applied to most personal checking by default unless customer requests 'Decline All Overdraft.'", "Notes": "This arbitration change is the single most important “issue pertaining to customers” flag in this whole batch — it reverses BofA's long-standing no-arbitration position and customers may not know about the opt-out window.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$113.1B", "Market Cap": "$414.2B", "Employees": "213,193", "HQ City": "Charlotte", "HQ State": "North Carolina", "CEO": "Brian Moynihan", "Ticker": "BAC", "Website (Corporate)": "bankofamerica.com", "Main Mailing Address (legal/privacy notices)": "PRIVACY & SECURITY MAILING ADDRESS (verified on BofA's own contact page, Aug 2026): Bank of America, PO Box 25118, Tampa, FL 33622-5118, USA. NOTE this is NOT the Charlotte, NC corporate headquarters — as with Capital One, the privacy-contact address is a separate P.O. box and is the one the bank directs privacy correspondence to.", "Legal / Privacy Contact Email": "No published privacy email; BofA offers a secure message channel inside Online Banking plus the Tampa P.O. box", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (BAC). Service route: c/o General Counsel / Corporate Secretary, Charlotte, North Carolina — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'North Carolina' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NC SOS Business Registration Search — sosnc.gov/online_services/search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Bank of America added mandatory arbitration and a class-action waiver to its Deposit Agreement for the first time.\nWHAT THE TERMS SAY: The tracker states BofA, previously one of the few large banks without arbitration, added mandatory binding arbitration and a class-action waiver to its Deposit Agreement in early 2026, with a time-limited opt-out window whose exact deadline the tracker says must be confirmed directly with BofA.\nWHY IT MATTERS: Customers who don't know about this reversal may lose their ability to sue in court and never learn the opt-out window even exists.\n(evidence: Arbitration / Class Action Waiver | SCARY | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] BofA shares customer info with affiliates and third parties for credit/insurance eligibility by default.\nWHAT THE TERMS SAY: Bank of America shares customer info among 'Bank of America Affiliates' and 'selected third parties' for credit/insurance eligibility by default; opting out requires a phone call or website form rather than being off by default.\nWHY IT MATTERS: Customers must proactively act to stop sharing that otherwise happens automatically.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[AUTO_RENEWAL_FEES · FL-1] BofA applies its 'Standard Overdraft Setting' to most checking accounts by default.\nWHAT THE TERMS SAY: An automatic 'Standard Overdraft Setting' is applied to most personal checking accounts by default unless the customer requests 'Decline All Overdraft.'\nWHY IT MATTERS: Customers who don't proactively opt out may incur overdraft fees on a coverage setting they didn't choose.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The new arbitration requirement is confirmed but its exact opt-out deadline is not, per the tracker's own caveat.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 23, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 8, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 23/30 (forced_arbitration+12, class_action_waiver+9, optout_window_unverified+2) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 8/20 (unilateral_modification+5, auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Bank of America  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Bank of America you gave up your data shared corporate-wide, your right to sue, your right to join a class action, your right to be consulted before terms change, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:22:47Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "For years, Bank of America was one of the ONLY major banks that did NOT force customers into arbitration — a genuine selling point. In early 2026, it quietly REVERSED that position, adding mandatory binding arbitration and a class-action waiver to its Deposit Agreement for the FIRST TIME EVER, with only a time-limited window to opt out. Most existing customers likely have no idea this window exists or that it's closing.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 37, "_entity_id": 62, "_entity_slug": "bank-of-america", "_issuer": "Bank of America", "_issuer_slug": "bank-of-america", "_ticker": "BAC", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Truist", "Category": "Bank", "Terms & Conditions URL": "truist.com/content/dam/truist-bank/us/en/documents/agreement/online-and-mobile-banking-service-agreement.pdf", "T&C Direct PDF?": "YES", "Privacy Policy URL": "truist.com/privacy (see Online & Mobile Banking Agreement Privacy sections)", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Standard affiliate/third-party sharing for servicing and marketing; opt-out mechanisms described in privacy notice.", "Arbitration / Class Action Waiver": "Mutual Arbitration Agreement (p.50 of a 54-page online/mobile banking agreement) + jury trial waiver + litigation class action waiver, all explicitly headed sections — notably long and buried deep in the document relative to peers.", "Fees / Billing Flags": "Standard deposit/overdraft fee schedule (review Truist Consumer Fee Schedule separately for current amounts).", "Notes": "Formed from BB&T + SunTrust merger; historically had large DMV branch presence inherited from SunTrust.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$18.3B", "Market Cap": "$63.2B", "Employees": "37,552", "HQ City": "Charlotte", "HQ State": "North Carolina", "CEO": "William Rogers Jr.", "Ticker": "TFC", "Website (Corporate)": "truist.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (TFC). Service route: c/o General Counsel / Corporate Secretary, Charlotte, North Carolina — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'North Carolina' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NC SOS Business Registration Search — sosnc.gov/online_services/search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Truist buries its Mutual Arbitration Agreement on page 50 of a 54-page banking agreement.\nWHAT THE TERMS SAY: Truist's Mutual Arbitration Agreement, along with a jury trial waiver and litigation class action waiver, appears as explicitly headed sections starting on page 50 of a 54-page online/mobile banking agreement -- notably long and buried deep relative to peers.\nWHY IT MATTERS: A customer would have to read nearly the entire document before discovering, four pages from the end, that they've signed away their day in court.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Truist's banking agreement also includes an explicit litigation class-action waiver clause.\nWHAT THE TERMS SAY: The agreement includes a separately headed litigation class action waiver section alongside the arbitration agreement and jury trial waiver.\nWHY IT MATTERS: Customers lose the ability to join a class lawsuit against Truist, in addition to losing access to a jury and to court.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data Sharing and Fees fields only describe standard/generic bank practices with no company-specific detail beyond the arbitration bundle buried at page 50 of 54, so a third distinct item wasn't supported.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause's existence and its buried location are documented, but no opt-out window is stated.", "Exposure Score (0-100)": 42, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 30, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 30/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Truist  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to a jury.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Truist you gave up your data shared corporate-wide, your right to sue, your right to join a class action, and your right to a jury. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:22:50Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Truist's Mutual Arbitration Agreement — the clause that takes away your right to sue in court — is buried on PAGE 50 of a 54-page banking agreement. You would have to read essentially the entire document before discovering, four pages from the end, that you've signed away your day in court.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 38, "_entity_id": 63, "_entity_slug": "truist", "_issuer": "Truist", "_issuer_slug": "truist", "_ticker": "TFC", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Wells Fargo", "Category": "Bank", "Terms & Conditions URL": "wellsfargo.com/assets/pdf/small-business/agreement.pdf (business version; consumer Deposit Account Agreement is a separate but similarly-structured PDF on wellsfargo.com)", "T&C Direct PDF?": "YES", "Privacy Policy URL": "wellsfargo.com/privacy-security/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Standard affiliate data sharing for servicing/marketing/fraud prevention as described in privacy notice.", "Arbitration / Class Action Waiver": "Deposit Account Agreement contains dispute-resolution provisions including an arbitration agreement, class action waiver, AND jury trial waiver, explicitly called out as affecting legal rights; customer is advised to keep a copy of the Agreement for the life of the account since it's referenced, not printed in full, at account opening.", "Fees / Billing Flags": "Standard checking/savings fee schedule.", "Notes": "Historical note: Wells Fargo has an extensive record of CFPB/regulatory consent orders over unauthorized accounts/fees (2016 fake-accounts scandal); useful context if your audit covers past conduct as well as current terms.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$83.7B", "Market Cap": "$264.5B", "Employees": "217,502", "HQ City": "San Francisco", "HQ State": "California", "CEO": "Charles Scharf", "Ticker": "WFC", "Website (Corporate)": "wellsfargo.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (WFC). Service route: c/o General Counsel / Corporate Secretary, San Francisco, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2016", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Wells Fargo's arbitration, class, and jury waivers aren't fully provided at account opening.\nWHAT THE TERMS SAY: The Deposit Account Agreement contains an arbitration agreement, class action waiver, and jury trial waiver explicitly called out as affecting legal rights; the agreement itself is only referenced, not printed in full, at account opening, so customers are advised to keep a copy for the life of the account.\nWHY IT MATTERS: Customers may agree to give up court access and jury trials without ever seeing the complete document at signup.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-4] Wells Fargo's terms come from a bank with a documented history of unauthorized-account openings.\nWHAT THE TERMS SAY: The tracker notes Wells Fargo has an extensive record of CFPB/regulatory consent orders over unauthorized accounts and fees, referencing the 2016 fake-accounts scandal, offered as context for evaluating today's disclosure practices.\nWHY IT MATTERS: The same bank now asking customers to trust a referenced-but-not-fully-printed agreement has a documented history of opening accounts customers never requested.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data Sharing and Fees fields describe only standard/generic practices; only the arbitration-disclosure gap and the historical unauthorized-accounts record are company-specific enough to support distinct items.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause's existence is confirmed, but the agreement itself isn't fully provided at account opening, per the tracker.", "Exposure Score (0-100)": 39, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 30, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 30/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 5/20 (severity2+2, penalty+3) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Wells Fargo  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to a jury.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Wells Fargo you gave up your data shared corporate-wide, your right to sue, your right to join a class action, and your right to a jury. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:22:52Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Wells Fargo — the same bank found to have opened millions of fake accounts customers never requested (2016) — tells customers to keep a copy of the Deposit Account Agreement 'for the life of the account' because it's only REFERENCED, not fully printed, at account opening. So the bank with the documented history of creating accounts people didn't ask for is also the one that doesn't hand you the complete legal terms when you actually open one.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 39, "_entity_id": 64, "_entity_slug": "wells-fargo", "_issuer": "Wells Fargo", "_issuer_slug": "wells-fargo", "_ticker": "WFC", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "PNC Bank", "Category": "Bank", "Terms & Conditions URL": "pnc.com/content/dam/pnc-com/pdf/personal/Checking/Account-Agreement-Personal-Accounts.pdf", "T&C Direct PDF?": "YES", "Privacy Policy URL": "pnc.com/en/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Collects geolocation data via mobile app (e.g., nearest-ATM lookups) explicitly tagged as personally identifiable; uses cookies/clickstream tools, some hosted by third-party vendors, for analytics, advertising personalization, and fraud prevention; monitors/records digital and phone communications.", "Arbitration / Class Action Waiver": "Binding arbitration provision (pages 15–17 of the Account Agreement) with an explicit Right to Opt Out section, plus a separate 'Public Injunctive Relief Waiver' — broader than a standard class-action waiver, worth flagging since it can affect a customer's ability to seek injunctions on behalf of the public.", "Fees / Billing Flags": "Standard checking/savings/CD fee schedules; Virtual Wallet product has its own fee sheet.", "Notes": "PNC has a significant DMV branch network (a legacy of National City/other regional mergers).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Pittsburgh", "HQ State": "Pennsylvania", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-3] PNC's arbitration terms include a 'Public Injunctive Relief Waiver' beyond a class-action waiver.\nWHAT THE TERMS SAY: Alongside its standard arbitration clause (pages 15-17), PNC includes a separate Public Injunctive Relief Waiver, which the tracker says can stop a customer from seeking a court order requiring PNC to change a practice for the benefit of the public at large, not just personal compensation.\nWHY IT MATTERS: A customer isn't just giving up their own day in court -- they may also lose the ability to ask a court to force PNC to stop a harmful practice for everyone.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] PNC requires binding arbitration (pages 15-17), with an opt-out whose window isn't verified.\nWHAT THE TERMS SAY: PNC's Account Agreement includes a binding arbitration provision at pages 15-17 with an explicit Right to Opt Out section, though the specific opt-out window is not verified in this pass.\nWHY IT MATTERS: Customers have a documented path to opt out, but without a verified deadline they risk missing it.\n(evidence: Arbitration / Class Action Waiver; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[LOCATION_TRACKING · FL-2] PNC treats mobile-app geolocation as personal data and also monitors digital and phone communications.\nWHAT THE TERMS SAY: PNC collects geolocation data via its mobile app (e.g., nearest-ATM lookups) explicitly tagged as personally identifiable, uses cookies/clickstream tools (some third-party) for analytics, ad personalization, and fraud prevention, and monitors/records digital and phone communications.\nWHY IT MATTERS: Customers using PNC's app or contacting the bank are subject to location tracking and communications monitoring as part of routine use.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration and the Public Injunctive Relief Waiver are documented, but the opt-out window itself is not verified.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 14, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 14/30 (forced_arbitration+12, optout_window_unverified+2) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "PNC Bank  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using PNC Bank you gave up your physical movements, your data shared corporate-wide, and your right to sue. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:22:56Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Buried alongside PNC's standard arbitration clause is something broader: a 'PUBLIC INJUNCTIVE RELIEF WAIVER.' A normal class-action waiver stops you from suing on behalf of OTHER CUSTOMERS. This one can stop you from even asking a court to order PNC to change a practice for the benefit of the PUBLIC AT LARGE — not just compensation for yourself, but the ability to make PNC stop doing something to everyone.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 40, "_entity_id": 65, "_entity_slug": "pnc-bank", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "JPMorgan Chase", "Category": "Bank", "Terms & Conditions URL": "chase.com/content/dam/chase-ux/documents/personal/checking/deposit-account-agreement.pdf", "T&C Direct PDF?": "YES", "Privacy Policy URL": "chase.com privacy center (linked from Deposit Account Agreement)", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CCPA disclosure available for CA residents; standard affiliate/servicer sharing for other states; business-group customers (e.g., Corporate Banking) get separate, different agreements.", "Arbitration / Class Action Waiver": "Dedicated 'Arbitration; Resolving Disputes' section (Section X, ~p.28 of Deposit Account Agreement); Chase notably reintroduced forced arbitration in 2019 after having removed it as part of a 2009 multi-bank settlement (per Public Citizen) — worth mentioning as a 'previously removed, later reinstated' pattern relevant to customer trust messaging.", "Fees / Billing Flags": "Standard checking/savings fee schedule; monthly service fee waivers tied to direct deposit/balance thresholds (verify current thresholds directly).", "Notes": "Chase has been aggressively expanding branches in the DMV in recent years.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$182.4B", "Market Cap": "$895.1B", "Employees": "317,233", "HQ City": "New York", "HQ State": "New York", "CEO": "Jamie Dimon", "Ticker": "JPM", "Website (Corporate)": "jpmorganchase.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (JPM). Service route: c/o General Counsel / Corporate Secretary, New York, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2009, 2019", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Chase quietly reinstated forced arbitration in 2019, a decade after removing it in a 2009 settlement.\nWHAT THE TERMS SAY: Chase has a dedicated 'Arbitration; Resolving Disputes' section (~page 28 of the Deposit Account Agreement); the tracker notes Chase reintroduced forced arbitration in 2019 after having removed it as part of a 2009 multi-bank settlement (per Public Citizen).\nWHY IT MATTERS: A customer protection Chase gave up as part of a 2009 multi-bank settlement was put back in place a decade later, once the settlement's obligations had presumably run their course.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data Sharing and Fees fields describe standard/compliance-driven practices with no company-specific troubling detail; only the arbitration reinstatement is a substantive, distinct finding.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause's location and history are documented, but no opt-out window is stated.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 5/20 (unilateral_modification+5) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "JPMorgan Chase  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using JPMorgan Chase you gave up your data shared corporate-wide, your right to sue, and your right to be consulted before terms change. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:22:59Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "In 2009, major banks (Chase included) REMOVED forced arbitration from their agreements as part of a multi-bank legal settlement — a genuine, hard-won customer protection. In 2019, Chase quietly PUT IT BACK, ten years later, once the settlement's obligations had presumably run their course. A right customers gained through litigation was handed back to the bank once nobody was looking.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 41, "_entity_id": 66, "_entity_slug": "jpmorgan-chase", "_issuer": "JPMorgan Chase", "_issuer_slug": "jpmorgan-chase", "_ticker": "JPM", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Citibank", "Category": "Bank", "Terms & Conditions URL": "online.citi.com/JRS/popups/ao/CDAA.pdf (Consumer Deposit Account Agreement)", "T&C Direct PDF?": "YES (may require an active session; if blocked, use the HTML account-agreements page)", "Privacy Policy URL": "citi.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Standard affiliate/third-party sharing per privacy notice; consumer complaints (per third-party legal aggregator sources) commonly involve disputed/unauthorized transaction handling.", "Arbitration / Class Action Waiver": "Binding arbitration under FAA, class action + jury trial waiver in card and deposit agreements; consumer-attorney sources describe Citi's arbitration clause as a recurring point of friction in billing-dispute and unauthorized-transaction complaints (treat as anecdotal, not verified litigation data).", "Fees / Billing Flags": "No overdraft fees on checking (BofA/PNC/Chase do charge overdraft fees — useful contrast point); $2.50 non-Citi ATM fee outside surcharge-free network unless in a higher relationship tier; new as of 7/18/2026, Access Checking monthly fee is waived for account owners age 23 or younger.", "Notes": "Citi has a much smaller DMV branch footprint than Capital One/BofA/Truist/Wells Fargo but is a major national issuer many DMV customers still hold cards/accounts with.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$85.2B", "Market Cap": "$221.8B", "Employees": "227,855", "HQ City": "New York", "HQ State": "New York", "CEO": "Jane Fraser", "Ticker": "C", "Website (Corporate)": "citigroup.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (C). Service route: c/o General Counsel / Corporate Secretary, New York, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Citi's arbitration clause is reportedly a recurring flashpoint in unauthorized-transaction disputes.\nWHAT THE TERMS SAY: Citi requires binding arbitration under the FAA in card and deposit agreements; consumer-attorney sources describe this clause as a recurring point of friction specifically in billing-dispute and unauthorized-transaction complaints.\nWHY IT MATTERS: The situation where a customer most needs an independent hearing -- someone else used their card or account -- is reportedly the exact situation the clause routes away from court, though the tracker treats this as anecdotal, not verified litigation data.\n(evidence: Arbitration / Class Action Waiver | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Citi's card and deposit agreements include a class-action waiver alongside mandatory arbitration.\nWHAT THE TERMS SAY: Citi's card and deposit agreements include a class action waiver in addition to the binding arbitration requirement.\nWHY IT MATTERS: Customers cannot join together to bring a collective claim against Citi over billing or account disputes.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[JURY_WAIVER · FL-3] Citi's card and deposit agreements also include a jury-trial waiver.\nWHAT THE TERMS SAY: Citi's card and deposit agreements include a jury trial waiver alongside the arbitration and class-action waiver provisions.\nWHY IT MATTERS: Even where a dispute reaches court, a Citi customer has given up the right to have it heard by a jury.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated, but the claim that it's a recurring friction point in disputes is explicitly anecdotal and unverified.", "Exposure Score (0-100)": 42, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 30, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 30/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Citibank  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to a jury.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Citibank you gave up your data shared corporate-wide, your right to sue, your right to join a class action, and your right to a jury. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:23:01Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Consumer-attorney sources describe Citi's mandatory arbitration clause as a RECURRING flashpoint specifically in DISPUTED AND UNAUTHORIZED TRANSACTION complaints — meaning the exact situation where a customer most needs a fair, independent hearing (someone else used my card/account) is the exact situation the arbitration clause routes away from open court most often.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 42, "_entity_id": 67, "_entity_slug": "citibank", "_issuer": "Citibank", "_issuer_slug": "citibank", "_ticker": "C", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Atlantic Union Bank", "Category": "Bank", "Terms & Conditions URL": "atlanticunionbank.com – Consumer Deposit Account Agreement", "T&C Direct PDF?": "check atlanticunionbank.com directly (not confirmed as direct PDF in this pass)", "Privacy Policy URL": "atlanticunionbank.com privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not yet independently verified this pass — flag for next research cycle.", "Arbitration / Class Action Waiver": "Not yet independently verified this pass — flag for next research cycle.", "Fees / Billing Flags": "Not yet independently verified this pass — flag for next research cycle.", "Notes": "IMPORTANT STATUS CHANGE: Atlantic Union Bank completed its acquisition of Sandy Spring Bank on Oct 13, 2025 — Sandy Spring customers are now Atlantic Union customers under Atlantic Union's account agreements, not Sandy Spring's. Atlantic Union is the largest VA-headquartered regional bank (VA deposit share 6.3%, MD share 4.8% as of June 2025) and now the largest lower mid-Atlantic regional franchise post-merger. If your original list included 'Sandy Spring Bank' as a separate entity, drop it and treat this row as covering both.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Richmond", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Richmond, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Sandy Spring Bank customers are now bound to Atlantic Union's terms without ever agreeing to switch.\nWHAT THE TERMS SAY: Atlantic Union completed its acquisition of Sandy Spring Bank on Oct 13, 2025; Sandy Spring customers are now Atlantic Union customers under Atlantic Union's account agreements, not Sandy Spring's.\nWHY IT MATTERS: Customers who chose Sandy Spring's terms are now governed by a different company's privacy and arbitration practices, none of which were independently verified in this pass.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data Sharing, Arbitration, and Fees fields are all marked 'not yet independently verified this pass' -- only the Sandy Spring acquisition/entity-change fact from Notes/SCARY is substantive enough to report.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Core data-sharing, arbitration, and fee fields are all marked not yet independently verified this pass.", "Exposure Score (0-100)": 7, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 5/20 (unilateral_modification+5) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Atlantic Union Bank  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Atlantic Union Bank you gave up your right to be consulted before terms change. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "If you banked with Sandy Spring Bank, you didn't choose to leave — Sandy Spring simply CEASED TO EXIST as of October 2025, absorbed into Atlantic Union Bank. Every Sandy Spring customer is now bound to a DIFFERENT company's account agreement, privacy practices, and arbitration terms than the ones they originally signed, without ever being asked to agree to the switch.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 43, "_entity_id": 68, "_entity_slug": "atlantic-union-bank", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Burke & Herbert Bank", "Category": "Bank", "Terms & Conditions URL": "burkeandherbertbank.com/wp-content/uploads/2026/03/Online-and-Mobile-Banking-Agreement_3.16.2026.pdf", "T&C Direct PDF?": "YES", "Privacy Policy URL": "burkeandherbertbank.com/disclosures/ (Privacy Notice linked from Disclosures page)", "Privacy Direct PDF?": "NOT CONFIRMED (HTML disclosures index; underlying Privacy Notice PDF not individually located this pass)", "Data Sharing/Selling Flags": "Standard disclosures list includes a dedicated Privacy Notice, Funds Availability Policy, and Digital Wallet Terms; no unusual data-sharing language found in the Online/Mobile Banking Agreement excerpt.", "Arbitration / Class Action Waiver": "Not confirmed in this pass whether the Deposit Account Agreement includes binding arbitration — Online/Mobile Banking Agreement excerpt did not surface an arbitration clause; verify directly.", "Fees / Billing Flags": "Standard Schedule of Fees (linked from Disclosures page, not itemized here).", "Notes": "Oldest bank in Virginia (est. 1852); announced acquisition of Pennsylvania's Linkbank in late 2025 (~$354M deal, creating an $11B combined bank) — will affect a wave of new PA customers under VA-based terms.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Alexandria", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Alexandria, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Burke & Herbert's ~$354M Linkbank deal will move Pennsylvania customers onto Virginia-based terms.\nWHAT THE TERMS SAY: Burke & Herbert (Virginia's oldest bank, est. 1852) announced acquisition of Pennsylvania's Linkbank in late 2025 (~$354M deal, creating an $11B combined bank), which will bring a wave of new Pennsylvania customers under Burke & Herbert's Virginia-based terms.\nWHY IT MATTERS: Pennsylvania customers who never chose a Virginia bank will have their accounts and governing terms transferred as part of the merger.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data Sharing found nothing unusual, Arbitration is unconfirmed for the Deposit Account Agreement, and Fees are not itemized -- only the Linkbank acquisition/terms-transfer fact is substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration status is unconfirmed and fees aren't itemized; only the pending Linkbank acquisition is clearly documented.", "Exposure Score (0-100)": 7, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 5/20 (unilateral_modification+5) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Burke & Herbert Bank  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Burke & Herbert Bank you gave up your right to be consulted before terms change. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "2026-09-08T19:23:03Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Virginia's OLDEST bank (founded 1852) just agreed to absorb Pennsylvania's Linkbank in a ~$354 million deal — meaning a wave of Pennsylvania customers who never chose a Virginia bank are about to have their accounts, and the legal terms governing them, silently transferred to Burke & Herbert's rules instead.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 44, "_entity_id": 69, "_entity_slug": "burke-herbert-bank", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "John Marshall Bank", "Category": "Bank", "Terms & Conditions URL": "johnmarshallbank.com/resources/faqs/ (Deposit Account Agreement not individually located as direct PDF)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "johnmarshallbank.com (privacy notice not individually located this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "POSITIVE FINDING: John Marshall Bank explicitly commits that its Adjustable Rate Mortgage product will NOT be sold to third-party financial institutions, framing this as part of a broader 'we keep relationships in-house' commitment — a genuine contrast to the many larger banks in this tab whose mortgages/loans are routinely sold/serviced by third parties.", "Arbitration / Class Action Waiver": "Not confirmed this pass — verify the actual Deposit Account Agreement directly.", "Fees / Billing Flags": "No points charged on the ARM mortgage product; standard fees described as 'reduced to a bare minimum' (not independently quantified this pass).", "Notes": "13th-largest bank headquartered in Virginia (~$2.33B assets, 8 branches, founded 2006); commercial-focused community bank serving Northern VA, MD, DC.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Reston", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Reston, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — No troubling company-specific finding is stated for John Marshall Bank: the Data Sharing field is a positive commitment not to sell the ARM mortgage to third parties, arbitration is unconfirmed this pass, and the SCARY entry is explicitly framed as a contrast about other banks' practices rather than a finding about John Marshall itself.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration was not confirmed this pass, and no other clause details are available beyond a positive mortgage-sale commitment.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "John Marshall Bank  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, John Marshall Bank takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 'scary' finding here is really about everyone ELSE: John Marshall explicitly promises it will NOT sell your mortgage to a third party — and frames this as a selling point specifically BECAUSE it's unusual. Read the other way around: at most larger banks in this tracker, having your mortgage sold off to a company you never chose and never agreed to deal with is simply the normal, expected outcome.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 45, "_entity_id": 70, "_entity_slug": "john-marshall-bank", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Presidential Bank", "Category": "Bank", "Terms & Conditions URL": "presidential.bank (Terms/Deposit Agreement not individually located this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "presidential.bank (privacy notice not individually located this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Gramm-Leach-Bliley Act privacy notice governs data sharing. As an OCC-supervised federal thrift, Presidential Bank must provide an annual GLBA privacy notice with affiliate-sharing opt-out. Community banks of this size generally have far smaller data-sharing footprints than the national banks in this tab (Capital One, Bank of America, Wells Fargo) — fewer affiliates, no in-house credit card program, no browser extension, no data-analytics subsidiary.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Not confirmed this pass.", "Notes": "Bethesda, MD-based community bank; appeared in DC-MSA deposit-share rankings (~0.3% share, per earlier John Marshall Bancorp market-share exhibit) alongside other small local banks; thin public search footprint typical of small community banks — recommend a direct site pull for final confirmation.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Bethesda", "HQ State": "Maryland", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Bethesda, Maryland (DC/MD/VA)", "Parent / Ultimate Owner": "Presidential Bank, FSB (privately held)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Maryland SDAT Business Entity Search — egov.maryland.gov/businessexpress/entitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Presidential Bank, FSB (privately held)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] Presidential Bank's actual account terms are unusually hard to locate at all, the tracker finds.\nWHAT THE TERMS SAY: The tracker states Presidential Bank has a 'thin public search footprint typical of small community banks,' with the Arbitration and Fees fields both marked not confirmed this pass, and recommends a direct site pull for final confirmation.\nWHY IT MATTERS: A customer may have an easier time finding and reading Chase's 54-page agreement than locating Presidential Bank's terms at all, per the tracker's own comparison.\n(evidence: SCARY | Notes | Arbitration / Class Action Waiver | Fees / Billing Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and Fees are both marked not confirmed this pass, and Data Sharing only describes generic GLBA/industry-typical practices; the sole substantive, company-specific finding is the tracker's own note about how hard Presidential Bank's terms are to locate.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration and fees are unconfirmed, and the tracker itself flags a thin public search footprint for this bank's terms.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Presidential Bank  <-  Presidential Bank, FSB (privately held)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Presidential Bank you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The most notable thing about Presidential Bank's terms is that there's almost nothing to find — a genuinely thin public record for a bank holding real customers' deposits. When a financial institution's actual account terms are this hard for an outside researcher to locate and verify, that opacity is itself worth flagging: you may have an easier time reading Chase's 54-page agreement than finding Presidential Bank's at all.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 46, "_entity_id": 72, "_entity_slug": "presidential-bank", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Chain Bridge Bank", "Category": "Bank", "Terms & Conditions URL": "chainbridgebank.com/disclosures", "T&C Direct PDF?": "NOT CONFIRMED (disclosures page is HTML index; did not resolve to a single T&C PDF this pass)", "Privacy Policy URL": "chainbridgebank.com/disclosures", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Niche bank serving political committees, trade associations, lobbying firms, and nonprofits nationwide from a single McLean, VA branch — given its client base (political committees, PACs), data-handling practices may be worth extra scrutiny even though no specific issue is confirmed yet.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Not confirmed this pass.", "Notes": "Founded 2007 by former Senator Peter Fitzgerald; only 1 physical branch (McLean, VA) despite nationwide client base — almost entirely a relationship/digital banking operation.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "McLean", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: McLean, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "Chain Bridge Bancorp, Inc. (NYSE: CBNA)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Chain Bridge Bancorp, Inc. (NYSE: CBNA)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Chain Bridge Bank concentrates sensitive political and lobbying-client data in one small institution.\nWHAT THE TERMS SAY: Chain Bridge Bank serves political committees, PACs, trade associations, lobbying firms, and nonprofits nationwide from a single McLean, VA branch; the tracker notes this client base may warrant extra scrutiny of data-handling practices, though no specific issue is confirmed yet.\nWHY IT MATTERS: The bank's systems likely hold an unusually sensitive concentration of political and financial data inside one small institution, whether or not any breach has ever been confirmed.\n(evidence: Data Sharing/Selling Flags | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and Fees are both marked not confirmed this pass; the only substantive item is the tracker's flag about Chain Bridge's concentrated, sensitive political/lobbying client data, itself explicitly unconfirmed as to any actual issue.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration and fees are unconfirmed, and the data-sensitivity concern itself is speculative, not a confirmed incident.", "Exposure Score (0-100)": 11, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Chain Bridge Bank  <-  Chain Bridge Bancorp, Inc. (NYSE: CBNA)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Chain Bridge Bank takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "2026-09-08T19:23:08Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Chain Bridge Bank operates almost entirely as the go-to bank for POLITICAL COMMITTEES, PACs, and LOBBYING FIRMS nationwide — out of a single branch in McLean, VA. That means its systems likely hold an unusually sensitive concentration of data: which political operations bank where, how much money moves through which committees, and lobbying-firm financial relationships — all sitting inside one small institution's data security, whether or not any breach has ever been confirmed.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 47, "_entity_id": 74, "_entity_slug": "chain-bridge-bank", "_issuer": "Chain Bridge Bancorp, Inc.", "_issuer_slug": "chain-bridge-bancorp-inc", "_ticker": "CBNA", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "MainStreet Bank", "Category": "Bank", "Terms & Conditions URL": "mstreetbank.com (Deposit Account Agreement not individually located this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "mstreetbank.com", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "GLBA privacy notice governs. MainStreet's banking-as-a-service line means the bank may hold deposit and transaction data for end users acquired through fintech partners rather than through its own branches — the same structural pattern documented in this tracker's Synchrony Financial row (store-brand credit cards) and Chime row (Chime is a fintech, banking services provided by partner banks). A DMV consumer using a fintech app may be a MainStreet Bank customer without knowing it.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Not confirmed this pass.", "Notes": "Fairfax, VA-based community/commercial bank; appears on Maryland's approved IOLTA (attorney trust account) financial institution list alongside Congressional Bank, John Marshall Bank, and Industrial Bank — confirms regulatory good-standing in Maryland specifically, though no privacy/arbitration specifics were captured this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Fairfax", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Fairfax, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "MainStreet Bancshares, Inc. (Nasdaq: MNSB)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: MainStreet Bancshares, Inc. (Nasdaq: MNSB)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-4] A fintech-app user may be a MainStreet Bank customer without realizing it, the tracker notes.\nWHAT THE TERMS SAY: MainStreet's banking-as-a-service line means the bank may hold deposit and transaction data for end users acquired through fintech partners rather than its own branches; the tracker notes this mirrors the pattern described elsewhere in the tracker for Synchrony Financial (store-brand cards) and Chime (a fintech backed by partner banks).\nWHY IT MATTERS: A customer's actual banking relationship, and whose privacy and arbitration terms govern their money, may not be the company whose app or brand they recognize.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-4] MainStreet Bank's actual account and privacy terms are hard for outsiders to locate or verify.\nWHAT THE TERMS SAY: The tracker states MainStreet's actual account/privacy terms are difficult for an outside researcher to find or verify, even though it appears on Maryland's official IOLTA financial institution list confirming good regulatory standing.\nWHY IT MATTERS: Regulatory good standing is a different question from whether an ordinary depositor could easily read and understand what they've agreed to, per the tracker.\n(evidence: SCARY | Arbitration / Class Action Waiver | Fees / Billing Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and Fees are marked not confirmed this pass; only the banking-as-a-service hidden-customer structure and the general difficulty of locating MainStreet's terms are substantive enough to report.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration and fees are both unconfirmed, and the tracker itself notes MainStreet's terms are hard for an outside researcher to verify.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "MainStreet Bank  <-  MainStreet Bancshares, Inc. (Nasdaq: MNSB)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using MainStreet Bank you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "2026-09-08T19:23:09Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Like several small community banks in this tracker, MainStreet's actual account/privacy terms are difficult for an outside researcher to find or verify — the bank shows up on official Maryland regulatory lists confirming it's in good standing, but that's a different question from whether an ordinary depositor could easily read and understand what they've agreed to.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 48, "_entity_id": 76, "_entity_slug": "mainstreet-bank", "_issuer": "MainStreet Bancshares, Inc.", "_issuer_slug": "mainstreet-bancshares-inc", "_ticker": "MNSB", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Congressional Bank", "Category": "Bank", "Terms & Conditions URL": "congressionalbank.com (Deposit Account Agreement not individually located this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "congressionalbank.com", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "GLBA privacy notice governs. Congressional Bank's commercial and mortgage-warehouse focus means its consumer data footprint is smaller than a comparable retail bank — most of its relationships are with businesses, not individual depositors.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Not confirmed this pass.", "Notes": "Bethesda, MD-based; on Maryland's approved IOLTA financial institution list. Still recommend a dedicated look at its fintech/BaaS partner agreements specifically, since those often layer additional data-sharing terms beyond the bank's own consumer-facing privacy policy.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Bethesda", "HQ State": "Maryland", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Bethesda, Maryland (DC/MD/VA)", "Parent / Ultimate Owner": "Congressional Bancshares, Inc. (privately held)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Maryland SDAT Business Entity Search — egov.maryland.gov/businessexpress/entitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Congressional Bancshares, Inc. (privately held)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-4] Congressional Bank's hidden banking-as-a-service role layers separate, largely invisible terms.\nWHAT THE TERMS SAY: Congressional Bank operates as a 'banking-as-a-service' provider behind the scenes for various fintech apps, meaning a customer's money and data may sit inside Congressional Bank's systems because some other app they signed up for uses it as its actual banking partner, with its own separate data-sharing terms layered on top.\nWHY IT MATTERS: A customer using an unrelated fintech app may be subject to a bank's data practices they never reviewed or agreed to directly.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and Fees are marked not confirmed this pass; the sole substantive, company-specific finding is Congressional Bank's hidden banking-as-a-service role and its separate, largely invisible data-sharing terms.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration and fees are both unconfirmed, and the bank's own note recommends a dedicated look at its largely invisible fintech/BaaS partner data-sharing terms.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Congressional Bank  <-  Congressional Bancshares, Inc. (privately held)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Congressional Bank you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Congressional Bank looks like a small Bethesda community bank — but it ALSO operates as a 'banking-as-a-service' provider behind the scenes for various FINTECH APPS. That means your money and personal data might be sitting inside Congressional Bank's systems not because you chose Congressional Bank, but because some OTHER app you signed up for quietly uses Congressional Bank as its actual banking partner — with its own separate, largely invisible data-sharing terms layered on top.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 49, "_entity_id": 78, "_entity_slug": "congressional-bank", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "FVCbank", "Category": "Bank", "Terms & Conditions URL": "fvcbank.com (Deposit Account Agreement not individually located as direct PDF this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "fvcbank.com (privacy notice not individually located this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "GLBA privacy notice governs. FVCbank's commercial-banking focus in the NoVA/DC corridor means its data holdings skew toward business account relationships rather than consumer deposit accounts.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Not confirmed this pass.", "Notes": "Virginia-chartered community bank (Fairfax, VA HQ, opened 2007) focused on small/mid-sized businesses, government contractors, and nonprofits in Northern VA/DC/Maryland; offers specialized banking for title/escrow companies, nonprofits, and private schools — a niche-focused commercial bank rather than a general consumer retail bank. Recommend a direct follow-up on actual account terms.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Fairfax", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Fairfax, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "FVCBankcorp, Inc. (Nasdaq: FVCB)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: FVCBankcorp, Inc. (Nasdaq: FVCB)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Homebuyers who've never heard of FVCbank may have it holding their closing's escrow funds.\nWHAT THE TERMS SAY: FVCbank specializes in banking title and escrow companies, making it a central hub for the money and paperwork involved in home purchases across Northern Virginia, even though most individual homebuyers have never heard of it.\nWHY IT MATTERS: A bank the homebuyer never chose may be holding their closing's escrow funds along with sensitive financial documentation from the transaction.\n(evidence: SCARY | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and Fees are marked not confirmed this pass, and FVCbank's data footprint mostly involves business rather than consumer accounts; the sole substantive item is its role as an often-unrecognized escrow/title custodian for home purchases.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration and fees are unconfirmed, and the tracker recommends a direct follow-up on FVCbank's actual account terms.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "FVCbank  <-  FVCBankcorp, Inc. (Nasdaq: FVCB)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, FVCbank takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "FVCbank specializes in banking TITLE AND ESCROW COMPANIES — meaning it's a central hub for the money and paperwork involved in people's HOME PURCHASES across Northern Virginia. A bank most individual homebuyers have never heard of may be holding the escrow funds for their closing, along with all the sensitive financial documentation that comes with buying a house.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 50, "_entity_id": 80, "_entity_slug": "fvcbank", "_issuer": "FVCBankcorp, Inc.", "_issuer_slug": "fvcbankcorp-inc", "_ticker": "FVCB", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "WesBanco (fmr. Old Line Bank)", "Category": "Bank", "Terms & Conditions URL": "wesbanco.com/disclosures/Disclosures-OnlineBanking.pdf", "T&C Direct PDF?": "YES (Online Banking disclosures specifically; general Deposit Account Agreement not located as direct PDF)", "Privacy Policy URL": "wesbanco.com/privacy-notice/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Standard e-disclosure consent process; no unusual third-party data-sharing language found in the Online Banking Agreement excerpt.", "Arbitration / Class Action Waiver": "Not confirmed whether Deposit Account Agreement includes arbitration — the Online Banking Agreement excerpt reviewed did not include an arbitration section; verify the separate core Deposit Account Agreement directly.", "Fees / Billing Flags": "Not confirmed this pass.", "Notes": "WV-headquartered regional bank; acquired Maryland's Old Line Bank (2019) — legacy Old Line/DMV customers are now under WesBanco's national terms, not a Maryland-specific agreement.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Wheeling", "HQ State": "West Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "WesBanco, Inc. (Nasdaq: WSBC)", "Years Referenced in Finding (heuristic)": "2019", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (West Virginia) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in West Virginia. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[UNILATERAL_CHANGES · FL-4] Old Line Bank customers were silently moved to WesBanco's national terms after the 2019 acquisition, with no new agreement signed.\nWHAT THE TERMS SAY: WesBanco (WV-headquartered) acquired Maryland's Old Line Bank in 2019; legacy Old Line/DMV customers are now governed by WesBanco's national terms rather than a Maryland-specific agreement, per the tracker's notes.\nWHY IT MATTERS: Customers who chose a local Maryland bank now bank under an out-of-state institution's terms without ever having signed anything new.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fees are both marked 'not confirmed this pass' for the Online Banking Agreement excerpt reviewed; only the merger/terms-transfer finding is substantive enough to report.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration and fee terms not confirmed this pass; only the merger-transfer fact is verified.", "Exposure Score (0-100)": 7, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 5/20 (unilateral_modification+5) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "WesBanco (fmr. Old Line Bank)  <-  WesBanco, Inc. (Nasdaq: WSBC)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using WesBanco (fmr. Old Line Bank) you gave up your right to be consulted before terms change. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:23:11Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "If you were a Maryland-based Old Line Bank customer, you're no longer under a Maryland-focused agreement at all — Old Line was absorbed into WesBanco, a West Virginia-headquartered bank, back in 2019, and your account now runs on WesBanco's NATIONAL terms. The same silent-transfer pattern seen across this whole tab: local banks disappear into out-of-state parents, and depositors' actual legal terms change without them ever signing anything new.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 51, "_entity_id": 82, "_entity_slug": "wesbanco-fmr-old-line-bank", "_issuer": "WesBanco, Inc.", "_issuer_slug": "wesbanco-inc", "_ticker": "WSBC", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Community Bank of the Chesapeake", "Category": "Bank", "Terms & Conditions URL": "communitybankofthechesapeake.com (not individually resolved this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "communitybankofthechesapeake.com", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "GLBA privacy notice governs. MERGER NOTE: bank mergers transfer customer data to the acquiring institution, and the acquiring bank's privacy policy and affiliate-sharing practices then apply. A customer who chose Community Bank of the Chesapeake for its local character became a Shore Bancshares customer without individually consenting to the change — a structural feature of bank M&A that has no consumer opt-out.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Not confirmed this pass.", "Notes": "Southern Maryland-focused community bank; queued for direct follow-up.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Waldorf", "HQ State": "Maryland", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Waldorf, Maryland (DC/MD/VA)", "Parent / Ultimate Owner": "Shore Bancshares, Inc. (Nasdaq: SHBI) — merged 2023", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Maryland SDAT Business Entity Search — egov.maryland.gov/businessexpress/entitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Shore Bancshares, Inc. (Nasdaq: SHBI) — merged 2023). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[UNILATERAL_CHANGES · FL-4] Community Bank of the Chesapeake customers became Shore Bancshares customers via merger, with no individual consent option for the transfer.\nWHAT THE TERMS SAY: GLBA privacy notice governs; the tracker notes that bank mergers transfer customer data to the acquiring institution and that Shore Bancshares' privacy/affiliate-sharing practices now apply, with no consumer opt-out for the change itself.\nWHY IT MATTERS: A customer who chose this bank for its local character is now under a different institution's data practices without having agreed to that switch.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-4] Community Bank of the Chesapeake's actual account terms and data practices are not publicly documented, per the tracker's own review.\nWHAT THE TERMS SAY: The tracker states there is 'remarkably little public information available' about this bank's account terms and data practices, consistent with several small Southern Maryland/regional banks reviewed.\nWHY IT MATTERS: Depositors and researchers alike cannot determine what they've agreed to without a direct follow-up request to the bank.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and fees are both marked 'not confirmed this pass'; only the merger-transfer and general-opacity findings are substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration, fees, and even general account terms are all unconfirmed or unlocated for this bank.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 5/20 (unilateral_modification+5) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Community Bank of the Chesapeake  <-  Shore Bancshares, Inc. (Nasdaq: SHBI) — merged 2023", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Community Bank of the Chesapeake you gave up your data shared corporate-wide and your right to be consulted before terms change. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "As with several other small Southern Maryland/regional banks in this tracker, there's remarkably little public information available about this bank's actual account terms and data practices — the kind of opacity that makes it genuinely hard for an ordinary depositor (or an outside researcher) to know what they've agreed to.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 52, "_entity_id": 84, "_entity_slug": "community-bank-of-the-chesapeake", "_issuer": "Shore Bancshares, Inc.  — merged 2023", "_issuer_slug": "shore-bancshares-inc-merged-2023", "_ticker": "SHBI", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "United Bank", "Category": "Bank", "Terms & Conditions URL": "accessunited.com/customer-service/disclosures (Deposit Account Agreement effective Aug 1, 2026 linked here)", "T&C Direct PDF?": "NOT CONFIRMED (disclosures page indexes several PDFs; the specific Deposit Account Agreement PDF URL was not resolved to a direct link this pass)", "Privacy Policy URL": "accessunited.com (Privacy Notice not individually located this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "GLBA privacy notice governs. United Bankshares has grown substantially through acquisition (including Piedmont Bancorp and Community Bankers Trust), meaning customer data from multiple predecessor institutions has been consolidated into one platform.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Fee schedule change effective 8/1/2026: non-United ATM withdrawal fee rising, NSF fee rising to $33/item, foreign currency order fee rising to $50 — concrete upcoming fee increases worth flagging to customers directly, independent of the arbitration/privacy questions.", "Notes": "WV/VA/MD-based regional bank (United Bankshares); absorbed Cardinal Bank and other DMV community banks over the years.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Fairfax", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Fairfax, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "United Bankshares, Inc. (Nasdaq: UBSI, Charleston WV)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: United Bankshares, Inc. (Nasdaq: UBSI, Charleston WV)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] United Bank is raising its NSF fee to $33 and other fees effective August 1, 2026, in a change few customers will notice until charged.\nWHAT THE TERMS SAY: Effective 8/1/2026, United Bank's non-United ATM withdrawal fee, NSF fee (rising to $33/item), and foreign currency order fee (rising to $50) are all increasing, per the tracker's fee schedule review.\nWHY IT MATTERS: NSF fees hit customers exactly when they have the least money in their account, and the increase is easy to miss until it's charged.\n(evidence: Fees / Billing Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[UNILATERAL_CHANGES · FL-4] United Bank consolidated customer data from multiple predecessor institutions onto one platform.\nWHAT THE TERMS SAY: United Bankshares grew through acquisitions including Piedmont Bancorp and Community Bankers Trust, and per the tracker, 'customer data from multiple predecessor institutions has been consolidated into one platform.'\nWHY IT MATTERS: Customers of predecessor banks acquired by United Bankshares now have their data held on a single consolidated platform.\n(evidence: Data Sharing/Selling Flags | Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration is not confirmed this pass; only the fee-increase and data-consolidation findings are substantive and company-specific.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms unconfirmed, but concrete fee changes and data-consolidation history are documented.", "Exposure Score (0-100)": 10, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 8, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 8/20 (unilateral_modification+5, auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "United Bank  <-  United Bankshares, Inc. (Nasdaq: UBSI, Charleston WV)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  2. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using United Bank you gave up your right to be consulted before terms change and your right to stop paying by inaction. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Effective August 1, 2026, United Bank is RAISING its overdraft-adjacent fees: the NSF (non-sufficient-funds) fee climbs to $33 per item, and out-of-network ATM and foreign-currency fees are also going up. NSF fees hit hardest exactly when a customer already has the least money in their account — and this increase is happening quietly, in a fee-schedule update most customers won't notice until they're charged it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 53, "_entity_id": 86, "_entity_slug": "united-bank", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "City First Bank", "Category": "Bank (CDFI)", "Terms & Conditions URL": "cityfirstbank.com/our-policies (Truth in Savings disclosure available on request)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "cityfirstbank.com/PrivacyPolicy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "GENUINELY POSITIVE FINDING relative to most other companies in this tracker: City First Bank's privacy policy explicitly states 'We do not sell, trade, or rent Users' personal identification information to others' — a direct, plain-language no-sale commitment rarely seen stated this simply elsewhere in this audit. It does share 'generic aggregated demographic information' (not individually identifiable) with business partners/advertisers, and uses standard third-party service providers for operational tasks like newsletters.", "Arbitration / Class Action Waiver": "Not confirmed this pass — the reviewed document was the website privacy policy, not the full Deposit Account Agreement, so the arbitration clause (if any) was not captured; recommend requesting the Personal/Commercial Account Fee Schedule and Truth in Savings disclosure directly, since City First does not publish these publicly and requires a direct request via email.", "Fees / Billing Flags": "Fee schedules are NOT publicly posted — customers must email info@cityfirstbank.com to request the current Personal or Commercial Accounts Fee Schedule, an unusual level of opacity compared to banks that post fee schedules directly on their websites (e.g., United Bank, elsewhere in this tab).", "Notes": "City First Bank is a certified Community Development Financial Institution (CDFI) — the first and only CDFI bank focused solely on DC community development, and following its merger with Broadway Federal Bank (Los Angeles), is now the LARGEST BLACK-LED BANK IN THE NATION. At least 60% of its lending/services must benefit low-income communities under CDFI certification requirements. This is directly relevant to BMHC's mission and worth highlighting as a genuinely different institution type from the large national banks elsewhere in this tab — not just for its privacy practices, but as a potential organizational banking partner or reference point.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Washington", "HQ State": "District of Columbia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Washington, District of Columbia (DC/MD/VA)", "Parent / Ultimate Owner": "Broadway Financial Corporation (Nasdaq: BYFC) — CDFI", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): DC DLCP CorpOnline — corponline.dcra.dc.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Broadway Financial Corporation (Nasdaq: BYFC) — CDFI). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] City First Bank doesn't publish fee schedules online — customers must email the bank directly to find out what they'd be charged.\nWHAT THE TERMS SAY: Per the tracker, City First Bank's Personal/Commercial Accounts Fee Schedule is not publicly posted; customers must email info@cityfirstbank.com to request it.\nWHY IT MATTERS: Prospective customers can't compare costs before opening an account, unlike other banks in this tab (e.g., United Bank) that post fee schedules directly.\n(evidence: Fees / Billing Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing practices are stated positively (explicit no-sale commitment) and arbitration was not confirmed this pass (only the website privacy policy was reviewed, not the Deposit Account Agreement); only the fee-schedule opacity is a substantive troubling finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Data-sharing practices are clearly and positively stated, but arbitration and fee schedules are unconfirmed/unpublished.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "City First Bank  <-  Broadway Financial Corporation (Nasdaq: BYFC) — CDFI", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using City First Bank you gave up your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:23:16Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "City First's privacy story is genuinely good — a plain 'we do not sell your data' commitment that's rare in this whole tracker. The one real gap: its FEE SCHEDULE isn't published anywhere online. To find out what you'd actually be charged for a personal or business account, you have to email the bank directly and ask — a level of opacity around COST that's unusual even among the small community banks in this tab.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 54, "_entity_id": 88, "_entity_slug": "city-first-bank", "_issuer": "Broadway Financial Corporation  — CDFI", "_issuer_slug": "broadway-financial-corporation-cdfi", "_ticker": "BYFC", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Industrial Bank", "Category": "Bank (CDFI)", "Terms & Conditions URL": "industrial-bank.com (specific Terms/Deposit Agreement URL not individually located this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "industrial-bank.com (privacy policy not individually located this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass — recommend a direct follow-up pulling the actual Deposit Account Agreement and Privacy Policy from the bank's site.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Not confirmed this pass.", "Notes": "SIGNIFICANT MISSION-RELEVANT INSTITUTION: founded 1913 (reorganized 1934), Industrial Bank is the oldest and largest Black-owned bank in Washington, DC, and the fifth-largest Black-owned bank nationwide (~$710M+ in assets, 140+ employees, branches in DC, MD, NJ, NY). Certified CDFI reinvesting 60% of assets into the community annually; still led by the Mitchell family (3rd generation, B. Doyle Mitchell Jr.) since 1934. Runs financial-literacy programming inside DC Department of Corrections facilities as part of a recidivism-reduction partnership. Directly relevant to BMHC's mission profile — worth a dedicated, careful follow-up pass on the actual account terms rather than the generic search results captured here, given how much institutional history and community trust is riding on this specific bank's practices.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Washington", "HQ State": "District of Columbia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Washington, District of Columbia (DC/MD/VA)", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "1913", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): DC DLCP CorpOnline — corponline.dcra.dc.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] Industrial Bank, DC's oldest and largest Black-owned bank, has little publicly available detail about its current account terms or privacy practices.\nWHAT THE TERMS SAY: The tracker states there is 'remarkably little publicly available detail about Industrial Bank's actual current account terms and privacy practices online,' despite its long operating history.\nWHY IT MATTERS: Customers and researchers can't verify what account terms and data practices actually apply without direct follow-up.\n(evidence: SCARY | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — All three fields (data sharing, arbitration, fees) are marked not confirmed this pass; only the general-opacity finding is stated, and it is the sole substantive item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No terms located for data sharing, arbitration, or fees; opacity itself is the finding.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Industrial Bank  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Industrial Bank takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Despite being the oldest and largest Black-owned bank in DC — in continuous operation since 1913 — there is remarkably little publicly available detail about Industrial Bank's actual current account terms and privacy practices online. For an institution this historically significant and this trusted within the community it serves, that thinness of public documentation is worth noting on its own, independent of whether anything is actually wrong.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 55, "_entity_id": 89, "_entity_slug": "industrial-bank", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Freedom Bank of Virginia", "Category": "Bank", "Terms & Conditions URL": "freedombankva.com (not individually resolved this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "freedombankva.com", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "GLBA privacy notice governs. Small community bank with a correspondingly limited data-sharing footprint — no affiliate network of the kind that makes GLBA affiliate-sharing opt-outs consequential at large national banks.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Not confirmed this pass.", "Notes": "Small Fairfax, VA community bank; queued for direct follow-up.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Fairfax", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Fairfax, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "Freedom Financial Holdings, Inc. (OTCQX: FDVA)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Freedom Financial Holdings, Inc. (OTCQX: FDVA)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] Freedom Bank of Virginia doesn't post account terms or fee schedules online, so customers see the deposit agreement only after opening an account.\nWHAT THE TERMS SAY: Per the tracker, 'account terms, fee schedules and the deposit agreement are not readily available online, so a prospective customer cannot compare terms before opening an account — they receive the agreement after committing.'\nWHY IT MATTERS: Customers commit to an account before they can review the actual terms governing it.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-2] Like many small banks, Freedom Bank of Virginia likely outsources core processing to a vendor (Fiserv or FIS)\nWHAT THE TERMS SAY: The tracker notes small banks like Freedom Bank 'typically outsource core processing to Fiserv or FIS... meaning the security posture that actually protects a depositor belongs to a vendor the bank chose and the customer will never hear named.'\nWHY IT MATTERS: The actual data-security practices protecting a depositor's account are set by a vendor the customer never selected or was told about.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 1: Hedge lost corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and fees are marked not confirmed this pass; only the opacity and vendor-dependency observations are substantive, and the tracker explicitly notes 'nothing adverse confirmed this pass.'", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Terms, fees, and arbitration are all unavailable/unconfirmed; the tracker frames this bank as an opacity case, not a misconduct case.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Freedom Bank of Virginia  <-  Freedom Financial Holdings, Inc. (OTCQX: FDVA)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Freedom Bank of Virginia takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:23:17Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "A small Northern Virginia community bank, and the finding is opacity rather than misconduct: account terms, fee schedules and the deposit agreement are not readily available online, so a prospective customer cannot compare terms before opening an account — they receive the agreement after committing. Small banks are also exempt from much of the public reporting that makes larger institutions auditable, and they typically outsource core processing to Fiserv or FIS (see those rows in F500 Financial Svcs Remainder), meaning the security posture that actually protects a depositor belongs to a vendor the bank chose and the customer will never hear named. Nothing adverse confirmed this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 56, "_entity_id": 91, "_entity_slug": "freedom-bank-of-virginia", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "TowneBank (now incl. Old Point National Bank)", "Category": "Bank", "Terms & Conditions URL": "townebank.com (Deposit Account Agreement not individually located as direct PDF this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "townebank.com (privacy notice not individually located this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "GLBA privacy notice governs. TowneBank operates insurance and realty subsidiaries (Towne Insurance, Towne Realty) in addition to banking — meaning GLBA affiliate-sharing is more consequential here than at a bank-only institution: a mortgage customer's data can flow to the affiliated title, insurance, and realty businesses under the affiliate-sharing provisions, subject to the annual notice opt-out.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Not confirmed this pass.", "Notes": "MAJOR CONSOLIDATION RELEVANT TO THIS LIST: TowneBank has been on an active acquisition spree — it acquired Village Bank & Trust (closed April 2025), then Old Point National Bank / Old Point Financial Corp (agreed April 2025, ~$203M deal, completed Sept 2025–Feb 2026 systems conversion), bringing combined assets to ~$19.5B. If your original bank list included 'Old Point National Bank' as a separate entity, it no longer exists independently — those customers are now under TowneBank's account agreements, mobile app, and routing number. TowneBank is now one of the largest Virginia-headquartered banks (~$17.25B+ assets pre-merger).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Suffolk", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Suffolk, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "TowneBank (Nasdaq: TOWN)", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: TowneBank (Nasdaq: TOWN)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] TowneBank's affiliate network (Towne Insurance, Towne Realty) means mortgage customer data can flow to affiliated insurance, title, and realty businesses.\nWHAT THE TERMS SAY: TowneBank operates insurance and realty subsidiaries in addition to banking; per the tracker, 'a mortgage customer's data can flow to the affiliated title, insurance, and realty businesses under the affiliate-sharing provisions,' subject to the annual notice opt-out.\nWHY IT MATTERS: Customers must actively opt out via an annual notice or their data is shared across a wider affiliate network than at a bank-only institution.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[UNILATERAL_CHANGES · FL-4] TowneBank's acquisition of Old Point National Bank means former Old Point customers now have a different routing number, app, and account agreement simply because their bank was bought.\nWHAT THE TERMS SAY: TowneBank acquired Village Bank & Trust (April 2025) and Old Point National Bank (~$203M deal, completed by early 2026); per the tracker, affected customers 'now have a different routing number, a different mobile app, and a different account agreement than the one you originally signed.'\nWHY IT MATTERS: Customers' banking relationship and legal terms change without them choosing or signing anything new.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and fees are not confirmed this pass; only the affiliate-sharing and merger-transfer findings are substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Affiliate-sharing and merger history are documented, but arbitration and fees remain unconfirmed.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 5/20 (unilateral_modification+5) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "TowneBank (now incl. Old Point National Bank)  <-  TowneBank (Nasdaq: TOWN)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using TowneBank (now incl. Old Point National Bank) you gave up your data shared corporate-wide and your right to be consulted before terms change. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "TowneBank has been on an active buying spree — Village Bank & Trust in April 2025, then Old Point National Bank (a ~$203 million deal) completed by early 2026. If you banked at either, you now have a different routing number, a different mobile app, and a different account agreement than the one you originally signed, simply because your bank got bought.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 57, "_entity_id": 93, "_entity_slug": "townebank-now-incl-old-point-national-bank", "_issuer": "TowneBank", "_issuer_slug": "townebank", "_ticker": "TOWN", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Old Point National Bank", "Category": "Bank (MERGED - see TowneBank row)", "Terms & Conditions URL": "N/A - merged into TowneBank", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "N/A", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "N/A - see TowneBank row for current entity", "Arbitration / Class Action Waiver": "N/A", "Fees / Billing Flags": "N/A", "Notes": "NO LONGER A SEPARATE ENTITY: Old Point National Bank (Hampton, VA) completed its merger into TowneBank between Sept 2025 and Feb 2026. All former Old Point customers are now TowneBank customers under TowneBank's account agreements, routing number, and mobile app. Do not treat this as a distinct row in any final customer-facing list — consolidate with the TowneBank row above.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Hampton", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Hampton, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Old Point National Bank no longer exists as a separate entity (merged into TowneBank, completed by Feb 2026); the tracker marks Data Sharing, Arbitration, and Fees fields N/A and directs readers to the TowneBank row for current findings — no company-specific finding remains for this row.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "This entity no longer has independent account terms; all fields are marked N/A and merged into TowneBank.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Old Point National Bank  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Old Point National Bank takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "N/A — see TowneBank row; this bank no longer exists as a separate entity.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Banks (DMV)", "_row_id": 58, "_entity_id": 94, "_entity_slug": "old-point-national-bank", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Navy Federal Credit Union", "Category": "Credit Union", "Terms & Conditions URL": "navyfederal.org/content/dam/nfculibs/pdfs/membership/nfcu_606.pdf (Important Disclosures)", "T&C Direct PDF?": "YES", "Privacy Policy URL": "navyfederal.org/policy/privacy.html + navyfederal.org/content/dam/nfculibs/pdfs/membership/nfcu_198_privacypolicy.pdf", "Privacy Direct PDF?": "YES (the GLBA-style 'FACTS' notice)", "Data Sharing/Selling Flags": "Explicitly states it does NOT sell member information for monetary consideration; has its own API (via Finicity/Mastercard partnership) for member-controlled data sharing with third-party apps, framed as a more secure/consent-based alternative to screen-scraping.", "Arbitration / Class Action Waiver": "Disclosures reviewed this pass did not surface a binding arbitration/class-action-waiver clause — unlike most large banks above. Confirm directly since credit unions can still include arbitration in membership agreements even if not in this specific disclosure document.", "Fees / Billing Flags": "NSF fee charged on first returned item per current fee schedule (amount not itemized in excerpt).", "Notes": "Largest credit union in the US by membership/assets, HQ Vienna, VA — an enormous share of DMV military-affiliated households bank here; member-owned (not a bank), so it's regulated by NCUA not FDIC.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Vienna", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Vienna, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "Navy Federal Credit Union (federal charter, member-owned)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Federally chartered credit union — no state registered agent; NCUA-supervised", "Registered Agent Address / Service Notes": "Navy Federal Credit Union, 820 Follin Lane SE, Vienna, VA 22180. As a FEDERALLY CHARTERED credit union, Navy Federal is not registered with a state corporation commission and does not have a state-appointed registered agent in the way a state-chartered corporation does. Regulatory correspondence and complaints route through the National Credit Union Administration (NCUA) Consumer Assistance Center, not through a state banking department or the OCC. This is a materially different escalation path from every bank in this tracker.", "Company Brief": "Navy Federal Credit Union is the world's largest credit union by both assets and membership, headquartered in Vienna, Virginia. Membership is restricted to armed-forces members, veterans, Department of Defense civilian personnel, and their families. It is member-owned and not-for-profit, and is the largest originator of VA home loans in the country.", "Investor Overview": "Not publicly traded — member-owned cooperative under federal charter. ~13 million members, ~$165B+ in assets. INVESTOR/ANALYST-RELEVANT: as a credit union, Navy Federal returns surplus to members through rates and fee structures rather than to shareholders, and is exempt from federal income tax on that basis. Its regulator is the NCUA; deposits are insured by the NCUSIF rather than the FDIC. Concentration risk is unusual and structural: its entire membership is tied to military and DoD employment.", "Major Issues Record": "Structural, not incident-based: Navy Federal's 60-day arbitration opt-out is among the longest documented in this tracker — but its member population is uniquely likely to be unable to use it. A service member who receives deployment orders shortly after opening an account may have no reliable mail access for longer than the opt-out window, and the opt-out requires written notice. Navy Federal has also been the subject of public reporting and regulatory attention regarding mortgage-lending approval-rate disparities; that reporting was NOT independently verified this pass and should be confirmed before being cited.", "T&C Key Provisions (paraphrased)": "PARAPHRASED, not quoted. Navy Federal's account agreements provide for binding arbitration with a class-action waiver and a 60-day window to opt out by written notice. Because the institution is federally chartered, disputes that are not arbitrated fall under federal credit union law and NCUA supervision rather than state banking regulation. CONSUMER ACTION: for deploying service members, exercise the arbitration opt-out AT ACCOUNT OPENING rather than later — the 60-day clock does not pause for deployment.", "Re-verify By": "2027-02-13", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Navy Federal's binding arbitration clause has a 60-day opt-out that many deploying service members can't reasonably use.\nWHAT THE TERMS SAY: Per the tracker's paraphrase of the Key Provisions, Navy Federal's account agreements include binding arbitration with a class-action waiver and a 60-day window to opt out by written notice; the clock does not pause for deployment.\nWHY IT MATTERS: A service member who receives deployment orders shortly after opening an account may lack reliable mail access within the 60-day window, structurally locking a uniquely mobile membership base into arbitration.\n(evidence: T&C Key Provisions (paraphrased) | Major Issues Record; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] Navy Federal is not FDIC-insured — it's insured by NCUA instead, a distinction many military families banking there may not realize.\nWHAT THE TERMS SAY: Navy Federal is a credit union regulated by NCUA, not FDIC, per the tracker; 'FDIC-insured' is the phrase most consumers are trained to look for.\nWHY IT MATTERS: Members may not recognize their deposit insurance comes from a different (though comparable) federal system.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DISCRIMINATORY_PRACTICE · FL-4] Public reporting alleges mortgage-lending approval-rate disparities at Navy Federal, though the tracker says this was not independently verified.\nWHAT THE TERMS SAY: The tracker notes Navy Federal 'has also been the subject of public reporting and regulatory attention regarding mortgage-lending approval-rate disparities; that reporting was NOT independently verified this pass and should be confirmed before being cited.'\nWHY IT MATTERS: If confirmed, this would raise fair-lending concerns for a uniquely large military-serving institution; as of this review it remains an unverified allegation.\n(evidence: Major Issues Record; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are stated via paraphrase (with some inconsistency in the tracker's own summary field), and a discrimination allegation is explicitly unverified.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 23, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 23/30 (forced_arbitration+12, class_action_waiver+9, optout_window_unverified+2) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Navy Federal Credit Union  <-  Navy Federal Credit Union (federal charter, member-owned)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (10 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Navy Federal Credit Union you gave up your right to sue and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 60.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Navy Federal is the single largest financial institution serving military-affiliated households in this entire region — and it is NOT insured by the FDIC. It's insured by the NCUA instead (a comparable but separate federal insurance system for credit unions), a distinction many military families banking here may not realize, since 'FDIC-insured' is the phrase most people are trained to look for.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Banks (DMV)", "_row_id": 59, "_entity_id": 95, "_entity_slug": "navy-federal-credit-union", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "PenFed Credit Union", "Category": "Credit Union", "Terms & Conditions URL": "penfed.org (Membership/Account Agreement not individually located this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "penfed.org/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Does not share mobile contact info with third parties/affiliates for marketing; explicitly excludes text-message opt-in/consent data from any third-party sharing; standard cookie/ad-tech data collection otherwise.", "Arbitration / Class Action Waiver": "Not confirmed whether membership/account agreement includes arbitration — verify directly.", "Fees / Billing Flags": "Not confirmed this pass.", "Notes": "Second-largest DMV-headquartered credit union (HQ McLean/Alexandria/Tysons area, VA); member-owned, regulated by NCUA not FDIC.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "McLean", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Pentagon Federal Credit Union, Box 1432, Alexandria, VA 22313-2032, USA (stated in PenFed's own privacy policy as the written-request address). DMV-local: PenFed is headquartered in the Washington metro area and its membership skews heavily toward military and federal households in this tracker's core region.", "Legal / Privacy Contact Email": "privacy@penfed.org (also 1-800-247-5626)", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: McLean, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "Pentagon Federal Credit Union (federal charter, member-owned)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Pentagon Federal Credit Union (federal charter, member-owned)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] Whether PenFed's membership agreement includes an arbitration clause was not confirmed, despite otherwise clean data-sharing disclosures.\nWHAT THE TERMS SAY: The tracker states 'whether its actual membership agreement contains an arbitration clause was NOT confirmed in this review, meaning the right to sue in court could still be waived.'\nWHY IT MATTERS: Members can't tell from this review whether they've given up their right to sue in court.\n(evidence: Arbitration / Class Action Waiver | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing practices are stated positively; fees were not confirmed this pass; only the arbitration open-question is a substantive (if unconfirmed) concern.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=N; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Data-sharing disclosures are clear and specific, but arbitration and fees remain unconfirmed.", "Exposure Score (0-100)": 8, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "PenFed Credit Union  <-  Pentagon Federal Credit Union (federal charter, member-owned)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your data shared corporate-wide.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, PenFed Credit Union takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "PenFed's disclosures are notably better than most large banks in this tab — no third-party marketing sharing of mobile contact info, explicit exclusion of text-consent data from sharing. The one open question: whether its actual membership agreement contains an arbitration clause was NOT confirmed in this review, meaning the right to sue in court could still be waived even though the data-sharing practices themselves look comparatively clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Banks (DMV)", "_row_id": 60, "_entity_id": 97, "_entity_slug": "penfed-credit-union", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fidelity Investments", "Category": "Brokerage", "Terms & Conditions URL": "fidelity.com/bin-public/060_www_fidelity_com/documents/customer-service/updated-agreements/Updated-Fidelity-Account-Customer-Agreement.pdf", "T&C Direct PDF?": "YES", "Privacy Policy URL": "fidelity.com/go/privacy (privacy policy not individually located as direct PDF this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Does NOT receive payment for order flow (PFOF) — one of only 4 major US brokers (with Vanguard, Merrill Edge, Interactive Brokers' pro accounts) that avoids this conflict-of-interest revenue model; Fidelity has marketed this as a differentiator, claiming better execution quality than PFOF-reliant peers.", "Arbitration / Class Action Waiver": "Standard FINRA-required predispute arbitration disclosure expected in brokerage agreements (industry standard — not independently confirmed word-for-word this pass, but Customer Agreement references dispute resolution).", "Fees / Billing Flags": "Foreign ordinary share trading and international market access carry additional risks/fees noted in the agreement; standard commission-free stock/ETF trading otherwise.", "Notes": "Largest brokerage in the US by assets under administration (~$17.5T AUA, 51.5M+ clients); the no-PFOF positioning is a genuine, verifiable point of contrast worth highlighting to customers comparing brokers.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Boston", "HQ State": "Massachusetts", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Fidelity Brokerage Services LLC, 900 Salem Street, Smithfield, RI 02917, USA (the entity address stated on Fidelity's privacy pages). IMPORTANT CAVEAT, and it is itself a finding: Fidelity's privacy policy does NOT publish a single privacy mailing address — it states that the applicable addresses are listed on your own statements and correspondence, and directs customers served through an investment professional to contact that professional instead. General correspondence has historically routed to P.O. Box 500, Merrimack, NH 03054-0500. Confirm against your current statement before sending anything time-sensitive.", "Legal / Privacy Contact Email": "No published privacy email; secure message via account login, or 800-544-6666", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Massachusetts' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Massachusetts SOC Corporate Search — corp.sec.state.ma.us/corpweb/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Even Fidelity is expected to carry the standard FINRA arbitration clause, though not confirmed this pass.\nWHAT THE TERMS SAY: Per the tracker, a standard FINRA-required predispute arbitration disclosure is expected in Fidelity's brokerage agreements (industry standard; not independently confirmed word-for-word this pass, though the Customer Agreement references dispute resolution).\nWHY IT MATTERS: Fidelity's no-PFOF positioning on execution quality doesn't extend to preserving a customer's right to sue in open court.\n(evidence: Arbitration / Class Action Waiver | SCARY; Inferred from tracker text (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No-PFOF status is a positive differentiator, not a troubling term, and fee disclosures are minor (foreign-share trading risk only); only the industry-standard arbitration clause is a substantive, if unconfirmed-verbatim, finding.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration is only inferred as industry-standard, not independently confirmed word-for-word.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Fidelity Investments  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Fidelity Investments you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:24:02Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Even Fidelity — the broker that markets itself as the customer-friendly, no-conflict choice by refusing payment-for-order-flow — still requires the same industry-standard FINRA arbitration clause as everyone else. Being the 'good' broker on execution quality doesn't mean you keep your right to sue in open court if something goes wrong.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 61, "_entity_id": 98, "_entity_slug": "fidelity-investments", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Charles Schwab (incl. legacy TD Ameritrade)", "Category": "Brokerage", "Terms & Conditions URL": "schwab.com/legal/schwab-brokerage-account-agreement", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "schwab.com privacy policy (not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "DOES receive PFOF (unlike Fidelity/Vanguard/Merrill) — a real conflict-of-interest disclosure point since Schwab markets itself similarly to Fidelity on cost/quality grounds without the same no-PFOF claim.", "Arbitration / Class Action Waiver": "Contains a predispute arbitration clause with the FULL regulatory-mandated disclosure text (FINRA requires this exact disclosure in all brokerage agreements): customers give up the right to sue in court AND to a jury trial; discovery is more limited than in court; arbitrators need not explain their reasoning unless jointly requested; a minority of arbitrators may be affiliated with the securities industry itself; class actions are blocked UNLESS a customer already opted out of a certified class before Schwab could compel arbitration. Governed by California law generally, but arbitration section specifically governed by the Federal Arbitration Act.", "Fees / Billing Flags": "0.01% APY on uninvested cash (notably low, called out by Forbes as a shortcoming); margin rates 10.075%–11.825% depending on balance.", "Notes": "Acquired TD Ameritrade in 2019/2020 — legacy TD Ameritrade customers are now under Schwab's account agreement and arbitration terms, not TD Ameritrade's original ones.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$23.9B", "Market Cap": "$175.3B", "Employees": "32,100", "HQ City": "Westlake", "HQ State": "Texas", "CEO": "Richard Wurster", "Ticker": "SCHW", "Website (Corporate)": "aboutschwab.com", "Main Mailing Address (legal/privacy notices)": "NO US PRIVACY MAILING ADDRESS PUBLISHED in the notices reviewed this pass. Schwab's consumer privacy notice routes the federal sharing opt-out to a PHONE line: 1-877-812-1817 within the US, or +1-415-667-8400 from outside. The only mailing address surfaced is for international clients — Charles Schwab & Co., Inc., Attn: International Operations, 1945 Northwestern Drive, El Paso, TX 79912-1108 — which is NOT a general privacy address. Schwab also operates through multiple entities (Charles Schwab & Co., Inc. and Charles Schwab Bank, SSB), so identify the one holding your account before writing.", "Legal / Privacy Contact Email": "No published privacy email; opt-out is by phone at 1-877-812-1817", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (SCHW). Service route: c/o General Counsel / Corporate Secretary, Westlake, Texas — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Schwab's arbitration clause admits arbitrators may be affiliated with the securities industry and need not explain their rulings.\nWHAT THE TERMS SAY: Schwab's predispute arbitration clause requires customers to give up the right to sue in court and to a jury trial; discovery is more limited than in court; arbitrators need not explain their reasoning unless jointly requested; and a minority of arbitrators may be affiliated with the securities industry itself.\nWHY IT MATTERS: A customer disputing their broker may be judged by someone with industry ties and may never learn the reasoning behind an adverse ruling.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Schwab's agreement blocks class actions unless a customer already opted out of a certified class before Schwab could compel arbitration.\nWHAT THE TERMS SAY: Per the tracker, class actions are blocked 'UNLESS a customer already opted out of a certified class before Schwab could compel arbitration.'\nWHY IT MATTERS: This narrow carve-out makes group litigation against Schwab practically difficult to pursue for most customers.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-1] Schwab receives payment for order flow, unlike Fidelity, Vanguard, and Merrill Edge.\nWHAT THE TERMS SAY: Unlike Fidelity/Vanguard/Merrill, Schwab DOES receive PFOF, per the tracker, despite marketing itself similarly to Fidelity on cost/quality without making the same no-PFOF claim.\nWHY IT MATTERS: The tracker calls Schwab's receipt of PFOF a real conflict-of-interest disclosure point, since Schwab markets itself similarly to Fidelity on cost/quality grounds without making the same no-PFOF claim.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Arbitration terms are stated in detail with the full regulatory disclosure text quoted/paraphrased.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 30, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 30/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Charles Schwab (incl. legacy TD Ameritrade)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to a jury.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Charles Schwab (incl. legacy TD Ameritrade) you gave up your right to sue, your right to join a class action, and your right to a jury. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:24:05Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Schwab's own required arbitration disclosure admits, in writing, that 'a MINORITY OF ARBITRATORS MAY BE AFFILIATED WITH THE SECURITIES INDUSTRY' — meaning the person deciding your dispute against your broker could have professional ties to the very industry your broker belongs to. The same disclosure notes arbitrators 'need not explain their reasoning' for a ruling, so you may never even learn WHY you lost.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 62, "_entity_id": 99, "_entity_slug": "charles-schwab-incl-legacy-td-ameritrade", "_issuer": "Charles Schwab (incl. legacy TD Ameritrade)", "_issuer_slug": "charles-schwab-incl-legacy-td-ameritrade", "_ticker": "SCHW", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Vanguard", "Category": "Brokerage", "Terms & Conditions URL": "investor.vanguard.com (Brokerage Account Agreement — direct URL not individually captured this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "vanguard.com privacy policy (not individually located this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Does NOT receive PFOF — same no-conflict positioning as Fidelity and Merrill Edge.", "Arbitration / Class Action Waiver": "Standard FINRA-mandated predispute arbitration disclosure expected (industry standard for all US broker-dealers) — not independently confirmed word-for-word this pass.", "Fees / Billing Flags": "Some Vanguard mutual funds carry higher minimum initial investments (e.g., $3,000 for Admiral Shares funds) compared to $0-minimum competitor funds — a real access/equity consideration for lower-balance investors, distinct from any legal-terms issue.", "Notes": "Second/third-largest brokerage by AUM (~$11.6–12T); more focused on long-term/retirement investing than active trading; largest single owner-structure distinction is that Vanguard funds are owned by their own shareholders (the funds themselves own Vanguard) — a genuinely different corporate structure from every other for-profit brokerage on this list, worth noting if governance/incentive-alignment is relevant to your audit.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Malvern", "HQ State": "Pennsylvania", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "The Vanguard Group, Inc., 100 Vanguard Boulevard, Malvern, PA 19355-2331, USA. Vanguard's own privacy notice additionally gives a mailing address of P.O. Box 1110, Valley Forge, PA 19482-1110 — use the P.O. box for written correspondence, consistent with the pattern across this tracker that the policy address is not the headquarters.", "Legal / Privacy Contact Email": "No published privacy email; written requests to the Valley Forge P.O. box", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[OTHER · FL-1] Vanguard requires a $3,000 minimum investment to access its lower-fee Admiral Shares tier, so lower-balance investors pay higher ongoing fees on the same funds.\nWHAT THE TERMS SAY: Per the tracker, some Vanguard mutual funds (e.g., Admiral Shares) require a $3,000 minimum initial investment, compared to $0-minimum competitor funds; investors below that threshold are stuck on higher-fee share classes of the same fund.\nWHY IT MATTERS: Customers with the least money to invest pay proportionally more in fees for identical underlying funds.\n(evidence: Fees / Billing Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Vanguard, like other brokers, is expected to include the standard FINRA predispute arbitration clause, though this wasn't independently confirmed word-for-word.\nWHAT THE TERMS SAY: The tracker notes a standard FINRA-mandated predispute arbitration disclosure is expected industry-wide for all US broker-dealers, but was not independently confirmed word-for-word for Vanguard this pass.\nWHY IT MATTERS: Absent independent confirmation, customers can't be certain of the exact arbitration terms governing disputes with Vanguard.\n(evidence: Arbitration / Class Action Waiver; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No-PFOF status is a positive differentiator, and the arbitration clause is only presumed industry-standard rather than confirmed; only the fee-tier and presumed-arbitration items are substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Fee-tier structure is clearly stated, but PFOF-free status is positive and arbitration terms are unconfirmed.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Vanguard  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Vanguard takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Vanguard markets itself as the low-cost, investor-owned choice — but its Admiral Shares mutual funds require a $3,000 MINIMUM investment to access the lower fee tier. Investors who can't reach that threshold are stuck paying HIGHER ongoing fees on the exact same fund, meaning the customers with the LEAST money to invest pay proportionally more for the privilege.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 63, "_entity_id": 100, "_entity_slug": "vanguard", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Robinhood", "Category": "Brokerage", "Terms & Conditions URL": "robinhood.com/us/en/support/articles/customer-agreement/ (Customer Agreement — direct URL not individually captured this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "robinhood.com/us/en/support/articles/robinhood-privacy-policy/", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "PFOF has historically been Robinhood's PRIMARY revenue source — 77% of net revenue in 2021 ($1.4B, split 49% options/30% crypto/21% equities); SEC found in a Dec 2020 settlement that Robinhood made misleading statements about PFOF as its main revenue source and failed its 'best execution' duty to customers, resulting in a $65 MILLION SEC FINE — among the largest broker-specific enforcement actions in this audit's carrier/bank/ISP/auto findings so far. SEC also found Robinhood customers got meaningfully worse execution prices (up to $15 worse per 500-share order) than customers at non-PFOF brokers, even after accounting for those brokers' per-trade commissions.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 60-DAY opt-out from account opening (double the industry standard). AAA rules, Federal Arbitration Act. CRITICAL TENSION: FINRA Rule 2268 and Regulatory Notice 21-16 (April 2021) explicitly PROHIBIT FINRA member firms from including class action waivers in customer agreements — yet Robinhood's agreement includes one. Robinhood's securities brokerage (Robinhood Financial LLC) is a FINRA member, but Robinhood Crypto LLC is NOT. The class action waiver may be unenforceable for securities disputes but enforceable for crypto disputes. The $65M SEC settlement (Dec 2020) over PFOF was a regulatory action not affected by the arbitration clause.", "Fees / Billing Flags": "Zero-commission model funded almost entirely by PFOF and other transaction-based revenue rather than direct customer fees.", "Notes": "This is a genuinely major, concrete, already-adjudicated regulatory finding (not a live lawsuit like Toyota's, but a completed and paid SEC settlement) — one of the strongest customer-protection findings in the entire audit to date.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Menlo Park", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 60, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": "https://www.sec.gov/newsroom/press-releases/2020-321", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Robinhood Markets, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Robinhood Markets, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] The SEC fined Robinhood $65 million after finding it misled customers about relying on payment for order flow for 77% of revenue while giving worse trade execution.\nWHAT THE TERMS SAY: Per the tracker, the SEC's Dec 2020 settlement found Robinhood made misleading statements about PFOF as its main revenue source (77% of 2021 net revenue, $1.4B) and failed its 'best execution' duty; customers got execution prices up to $15 worse per 500-share order than at non-PFOF brokers.\nWHY IT MATTERS: Customers paid a hidden cost in worse trade prices while believing the 'commission-free' app had no cost, and Robinhood has already paid a $65M fine for the misrepresentation.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Robinhood's class-action waiver may violate a FINRA rule that bars such waivers, though it may still be enforceable for crypto disputes.\nWHAT THE TERMS SAY: Per the tracker, FINRA Rule 2268 prohibits FINRA member firms from including class-action waivers, yet Robinhood's agreement includes one; because Robinhood Financial LLC is a FINRA member but Robinhood Crypto LLC is not, the waiver 'may be unenforceable for securities disputes but enforceable for crypto disputes.'\nWHY IT MATTERS: Customers face real uncertainty about whether they've actually given up their right to join a class action, depending on which Robinhood entity governs their account.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OPT_OUT_DEADLINE · FL-3] Robinhood's arbitration opt-out runs 60 days from account opening - double the industry standard.\nWHAT THE TERMS SAY: Robinhood requires mandatory binding arbitration with a class-action waiver, with a 60-day opt-out window from account opening, using AAA rules under the Federal Arbitration Act.\nWHY IT MATTERS: Customers who don't affirmatively opt out within 60 days of opening an account are bound to arbitration for future disputes.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Regulatory findings, fine amount, and arbitration terms are all stated in specific, confirmed detail.", "Exposure Score (0-100)": 36, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 22, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 22/30 (forced_arbitration+12, class_action_waiver+9, optout_60d+1) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Robinhood  <-  Robinhood Markets, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Robinhood you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:24:07Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "The SEC found that Robinhood publicly downplayed how much it relied on selling your trades to market makers (payment for order flow) — which was actually 77% OF ALL COMPANY REVENUE — while customers got EXECUTION PRICES UP TO $15 WORSE per 500-share order than they would have gotten elsewhere. Robinhood paid a $65 MILLION fine for it. The 'commission-free' app wasn't free — the cost was just hidden in the price you actually got for your trade.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 64, "_entity_id": 102, "_entity_slug": "robinhood", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Merrill Edge (Bank of America)", "Category": "Brokerage", "Terms & Conditions URL": "merrilledge.com (Customer Agreement — direct URL not individually captured this pass; likely shares Bank of America's broader arbitration framework given the parent relationship)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "merrilledge.com / bankofamerica.com/privacy (shared parent privacy policy likely applies)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Does NOT receive PFOF — same no-conflict positioning as Fidelity and Vanguard.", "Arbitration / Class Action Waiver": "IMPORTANT CROSS-REFERENCE: Bank of America (Merrill's parent) added mandatory arbitration + a class action waiver to its Deposit Agreement in early 2026 (see Banks tab) — verify directly whether this change also extends to or mirrors Merrill Edge's separate brokerage account agreement, since the two products are legally distinct documents even under the same parent company.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Part of Bank of America's Global Wealth and Investment Management division (with Merrill and BofA Private Bank), overseeing $2.2T+ in combined client balances.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Charlotte", "HQ State": "North Carolina", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NC SOS Business Registration Search — sosnc.gov/online_services/search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] Whether Merrill Edge's brokerage agreement now includes forced arbitration, following parent Bank of America's 2026 change to its deposit agreements, is unconfirmed.\nWHAT THE TERMS SAY: The tracker flags that Bank of America (Merrill's parent) added mandatory arbitration and a class-action waiver to its bank Deposit Agreement in early 2026 [a Bank of America finding, documented on the Banks tab], and notes it has not been independently confirmed whether this extends to or mirrors Merrill Edge's separate brokerage account agreement.\nWHY IT MATTERS: Merrill Edge investment customers can't currently tell whether the arbitration terms governing their checking account now also apply to their separate investment account.\n(evidence: Arbitration / Class Action Waiver | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No-PFOF status is a positive differentiator and fees are not itemized this pass; the only substantive, company-specific concern is the open question of whether Merrill Edge's own brokerage agreement now includes forced arbitration, which was not independently confirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Merrill Edge's own arbitration terms are entirely unconfirmed; only the parent bank's separate policy change is documented.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Merrill Edge (Bank of America)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Merrill Edge (Bank of America) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Merrill Edge's parent, Bank of America, just reversed decades of policy and added FORCED ARBITRATION to its bank deposit agreements in early 2026 (see the Bank of America row, Banks tab). Whether that same reversal has quietly crept into Merrill's SEPARATE brokerage agreement — the one governing your actual investments — has not been independently confirmed. Two related products, same parent company, and a real open question about whether your investment account is now covered by the same new waiver as your checking account.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 65, "_entity_id": 103, "_entity_slug": "merrill-edge-bank-of-america", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Morgan Stanley / E*TRADE", "Category": "Brokerage", "Terms & Conditions URL": "etrade.com / morganstanley.com (Customer Agreement — direct URL not individually captured this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "etrade.com privacy policy (not individually located this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "E*TRADE DOES receive PFOF (per the PFOF broker list) — same conflict-of-interest consideration as Robinhood/Schwab/Ally/Webull/TradeStation/tastytrade, though no equivalent SEC enforcement action was found for E*TRADE specifically this pass.", "Arbitration / Class Action Waiver": "MANDATORY pre-dispute arbitration per FINRA rules (Morgan Stanley is a FINRA member). FINRA arbitration is structurally different from AAA/JAMS consumer arbitration — it uses FINRA's own forum, its own neutrals, and its own procedural rules. FINRA Rule 2268 prohibits class action waivers in customer agreements, so Morgan Stanley/E*TRADE CANNOT include a class action waiver for securities disputes, unlike Robinhood's crypto agreement.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Morgan Stanley acquired E*TRADE in 2020; legacy E*TRADE retail customers are now under a Morgan Stanley-affiliated entity's terms — verify which specific account agreement (legacy E*TRADE vs. Morgan Stanley proper) currently governs any given customer relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$70.6B", "Market Cap": "$343.5B", "Employees": "80,478", "HQ City": "New York", "HQ State": "New York", "CEO": "Edward Pick", "Ticker": "MS", "Website (Corporate)": "morganstanley.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (MS). Service route: c/o General Counsel / Corporate Secretary, New York, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2020", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[UNILATERAL_CHANGES · FL-4] Legacy E*TRADE customers are now bound by a Morgan Stanley-affiliated entity's terms they may never have directly reviewed.\nWHAT THE TERMS SAY: Morgan Stanley acquired E*TRADE in 2020; per the tracker, legacy E*TRADE retail customers are now under a Morgan Stanley-affiliated entity's terms, and 'depending on exactly which legal entity governs your specific account, you may be bound to terms you never directly reviewed or agreed to.'\nWHY IT MATTERS: Customers who opened accounts with E*TRADE may not know which specific legal entity and terms now govern their account.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-1] E*TRADE receives payment for order flow; no equivalent SEC enforcement was found for it this pass.\nWHAT THE TERMS SAY: Per the tracker, E*TRADE receives PFOF, grouping it with Robinhood, Schwab, Ally, Webull, TradeStation, and tastytrade on this conflict-of-interest point; no equivalent SEC enforcement action was found for E*TRADE specifically this pass.\nWHY IT MATTERS: E*TRADE carries the same conflict-of-interest consideration the tracker applies to the other PFOF brokers it lists, though no equivalent SEC enforcement action was found for E*TRADE specifically this pass.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (firewall-edited: unverifiable figure removed) (fidelity pass 2 (strict): Cross-ref leak corrected))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Morgan Stanley/E*TRADE requires mandatory predispute arbitration under FINRA rules for all customer disputes.\nWHAT THE TERMS SAY: Per the tracker, mandatory pre-dispute arbitration applies per FINRA rules since Morgan Stanley is a FINRA member; FINRA's own forum, neutrals, and procedural rules apply, distinct from AAA/JAMS consumer arbitration.\nWHY IT MATTERS: Customers give up the option to sue in court, though FINRA Rule 2268 does at least bar a class-action waiver for securities disputes here.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=N; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration structure and PFOF status are documented, but fees are not itemized and the exact governing entity/terms post-merger is uncertain.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 5/20 (unilateral_modification+5) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Morgan Stanley / E*TRADE  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Morgan Stanley / E*TRADE you gave up your right to sue and your right to be consulted before terms change. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "If you opened your account with E*TRADE, you're now technically a Morgan Stanley customer — Morgan Stanley acquired E*TRADE in 2020, and legacy E*TRADE accounts now sit under a Morgan Stanley-affiliated entity's terms. Depending on exactly which legal entity governs your specific account, you may be bound to terms you never directly reviewed or agreed to.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 66, "_entity_id": 104, "_entity_slug": "morgan-stanley-e-trade", "_issuer": "Morgan Stanley / E*TRADE", "_issuer_slug": "morgan-stanley-e-trade", "_ticker": "MS", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "J.P. Morgan Self-Directed Investing", "Category": "Brokerage", "Terms & Conditions URL": "static.chasecdn.com/content/dam/legal-agreements/library/en/dwm_olt_brok-acct_esign_la/versions/dwm_olt_brok-acct_esign_la.pdf", "T&C Direct PDF?": "YES", "Privacy Policy URL": "jpmorgan.com/wealth-management (privacy notice not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "JPMS (the broker-dealer entity) is an affiliate of Chase Bank and other JPMorgan Chase entities; affiliates are paid fees for providing services to J.P. Morgan-branded mutual funds held in customer accounts — a standard but disclosed affiliate-compensation conflict.", "Arbitration / Class Action Waiver": "Dispute arbitration clause confirmed in Section 10 (pages 13+) of the Disclosures document — standard FINRA-style predispute arbitration expected industry-wide.", "Fees / Billing Flags": "Does NOT accept PFOF (payment for order flow) — joins Fidelity, Vanguard, Merrill Edge, and Interactive Brokers as one of the no-PFOF brokers in this tracker; 2026 execution quality reported at 97.75%, slightly above the ~97.51% industry average across all reviewed brokers. Does not support futures, forex, or IPO access — a real product-limitation trade-off for the no-PFOF/low-cost model.", "Notes": "Same parent company (JPMorgan Chase) as the Chase bank already documented in the Banks tab — a customer using both Chase banking and J.P. Morgan Self-Directed Investing is under two related but legally distinct agreements from the same corporate family.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] J.P. Morgan's own affiliates get paid fees for servicing J.P. Morgan-branded funds held inside your self-directed investing account.\nWHAT THE TERMS SAY: Per the tracker, JPMS (the broker-dealer) is an affiliate of Chase Bank and other JPMorgan Chase entities, and affiliates are paid fees for providing services to J.P. Morgan-branded mutual funds held in customer accounts — a disclosed affiliate-compensation conflict.\nWHY IT MATTERS: The broker has a built-in financial incentive tied to whether customers hold its own house-brand funds, a conflict that's disclosed but not prominently advertised.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] J.P. Morgan Self-Directed Investing's customer agreement contains a confirmed mandatory arbitration clause in Section 10.\nWHAT THE TERMS SAY: The tracker confirms a dispute arbitration clause in Section 10 (pages 13+) of the Disclosures document, standard FINRA-style predispute arbitration expected industry-wide.\nWHY IT MATTERS: Customers give up the right to sue in court over account disputes.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No-PFOF status and above-average execution quality are positive findings, and product limitations (no futures/forex/IPO) are a disclosed trade-off rather than a troubling term; only the affiliate-compensation conflict and confirmed arbitration clause are substantive troubling items.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Arbitration clause location and affiliate-compensation practice are both specifically confirmed and cited.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "J.P. Morgan Self-Directed Investing  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using J.P. Morgan Self-Directed Investing you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:24:09Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "J.P. Morgan's own AFFILIATES get paid fees for servicing J.P. Morgan-BRANDED mutual funds — the same funds sitting inside YOUR self-directed account. Your broker has a built-in financial incentive tied to whether you hold its own house-brand products, quietly disclosed rather than loudly advertised.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 67, "_entity_id": 105, "_entity_slug": "j-p-morgan-self-directed-investing", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ally Invest", "Category": "Brokerage", "Terms & Conditions URL": "ally.com/content/dam/pdf/invest/customer-agreement.pdf", "T&C Direct PDF?": "YES", "Privacy Policy URL": "ally.com/legal/privacy/ (not individually confirmed as a distinct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "By default, discloses customer name/address/securities positions to requesting companies under SEC Rule 14b-1(c) UNLESS the customer sends written objection — an opt-OUT (not opt-in) default; uses Apex Clearing as third-party custodian, meaning customer securities legally reside at Apex, not Ally, creating a split counterparty structure.", "Arbitration / Class Action Waiver": "Standard FINRA predispute arbitration clause for securities accounts (Section 38, mandatory, same boilerplate disclosure language as Schwab/Fidelity/industry standard). NOTABLE CONTRAST: Ally's SEPARATE futures-trading arbitration agreement is explicitly OPTIONAL and 'MAY BE DECLINED BY CUSTOMER' — unlike the mandatory securities-account arbitration, this is a real, functioning opt-in structure for futures accounts specifically (CFTC rules require this distinction, unlike SEC/FINRA rules for securities).", "Fees / Billing Flags": "DOES receive PFOF; routes nearly 100% of equity order flow to wholesalers (Citadel, Virtu, etc.) per 2026 forensic review; cash sweep rates in the brokerage account earn NO interest by default (separate from Ally's own high-yield savings product) — a real 'idle cash' yield gap customers should know to actively manage; received a $75,000 FINRA fine in Oct 2025 for lapses in monitoring customers' 'outside accounts.'", "Notes": "Loss-leader positioning for parent Ally Bank; no fractional shares as of Feb 2026, unlike most peers.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Charlotte", "HQ State": "North Carolina", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'North Carolina' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NC SOS Business Registration Search — sosnc.gov/online_services/search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Ally Invest discloses your name, address, and stock holdings to outside companies by default unless you send a written objection.\nWHAT THE TERMS SAY: Per the tracker, under SEC Rule 14b-1(c), Ally by default discloses customer name/address/securities positions to requesting companies unless the customer sends written objection — an opt-out, not opt-in, default.\nWHY IT MATTERS: Customers who don't proactively object have their identity and specific stock holdings shared with outside requesting companies.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-1] Ally Invest paid a $75,000 FINRA fine in October 2025 for lapses in monitoring customers' outside accounts.\nWHAT THE TERMS SAY: Per the tracker, Ally received a $75,000 FINRA fine in Oct 2025 for lapses in monitoring customers' 'outside accounts.'\nWHY IT MATTERS: A confirmed regulatory finding of inadequate compliance monitoring by the broker.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-1] Ally routes nearly 100% of equity order flow to wholesalers like Citadel for payment, while paying $0 interest by default on uninvested cash in the brokerage account.\nWHAT THE TERMS SAY: Per the tracker's 2026 forensic review, Ally routes nearly 100% of equity order flow to wholesalers (Citadel, Virtu, etc.) for PFOF payment; cash sweep balances in the brokerage account earn no interest by default, separate from Ally's own high-yield savings product.\nWHY IT MATTERS: Customers face both an execution-quality conflict of interest and an easily-missed zero-yield default on cash sitting in their account.\n(evidence: Fees / Billing Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Default data-sharing rule, PFOF routing, fine amount, and cash-sweep terms are all specifically documented.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 14, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 14/30 (forced_arbitration+12, optout_window_unverified+2) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 11/20 (severity3+8, penalty+3) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Ally Invest  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ally Invest you gave up your data shared corporate-wide, your right to sue, and your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:24:12Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "By DEFAULT, Ally will hand your name, address, and exactly which STOCKS YOU PERSONALLY OWN to any outside company that requests it under an SEC rule — unless YOU proactively send a WRITTEN OBJECTION to opt out. Combine that with Ally routing nearly 100% of trades to firms like Citadel for payment, a $75,000 FINRA fine for failing to monitor customers' outside accounts, and $0 interest by default on uninvested cash sitting in the brokerage account — several separate, quietly stacked disadvantages for the average Ally Invest customer.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 68, "_entity_id": 106, "_entity_slug": "ally-invest", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Interactive Brokers", "Category": "Brokerage", "Terms & Conditions URL": "interactivebrokers.com (Customer Agreement — direct URL not individually captured this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "interactivebrokers.com privacy policy (not individually located this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass.", "Arbitration / Class Action Waiver": "MANDATORY pre-dispute arbitration per FINRA rules. FINRA member. Same FINRA Rule 2268 protection: no class action waiver permitted for securities disputes. Interactive Brokers' customer agreement uses the standard FINRA disclosure language required by the rule.", "Fees / Billing Flags": "Does NOT receive PFOF on its commission-charging 'Pro' account tier (unique among major discount brokers reviewed here — achieves this by charging per-trade commissions instead of relying on order-flow rebates); consistently cited as having the fastest trade execution speeds in the industry (sub-100ms per one 2026 forensic comparison, ~10x faster than PFOF-heavy competitors like Ally).", "Notes": "Positioned as the choice for active/professional traders wanting execution-speed transparency rather than a PFOF-subsidized zero-commission model — a genuinely different value proposition worth explaining to customers comparing brokers on more than headline price.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Greenwich", "HQ State": "Connecticut", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Connecticut' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Connecticut SOTS CONCORD — service.ct.gov/business/s/onlinebusinesssearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Interactive Brokers requires mandatory FINRA arbitration for disputes, though its specific retail arbitration clause language was not independently confirmed.\nWHAT THE TERMS SAY: Per the tracker, mandatory pre-dispute arbitration applies since Interactive Brokers is a FINRA member, using the standard FINRA disclosure language required by the rule; however, the SCARY note states the actual retail-account arbitration clause was not independently confirmed this pass.\nWHY IT MATTERS: Customers give up the right to sue in court, and the exact terms of that trade-off for retail accounts remain unverified.\n(evidence: Arbitration / Class Action Waiver | SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing practices were not independently confirmed this pass, and the no-PFOF/fast-execution findings are positive rather than troubling; only the arbitration clause (mandatory in principle, but not independently verified in its specific retail-account language) is a substantive concern.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=N; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration is stated as mandatory in principle via FINRA membership, but the specific retail clause language and data-sharing practices are unconfirmed.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Interactive Brokers  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nTHE DOCUMENT DOES NOT TAKE: your right to join a class action.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Interactive Brokers you gave up your right to sue. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Interactive Brokers earns some of the strongest marks in this entire tracker for NOT taking payment for order flow and delivering sub-100ms trade execution — but its actual arbitration clause for retail accounts was NOT independently confirmed in this review. Fast, transparent execution doesn't automatically tell you what happens to your legal rights if a dispute arises.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 69, "_entity_id": 107, "_entity_slug": "interactive-brokers", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Wealthfront", "Category": "Brokerage (robo-advisor)", "Terms & Conditions URL": "wealthfront.com/static/documents/client-agreements/WEALTHFRONT-STOCK-INVESTING-CLIENT-AGREEMENT.pdf", "T&C Direct PDF?": "YES", "Privacy Policy URL": "wealthfront.com (privacy policy not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass beyond the arbitration/structural findings below.", "Arbitration / Class Action Waiver": "STRUCTURAL COMPLEXITY FLAG: Wealthfront customers are actually bound by TWO SEPARATE legal entities with two separate arbitration clauses — 'Wealthfront Advisers' (the advisory/robo side, Section 22 or 23 depending on account type) and 'Wealthfront Brokerage' (the custody/execution side, a different section number in a different document) — both mandatory, both AAA Consumer Rules, both governed by California law and Federal Arbitration Act, but a customer would need to read TWO documents to understand their full arbitration exposure, not one. Customers CAN opt out of proxy-voting authority (a good transparency feature) but CANNOT opt out of proxy voting for securities currently out on loan through Wealthfront's Securities Lending Program — a real, specific limitation on customer control.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The two-entity/two-arbitration-clause structure is worth flagging as a comprehension burden distinct from the clause content itself — similar in spirit to the SoFi multi-product-single-Terms concern noted above, but here it's the reverse problem (one product, two separate legal agreements).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Palo Alto", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Wealthfront splits into two legal entities with two separate mandatory arbitration clauses, forcing customers to read two documents to know their rights.\nWHAT THE TERMS SAY: Per the tracker, Wealthfront customers are bound by two separate entities — 'Wealthfront Advisers' and 'Wealthfront Brokerage' — each with its own mandatory arbitration clause (AAA Consumer Rules, California law, Federal Arbitration Act) in a different document.\nWHY IT MATTERS: A customer trying to fully understand what dispute rights they've given up must locate and reconcile two separate agreements rather than one.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] Wealthfront's proxy-voting opt-out disappears for any of your securities currently loaned out through its Securities Lending Program.\nWHAT THE TERMS SAY: Customers can opt out of letting Wealthfront vote their shares by proxy, but per the tracker, that opt-out 'DISAPPEARS for any of your securities currently loaned out through its Securities Lending Program.'\nWHY IT MATTERS: A customer who believes they've retained control over how their shares are voted may lose that control silently whenever their shares are on loan.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data-sharing practices and fees were not independently confirmed/itemized this pass; only the two-entity arbitration structure and the proxy-vote opt-out limitation are substantive findings.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration structure and proxy-voting nuance are specifically documented, but data-sharing and fees are unconfirmed/unitemized.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Wealthfront  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Wealthfront you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:24:18Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Wealthfront splits itself into TWO separate legal entities — 'Wealthfront Advisers' and 'Wealthfront Brokerage' — each with its OWN separate arbitration clause in a different document. A customer trying to fully understand what rights they've given up would need to read and reconcile two different agreements, not one. And even where Wealthfront lets you opt out of letting it vote your shares by proxy, that opt-out DISAPPEARS for any of your securities currently loaned out through its Securities Lending Program.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 70, "_entity_id": 108, "_entity_slug": "wealthfront", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Betterment", "Category": "Brokerage (robo-advisor)", "Terms & Conditions URL": "betterment.com/legal/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "betterment.com/legal (privacy policy not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass.", "Arbitration / Class Action Waiver": "Binding arbitration + explicit constitutional-rights waiver language ('YOU AND BETTERMENT HEREBY WAIVE ANY CONSTITUTIONAL AND STATUTORY RIGHTS TO SUE IN COURT') + class action waiver; REQUIRES a good-faith 'Informal Dispute Resolution' notice-and-negotiation process before either party can initiate arbitration — similar to Coinbase's mandatory pre-arbitration complaint process, adding a procedural step most traditional brokerages' clauses don't require; separately carves out 401(k) plan participants and clients under a login/password 'simple services' agreement, whose specific Client Agreements override these general Terms if there's a conflict — meaning the applicable arbitration terms can vary by which specific Betterment product/relationship type a customer has.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Like SoFi and Wealthfront, Betterment's terms structure varies by exactly which product tier a customer uses (retail investor vs. 401(k) participant vs. basic non-discretionary advice client) — a recurring pattern across the robo-advisor/fintech brokerages in this audit worth calling out as a category-wide trend, not a Betterment-specific quirk.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Betterment customers waive constitutional rights to sue in court, not just class actions.\nWHAT THE TERMS SAY: Terms state both parties 'HEREBY WAIVE ANY CONSTITUTIONAL AND STATUTORY RIGHTS TO SUE IN COURT' and require a good-faith 'Informal Dispute Resolution' notice-and-negotiation process before either party can initiate arbitration.\nWHY IT MATTERS: Customers give up the right to a courtroom trial entirely and must first navigate an added negotiation step before they can even begin arbitration.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Betterment also bars customers from joining class actions against it.\nWHAT THE TERMS SAY: The same arbitration clause includes an explicit class action waiver alongside the binding-arbitration and rights-waiver language.\nWHY IT MATTERS: Customers with small individual claims lose the ability to band together, which can make pursuing a claim economically unfeasible.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-3] Which arbitration rules apply to a Betterment customer depends on which product they use.\nWHAT THE TERMS SAY: 401(k) plan participants and 'simple services' login/password clients are carved out, with their specific Client Agreements overriding the general Terms if there's a conflict.\nWHY IT MATTERS: A customer may not know which dispute-resolution rules actually govern them without checking the specific agreement tied to their product tier.\n(evidence: Arbitration | Notes; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are described in detail and quoted directly, but data-sharing and fee practices are both unconfirmed this pass.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Betterment  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Betterment you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:24:20Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Betterment's terms include explicit language stating that BOTH the customer AND Betterment are giving up their CONSTITUTIONAL right to sue in court — phrased in the kind of stark, direct language rarely spelled out this plainly. On top of that, which specific arbitration terms apply to you depends on which Betterment product you're actually using (retail investing vs. 401(k) vs. basic advice) — the SAME company can have DIFFERENT dispute rules depending on which door you came in through.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 71, "_entity_id": 109, "_entity_slug": "betterment", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "M1 Finance", "Category": "Brokerage (robo-advisor + self-directed hybrid)", "Terms & Conditions URL": "m1.com/legal/agreements/", "T&C Direct PDF?": "NO (index page linking to separate PDFs, incl. 'M1 Apex Clearing Customer Account Agreement')", "Privacy Policy URL": "m1.com (privacy notice not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass.", "Arbitration / Class Action Waiver": "Uses Apex Clearing as custodian (same as tastytrade and Ally Invest — see tastytrade row); standard binding arbitration expected via the Apex Customer Account Agreement referenced in M1's own agreements index (not independently confirmed word-for-word this pass).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "M1 also offers banking and lending products (per its agreements page listing 'investing, banking, and lending services') under one umbrella — similar multi-product-single-relationship structure as SoFi, worth the same caution about which specific product's terms actually govern a given customer dispute.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Chicago", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-3] M1 bundles investing, banking, and lending, blurring which agreement covers a dispute.\nWHAT THE TERMS SAY: M1's agreements page lists investing, banking, and lending services under one relationship, without clarity on which specific agreement governs a given customer's issue.\nWHY IT MATTERS: A customer with a problem may not know whether the investing, banking, or lending terms actually apply to their situation.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] M1's arbitration terms are only 'expected,' not independently confirmed word-for-word.\nWHAT THE TERMS SAY: M1 uses Apex Clearing as custodian, and standard binding arbitration is expected via Apex's Customer Account Agreement referenced in M1's agreements index, but the tracker did not independently confirm the exact clause text.\nWHY IT MATTERS: Customers can't be certain of the exact arbitration terms governing them without checking the referenced Apex agreement directly.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data-sharing and fee fields are both unconfirmed this pass; only the product-bundling structure and the unconfirmed arbitration setup are substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration terms are only 'expected' rather than confirmed, and data-sharing and fees are both unconfirmed this pass.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "M1 Finance  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, M1 Finance takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:24:23Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "M1 bundles investing, banking, AND lending into 'one' relationship — but that means when something goes wrong, which specific agreement actually governs your dispute (the investing terms? the banking terms? the lending terms?) is genuinely unclear from the outside. The more products a company bundles together, the harder it becomes for an ordinary customer to know exactly which rulebook applies to their specific problem.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 72, "_entity_id": 110, "_entity_slug": "m1-finance", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Webull", "Category": "Brokerage", "Terms & Conditions URL": "webull.com/protocol/webull_terms_of_service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "webull.com/protocol/webull_privacy_policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "OWNERSHIP FLAG: Webull is owned by Chinese holding company Fumi Technology — a foreign-ownership structure worth flagging given the same national-security/data-security concerns already noted elsewhere in this audit regarding China-linked connected-vehicle technology; broker-dealer/financial services are actually provided by a separate US affiliate under additional privacy guidelines layered on top of the general Webull Privacy Policy — a two-tier structure customers should understand.", "Arbitration / Class Action Waiver": "Notably VAGUE/WEAK arbitration language compared to every other brokerage in this audit: 'both parties agree to settle the dispute through friendly negotiation or arbitration... either party may initiate a lawsuit through local courts in the jurisdiction where Webull is registered' — this is far less specific than the detailed FINRA-style predispute arbitration clauses at Fidelity/Schwab/Ally/etc., and doesn't clearly specify a class-action waiver, arbitration provider, or opt-out process the way US-regulated peers do.", "Fees / Billing Flags": "Requires SSN/ITIN and US citizenship/permanent residency/valid visa to open an account; runs a soft credit inquiry at account opening (does not affect credit score, per company statements).", "Notes": "The vague dispute-resolution language combined with foreign ownership is a genuinely distinct risk profile compared to the US-headquartered brokerages elsewhere in this tab — worth flagging as a structural difference, not just a fine-print difference.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Webull is owned by a Chinese holding company, raising the data-security concerns flagged elsewhere.\nWHAT THE TERMS SAY: Webull is owned by Chinese holding company Fumi Technology; US broker-dealer services are provided by a separate US affiliate under additional privacy guidelines layered on top of the general Webull Privacy Policy.\nWHY IT MATTERS: Customers face a two-tier privacy structure and the same national-security/data-security concerns raised elsewhere in the audit for China-linked companies.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Webull's dispute clause is vaguer than every other brokerage in the audit, naming no provider.\nWHAT THE TERMS SAY: The clause only says parties will settle disputes via 'friendly negotiation or arbitration' or a lawsuit in 'local courts in the jurisdiction where Webull is registered,' without naming an arbitration provider or a class-action waiver.\nWHY IT MATTERS: A customer may not know which country's legal system or arbitration rules would actually govern their dispute.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The fee field only covers account-opening eligibility requirements (SSN/citizenship), not a distinct consumer harm; only the ownership/data-security flag and the vague arbitration clause are substantive.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Ownership structure is clearly disclosed but the arbitration clause itself is vague and doesn't name a provider or process.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Webull  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Webull takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:24:25Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Webull is owned by a CHINESE holding company, and its dispute-resolution language is genuinely vaguer than every other brokerage in this tracker — it simply says disputes go to arbitration or 'local courts in the jurisdiction where Webull is registered,' without clearly naming an arbitration provider, specifying a class-action waiver, or laying out an opt-out process the way every US-regulated peer in this tab does. You may not actually know which country's legal system your dispute would even fall under.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 73, "_entity_id": 111, "_entity_slug": "webull", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "SoFi Invest", "Category": "Brokerage", "Terms & Conditions URL": "sofi.com/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "sofi.com (GLBA Privacy Notice referenced/incorporated by the Terms of Use, not individually located as a direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "SoFi operates as an umbrella brand across SoFi Bank, SoFi Lending Corp, SoFi Securities LLC, SoFi Wealth LLC, SoFi Credit LLC, SoFi Digital Assets LLC, and a life insurance agency — a single Terms of Use covers all of these, meaning a customer using one SoFi product (e.g., investing) may be bound by terms written with an entirely different product (e.g., lending/insurance) in mind; when SoFi connects users to third-party lenders via its 'Marketplace,' SoFi is paid a marketing fee by the lender (not the customer) but is NOT involved in loan eligibility decisions — a genuine, disclosed conflict-of-interest-adjacent referral-fee structure worth flagging.", "Arbitration / Class Action Waiver": "Has a dedicated separate Arbitration Agreement (sofi.com/login/policy/arbitration) apart from the general Terms of Use — confirms binding arbitration is used, though full clause text not captured this pass (page required an authenticated session).", "Fees / Billing Flags": "SoFi Invest does not charge sales commissions, 12b-1 fees, or other fees from ETFs held in advisory accounts; standard IPO-allocation risk disclosures for customers participating in new offerings.", "Notes": "The multi-product single-Terms-of-Use structure is worth flagging on its own — a customer signing up for investing may not realize they're also agreeing to terms drafted for banking/lending/insurance products they don't currently use.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] One SoFi Terms of Use covers banking, lending, insurance, crypto, and investing all at once.\nWHAT THE TERMS SAY: A single Terms of Use spans SoFi Bank, SoFi Lending Corp, SoFi Securities, SoFi Wealth, SoFi Credit, SoFi Digital Assets, and a life insurance agency.\nWHY IT MATTERS: A customer signing up only for investing may unknowingly be bound by contract language drafted for lending, insurance, or crypto products they never use.\n(evidence: Data Sharing | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] SoFi confirms mandatory arbitration exists but the full clause wasn't captured this pass.\nWHAT THE TERMS SAY: SoFi maintains a dedicated Arbitration Agreement page separate from its general Terms of Use, confirming binding arbitration applies, though the full clause text wasn't captured because the page required an authenticated session.\nWHY IT MATTERS: Customers can't fully assess their arbitration rights and any opt-out process from the publicly available page alone.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-1] SoFi is paid a marketing fee by the lender when it connects users to third-party lenders via Marketplace.\nWHAT THE TERMS SAY: When SoFi connects users to third-party lenders through its Marketplace, SoFi is paid a marketing fee by the lender, not the customer, though SoFi says it is not involved in loan eligibility decisions.\nWHY IT MATTERS: The tracker flags this as a genuine, disclosed conflict-of-interest-adjacent referral-fee structure, even though SoFi is not involved in loan eligibility decisions.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The multi-product bundling and referral-fee structure are clearly described, but the full arbitration clause text wasn't captured behind SoFi's login wall.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "SoFi Invest  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using SoFi Invest you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:24:26Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "ONE single Terms of Use covers SoFi's bank, lending arm, securities brokerage, wealth management, credit products, crypto arm, AND its life insurance agency all at once. Sign up just to invest, and you may be agreeing to contract language that was actually written with SoFi's INSURANCE or LENDING business in mind — products you never touched, bundled into the same document you clicked 'agree' on.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 74, "_entity_id": 112, "_entity_slug": "sofi-invest", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Public.com", "Category": "Brokerage", "Terms & Conditions URL": "public.com (Customer Agreement — direct URL not individually captured this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "public.com privacy policy (not individually located this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Public.com publicly markets itself as having ABANDONED payment for order flow (PFOF) entirely, instead using 'Safety Labels' on certain stocks and other revenue models — a genuine, verifiable point of differentiation similar to Fidelity/Vanguard/Merrill's no-PFOF stance, but achieved via a different business-model choice (per Wikipedia's PFOF entry) rather than simply charging commissions like Interactive Brokers.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard FINRA arbitration disclosure expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Worth grouping with Fidelity/Vanguard/Merrill/Interactive Brokers as a 'no-PFOF' broker in any customer-facing comparison of execution-quality conflicts of interest.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Public.com's arbitration clause was not independently confirmed despite its no-PFOF stance.\nWHAT THE TERMS SAY: The tracker notes Public.com's actual arbitration clause was not independently confirmed this pass, with only standard FINRA arbitration disclosure expected.\nWHY IT MATTERS: A customer attracted by Public.com's ethical no-PFOF positioning still doesn't know what happens to their right to sue if something else goes wrong.\n(evidence: Arbitration | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing and fee fields contain no troubling content (the no-PFOF item is a positive differentiator, not a harm), and the arbitration clause is unconfirmed rather than a stated practice, leaving only one thin item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Almost nothing about Public.com's actual terms was confirmed this pass; only its public no-PFOF marketing claim is verifiable.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Public.com  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Public.com takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Public.com deserves credit for publicly walking away from payment-for-order-flow entirely — a genuine, verifiable stance. But its actual arbitration clause was NOT independently confirmed in this review, meaning a customer attracted by the ethical PFOF stance still doesn't necessarily know what happens to their right to sue if something else goes wrong.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 75, "_entity_id": 113, "_entity_slug": "public-com", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Edward Jones", "Category": "Brokerage (full-service/advisor)", "Terms & Conditions URL": "edwardjones.com/sites/default/files/acquiadam/2023-03/account-agreement-and-other-disclosures.pdf", "T&C Direct PDF?": "YES", "Privacy Policy URL": "edwardjones.com privacy policy (not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass.", "Arbitration / Class Action Waiver": "Standard pre-dispute arbitration clause (Section VIII of Account Agreement) — industry-standard FINRA-style disclosure.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "CATEGORY-WIDE PATTERN FOR FULL-SERVICE/ADVISOR-BASED BROKERAGES (Edward Jones, Raymond James, LPL, UBS, and similar firms): unlike the self-directed apps above, these firms' customer-protection risk is concentrated at the INDIVIDUAL FINANCIAL ADVISOR level rather than in the platform's own terms. FINRA arbitration/investigation trackers show an ongoing, active stream of complaints against advisors at these firms (and peers like Merrill Lynch, Morgan Stanley, Ameriprise, MML) for unsuitable recommendations, unauthorized trading, failure to disclose tax consequences, and unsuitable complex/non-traded products — as recently as March/April 2026. Because customers already signed a pre-dispute arbitration agreement at account opening, these complaints are resolved via FINRA arbitration rather than public lawsuits, so patterns of advisor misconduct are much less visible to the public than class-action-driven complaints against the self-directed apps above.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$16.3B", "Market Cap": "Non-public", "Employees": "55,000", "HQ City": "Des Peres", "HQ State": "Missouri", "CEO": "Penny Pennington", "Ticker": "Non-public", "Website (Corporate)": "edwardjones.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (Non-public). Service route: c/o General Counsel / Corporate Secretary, Des Peres, Missouri — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Missouri' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Missouri SOS Business Search — bsd.sos.mo.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Edward Jones' mandatory arbitration keeps advisor-misconduct complaints out of public view.\nWHAT THE TERMS SAY: Customers sign a pre-dispute arbitration agreement (Section VIII of the Account Agreement) at account opening; FINRA trackers show an active stream of complaints against Edward Jones advisors for unsuitable recommendations, unauthorized trading, and undisclosed tax consequences, tracked as recently as March/April 2026.\nWHY IT MATTERS: Because disputes go through private FINRA arbitration rather than public lawsuits, patterns of advisor misconduct stay largely invisible to prospective customers.\n(evidence: Arbitration | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing and fee fields are unconfirmed this pass; only the arbitration/advisor-complaint-opacity finding is substantive.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause itself is clearly documented, but data-sharing and fee details are unconfirmed, and its practical effect is to hide advisor-complaint patterns from public view.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Edward Jones  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Edward Jones you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:24:28Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Because Edward Jones customers already sign a mandatory arbitration agreement at account opening, complaints against individual FINANCIAL ADVISORS — unsuitable recommendations, unauthorized trading, undisclosed tax consequences — get resolved quietly through PRIVATE FINRA arbitration instead of public lawsuits. That means a pattern of advisor misconduct that would make headlines as a class action anywhere else stays largely INVISIBLE to the public at firms structured this way — active investigations were still being tracked as recently as March/April 2026.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 76, "_entity_id": 114, "_entity_slug": "edward-jones", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Raymond James", "Category": "Brokerage (full-service/advisor)", "Terms & Conditions URL": "raymondjames.com (Account Agreement — direct URL not individually captured this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "raymondjames.com privacy policy (not individually located this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass.", "Arbitration / Class Action Waiver": "Standard FINRA pre-dispute arbitration clause expected (industry standard for full-service brokerages).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Named in active 2026 FINRA arbitration investigations against individual advisors for unsuitable investment recommendations — see the Edward Jones row above for the category-wide context.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "St. Petersburg", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Raymond James advisors face active 2026 FINRA investigations resolved privately under arbitration.\nWHAT THE TERMS SAY: Raymond James is named in active 2026 FINRA arbitration investigations against individual advisors for unsuitable investment recommendations, and customers are subject to a standard pre-dispute arbitration clause expected industry-wide for full-service brokerages.\nWHY IT MATTERS: Because customers pre-sign arbitration agreements, advisor-misconduct complaints are resolved privately, making it harder for a prospective customer to see a pattern before choosing an advisor.\n(evidence: Notes | SCARY | Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing and fee fields are unconfirmed, and Raymond James' own arbitration clause is only described as industry-standard/expected rather than independently confirmed; only the advisor-investigation finding is substantive.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause is only described as industry-standard/expected, and data-sharing and fees are both unconfirmed, while the advisor-investigation pattern is clearly stated.", "Exposure Score (0-100)": 22, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Raymond James  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Raymond James you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same structural pattern as Edward Jones (this same tab): mandatory pre-signed arbitration means advisor-misconduct complaints — including active 2026 investigations — get resolved privately rather than publicly, making it much harder for a prospective customer to see a pattern before choosing an advisor.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 77, "_entity_id": 115, "_entity_slug": "raymond-james", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "LPL Financial", "Category": "Brokerage (full-service/advisor, independent-advisor network)", "Terms & Conditions URL": "lplfinancial.com (Account Agreement — direct URL not individually captured this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "lplfinancial.com privacy policy (not individually located this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "LPL operates as a network/custodian for thousands of INDEPENDENT financial advisors rather than employing them directly — meaning a customer's actual advisor may operate under their own separate business name/DBA while custodying assets through LPL, adding a layer of complexity to figuring out who is actually accountable for a given complaint.", "Arbitration / Class Action Waiver": "Standard FINRA pre-dispute arbitration clause expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Named in MULTIPLE active 2026 FINRA investigations (at least 2 separate advisors under investigation as of March/April 2026) for unsuitable recommendations involving complex, non-traded, non-transparent products and failure to disclose tax consequences — the independent-advisor network structure may make this pattern harder for customers to trace back to the parent company.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$17.0B", "Market Cap": "$26.2B", "Employees": "9,000", "HQ City": "San Diego", "HQ State": "California", "CEO": "Rich Steinmeier", "Ticker": "LPLA", "Website (Corporate)": "lpl.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (LPLA). Service route: c/o General Counsel / Corporate Secretary, San Diego, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-3] LPL's independent-advisor network structure obscures accountability when advisors are investigated.\nWHAT THE TERMS SAY: LPL operates as a custodian/network for thousands of independent financial advisors who may use their own business names, and at least two LPL-affiliated advisors were under active FINRA investigation as of March/April 2026 for pushing complex, non-transparent products and failing to disclose tax consequences.\nWHY IT MATTERS: Customers may struggle to trace a pattern of advisor misconduct back to LPL itself rather than seeing it as an isolated bad-advisor problem.\n(evidence: Data Sharing | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] LPL's arbitration clause is only described as industry-standard/expected, not independently confirmed.\nWHAT THE TERMS SAY: The tracker notes a standard FINRA pre-dispute arbitration clause is expected for LPL but was not independently confirmed word-for-word this pass.\nWHY IT MATTERS: Customers can't verify the exact arbitration terms and any opt-out rights without checking the actual agreement.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fee details are unconfirmed and the arbitration clause is only assumed industry-standard rather than confirmed; the advisor-network accountability gap is the only fully stated finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The advisor-investigation pattern is clearly stated, but LPL's own arbitration clause is only assumed/expected rather than confirmed, and fees are unconfirmed.", "Exposure Score (0-100)": 4, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "LPL Financial  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, LPL Financial takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "LPL doesn't employ most of its advisors — they're INDEPENDENT businesses operating under their own names while LPL just custodies the money behind the scenes. That structure means when multiple advisors get investigated by FINRA (as at least two were in early 2026, for pushing complex products and hiding tax consequences), it's genuinely harder for a customer to trace the pattern back to LPL itself rather than seeing it as an isolated 'bad advisor' problem.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Brokerages", "_row_id": 78, "_entity_id": 116, "_entity_slug": "lpl-financial", "_issuer": "LPL Financial", "_issuer_slug": "lpl-financial", "_ticker": "LPLA", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "TIAA", "Category": "Brokerage (retirement-focused)", "Terms & Conditions URL": "tiaa.org/public/pdf/BrokerageAccountCustomerAgreement.pdf", "T&C Direct PDF?": "YES", "Privacy Policy URL": "tiaa.org (privacy notice not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "TIAA receives remuneration connected to the mutual funds/money market funds/ETFs customers invest in, INCLUDING 12b-1 FEES — a standard but disclosed revenue-sharing arrangement that creates an incentive to favor funds that pay TIAA more.", "Arbitration / Class Action Waiver": "Standard FINRA-mandated predispute arbitration clause (paragraphs 13/16 depending on account type), must be brought before FINRA specifically; TIAA holds a LIEN against customer account assets for any debts/obligations owed to TIAA, and can unilaterally decide which securities to sell to satisfy that lien 'except where prohibited by law' — a notable degree of unilateral control worth flagging.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "TIAA is historically the dominant retirement-plan provider for university/nonprofit/education-sector employees — relevant if any BMHC staff or Gazette colleagues have 403(b) plans through TIAA rather than a typical employer 401(k) provider covered elsewhere in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$46.9B", "Market Cap": "Non-public", "Employees": "15,623", "HQ City": "New York", "HQ State": "New York", "CEO": "Thasunda Brown Duckett", "Ticker": "Non-public", "Website (Corporate)": "tiaa.org", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (Non-public). Service route: c/o General Counsel / Corporate Secretary, New York, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[TERMINATION_CONFISCATION · FL-4] TIAA holds a lien on customer accounts and can unilaterally choose which securities to sell.\nWHAT THE TERMS SAY: TIAA's account agreement grants it a lien against customer assets for any debts owed to TIAA and lets TIAA unilaterally decide which securities to sell to satisfy that lien, 'except where prohibited by law.'\nWHY IT MATTERS: A customer's retirement broker, not the customer, can choose which of the customer's own investments to liquidate to cover a debt.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-1] TIAA earns 12b-1 fees tied to the funds customers invest in, incentivizing higher-paying funds.\nWHAT THE TERMS SAY: TIAA receives remuneration connected to the mutual funds, money market funds, and ETFs customers invest in, including 12b-1 fees — a disclosed but standard revenue-sharing arrangement.\nWHY IT MATTERS: This creates a financial incentive for TIAA to favor funds that pay it more, which may not align with a customer's best interest.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] TIAA customers must arbitrate specifically before FINRA under a standard predispute clause.\nWHAT THE TERMS SAY: TIAA imposes a standard FINRA-mandated predispute arbitration clause (paragraphs 13/16 depending on account type) requiring disputes to go before FINRA specifically.\nWHY IT MATTERS: Customers give up the ability to sue in court and must use FINRA's arbitration forum for disputes.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "TIAA's arbitration clause, lien rights, and revenue-sharing arrangement are all specifically cited and clearly described.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 4/20 (termination_or_confiscation+4) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "TIAA  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using TIAA you gave up your right to sue and your right to keep what you paid for. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "TIAA's account agreement gives it a LIEN over your account for any debt you owe it — and lets TIAA UNILATERALLY DECIDE WHICH OF YOUR SECURITIES TO SELL to satisfy that debt, 'except where prohibited by law.' Your retirement broker can pick which of your own investments to liquidate on its own authority, not yours.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 79, "_entity_id": 117, "_entity_slug": "tiaa", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Stash", "Category": "Brokerage (subscription-fee micro-investing + banking)", "Terms & Conditions URL": "stash.com/termsofuse", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "stash.com/privacy (referenced, not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Stash shares customer 'Subscription Data' (legal name, address, phone, email, billing info) with THIRD PARTIES for identity verification and billing purposes as a standard part of its subscription process; payment processing is handled by a named third party (Tabapay) with its own separate privacy policy customers are bound by when paying via card.", "Arbitration / Class Action Waiver": "Terms of Use confirm the electronic Account Contracts (Terms, Advisory Agreement, ESIGN Agreement, Privacy Policy) 'can be admitted as evidence or otherwise used in arbitration' — confirming binding arbitration applies, though full clause text not captured this pass; investment products offered through Apex Clearing (same custodian as tastytrade/Ally Invest/M1 Finance in this tab), covered up to $500,000 via SIPC.", "Fees / Billing Flags": "CONCRETE, FLAG-WORTHY FEE STRUCTURE ISSUE: Stash charges a FLAT MONTHLY SUBSCRIPTION FEE ($3–$12/month depending on tier) rather than a percentage-of-assets fee — which independent reviewers calculate can amount to roughly 10.8% ANNUALLY in fees on a $1,000 balance (vs. ~0.25%/year at Betterment for the same balance). This flat-fee model disproportionately penalizes customers with SMALLER account balances, which is a real equity concern for a company positioning itself (per its marketing) as beginner/first-time-investor-friendly. Also charges a 0.25% annual AUM advisory fee on top of the subscription for 'Smart Portfolio' balances ≥$1,000, plus additional crypto-transaction fees via a third party (Apex Crypto).", "Notes": "The flat-fee-penalizes-small-balances structure is one of the more directly relevant findings in this audit if BMHC's mission includes financial empowerment/first-time investor education — worth flagging prominently, since a well-intentioned beginner investor could unknowingly pay a much higher effective fee rate than a wealthier investor at the same platform.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] Stash's flat monthly fee can cost small-balance customers roughly 10.8% annually.\nWHAT THE TERMS SAY: Stash charges a flat $3-$12/month subscription fee regardless of balance, which independent reviewers calculate works out to about 10.8% annually on a $1,000 balance, versus roughly 0.25%/year at percentage-fee competitor Betterment for the same balance; Stash also charges a 0.25% AUM fee on Smart Portfolio balances of $1,000+ plus separate crypto fees via Apex Crypto.\nWHY IT MATTERS: Beginner investors with the smallest balances, exactly who Stash markets itself to, end up paying the highest effective fee rate.\n(evidence: Fees | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Stash shares customer identity and billing data with third parties, including a payment processor.\nWHAT THE TERMS SAY: Stash shares customer 'Subscription Data' (legal name, address, phone, email, billing info) with third parties for identity verification and billing, and payment processing runs through third party Tabapay under its own separate privacy policy.\nWHY IT MATTERS: Customers paying by card are also bound by a third party's privacy policy they may not have separately reviewed.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Stash confirms binding arbitration applies, though the full clause text wasn't captured.\nWHAT THE TERMS SAY: Stash's Terms of Use state that its Account Contracts 'can be admitted as evidence or otherwise used in arbitration,' confirming binding arbitration applies, though the full clause wasn't captured this pass.\nWHY IT MATTERS: Customers can't fully assess their dispute-resolution rights from what's publicly documented.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Fees and data-sharing practices are clearly itemized, but the full arbitration clause text was not captured this pass.", "Exposure Score (0-100)": 27, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Stash  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Stash you gave up your data shared corporate-wide, your right to sue, and your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:25:09Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Stash markets itself to first-time, beginner investors — but charges a FLAT monthly fee regardless of balance, which independent reviewers calculate works out to roughly 10.8% ANNUALLY on a $1,000 account, compared to about 0.25%/year at a percentage-fee competitor like Betterment for the exact same balance. The customers Stash is explicitly trying to attract — people just starting out with small amounts — are the ones paying the highest effective rate.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Brokerages", "_row_id": 80, "_entity_id": 118, "_entity_slug": "stash", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Acorns", "Category": "Brokerage (robo-advisor, micro-investing)", "Terms & Conditions URL": "acorns.com/program-agreement/ ; acorns.com/terms/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "acorns.com/privacy/ (referenced, not individually captured as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass.", "Arbitration / Class Action Waiver": "Mandatory binding arbitration (administered by JAMS in Orange, CA, not the more common AAA/FINRA) + class action waiver; NOTABLY LIMITS THE TYPES OF DAMAGES available even if a customer wins — the arbitrator is explicitly NOT authorized to award non-economic damages (emotional distress, pain and suffering) or punitive/consequential damages, only compensatory damages. This is a more restrictive damages cap than most other arbitration clauses in this tracker, which typically just limit the FORUM (arbitration vs. court) without also capping the TYPES of damages available within that forum.", "Fees / Billing Flags": "Not itemized this pass — note the 'preauthorized recurring monthly electronic funds transfer debit' language in the Program Agreement confirms Acorns' signature subscription-fee model (a recurring monthly charge for the investing account) rather than a per-trade commission model.", "Notes": "The damages-type restriction (no emotional distress/punitive/consequential damages, only compensatory) is a distinctive, more customer-limiting clause than most other arbitration provisions found in this audit — worth flagging specifically since it caps not just WHERE a dispute is heard but WHAT a customer could actually recover even if they win.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Irvine", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Acorns caps arbitration winnings to compensatory damages only, barring punitive or emotional damages.\nWHAT THE TERMS SAY: Acorns requires mandatory binding arbitration through JAMS (not the more common AAA or FINRA) with a class action waiver, and explicitly bars the arbitrator from awarding non-economic, punitive, or consequential damages — only compensatory damages are allowed.\nWHY IT MATTERS: Even a customer who wins their arbitration case can't recover for emotional distress or be awarded punitive damages, unlike most other arbitration clauses in this audit, which only restrict where a case is heard.\n(evidence: Arbitration | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Acorns also bars customers from bringing class actions.\nWHAT THE TERMS SAY: The same arbitration clause includes a class action waiver alongside the mandatory JAMS arbitration requirement.\nWHY IT MATTERS: Customers cannot band together to pursue claims collectively against Acorns.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data-sharing is unconfirmed and the fee field only confirms a standard subscription billing model without itemized amounts; only the two arbitration-related findings are substantive.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration and damages-cap terms are described in specific detail, but data-sharing practices and itemized fees are both unconfirmed.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Acorns  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Acorns you gave up your right to sue, your right to join a class action, and your right to meaningful compensation. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:25:13Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Even if you WIN your arbitration case against Acorns, the arbitrator is explicitly BARRED from awarding you anything beyond straight compensatory damages — no emotional distress, no pain and suffering, no punitive damages, no matter how badly Acorns messed up. Most arbitration clauses only control WHERE your case is heard; this one also controls WHAT you're allowed to recover even after winning.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 81, "_entity_id": 119, "_entity_slug": "acorns", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "tastytrade", "Category": "Brokerage (options/futures-focused)", "Terms & Conditions URL": "assets.tastyworks.com/production/documents/broker_customer_agreement.pdf", "T&C Direct PDF?": "YES", "Privacy Policy URL": "tastytrade.com (privacy notice not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass.", "Arbitration / Class Action Waiver": "Standard FINRA-style predispute arbitration clause; governed by Illinois law specifically (unusual — most brokerages in this tracker specify California or New York law); uses Apex Clearing as third-party custodian (same clearing firm used by Ally Invest and M1 Finance elsewhere in this tab), meaning tastytrade customer securities legally reside with Apex, not tastytrade directly.", "Fees / Billing Flags": "DOES receive PFOF, per the industry-wide PFOF broker list identified earlier in this research (grouped with Robinhood, E*TRADE, Ally, Webull, TradeStation).", "Notes": "The shared Apex Clearing relationship across tastytrade/Ally Invest/M1 Finance means a counterparty-risk/custody question applies identically across all three — worth a consolidated note if this audit informs customer education about brokerage custody structures.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] tastytrade customer securities legally reside with third-party custodian Apex Clearing, not tastytrade.\nWHAT THE TERMS SAY: tastytrade uses Apex Clearing as custodian (also used by Ally Invest and M1 Finance), meaning customer securities legally reside with Apex rather than with tastytrade directly.\nWHY IT MATTERS: Customers may not realize the company actually holding their investments is a separate, less-visible entity than the brokerage brand they signed up under.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-1] tastytrade receives payment for order flow, per the industry-wide PFOF broker list in this research.\nWHAT THE TERMS SAY: tastytrade is listed among brokers that receive payment for order flow (PFOF), grouped with Robinhood, E*TRADE, Ally, Webull, and TradeStation.\nWHY IT MATTERS: The tracker groups tastytrade with Robinhood, E*TRADE, Ally, Webull, and TradeStation as brokers that do receive payment for order flow.\n(evidence: Fees; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data-sharing is unconfirmed this pass; the custody structure and PFOF status are the only two substantive, distinct findings.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Custody arrangement, governing law, and PFOF status are all clearly and specifically documented.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "tastytrade  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using tastytrade you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:25:17Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Your tastytrade account's actual securities don't legally sit with tastytrade at all — they're held by a separate custodian, Apex Clearing (the same one used by Ally Invest and M1 Finance in this tab). If you've never heard of Apex, that's the point: it's the invisible company actually holding your investments behind the tastytrade name you signed up under.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 82, "_entity_id": 120, "_entity_slug": "tastytrade", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "moomoo", "Category": "Brokerage", "Terms & Conditions URL": "moomoo.com (Customer Agreement — direct URL not individually captured this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "moomoo.com privacy policy (not individually located this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "OWNERSHIP FLAG (same category as Webull): moomoo is operated by Futu Holdings, a company with roots in and significant ties to the Chinese market, similar in structure to Webull/Fumi Technology — worth the same foreign-ownership/data-security flag noted for Webull above.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — verify current Customer Agreement arbitration clause directly.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend researching moomoo and Webull together given their structurally similar (Chinese-parent-company) ownership profile relative to every other US brokerage in this audit.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] moomoo is operated by Futu Holdings, a company with significant ties to the Chinese market.\nWHAT THE TERMS SAY: moomoo is operated by Futu Holdings, which the tracker notes has significant ties to the Chinese market, structurally similar to Webull's Fumi Technology ownership.\nWHY IT MATTERS: This raises the same foreign-ownership/data-security concerns flagged elsewhere in the audit for China-linked companies.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] moomoo's arbitration clause was not independently confirmed this pass, unlike Webull's.\nWHAT THE TERMS SAY: The tracker notes moomoo's arbitration clause was not independently confirmed this pass, recommending direct verification of the current Customer Agreement.\nWHY IT MATTERS: Customers have no confirmed information about their dispute-resolution rights with moomoo.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity pass 2 (strict): Cross-ref leak corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees are unconfirmed and no additional distinct practice is documented; only the ownership flag and the unconfirmed-arbitration finding are substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Almost nothing about moomoo's actual terms was confirmed this pass beyond its parent company's identity.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "moomoo  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, moomoo takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Like Webull (this same tab), moomoo is operated by a company with significant ties to the Chinese market (Futu Holdings) — the same foreign-ownership/data-security profile applies here, and unlike Webull, moomoo's specific arbitration clause wasn't even independently confirmed in this review.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 83, "_entity_id": 121, "_entity_slug": "moomoo", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "UBS", "Category": "Brokerage (full-service/advisor)", "Terms & Conditions URL": "ubs.com (Master Account Agreement — direct URL not individually captured this pass; historical filing confirms 'Arbitration' is the final paragraph of the Master Account Agreement)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "ubs.com privacy policy (not individually located this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "UBS Financial Services explicitly discloses it does NOT provide legal or tax advice despite the advisory relationship; margin account securities may be loaned to UBS itself or to others as part of standard margin agreement terms — a real, if standard-for-the-industry, use of customer securities.", "Arbitration / Class Action Waiver": "Standard pre-dispute arbitration clause (final paragraph of Master Account Agreement, confirmed via historical SEC filing) — customers agree in advance to arbitrate controversies.", "Fees / Billing Flags": "Annual service fee applies to certain 'RMA' (Resource Management Account) feature selections.", "Notes": "Named in an active April 2026 FINRA investigation against an individual advisor for failure to warn of variable annuity tax consequences — see Edward Jones row above for category-wide context. UBS is also reportedly moving toward becoming a full-service US bank per 2026 industry reporting, which could change its consumer terms/structure going forward.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] UBS can loan out securities in customer margin accounts to itself or other parties.\nWHAT THE TERMS SAY: UBS's standard margin agreement lets it loan out the securities in a customer's margin account, to itself or to other parties, as a routine part of doing business.\nWHY IT MATTERS: Customers who assume their shares just sit in their account may not realize they can be lent out to someone else in the meantime.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] UBS customers pre-agree to arbitrate disputes under a clause confirmed via SEC filing.\nWHAT THE TERMS SAY: UBS's Master Account Agreement includes a standard pre-dispute arbitration clause in its final paragraph, confirmed through a historical SEC filing, requiring customers to agree in advance to arbitrate controversies.\nWHY IT MATTERS: Customers give up the ability to sue UBS in court for covered disputes.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[PENDING_LITIGATION · FL-1] UBS is named in an active April 2026 FINRA investigation of an advisor over annuity tax warnings.\nWHAT THE TERMS SAY: UBS is named in an active April 2026 FINRA investigation against an individual advisor for failure to warn of variable annuity tax consequences.\nWHY IT MATTERS: The tracker records this as an active investigation against an individual advisor and points to the Edward Jones row for category-wide context on full-service/advisor-based brokerages.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The arbitration clause, margin securities-lending practice, and the advisor investigation are all specifically documented and sourced.", "Exposure Score (0-100)": 27, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 4/20 (severity2+2, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "UBS  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using UBS you gave up your right to sue and your right to meaningful compensation. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "UBS's standard margin agreement lets it LOAN OUT the securities in your margin account — to itself, or to other parties — as a routine part of doing business. Many customers assume the stocks in their account just sit there until they decide to trade them; in reality, shares can be quietly lent out to someone else in the meantime.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Brokerages", "_row_id": 84, "_entity_id": 122, "_entity_slug": "ubs", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Coinbase", "Category": "Cryptocurrency Exchange", "Terms & Conditions URL": "https://www.coinbase.com/legal/user-agreement", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.coinbase.com/legal/privacy", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "Coinbase processes cryptocurrency transaction data, wallet addresses, government-issued ID (KYC/AML compliance), bank account linkages, and trading patterns. As a publicly traded company (COIN, Nasdaq) registered as a Money Services Business with FinCEN, Coinbase reports transactions exceeding $10,000 to the IRS (Form 1099-MISC). Coinbase's 2023 SEC lawsuit (securities-law violations) and the resulting settlement shape how crypto-exchange data is classified — as securities data or currency data — with different regulatory implications for each.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Coinbase User Agreement, AAA rules, California law. 30-day opt-out via written notice. The Supreme Court ruled in Coinbase Inc. v. Bielski (2023) that filing an appeal of a district court's denial of arbitration automatically STAYS the case — a procedural ruling that benefits ALL companies with arbitration clauses, not just Coinbase. Coinbase's arbitration clause has been extensively litigated and is one of the most court-tested in the crypto industry.", "Fees / Billing Flags": "Trading fees (maker/taker model), spread fees on retail purchases, network (gas) fees passed through, Coinbase One subscription ($29.99/month for zero-fee trading).", "Notes": "Largest US-based cryptocurrency exchange by volume. The Coinbase v. Bielski Supreme Court ruling (2023) created new procedural law benefiting all companies with arbitration clauses. Coinbase Wallet (self-custody) is governed by separate terms from Coinbase exchange (custodial).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Added 2026-08-06 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Coinbase Global, Inc.", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Coinbase Global, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Coinbase's arbitration clause underpins a Supreme Court ruling letting companies freeze cases on appeal.\nWHAT THE TERMS SAY: Coinbase requires mandatory binding arbitration with a class action waiver under AAA rules and California law, with a 30-day opt-out by written notice; its clause was the basis for Coinbase Inc. v. Bielski (2023), where the Supreme Court ruled 5-4 that appealing a denial of arbitration automatically stays the underlying case.\nWHY IT MATTERS: This procedural ruling lets a company appeal a court's rejection of its arbitration demand and freeze the case for months or years, benefiting every company with an arbitration clause, not just Coinbase.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] Coinbase's exchange and self-custody Wallet operate under two different legal frameworks.\nWHAT THE TERMS SAY: Coinbase's User Agreement splits into two regimes: the custodial exchange (Coinbase holds your crypto, 30-day arbitration opt-out) and Coinbase Wallet (self-custody, you hold your own keys, governed by different terms).\nWHY IT MATTERS: A user moving assets from the exchange to Wallet is moving between two different legal frameworks on the same platform without necessarily realizing it.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CLASS_ACTION_WAIVER · FL-3] Coinbase's class action waiver may be legally vulnerable if its crypto products are ruled securities.\nWHAT THE TERMS SAY: The SEC's 2023 lawsuit against Coinbase alleges unregistered securities offerings; the tracker notes that if crypto assets are found to be securities, FINRA's prohibition on class-action waivers might apply to Coinbase's brokerage activities, a tension also documented in the Robinhood row.\nWHY IT MATTERS: Coinbase's current class action waiver could become unenforceable for brokerage-like activities if regulators or courts classify its crypto assets as securities.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Coinbase's arbitration process, opt-out window, and dual exchange/Wallet legal structure are all specifically and clearly documented.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Coinbase  <-  Coinbase Global, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Coinbase you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:25:19Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Coinbase is the largest US cryptocurrency exchange — and its arbitration clause made SUPREME COURT LAW. In Coinbase Inc. v. Bielski (June 2023), the Court ruled 5-4 that when a company appeals a lower court's refusal to enforce arbitration, the underlying case must be STAYED (paused) until the appeal is resolved. This procedural ruling benefits every company in this tracker that has an arbitration clause, not just Coinbase — it means that even when a court REJECTS a company's arbitration demand, the company can appeal and freeze the case for months or years. Separately, Coinbase's User Agreement splits the crypto world into two regimes: Coinbase exchange (custodial — Coinbase holds your crypto, 30-day arbitration opt-out) and Coinbase Wallet (self-custody — you hold your own keys, different terms). A user who moves assets from exchange to wallet is moving between two different legal frameworks on the same platform. The SEC's 2023 lawsuit against Coinbase (alleging unregistered securities offerings) creates additional uncertainty: if crypto assets ARE securities, FINRA's class-action-waiver prohibition might apply to Coinbase's brokerage activities — the same tension documented in the Robinhood row.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Brokerages", "_row_id": 85, "_entity_id": 124, "_entity_slug": "coinbase", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Meta (Facebook / Instagram / WhatsApp)", "Category": "Social/Messaging", "Terms & Conditions URL": "facebook.com/terms.php ; instagram.com/legal/terms/ ; whatsapp.com/legal/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "facebook.com/privacy/policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MASSIVE, ONGOING LITIGATION LANDSCAPE (as of mid-2026): Meta is defending 2,400+ consolidated federal lawsuits, a 42-state AG coalition case, and 800+ cases in a California state consolidation (JCCP 5255) over allegedly addictive design (infinite scroll, autoplay, notification manipulation) causing depression, anxiety, eating disorders, and self-harm in minors. A New Mexico jury ordered Meta to pay $375 MILLION in civil penalties (March 2026) for misleading consumers about child safety; a Los Angeles jury separately found Meta and Google/YouTube negligent and awarded $6 million to one plaintiff. A March 2026 case (Shirazi et al. v. Meta) alleges Meta and Accenture intercepted/read/stored 'private' WhatsApp messages despite marketing the platform as end-to-end encrypted — a direct contradiction of Meta's core privacy claim if proven. Meta also operates under a 2022 DOJ consent agreement after violating the Fair Housing Act by letting housing ads be targeted/excluded by race, sex, and religion. ADDITIONAL CONFIRMED HISTORY: separate from the litigation above, Meta previously paid a $5.0 BILLION FTC penalty (2020 consent order) over the Cambridge Analytica data-misuse scandal, plus a separate $725 MILLION private class-action settlement (paid Nov 2023) for the same underlying conduct — meaning Meta's cumulative confirmed privacy-related payouts across just these few incidents exceed $6 billion, likely making it the single largest cumulative privacy-penalty payer of any company in this entire audit, ahead of even Google/Alphabet's individual settlements.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver and jury trial waiver across ALL Meta products (Facebook, Instagram, WhatsApp). 30-day opt-out via written notice to Meta Platforms Inc., ATTN: Arbitration Opt-Out, 1 Meta Way, Menlo Park, CA 94025. Federal Arbitration Act governs.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is arguably the single richest 'issue pertaining to customers' finding in the ENTIRE audit so far, spanning youth mental health, encryption-marketing-vs-reality, housing discrimination, and antitrust — recommend treating Meta as a dedicated deep-dive rather than a single spreadsheet row if this audit informs any customer-facing communication.", "Industry (Fortune 500)": "Internet Services and Retailing", "Revenue (Fortune 500)": "$201.0B", "Market Cap": "$1.6T", "Employees": "74,067", "HQ City": "Menlo Park", "HQ State": "California", "CEO": "Mark Zuckerberg", "Ticker": "META", "Website (Corporate)": "meta.com", "Main Mailing Address (legal/privacy notices)": "Meta Platforms, Inc., ATTN: Privacy Operations, 1 Meta Way, Menlo Park, CA 94025, USA (corporate/SEC address: 1601 Willow Road, Menlo Park, CA 94025)", "Legal / Privacy Contact Email": "No published privacy email; Meta routes all requests through in-product privacy forms", "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (META). Service route: c/o General Counsel / Corporate Secretary, Menlo Park, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": "https://www.ftc.gov/news-events/news/press-releases/2019/07/ftc-imposes-5-billion-penalty-sweeping-new-privacy-restrictions-facebook", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "N/A - this row IS the parent entity", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: N/A - this row IS the parent entity). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] Meta's confirmed privacy penalties and settlements exceed $6 billion, likely the largest in this audit.\nWHAT THE TERMS SAY: The tracker documents a $5.0 billion FTC penalty (2020 consent order) over Cambridge Analytica, a separate $725 million private class-action settlement (paid Nov 2023) for the same conduct, and a $375 million New Mexico jury penalty (March 2026) for misleading consumers about child safety, a cumulative confirmed total exceeding $6 billion.\nWHY IT MATTERS: This makes Meta's confirmed privacy-related payouts likely the largest of any company in the entire audit, reflecting a sustained pattern rather than a single incident.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] A 2026 lawsuit alleges Meta and Accenture read and stored 'encrypted' WhatsApp messages.\nWHAT THE TERMS SAY: A March 2026 case, Shirazi et al. v. Meta, alleges Meta and Accenture intercepted, read, and stored supposedly private WhatsApp messages despite Meta marketing the platform as end-to-end encrypted.\nWHY IT MATTERS: If proven, this would directly contradict the end-to-end encryption promise Meta has made to hundreds of millions of WhatsApp users - not a fine-print surprise but its core privacy claim.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[DISCRIMINATORY_PRACTICE · FL-2] Meta operates under a 2022 DOJ consent agreement for discriminatory housing-ad targeting.\nWHAT THE TERMS SAY: Meta operates under a 2022 DOJ consent agreement after violating the Fair Housing Act by allowing housing ads to be targeted and excluded by race, sex, and religion.\nWHY IT MATTERS: This confirms Meta's ad-targeting tools were used to discriminate in a protected area (housing) based on legally protected characteristics.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "This row is unusually well-documented, citing specific case names, dollar figures, dates, and regulatory actions throughout.", "Exposure Score (0-100)": 50, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "App / Service", "Ownership Path": "Meta (Facebook / Instagram / WhatsApp)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to a jury.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Meta (Facebook / Instagram / WhatsApp) you gave up your right to sue, your right to join a class action, and your right to a jury. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "2026-09-08T19:25:23Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Meta has told hundreds of millions of WhatsApp users their messages are 'end-to-end encrypted' — meaning not even Meta can read them. A March 2026 lawsuit alleges Meta and its contractor Accenture actually INTERCEPTED, READ, AND STORED those supposedly private messages anyway. If proven, this isn't a fine-print surprise — it's a direct contradiction of the single most-marketed privacy promise Meta makes to over 2 billion people. And this sits alongside a $375 MILLION jury penalty for misleading parents about child safety, a $5 BILLION FTC fine, and a $725 MILLION settlement over Cambridge Analytica — Meta's cumulative privacy-related payouts likely exceed $6 billion, the largest of any company in this entire tracker.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 86, "_entity_id": 125, "_entity_slug": "meta-facebook-instagram-whatsapp", "_issuer": "Meta (Facebook / Instagram / WhatsApp)", "_issuer_slug": "meta-facebook-instagram-whatsapp", "_ticker": "META", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "TikTok", "Category": "Social/Messaging", "Terms & Conditions URL": "tiktok.com/legal/page/us/terms-of-service/en", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "tiktok.com/legal/page/us/privacy-policy/en", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Named alongside Meta and Snapchat in consolidated litigation over collecting data from users under 18 without parental consent; TikTok settled individually with the lead plaintiff in the first federal bellwether youth-addiction trial in Jan 2026 (before trial began) and again in a separate California state bellwether in mid-2026, resolving its own individual exposure without addressing the broader multi-district litigation or California state court inventory it remains named in.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out via written notice to TikTok Inc., Attn: Arbitration Opt-Out, 5800 Bristol Parkway, Suite 100, Culver City CA 90230. TikTok's ToS are governed by California law despite ByteDance being Beijing-headquartered. Given the ongoing national-security divestiture litigation (TikTok Inc. v. Garland, D.C. Circuit), the arbitration clause has an uncertain future — a forced sale to a US buyer could change the governing terms entirely.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "TikTok's pattern of settling INDIVIDUAL bellwether cases just before trial (rather than the broader MDL) is worth flagging as a strategy that limits public disclosure of internal evidence/practices compared to a full trial verdict.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Culver City", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "ByteDance Ltd.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: ByteDance Ltd.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] TikTok is accused of collecting data from users under 18 without parental consent.\nWHAT THE TERMS SAY: TikTok is named alongside Meta and Snapchat in consolidated litigation over collecting data from users under 18 without parental consent.\nWHY IT MATTERS: Minors' personal data may have been collected without the legally required parental consent, exposing them to unknown downstream data use.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] TikTok settles individual youth-safety bellwether cases right before trial, keeping evidence hidden.\nWHAT THE TERMS SAY: TikTok settled individually with the lead plaintiff in the January 2026 federal bellwether trial before it began, and again in a separate California state bellwether in mid-2026, resolving its own exposure without addressing the broader multi-district litigation or state court inventory it remains named in.\nWHY IT MATTERS: Settling before a verdict means the internal evidence and practices that would surface in a public trial never become public, even though the broader litigation against TikTok continues.\n(evidence: Data Sharing | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] TikTok's arbitration clause faces an uncertain future amid national-security divestiture litigation.\nWHAT THE TERMS SAY: TikTok requires mandatory binding arbitration with a class action waiver and a 30-day opt-out, governed by California law despite ByteDance's Beijing headquarters; the tracker notes the ongoing TikTok Inc. v. Garland divestiture case could change the governing terms entirely if TikTok is forced to sell to a US buyer.\nWHY IT MATTERS: A customer's dispute-resolution rights could shift with a change of ownership, adding uncertainty on top of the standard arbitration waiver.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The litigation and settlement pattern is clearly documented, but the arbitration clause's future is uncertain pending the divestiture case.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "TikTok  <-  ByteDance Ltd.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using TikTok you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:25:25Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "TikTok has repeatedly settled individual bellwether lawsuits over child-safety allegations RIGHT BEFORE trial was set to begin — once in a federal case, once in a California state case. Settling before a verdict means the internal evidence and company practices that would come out in a full public trial never actually become public. It resolves the individual plaintiff's case while the broader pattern stays largely hidden from view.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 87, "_entity_id": 127, "_entity_slug": "tiktok", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Snapchat (Snap Inc.)", "Category": "Social/Messaging", "Terms & Conditions URL": "snap.com/en-US/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "snap.com/en-US/privacy/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same youth-data-collection-without-parental-consent litigation category as Meta/TikTok; Snap settled individually before the Jan 2026 federal bellwether trial and again before a separate 2026 state trial, following the same 'early individual settlement' pattern as TikTok.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out via email to arbitration-opt-out@snap.com. Snap's ToS cover Snapchat, Bitmoji, and Spectacles. Snap's location-sharing feature (Snap Map) and face-scanning AR filters collect sensitive biometric and location data — the arbitration clause covers disputes over these data practices. Snap paid $35M to settle an Illinois BIPA class action over facial-recognition data (2022).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Consider grouping Meta/TikTok/Snapchat/YouTube together in any customer communication about youth social media safety, since the litigation, allegations, and settlement patterns are closely parallel across all four platforms.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Santa Monica", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Snap Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Snap Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] Snap paid $35 million in 2022 to settle an Illinois BIPA class action over facial-recognition data.\nWHAT THE TERMS SAY: Snap's location-sharing Snap Map feature and face-scanning AR filters collect sensitive biometric and location data; Snap paid $35 million in 2022 to settle an Illinois BIPA class action over its facial-recognition data practices.\nWHY IT MATTERS: This is a confirmed, paid settlement over biometric/facial-recognition data, not just a pending allegation.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] Snap settles individual youth-safety bellwether cases before trial, following TikTok's pattern.\nWHAT THE TERMS SAY: Snap settled individually before the January 2026 federal bellwether trial and again before a separate 2026 state trial, following the same early-settlement pattern as TikTok, in litigation alleging youth data collection without parental consent.\nWHY IT MATTERS: Settling before trial avoids the public disclosure of internal evidence that a full verdict would produce.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[LOCATION_TRACKING · FL-2] Snap Map and AR filters collect sensitive location and biometric data covered by mandatory arbitration.\nWHAT THE TERMS SAY: Snap's arbitration clause explicitly covers disputes over Snap Map's location-sharing and face-scanning AR filter data practices, under mandatory binding arbitration with a class action waiver and 30-day opt-out via email.\nWHY IT MATTERS: Disputes over ongoing sensitive location and biometric data collection are funneled into arbitration rather than court, limiting public visibility.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The BIPA settlement amount, biometric/location data practices, and arbitration coverage are all specifically documented.", "Exposure Score (0-100)": 47, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 10/30 (biometric_collection+6, precise_location_tracking+4) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Snapchat (Snap Inc.)  <-  Snap Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Snapchat (Snap Inc.) you gave up your biometric identifiers, your physical movements, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "2026-09-08T19:25:28Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Same pattern as TikTok (this same tab): Snap has settled individual youth-safety bellwether cases just before trial, both in a federal case and a separate state case, avoiding the kind of public verdict that would force its internal practices into the open.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 88, "_entity_id": 129, "_entity_slug": "snapchat-snap-inc", "_issuer": "Snap Inc.", "_issuer_slug": "snap-inc", "_ticker": "SNAP", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "YouTube (Google/Alphabet)", "Category": "Social/Messaging (video)", "Terms & Conditions URL": "youtube.com/t/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy (Google's overall privacy policy governs YouTube)", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same youth-addiction litigation category as Meta/TikTok/Snapchat; Google agreed to a confidential settlement for a Florida teenager's individual claims (alleging depression, anxiety, and sleep loss from YouTube's 'addictive design') in June 2026, removing YouTube from that specific bellwether trial while Google/Meta remained co-defendants and were found negligent by a Los Angeles jury (awarded $6M to a separate plaintiff, March 2026).", "Arbitration / Class Action Waiver": "YouTube ToS governed by Google's general Terms of Service. Arbitration clause applies to device-related disputes; YouTube-specific web/app disputes may not carry the same mandatory arbitration. NOT FULLY VERIFIED THIS PASS — recommend checking youtube.com/t/terms directly.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Because YouTube is governed by GOOGLE's overall privacy policy and terms rather than a standalone document, any audit of 'Google' as a company should account for YouTube-specific litigation exposure even though the legal documents themselves are shared across Google's whole product suite (Search, Gmail, Maps, Drive, Android, etc.).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Bruno", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": "https://www.ftc.gov/business-guidance/blog/2019/09/170-million-ftc-ny-youtube-settlement-offers-coppa-compliance-tips-platforms-providers", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alphabet Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[OTHER · FL-3] Google reached a confidential settlement with a teen alleging YouTube's 'addictive design' caused harm.\nWHAT THE TERMS SAY: Google agreed to a confidential settlement in June 2026 with a Florida teenager's individual claims alleging depression, anxiety, and sleep loss from YouTube's 'addictive design,' removing YouTube from that bellwether trial.\nWHY IT MATTERS: The confidential settlement removed YouTube from a bellwether trial before the public could see what internal evidence might have surfaced.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] A Los Angeles jury found Google (and Meta) negligent, awarding $6 million over youth-addiction harm.\nWHAT THE TERMS SAY: A separate Los Angeles jury found Google and Meta negligent regarding youth-addiction claims and awarded $6 million to a different plaintiff in March 2026, even as YouTube's own case was separately settled confidentially.\nWHY IT MATTERS: This is a confirmed jury finding of negligence and monetary award, not just an allegation, showing the underlying concern didn't simply disappear after Google's confidential settlement.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Whether YouTube disputes are covered by Google's mandatory arbitration clause is unclear.\nWHAT THE TERMS SAY: YouTube's Terms are governed by Google's general Terms of Service; arbitration applies to device-related disputes, but whether YouTube-specific web/app disputes carry the same mandatory arbitration was not fully verified this pass.\nWHY IT MATTERS: A YouTube user may not know whether they're bound by mandatory arbitration for a web/app dispute without checking the terms directly.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The litigation and settlement facts are clearly documented, but whether YouTube-specific disputes fall under Google's mandatory arbitration clause was not fully verified this pass.", "Exposure Score (0-100)": 16, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "App / Service", "Ownership Path": "YouTube (Google/Alphabet)  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, YouTube (Google/Alphabet) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:25:31Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Same quiet-settlement pattern as TikTok and Snapchat (this same tab): Google reached a CONFIDENTIAL settlement with a Florida teenager who alleged depression, anxiety, and sleep loss from YouTube's 'addictive design' — removing YouTube from the bellwether trial before the public could see what internal evidence might have surfaced. A separate Los Angeles jury still found Google negligent and awarded $6 million to a different plaintiff, so the underlying concern didn't just disappear.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 89, "_entity_id": 131, "_entity_slug": "youtube-google-alphabet", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Temu", "Category": "Shopping/Retail", "Terms & Conditions URL": "temu.com/legal-policy-terms-of-use.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "temu.com/privacy-and-cookie-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "EXTENSIVE, CONCRETE ISSUES: multiple class actions (Ziboukh v. Whaleco; Hu v. Whaleco) allege Temu's app collects personal AND biometric data from users and non-users without consent, beyond what it discloses, with expert claims the app loads tools that 'execute virulent and dangerous malware and spyware activities' on user devices; as of July 2026, SEVEN state Attorneys General (Texas, Arkansas, Kentucky, Nebraska, Oklahoma, Arizona, and newly Iowa) have sued Temu over data collection (including from minors), misleading pricing, and counterfeit goods sold under state/local brand names; a Congressional inquiry asked the FTC to investigate Temu's ties to the Chinese Communist Party; parent company is PDD Holdings (formerly Pinduoduo).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. Temu (PDD Holdings, Shanghai/Boston) ToS governed by Massachusetts law. Temu has faced multiple state AG investigations and class actions over deceptive pricing and gamification mechanics (the 'spin the wheel' feature). The arbitration clause is the primary defense. In Sept 2024, Arkansas AG sued Temu under the state's deceptive trade practices act.", "Fees / Billing Flags": "FTC/DOJ enforcement (Sept 2025): Temu paid a $2 MILLION civil penalty for INFORM Consumers Act violations — failing to give consumers a way to report suspicious seller activity and hiding required seller identity/address information behind multiple steps; also accused in a separate class action of 'phantom pricing' (showing fake inflated 'original' prices to make discounts look bigger than they are).", "Notes": "This is one of the most heavily-documented, multi-pronged 'issue pertaining to customers' companies found in this entire audit — spanning privacy, national security, consumer fraud, and access-to-justice (arbitration-blocking) concerns simultaneously. Recommend treating as a priority company if this informs any customer warning/education materials.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Boston", "HQ State": "Massachusetts", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Massachusetts' is a non-DMV US state", "Parent / Ultimate Owner": "PDD Holdings Inc. (Shanghai/Dublin)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Massachusetts SOC Corporate Search — corp.sec.state.ma.us/corpweb/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: PDD Holdings Inc. (Shanghai/Dublin)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Court filings allege Temu's app loads tools that execute malware and spyware on user devices.\nWHAT THE TERMS SAY: Class actions (Ziboukh v. Whaleco; Hu v. Whaleco) allege Temu's app collects personal and biometric data from both users and non-users without consent, beyond what it discloses, with expert claims the app loads tools that 'execute virulent and dangerous malware and spyware activities' on user devices.\nWHY IT MATTERS: An app installed by tens of millions of Americans is alleged to run malware/spyware-like tools and collect biometric data even from people who never signed up for it.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-1] Temu paid a $2 million FTC penalty for hiding seller identity and blocking suspicious-activity reports.\nWHAT THE TERMS SAY: In a September 2025 FTC/DOJ enforcement action, Temu paid a $2 million civil penalty for INFORM Consumers Act violations, failing to give consumers a way to report suspicious seller activity and hiding required seller identity and address information behind multiple steps.\nWHY IT MATTERS: This is a confirmed, paid federal penalty, not just an allegation, tied to Temu making it harder for consumers to identify or report bad sellers.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[PENDING_LITIGATION · FL-3] Seven state Attorneys General have sued Temu over data collection from minors, pricing, and counterfeits.\nWHAT THE TERMS SAY: As of July 2026, seven state Attorneys General (Texas, Arkansas, Kentucky, Nebraska, Oklahoma, Arizona, and Iowa) have sued Temu over data collection including from minors, misleading pricing, and counterfeit goods sold under state/local brand names.\nWHY IT MATTERS: Multiple state governments, not just private plaintiffs, are pursuing Temu simultaneously over how it handles consumer data and marketing.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "This row is exceptionally well-documented, citing specific case names, state AG actions, penalty amounts, and dates.", "Exposure Score (0-100)": 46, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 9/30 (biometric_collection+6, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Temu  <-  PDD Holdings Inc. (Shanghai/Dublin)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Temu you gave up your biometric identifiers, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:25:34Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Court filings cite expert claims that Temu's app loads tools capable of executing 'virulent and dangerous MALWARE AND SPYWARE activities' on your phone — an app installed by tens of millions of Americans. Separately, Temu's OWN legal strategy is to push individual customer lawsuits into PRIVATE ARBITRATION specifically because that route is confidential, meaning even when law firms win, the outcomes and Temu's underlying practices stay hidden from public view.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 90, "_entity_id": 133, "_entity_slug": "temu", "_issuer": "PDD Holdings Inc.", "_issuer_slug": "pdd-holdings-inc", "_ticker": "PDD", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Shein", "Category": "Shopping/Retail", "Terms & Conditions URL": "shein.com/Terms-of-Use-a-3007.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "shein.com/Privacy-Policy-a-2115.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same general category of concerns as Temu (Chinese-owned, fast-fashion/discount marketplace); Shein and Temu are also suing EACH OTHER — Shein alleges Temu used thousands of Shein's copyrighted images as promotional photos, while Temu has separately accused Shein of anticompetitive conduct — a genuinely unusual dynamic where two companies with similar customer-data concerns are also adversaries in litigation against each other.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver and jury trial waiver. AAA rules. 30-day opt-out via email to legal@shein.com. SHEIN Terms governed by New York law despite the company being headquartered in Singapore (moved from Guangzhou, China). Given SHEIN's well-documented labor and environmental controversies, the arbitration clause insulates the company from US class actions over supply-chain conditions.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Worth researching in the same dedicated pass as Temu given the parallel business model and cross-litigation between the two companies.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Singapore", "HQ State": "Singapore", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ in Singapore, Singapore (non-US)", "Parent / Ultimate Owner": "SHEIN Group (Singapore)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Singapore) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Singapore. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Shein's mandatory arbitration clause shields it from US class actions over its supply chain\nWHAT THE TERMS SAY: Shein imposes mandatory binding arbitration under AAA rules, with a 30-day opt-out by emailing legal@shein.com, governed by New York law despite the company being headquartered in Singapore.\nWHY IT MATTERS: Given Shein's well-documented labor and environmental controversies, the tracker notes this clause specifically insulates the company from US class actions over supply-chain conditions.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Shein bundles a class action waiver into its mandatory arbitration terms\nWHAT THE TERMS SAY: The same arbitration clause includes a class action waiver, meaning customers cannot band together to sue Shein as a group.\nWHY IT MATTERS: Consumers with small individual claims lose the practical leverage of a class action and must pursue disputes alone.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[JURY_WAIVER · FL-3] Shein's terms also waive customers' right to a jury trial\nWHAT THE TERMS SAY: Alongside arbitration and the class waiver, Shein's terms include a jury trial waiver.\nWHY IT MATTERS: Customers give up the option of having a jury, rather than a private arbitrator, decide any dispute with Shein.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly documented, but the Fees/Billing field is explicitly not itemized this pass.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Shein  <-  SHEIN Group (Singapore)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to a jury.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Shein you gave up your right to sue, your right to join a class action, and your right to a jury. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Shein and Temu — two companies facing strikingly similar customer-data and counterfeiting concerns — are simultaneously SUING EACH OTHER, with Shein accusing Temu of stealing its copyrighted product photos and Temu accusing Shein of anticompetitive conduct. Two companies with parallel privacy problems are, at the same time, adversaries fighting over stolen images and market tactics.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 91, "_entity_id": 135, "_entity_slug": "shein", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Amazon", "Category": "Shopping/Retail", "Terms & Conditions URL": "amazon.com/gp/help/customer/display.html?nodeId=508088", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "amazon.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same law firm pursuing the Temu data class action has 'recently initiated class action lawsuits against companies such as Amazon and Apple' per a Temu company spokesperson's own public statement — confirms Amazon faces its own active, similarly-themed data-privacy litigation from the same plaintiffs' firm, though specific case details were not independently captured this pass.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Amazon REMOVED its arbitration clause and class action waiver entirely in July 2021, after facing 75,000+ individual arbitration demands over Alexa recordings (Keller Lenkner). Disputes now go to Washington state courts. This is the opposite direction from the industry trend.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a dedicated follow-up pass on Amazon given its scale and the confirmed-but-unspecified active litigation referenced above.", "Industry (Fortune 500)": "Internet Services and Retailing", "Revenue (Fortune 500)": "$716.9B", "Market Cap": "$2.6T", "Employees": "1,556,000", "HQ City": "Seattle", "HQ State": "Washington", "CEO": "Andrew R. Jassy", "Ticker": "AMZN", "Website (Corporate)": "amazon.com", "Main Mailing Address (legal/privacy notices)": "Amazon.com, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210, USA", "Legal / Privacy Contact Email": "Not verified this pass — Amazon routes privacy requests through its in-account privacy portal", "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AMZN). Service route: c/o General Counsel / Corporate Secretary, Seattle, Washington — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": "https://www.ftc.gov/news-events/news/press-releases/2025/09/ftc-secures-historic-25-billion-settlement-against-amazon", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "N/A - this row IS the parent entity", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Corporation Trust Company / CT Corporation System", "Registered Agent Address / Service Notes": "Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801. Reporting on CT Corporation's Delaware office identifies Alphabet, Amazon, Apple, and Facebook/Meta as among the entities served at this address — CT's Delaware office acts as registered agent for over two-thirds of the Fortune 500. VERIFY the specific Amazon entity on the Delaware registry before serving: Amazon.com, Inc. is distinct from Amazon.com Services LLC, Amazon Web Services, Inc., Whole Foods Market, and Audible — each may require its own service event.", "Company Brief": "Amazon.com, Inc. operates e-commerce, cloud computing (AWS), advertising, streaming (Prime Video), devices (Alexa, Kindle, Fire), grocery (Whole Foods), and healthcare lines. For this tracker its defining feature is that Amazon REMOVED its consumer arbitration clause in July 2021 — the only major US consumer technology company documented here to have done so — after being hit with roughly 75,000 individual arbitration demands over Alexa recordings.", "Investor Overview": "Nasdaq: AMZN. INVESTOR-RELEVANT LEGAL STRUCTURE: Amazon's 2021 removal of its arbitration clause is a case study in mass arbitration economics — filing fees on ~75,000 individual AAA demands exceeded the expected cost of class litigation, so the company chose courts instead. Amazon now litigates consumer disputes in Washington state courts. This increases class-action exposure but eliminates per-claim arbitration fee liability.", "Major Issues Record": "2021-06/07: Amazon removes the arbitration clause and class-action waiver from its Conditions of Use following ~75,000 individual arbitration demands coordinated by Keller Lenkner over Alexa voice recordings; disputes move to Washington state courts. | 2025-09-25: FTC stipulated order in the Prime enrollment/cancellation matter — $1B civil penalty plus $1.5B consumer redress ($2.5B total). NOTE: this is a penalty-plus-redress structure, not a $2.5B 'fine'. | Ongoing: Amazon subsidiaries inherit the no-arbitration posture, including Whole Foods, Audible, Ring, and Amazon One — the last of which collects irreversible palm-vein biometrics, making the absence of an arbitration clause unusually consequential.", "T&C Key Provisions (paraphrased)": "PARAPHRASED, not quoted. Amazon's Conditions of Use no longer contain a mandatory arbitration provision or class-action waiver. Disputes are directed to state or federal courts in King County, Washington, under Washington law. Separate terms govern AWS, Prime Video, Audible, and Ring. CONSUMER ACTION: no opt-out is required — Amazon customers retain court access and class-action rights by default, which is not true of most competitors in this tracker.", "Re-verify By": "2027-08-13 (watch for re-introduction of an arbitration clause — this is a reversible choice)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-4] FTC found Amazon used confusing checkout screens to sign millions up for Prime, then made it hard to cancel\nWHAT THE TERMS SAY: Per the FTC's finding, Amazon enrolled millions of people in Prime without clear consent using confusing checkout screens, then made cancellation deliberately difficult.\nWHY IT MATTERS: Amazon paid $2.5 billion total ($1.5B in customer refunds, $1B penalty) — the largest completed FTC settlement in this entire tracker — meaning many customers were charged for a subscription they may not have knowingly agreed to.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[BIOMETRICS · FL-2] Amazon One collects irreversible palm-vein biometrics, and Amazon has no arbitration clause.\nWHAT THE TERMS SAY: Amazon subsidiaries, including Amazon One, inherit Amazon's no-arbitration posture; Amazon One collects palm-vein biometric data described in the tracker as irreversible.\nWHY IT MATTERS: The tracker calls the absence of an arbitration clause unusually consequential here: Amazon customers retain court access and class-action rights by default, which is not true of most competitors in this tracker.\n(evidence: Major Issues Record; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[PENDING_LITIGATION · FL-2] Amazon reportedly faces its own active data-privacy class actions from the same firm suing Temu\nWHAT THE TERMS SAY: A Temu company spokesperson stated publicly that the same law firm pursuing Temu's data class action has 'recently initiated class action lawsuits against companies such as Amazon and Apple.'\nWHY IT MATTERS: This confirms Amazon faces similarly-themed data-privacy litigation, though the tracker notes specific case details were not independently captured this pass.\n(evidence: Data Sharing/Selling Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The $2.5B FTC settlement is clearly documented, but a separate Amazon-specific data-privacy suit is referenced only via a competitor's spokesperson, not independently confirmed.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 6/30 (biometric_collection+6) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 20/20 (severity5+20, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Amazon", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Amazon you gave up your biometric identifiers and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 66.7, "URL Last Validated": "2026-09-08T19:25:40Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "The FTC found Amazon used confusing checkout screens to sign millions of people up for Prime WITHOUT clear consent, then made it deliberately hard to cancel — the exact same 'dark pattern subscription trap' documented for Uber One elsewhere in this tab. Amazon paid $2.5 BILLION total ($1.5B in customer refunds, $1B penalty) — the single largest completed FTC settlement found anywhere in this entire 890+ company tracker.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 92, "_entity_id": 136, "_entity_slug": "amazon", "_issuer": "Amazon", "_issuer_slug": "amazon", "_ticker": "AMZN", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Walmart", "Category": "Shopping/Retail", "Terms & Conditions URL": "corporate.walmart.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "corporate.walmart.com/privacy-security", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not itemized separately from the FTC finding below.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Walmart.com Terms of Use, AAA rules. 30-day opt-out via written notice to Walmart Inc., Legal Department, 702 SW 8th Street, Bentonville AR 72716. Covers Walmart.com, Walmart app, Walmart+, and Walmart Pay. Given Walmart's position as the largest US retailer by revenue ($648B, FY2024), the arbitration clause covers more consumer transactions than any other single retailer.", "Fees / Billing Flags": "CONFIRMED MAJOR FINDING: Walmart agreed to a $100 MILLION judgment (Feb 2026) to settle FTC and multi-state charges over DECEPTIVE EARNINGS CLAIMS related to its Spark Driver gig-delivery service — this is a gig-worker-facing issue (similar in spirit to the DoorDash/Instacart tip-transparency findings above) rather than a retail-customer privacy issue, but relevant if your audit also covers how these companies treat their delivery workforce, which indirectly affects customer-facing service quality and cost.", "Notes": "This is a large, concrete, dollar-quantified enforcement action — one of the bigger completed FTC settlements found in this whole audit, comparable in scale to the Cash App/Block CFPB action.", "Industry (Fortune 500)": "General Merchandisers", "Revenue (Fortune 500)": "$713.2B", "Market Cap": "$870.1B", "Employees": "2,100,000", "HQ City": "Bentonville", "HQ State": "Arkansas", "CEO": "John R. Furner", "Ticker": "WMT", "Website (Corporate)": "walmart.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (WMT). Service route: c/o General Counsel / Corporate Secretary, Bentonville, Arkansas — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Arkansas' is a non-DMV US state", "Parent / Ultimate Owner": "Walmart Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Arkansas) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Arkansas. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Walmart's mandatory arbitration clause covers more consumer transactions than any single US retailer\nWHAT THE TERMS SAY: Walmart's Terms of Use impose mandatory binding arbitration with a class action waiver under AAA rules, with a 30-day opt-out by written notice to its Bentonville, AR legal department, covering Walmart.com, the Walmart app, Walmart+, and Walmart Pay.\nWHY IT MATTERS: As the largest US retailer by revenue ($648B, FY2024), Walmart's clause reaches an unusually large share of everyday consumer transactions.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Walmart's arbitration terms bundle in a class action waiver across all its shopping platforms\nWHAT THE TERMS SAY: The same Walmart.com Terms of Use that impose arbitration also waive customers' ability to bring a class action.\nWHY IT MATTERS: Customers across Walmart.com, the app, Walmart+, and Walmart Pay must pursue disputes individually rather than as a group.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[REGULATORY_PENALTY · FL-1] Walmart paid a $100 million judgment over deceptive earnings claims to Spark Driver gig workers\nWHAT THE TERMS SAY: Walmart agreed to a $100 million judgment (Feb 2026) settling FTC and multi-state charges over deceptive earnings claims made to its Spark Driver gig-delivery workers.\nWHY IT MATTERS: The tracker notes this is a gig-worker-facing issue rather than a retail-customer privacy issue, but it indirectly affects delivery service quality and cost for shoppers.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are precisely documented, but Data Sharing/Selling flags were not itemized separately and the major penalty found concerns gig workers rather than shoppers.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 5/20 (severity2+2, penalty+3) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Walmart  <-  Walmart Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Walmart you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:25:43Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Walmart paid a $100 MILLION judgment over deceptive EARNINGS CLAIMS made to its own Spark Driver gig-delivery workers — people were reportedly told they could make more money than they actually could, a direct financial deception aimed at the workforce, not just shoppers.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 93, "_entity_id": 138, "_entity_slug": "walmart", "_issuer": "Walmart Inc.", "_issuer_slug": "walmart-inc", "_ticker": "WMT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Uber (rides + Uber Eats + Uber One)", "Category": "Rideshare/Delivery", "Terms & Conditions URL": "uber.com/legal/en/document/?name=general-terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "privacy.uber.com", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not itemized separately from the fee/billing findings below — this company's most significant current issue is billing/subscription practice, not data privacy per se.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out via email to optout@uber.com. Uber's June 2026 ToS update introduced three structural changes: (1) an AUTONOMOUS VEHICLE clause — by accepting the ToS, you acknowledge you may be matched with an AV at SAE Level 3-5, and the arbitration clause covers AV-related injuries; (2) a new LITIGATION FUNDING DISCLOSURE requirement — plaintiffs must reveal third-party funding arrangements; (3) the Nogare v. Uber ruling (11th Circuit, 2025) upheld Uber's arbitration clause against an unconscionability challenge from an injured passenger, establishing that clicking 'accept' on a terms update binds you to arbitration for future injuries. Like Amtrak, Uber's clause covers personal injury, not just billing.", "Fees / Billing Flags": "MAJOR ACTIVE FEDERAL CASE: the FTC, joined by 21 STATES and DC, filed an amended complaint (Dec 2025) alleging Uber charged consumers for Uber One subscriptions WITHOUT CONSENT, failed to deliver promised savings (including advertised $0 delivery fees), and made cancellation deliberately difficult — the FTC specifically alleges canceling Uber One can require navigating up to 23 SCREENS AND 32 ACTIONS, directly contradicting Uber's own public claim that cancellation takes '20 seconds or less.' A separate class action (Warren, et al.) alleges hidden fees/false advertising and directly argues Uber's own Uber One arbitration clause is 'unconscionable and unenforceable.' Uber and DoorDash have also jointly sued New York City to block a law requiring a 10% minimum tip prompt at checkout for delivery workers.", "Notes": "This is a textbook 'dark pattern' subscription-cancellation case with a specific, quantified obstruction (23 screens/32 actions) — one of the most concrete, quotable findings in this entire audit for customer-facing education about subscription traps.", "Industry (Fortune 500)": "Internet Services and Retailing", "Revenue (Fortune 500)": "$52.0B", "Market Cap": "$143.2B", "Employees": "31,100", "HQ City": "San Francisco", "HQ State": "California", "CEO": "Dara Khosrowshahi", "Ticker": "UBER", "Website (Corporate)": "uber.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (UBER). Service route: c/o General Counsel / Corporate Secretary, San Francisco, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-4] FTC alleges Uber One can take up to 23 screens and 32 actions to cancel, despite Uber's '20 seconds' claim\nWHAT THE TERMS SAY: An amended FTC complaint (joined by 21 states and DC, Dec 2025) alleges Uber charged consumers for Uber One without consent, failed to deliver promised savings like advertised $0 delivery fees, and made cancellation require up to 23 screens and 32 actions.\nWHY IT MATTERS: This directly contradicts Uber's own public claim that cancellation takes '20 seconds or less,' and a plaintiff's attorney is quoted calling Uber 'very aggressive' about using arbitration to make individual fee disputes too costly to pursue.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Uber's June 2026 terms update extends arbitration to autonomous-vehicle personal-injury claims.\nWHAT THE TERMS SAY: Uber's mandatory arbitration clause has a 30-day opt-out via email; a June 2026 update added an autonomous-vehicle clause covering AV-related injuries, and the Nogare v. Uber ruling (11th Circuit, 2025) upheld the clause against an unconscionability challenge, establishing that accepting a terms update binds riders to arbitration for future injuries.\nWHY IT MATTERS: Like Amtrak, Uber's clause covers personal injury, not just billing; per Nogare v. Uber (11th Circuit, 2025), clicking 'accept' on a terms update binds a rider to arbitration for future injuries.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[CLASS_ACTION_WAIVER · FL-3] A separate class action argues Uber One's own arbitration/class-waiver clause is unconscionable\nWHAT THE TERMS SAY: The Warren, et al. class action alleges hidden fees and false advertising and directly argues that Uber's Uber One arbitration clause is 'unconscionable and unenforceable.'\nWHY IT MATTERS: If the clause is enforced despite the challenge, affected subscribers cannot band together to dispute the alleged hidden fees.\n(evidence: Fees / Billing Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Both the arbitration clause's scope and the FTC's cancellation-difficulty allegations are documented with specific, sourced detail.", "Exposure Score (0-100)": 42, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 8, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 8/20 (unilateral_modification+5, auto_renewal_or_fee_trap+3) | Record 10/20 (severity3+8, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Uber (rides + Uber Eats + Uber One)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Uber (rides + Uber Eats + Uber One) you gave up your right to sue, your right to join a class action, your right to be consulted before terms change, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:25:45Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Uber publicly claims canceling Uber One takes '20 seconds or less.' The FTC's own investigation, joined by 21 states and DC, found it can actually take UP TO 23 SCREENS AND 32 SEPARATE ACTIONS to cancel — while Uber allegedly charged people for the subscription without clear consent in the first place and failed to deliver the '$0 delivery fees' it advertised. A plaintiff's attorney specifically calls Uber 'very aggressive' about using arbitration to make individual fee disputes too small and costly for customers to bother fighting.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 94, "_entity_id": 139, "_entity_slug": "uber-rides-uber-eats-uber-one", "_issuer": "Uber (rides + Uber Eats + Uber One)", "_issuer_slug": "uber-rides-uber-eats-uber-one", "_ticker": "UBER", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Lyft", "Category": "Rideshare", "Terms & Conditions URL": "lyft.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "lyft.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Claims involving misuse of personal data by rideshare apps/third parties are a recognized recurring category of mass-arbitration claims industry-wide (per Class Action U's rideshare-industry overview), though no Lyft-specific data breach was independently confirmed this pass.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out via email to legal@lyft.com. Lyft's arbitration clause also governs Capital Bikeshare (CaBi) — a DMV resident using government-sponsored bikeshare is bound by Lyft's private California-based terms. Lyft's clause has been upheld in multiple circuits.", "Fees / Billing Flags": "A March 2026 AAA arbitration award (in the broader rideshare industry, specifically referencing an Uber case per the same source) found a driver liable for a weather-related collision — illustrates that arbitration DOES sometimes rule in the customer's favor, not exclusively in the company's.", "Notes": "Financial analysts (Wedbush, May 2026) downgraded Lyft citing risk from autonomous-vehicle disruption to its business model — not a customer-protection issue, but relevant business-continuity context if this audit also considers company stability.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Lyft, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Lyft, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Lyft's mandatory arbitration clause also binds Capital Bikeshare riders in DC to private California terms\nWHAT THE TERMS SAY: Lyft imposes mandatory binding arbitration with a class action waiver and a 30-day opt-out via email; the clause also governs Capital Bikeshare (CaBi) and has been upheld in multiple circuits.\nWHY IT MATTERS: A DMV resident using government-sponsored bikeshare ends up bound by Lyft's private, California-based arbitration terms without necessarily realizing it.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Riders can waive their right to sue Lyft the moment they tap to request a ride\nWHAT THE TERMS SAY: Industry researchers describe Lyft's arbitration/class-waiver clause as something a rider may 'unknowingly waive [their rights]... the moment they tap to ride.'\nWHY IT MATTERS: A single tap made in the seconds before a car arrives gives up the right to sue in court over anything that happens during that ride.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data Sharing/Selling flags for Lyft are described as an industry-wide category with no Lyft-specific breach confirmed, and the Fees/Billing field actually cites an arbitration award that favored a driver, not a troubling company-specific fact; only the arbitration/class-waiver clause is substantiated enough for distinct items.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are well documented, but data-sharing and fee claims are explicitly unconfirmed or industry-wide rather than Lyft-specific.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Lyft  <-  Lyft, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Lyft you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:25:48Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Industry researchers describe Lyft's arbitration clause as something a rider may 'unknowingly waive [their rights]... the moment they tap to ride' — a single tap, made in the seconds before a car arrives, giving up the right to sue in court over anything that happens during that ride.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 95, "_entity_id": 141, "_entity_slug": "lyft", "_issuer": "Lyft, Inc.", "_issuer_slug": "lyft-inc", "_ticker": "LYFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "DoorDash", "Category": "Delivery", "Terms & Conditions URL": "doordash.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "doordash.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not itemized separately from the fee/billing findings below.", "Arbitration / Class Action Waiver": "Standard binding arbitration + class action waiver expected industry-wide for this category (not independently confirmed word-for-word this pass).", "Fees / Billing Flags": "NEW YORK AG SETTLEMENT: DoorDash was required to pay $16.75 MILLION after the NY AG investigated allegations that DoorDash misled consumers AND delivery workers about how tips were paid — specifically, using customer tips to SUBSIDIZE workers' base pay rather than paying the full tip on top of guaranteed pay, contrary to what customers reasonably believed their tip was doing. DoorDash controls the largest share of the food delivery market but did NOT submit a comment to the FTC's 2026 food-delivery junk-fee rulemaking process, unlike competitor Grubhub (which proactively supported extending its own post-settlement transparency reforms industry-wide). DoorDash and Uber jointly sued NYC to block a mandatory 10% tip-prompt law for delivery workers.", "Notes": "The 'tips subsidizing base pay instead of being additive' finding is a very concrete, easily-explained customer-trust issue — directly analogous to the earlier Instacart DC settlement on the same theme (see Instacart row below).", "Industry (Fortune 500)": "Internet Services and Retailing", "Revenue (Fortune 500)": "$13.7B", "Market Cap": "$77.4B", "Employees": "23,700", "HQ City": "San Francisco", "HQ State": "California", "CEO": "Tony Xu", "Ticker": "DASH", "Website (Corporate)": "doordash.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (DASH). Service route: c/o General Counsel / Corporate Secretary, San Francisco, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": "https://ag.ny.gov/press-release/2025/attorney-general-james-secures-1675-million-doordash-cheating-delivery-workers", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "DoorDash, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: DoorDash, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] NY AG found DoorDash used customer tips to subsidize workers' base pay; DoorDash paid $16.75M.\nWHAT THE TERMS SAY: The NY AG investigated allegations that DoorDash misled consumers and delivery workers about how tips were paid - specifically, using customer tips to subsidize workers' base pay rather than paying the full tip on top of guaranteed pay - and DoorDash was required to pay $16.75 million.\nWHY IT MATTERS: A customer's tip may not have added any extra money for the driver at all — it just replaced money DoorDash would otherwise have had to pay itself.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] DoorDash is expected to carry standard mandatory arbitration, though not independently confirmed this pass\nWHAT THE TERMS SAY: The tracker notes standard binding arbitration and a class action waiver are expected industry-wide for this category, but were not independently confirmed word-for-word for DoorDash this pass.\nWHY IT MATTERS: If confirmed, this would waive customers' ability to sue DoorDash in court or join a class action, but the tracker flags this specific detail as unverified.\n(evidence: Arbitration / Class Action Waiver; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-1] DoorDash and Uber jointly sued NYC to block a mandatory 10% tip-prompt law for delivery workers.\nWHAT THE TERMS SAY: DoorDash and Uber have jointly sued New York City to block a law requiring a 10% minimum tip prompt at checkout for delivery workers.\nWHY IT MATTERS: DoorDash is going to court to block a law that would require a 10% minimum tip prompt at checkout for delivery workers, on the same tipping issue as its $16.75 million NY AG settlement.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The tip-subsidy settlement is clearly documented, but arbitration terms are only assumed industry-standard and not independently confirmed for DoorDash.", "Exposure Score (0-100)": 16, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "DoorDash  <-  DoorDash, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, DoorDash takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:25:50Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "New York's AG found DoorDash was using customer TIPS to SUBSIDIZE delivery workers' base pay instead of paying tips on top of guaranteed wages — meaning a customer's tip may not have added any extra money for the driver at all; it just replaced money DoorDash would otherwise have had to pay itself. DoorDash paid $16.75 million over it, and also, alongside Uber, sued NYC to block a law requiring a mandatory tip prompt at checkout.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 96, "_entity_id": 143, "_entity_slug": "doordash", "_issuer": "DoorDash, Inc.", "_issuer_slug": "doordash-inc", "_ticker": "DASH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Instacart", "Category": "Delivery/Grocery", "Terms & Conditions URL": "instacart.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "instacart.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not itemized separately from the fee/billing findings below.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. Instacart ToS, AAA rules. Instacart processes grocery orders including items that reveal dietary restrictions, health conditions, and household composition — the arbitration clause covers disputes over how this sensitive purchase data is shared with CPG brands and advertising partners.", "Fees / Billing Flags": "TWO SEPARATE GOVERNMENT SETTLEMENTS: (1) FTC v. Maplebear Inc. d/b/a Instacart (stipulated final order, Jan 13, 2026) — FTC alleged Instacart falsely advertised 'free delivery' on orders that still carried mandatory 'service fees' and sometimes additional charges, and separately violated ROSCA by not clearly disclosing all material terms of its Instacart+ subscription before taking customers' billing information; Instacart was ordered to fix both practices going forward. (2) An earlier DC Attorney General case (settled 2022) found Instacart misled users into believing an 'optional service fee' was a tip that would go to delivery workers, when in fact that money funded Instacart's own operating expenses — Instacart paid $1.8 million and was enjoined from repeating similar fee-purpose misrepresentations.", "Notes": "The 'service fee disguised as a tip' finding directly parallels DoorDash's NY settlement above — together these make a strong, well-documented pattern across the food-delivery category specifically about tip/fee transparency, useful if this audit is meant to surface cross-company patterns rather than one-off company quirks.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Maplebear Inc. (d/b/a Instacart)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Maplebear Inc. (d/b/a Instacart)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] DC AG found Instacart labeled a mandatory charge an 'optional service fee' that customers believed was a tip\nWHAT THE TERMS SAY: An earlier DC Attorney General case (settled 2022) found Instacart misled users into believing an 'optional service fee' was a tip going to delivery workers, when it actually funded Instacart's own operating expenses.\nWHY IT MATTERS: Instacart paid $1.8 million and was enjoined from repeating similar fee-purpose misrepresentations, directly paralleling DoorDash's tip-labeling settlement elsewhere in this tracker.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[AUTO_RENEWAL_FEES · FL-1] FTC alleged Instacart advertised 'free delivery' on orders carrying mandatory fees; order requires fixes.\nWHAT THE TERMS SAY: In FTC v. Maplebear Inc. d/b/a Instacart (stipulated final order, Jan 13, 2026), the FTC alleged Instacart falsely advertised 'free delivery' on orders that still carried mandatory 'service fees' and sometimes additional charges, and separately violated ROSCA by not clearly disclosing all material terms of its Instacart+ subscription before taking customers' billing information; Instacart was ordered to fix both practices going forward.\nWHY IT MATTERS: Customers could be charged for a subscription whose terms weren't clearly disclosed before their billing information was collected.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Instacart's arbitration clause covers disputes over sensitive grocery data shared with CPG brands and advertisers\nWHAT THE TERMS SAY: Instacart processes grocery orders that reveal dietary restrictions, health conditions, and household composition; its arbitration clause covers disputes over how this sensitive purchase data is shared with CPG brands and advertising partners.\nWHY IT MATTERS: Grocery purchase history can reveal intimate details about a household's health and composition, and the tracker frames this data-sharing as a live source of disputes.\n(evidence: Arbitration / Class Action Waiver; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Both settlements are dated, named, and quantified, and the sensitive-data sharing is directly tied to the arbitration clause's stated scope.", "Exposure Score (0-100)": 42, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 11/20 (severity3+8, penalty+3) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Instacart  <-  Maplebear Inc. (d/b/a Instacart)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Instacart you gave up your data shared corporate-wide, your right to sue, your right to join a class action, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "DC's Attorney General found Instacart labeled a mandatory charge an 'optional service fee' that customers reasonably believed was a TIP going straight to their shopper — when in reality that money funded INSTACART'S OWN OPERATING EXPENSES. Separately, the FTC found Instacart advertised 'free delivery' on orders that still carried hidden mandatory fees. Two different regulators, two different years, same underlying pattern: money labeled one way that actually goes somewhere else.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 97, "_entity_id": 145, "_entity_slug": "instacart", "_issuer": "Maplebear Inc.", "_issuer_slug": "maplebear-inc", "_ticker": "CART", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Venmo (PayPal)", "Category": "Payments (P2P)", "Terms & Conditions URL": "venmo.com/legal/us-user-agreement/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "venmo.com/legal/us-privacy-policy/ (governed by PayPal's broader global privacy statement)", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "2018 FTC SETTLEMENT (Section 5 FTC Act + Gramm-Leach-Bliley Act violations): Venmo shared users' personal info with 'everyone on the Internet' by default — not just each user's 'social web' as its own privacy policy claimed — and its privacy notice link was printed in low-contrast dark-grey-on-light-grey text; a 2026 independent researcher scraped 207 MILLION public Venmo transactions via the API, demonstrating the real-world exposure created by public-by-default settings; Venmo's third-party bank-linking partner Plaid separately paid a $58 MILLION settlement for collecting more banking data (transaction history, investment data, salary info) than necessary when users entered bank credentials through Venmo's Plaid-powered login screen; as of 2026, Venmo reportedly still shares data with third parties for marketing, ignores Do Not Track signals, and states it will keep sharing data even after account closure. A New Hampshire AG settlement separately required Venmo to make privacy-as-default the sign-up option and add clearer scam warnings.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. PayPal's User Agreement governs Venmo. 30-day opt-out via written notice to PayPal Inc., Attn: Litigation Department, 2211 North First Street, San Jose, CA 95131. Venmo transaction data (who paid whom, for what, social feed comments) is uniquely revealing — the arbitration clause covers disputes over how this social-payment graph is monetized.", "Fees / Billing Flags": "ACTIVE FRAUD-REIMBURSEMENT LITIGATION (Al-Ramahi v. PayPal, N.D. Cal., ongoing in 2026): alleges Venmo structures peer-to-peer transfers to avoid Electronic Fund Transfer Act (EFTA) fraud-reimbursement protections that apply to debit/credit cards and checks, denying reimbursement to scam victims even when reported promptly; separate ongoing investigations into undisclosed credit-card cash-advance fees on Venmo transfers and Washington State unsolicited 'Invite Friends' referral texts (potentially $500/message under state law).", "Notes": "The 2018 FTC settlement is now 8 years old but the 2026 researcher's 207-million-transaction scrape shows the underlying public-by-default problem persists in practice — a good example of how a settlement can mandate disclosure changes without necessarily fixing the underlying default behavior.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Jose", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "PayPal Holdings, Inc.", "Years Referenced in Finding (heuristic)": "2018, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: PayPal Holdings, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] FTC found Venmo shared users' data with 'everyone on the Internet' by default, and the pattern reportedly persists\nWHAT THE TERMS SAY: The 2018 FTC settlement found Venmo shared personal info with 'everyone on the Internet' by default, not just each user's 'social web' as its privacy policy claimed, with the privacy notice link printed in low-contrast dark-grey-on-light-grey text. As of 2026, Venmo reportedly still shares data with third parties for marketing and ignores Do Not Track signals.\nWHY IT MATTERS: A 2026 independent researcher scraped 207 million public Venmo transactions via the app's own API, demonstrating the underlying public-by-default exposure never fully went away.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Venmo's bank-linking partner Plaid paid $58M for over-collecting banking data through Venmo's login screen\nWHAT THE TERMS SAY: Venmo's third-party bank-linking partner Plaid separately paid a $58 million settlement for collecting more banking data (transaction history, investment data, salary info) than necessary when users entered bank credentials through Venmo's Plaid-powered login screen.\nWHY IT MATTERS: Users connecting a bank account to Venmo may have had far more financial data collected than the transaction itself required.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[PENDING_LITIGATION · FL-1] Active suit alleges Venmo structures transfers to dodge federal fraud-reimbursement protections\nWHAT THE TERMS SAY: Al-Ramahi v. PayPal (N.D. Cal., ongoing in 2026) alleges Venmo structures peer-to-peer transfers to avoid Electronic Fund Transfer Act fraud-reimbursement protections that apply to debit/credit cards and checks.\nWHY IT MATTERS: If true, scam victims who report fraud promptly could still be denied reimbursement that they'd receive on a debit card or check transaction.\n(evidence: Fees / Billing Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2018 FTC findings and Plaid settlement are well documented, but current 2026 sharing practices are described only as 'reportedly' continuing.", "Exposure Score (0-100)": 52, "Exposure Band": "High", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 15, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 15/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Venmo (PayPal)  <-  PayPal Holdings, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Venmo (PayPal) you gave up your personal data sold onward, your data shared corporate-wide, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:25:51Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "In 2018, the FTC found Venmo was sharing users' personal transaction info with 'EVERYONE ON THE INTERNET' by default — not the limited 'social web' its own privacy policy claimed — while the link to that actual privacy policy was printed in barely-visible dark-grey-on-light-grey text. Eight years later, in 2026, a researcher simply scraped 207 MILLION public Venmo transactions through the app's own API, proving the underlying public-by-default exposure never really went away. On top of that: active litigation alleges Venmo deliberately structures money transfers to dodge federal fraud-reimbursement protections that apply to debit cards and checks — meaning scam victims who report fraud promptly can still be denied reimbursement.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 98, "_entity_id": 147, "_entity_slug": "venmo-paypal", "_issuer": "PayPal Holdings, Inc.", "_issuer_slug": "paypal-holdings-inc", "_ticker": "PYPL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cash App (Block, Inc.)", "Category": "Payments (P2P)", "Terms & Conditions URL": "cash.app/legal/us/en-us/tos", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "cash.app/legal/us/en-us/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Consumer Reports' 2023 multi-app investigation found Cash App was the ONLY one of four P2P apps tested (Cash App, Venmo, Zelle, Apple Cash) whose company explicitly acknowledged data-sharing transparency as an area needing improvement and committed to working with CR on it — a real point of contrast worth noting, though it doesn't resolve the underlying practice.", "Arbitration / Class Action Waiver": "Standard mandatory binding arbitration; gives users a 30-day opt-out window by mail, same as Venmo/Zelle.", "Fees / Billing Flags": "MAJOR CFPB ENFORCEMENT ACTION (Jan 2025): the CFPB ordered Cash App's parent company Block, Inc. to pay UP TO $120 MILLION in consumer refunds plus a separate $55 MILLION penalty for failing to prevent fraud and misrepresenting the consumer protections actually available to Cash App users — one of the largest single enforcement actions found anywhere in this entire audit by dollar amount.", "Notes": "The $120M+$55M combined CFPB action is a genuinely major, already-adjudicated finding — worth highlighting prominently alongside Robinhood's SEC settlement as one of the two largest completed regulatory actions across this whole tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Oakland", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": "https://www.consumerfinance.gov/archive/newsroom/cfpb-orders-operator-of-cash-app-to-pay-175-million-and-fix-its-failures-on-fraud/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Block, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Block, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] CFPB ordered Block to pay up to $120M in refunds plus a $55M penalty over Cash App fraud failures\nWHAT THE TERMS SAY: A January 2025 CFPB enforcement action ordered Cash App's parent company Block, Inc. to pay up to $120 million in consumer refunds plus a separate $55 million penalty for failing to prevent fraud and misrepresenting the consumer protections actually available to Cash App users.\nWHY IT MATTERS: People may have believed they had safeguards that, in practice, weren't there when they needed them; the tracker calls this one of the largest single enforcement actions found anywhere in the audit by dollar amount.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Cash App imposes standard mandatory binding arbitration with a 30-day opt-out\nWHAT THE TERMS SAY: Cash App's terms include standard mandatory binding arbitration, giving users a 30-day opt-out window by mail, the same pattern as Venmo and Zelle.\nWHY IT MATTERS: Customers must affirmatively opt out within 30 days or give up default access to court for disputes with Cash App.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The Data Sharing field describes a comparatively positive contrast (Cash App was the only app in a Consumer Reports study to acknowledge its data-sharing transparency gap) rather than a distinct troubling practice, and the row's own text does not explicitly confirm a class action waiver for Cash App specifically; only the CFPB penalty and the arbitration mandate are substantive enough for distinct items.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The CFPB penalty is clearly detailed, but the arbitration clause and data-sharing practices are only briefly summarized by comparison to peer apps.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Cash App (Block, Inc.)  <-  Block, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Cash App (Block, Inc.) you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:25:56Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "The CFPB ordered Cash App's parent company to pay UP TO $120 MILLION back to defrauded customers plus a separate $55 MILLION penalty, finding Cash App failed to prevent fraud AND misrepresented what protections were actually available to users — meaning people may have believed they had safeguards that, in practice, weren't there when they needed them.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 99, "_entity_id": 149, "_entity_slug": "cash-app-block-inc", "_issuer": "Block, Inc.", "_issuer_slug": "block-inc", "_ticker": "XYZ", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Zelle", "Category": "Payments (P2P bank network)", "Terms & Conditions URL": "zellepay.com/legal (Terms — direct URL not individually captured this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "zellepay.com/privacy-policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Zelle processes real-time payment data (sender, recipient, amount, memo, timestamp) through the Early Warning Services infrastructure owned by 7 major US banks (JPMorgan Chase, Bank of America, Wells Fargo, Capital One, PNC, Truist, US Bancorp). Zelle's data is accessible to all 7 owner-banks. The NY AG complaint (2024) alleged Zelle's weak fraud protections enabled $300M+ in consumer losses — Zelle's data-sharing with the owner-bank consortium means fraud-detection data flows across competing banks.", "Arbitration / Class Action Waiver": "Standard mandatory binding arbitration; per Consumer Reports, gives users a 30-day opt-out window by mail, same pattern as Venmo/Cash App.", "Fees / Billing Flags": "Zelle has faced CONGRESSIONAL SCRUTINY specifically over fraud-reimbursement practices — unlike Venmo/Cash App, Zelle is operated directly by a consortium of major banks (Early Warning Services, jointly owned by Bank of America, Chase, Wells Fargo, and others) rather than a standalone fintech, meaning a Zelle fraud dispute may implicate BOTH Zelle's own terms AND the customer's underlying bank account agreement (several of which are already documented in the Banks tab of this tracker) — worth cross-referencing rather than treating as fully separate.", "Notes": "Zelle's bank-consortium ownership structure is structurally different from every other payment app in this batch — worth flagging since a customer's Zelle complaint may actually route back to their bank's own arbitration clause (e.g., Bank of America's newly-added arbitration, or Chase's reinstated clause, both already documented in the Banks tab).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Scottsdale", "HQ State": "Arizona", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Original tracker build — origin not recorded | Corrected 2026-08-06 (dollar-figure/date precision, sources re-verified via web search)", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.consumerfinance.gov/enforcement/actions/early-warning-services-llc-bank-of-america-na-jpmorgan-chase-bank-na-wells-fargo-bank-na/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Early Warning Services, LLC (owned by 7 largest US banks)", "Years Referenced in Finding (heuristic)": "2019, 2023, 2025, 2017", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Arizona Corporation Commission eCorp — ecorp.azcc.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Early Warning Services, LLC (owned by 7 largest US banks)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[LIABILITY_CAP_INDEMNITY · FL-1] CFPB suit: Chase/BofA/Wells customers lost $870M+ to Zelle fraud as reimbursement fell 62% to 38%.\nWHAT THE TERMS SAY: Customers of Chase, Bank of America, and Wells Fargo lost more than $870 million to Zelle fraud over seven years, and the banks' own reimbursement rate for victims fell from 62% in 2019 to just 38% in 2023, per the CFPB's own lawsuit.\nWHY IT MATTERS: The tracker notes a genuine gap in federal law: if a hacker steals your login, you're protected, but if a scammer tricks you into sending money yourself, federal law provides no reimbursement right at all because you technically authorized the transfer.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[PENDING_LITIGATION · FL-1] CFPB's Zelle fraud lawsuit was dropped with prejudice in 2025; New York State picked up a larger claim\nWHAT THE TERMS SAY: The CFPB's lawsuit over Zelle fraud reimbursement was dropped entirely in 2025 under a new administration, dismissed 'with prejudice.' New York's AG then filed its own related lawsuit (Aug 13, 2025) alleging a larger figure — more than $1 billion stolen from 2017-2023 — under NY's own fraud statute.\nWHY IT MATTERS: The tracker notes NY's action is a parallel case under state law, not identical litigation, so federal accountability on this specific claim is now foreclosed.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Zelle payment data is accessible to all seven bank owners of its Early Warning Services infrastructure\nWHAT THE TERMS SAY: Zelle processes real-time payment data (sender, recipient, amount, memo, timestamp) through the Early Warning Services infrastructure jointly owned by JPMorgan Chase, Bank of America, Wells Fargo, Capital One, PNC, Truist, and US Bancorp, and that data is accessible to all seven owner-banks.\nWHY IT MATTERS: Fraud-detection data flows across otherwise-competing banks, a structure the tracker flags as unlike any other payment app in this batch.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The fraud-reimbursement statistics, CFPB dismissal, and NY AG lawsuit are all dated and quantified in detail.", "Exposure Score (0-100)": 44, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 20/20 (severity5+20, litigation+2) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Zelle  <-  Early Warning Services, LLC (owned by 7 largest US banks)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Zelle you gave up your data shared corporate-wide, your right to sue, and your right to meaningful compensation. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:25:58Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Customers of Chase, Bank of America, and Wells Fargo lost more than $870 MILLION to Zelle fraud over seven years — and the banks' own reimbursement rate for victims FELL from 62% in 2019 to just 38% in 2023, getting WORSE as the problem grew, according to the CFPB's own lawsuit. That lawsuit was then DROPPED ENTIRELY in 2025 under a new administration — dismissed 'with prejudice,' meaning it can never be revived by the federal government again. New York State picked up a related claim in its own lawsuit (NY AG, Aug. 13, 2025) — though NY's complaint alleges a LARGER figure, more than $1 billion stolen from 2017-2023, under NY's own fraud statute rather than the CFPB's authority, so it is a parallel action, not identical litigation. Underneath all of it sits a genuine gap in federal law: if a hacker steals your login and moves your money, you're protected. But if a SCAMMER TRICKS you into sending the money yourself — a fake bank-fraud call convincing you to 'protect' your own funds by Zelle-ing them somewhere — federal law provides NO reimbursement right at all, because you technically authorized the transfer yourself, however deceived you were.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 100, "_entity_id": 151, "_entity_slug": "zelle", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Match Group (Tinder / Hinge / Match.com / OkCupid / PlentyOfFish)", "Category": "Dating", "Terms & Conditions URL": "tinder.com/en/legal/terms (Match Group apps each have their own Terms but share a parent-company legal framework)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "tinder.com/en/legal/privacy (each app has its own privacy policy referencing Match Group's shared practices)", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Tinder's Terms reportedly grant the company a perpetual, worldwide, irrevocable license to use a user's photos/bio/content for ANY purpose — including advertising or AI training — even AFTER the user deletes their account, per a third-party ToS review; a ban on one Match Group app (Tinder) can extend across ALL Match Group platforms (Hinge, Match, OkCupid) simultaneously, with no notice and no formal appeal process.", "Arbitration / Class Action Waiver": "FTC LAWSUIT + $14 MILLION SETTLEMENT (2019 suit, settled 2025): the FTC sued Match Group alleging it used FAKE 'love interest' advertisements — generated from accounts Match had ALREADY internally flagged as likely fraudulent — to trick hundreds of thousands of non-subscribers into buying paid subscriptions just to respond to a message from a probable scammer; Match also allegedly offered a misleading '6-month guarantee' with undisclosed conditions, and RETALIATED against customers who filed credit-card chargeback disputes by locking their accounts. Match admitted no liability but agreed to pay $14M in consumer redress and to implement simple, clear cancellation mechanisms and guarantee disclosures going forward. Separately, a 2024 lawsuit (Tinder/Hinge) alleges the apps are deliberately designed to be ADDICTIVE using dark-pattern techniques, drawing explicit comparisons to the same FTC dark-patterns enforcement trend later used against Vonage ($100M) in the same period. Tinder also reportedly practices undisclosed 'shadow banning' — reducing a paying subscriber's visibility to other users with zero notification, while continuing to collect the subscription fee.", "Fees / Billing Flags": "Standard mandatory binding arbitration + class action waiver in Tinder's Terms (Section 15 per third-party ToS review) — makes individual disputes over the practices above 'economically unfeasible to pursue' according to the same review, given typical subscription amounts are small relative to arbitration costs.", "Notes": "Not itemized separately beyond the FTC settlement above.\n\n[RECOVERED from an unheaded column during the Aug 2026 structural fix; this text was present in the file but sat outside any labelled column] The combination of (1) a completed $14M FTC settlement for fake-scammer-driven subscription tricks, (2) active addiction-design litigation, and (3) alleged undisclosed shadow-banning while still charging fees makes Match Group one of the more thoroughly-documented 'issue' companies in the apps category — on par with Uber/DoorDash/Instacart for concreteness.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Dallas", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Match Group, Inc.", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Match Group, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-1] FTC alleges Match used fake 'love interest' ads from accounts it had already flagged as fraudulent\nWHAT THE TERMS SAY: The FTC sued Match Group alleging it used fake 'love interest' advertisements generated from accounts Match had already internally flagged as likely fraudulent, tricking hundreds of thousands of non-subscribers into buying paid subscriptions to respond, plus a misleading '6-month guarantee' and retaliation against customers who filed chargeback disputes by locking their accounts.\nWHY IT MATTERS: Match admitted no liability but agreed to pay $14 million in consumer redress and implement clearer cancellation and guarantee disclosures going forward.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity pass 1: Hedge lost corrected))", "Top Troubling #2": "[CONTENT_LICENSE · FL-4] Tinder reportedly keeps a perpetual, irrevocable license to users' photos even after account deletion\nWHAT THE TERMS SAY: Per a third-party ToS review, Tinder's Terms grant the company a perpetual, worldwide, irrevocable license to use a user's photos, bio, and content for any purpose — including advertising or AI training — even after the user deletes their account.\nWHY IT MATTERS: Deleting your account does not necessarily stop Match Group from continuing to use your photos and bio as it sees fit.\n(evidence: Data Sharing/Selling Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[TERMINATION_CONFISCATION · FL-4] A ban on one Match Group app can lock a user out of Tinder, Hinge, Match, and OkCupid at once, without appeal\nWHAT THE TERMS SAY: A ban on one Match Group app (Tinder) can extend across all Match Group platforms (Hinge, Match, OkCupid) simultaneously, with no notice and no formal appeal process.\nWHY IT MATTERS: A single moderation decision on one app can cut a paying user off from every Match Group service they use, with no way to contest it.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=?; liabcap=?; contentlic=Y; confiscation=Y; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Several findings — the perpetual content license and cross-platform bans — are sourced to a third-party ToS review rather than the tracker's own confirmed reading of the terms.", "Exposure Score (0-100)": 52, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 7, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 5/30 (ai_training_on_user_data+5) | Contract 7/20 (broad_content_license+3, termination_or_confiscation+4) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Match Group (Tinder / Hinge / Match.com / OkCupid / PlentyOfFish)  <-  Match Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Match Group (Tinder / Hinge / Match.com / OkCupid / PlentyOfFish) you gave up your content used as AI training data, a broad licence to your own content, your right to sue, your right to join a class action, and your right to keep what you paid for. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:26:00Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Hinge markets itself as 'Designed to be Deleted' — but a 2024 lawsuit alleges the algorithm deliberately hides the profiles it already knows you'd like MOST behind a scarce 'rose' mechanic (just ONE free rose per week), while showing you a stream of less-compelling matches through regular likes instead. Users have nicknamed this 'rose jail.' Separately, the lawsuit alleges Tinder gives women more free likes than men by default — an artificial, built-in scarcity for men specifically engineered to push them toward paid subscriptions. Match Group's own court filings confirm 98% OF ITS REVENUE comes directly from people paying to unlock features an app that's supposedly 'designed to be deleted' is built to keep you paying for.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 101, "_entity_id": 153, "_entity_slug": "match-group-tinder-hinge-match-com-okcupid-plentyoffish", "_issuer": "Match Group, Inc.", "_issuer_slug": "match-group-inc", "_ticker": "MTCH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Netflix", "Category": "Streaming", "Terms & Conditions URL": "help.netflix.com/legal/termsofuse", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "help.netflix.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ACTIVE MAJOR STATE LAWSUIT (Texas AG, filed May 11, 2026, under the Texas Deceptive Trade Practices Act): alleges Netflix collected personal information — INCLUDING FROM CHILDREN — based on misleading disclosures, and specifically misrepresented that (1) paid subscribers would NOT be subject to data-driven advertising, (2) how it actually shares user data, and (3) that it does not collect behavioral data from children. Texas AG Ken Paxton specifically called Netflix's always-on-by-default AUTOPLAY feature (active on every profile including kids' profiles) a deliberate 'vise grip' dark pattern designed to 'override conscious decision-making, extend viewing sessions, and eliminate stopping cues' so more data could be harvested and sold — while noting Netflix's revenue more than tripled (2018–2026, ~$15B to ~$50B+) and paid memberships grew from ~130M to 300M+ households over the same period.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver and jury trial waiver. AAA Consumer Arbitration Rules. Notice by certified mail to General Counsel, Netflix Inc., 100 Winchester Circle, Los Gatos CA 95032. Netflix reimburses filing fees for claims under $10,000. POLICY CHANGE: Netflix updated its Terms on April 19, 2026, adding 172 sentences — the most material addition was a new mandatory arbitration clause with a time-limited opt-out (ConductAtlas tracked this change). Prior terms apparently lacked a standalone arbitration clause; the April 2026 update added one.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The autoplay-as-dark-pattern framing, explicitly targeting children's default profiles, is a genuinely novel and well-documented finding distinct from the more common 'data sharing' complaints seen elsewhere in this audit — worth its own callout given how recent (May 2026) and specific the allegations are.", "Industry (Fortune 500)": "Entertainment", "Revenue (Fortune 500)": "$45.2B", "Market Cap": "$285.4B", "Employees": "14,000", "HQ City": "Los Gatos", "HQ State": "California", "CEO": "Ted Sarandos & Greg Peters", "Ticker": "NFLX", "Website (Corporate)": "netflix.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (NFLX). Service route: c/o General Counsel / Corporate Secretary, Los Gatos, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Netflix, Inc.", "Years Referenced in Finding (heuristic)": "2026, 2015", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Netflix, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SALE · FL-2] Texas AG alleges Netflix shared up to 160,000 data points per 30 seconds with brokers despite 'zero interest' in ads claim\nWHAT THE TERMS SAY: A May 2026 Texas AG lawsuit alleges Netflix logged over 550 billion user events per day as early as 2015 while publicly claiming 'zero interest' in advertising, and shared as many as 160,000 unique data points per 30 seconds of viewing with data brokers like Experian and Acxiom and ad platforms including Google, Amazon, Yahoo, and The Trade Desk.\nWHY IT MATTERS: The suit also alleges Netflix misrepresented to paid subscribers that they would not be subject to data-driven advertising; Texas is seeking $10,000 per violation, rising to $250,000 per violation for consumers 65 or older.\n(evidence: Data Sharing/Selling Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[UNILATERAL_CHANGES · FL-3] Netflix's April 19, 2026 terms update added a mandatory arbitration clause with a time-limited opt-out.\nWHAT THE TERMS SAY: Netflix updated its Terms on April 19, 2026, adding 172 sentences — the most material addition being a new mandatory arbitration clause with a time-limited opt-out; prior terms apparently lacked a standalone arbitration clause.\nWHY IT MATTERS: Existing subscribers who don't notice or act on the time-limited opt-out window are newly bound to arbitration for a right they previously didn't have to waive.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #3": "[DARK_PATTERN_CONSENT · FL-2] Texas AG calls Netflix's always-on autoplay, active on kids' profiles, a deliberate 'vise grip' dark pattern\nWHAT THE TERMS SAY: Texas AG Ken Paxton called Netflix's always-on-by-default autoplay feature, active on every profile including kids' profiles, a deliberate 'vise grip' dark pattern designed to 'override conscious decision-making, extend viewing sessions, and eliminate stopping cues' so more data could be harvested and sold.\nWHY IT MATTERS: The lawsuit alleges Netflix tracks exactly what children click, how long they watch, what they skip, when they pause, and what they replay on Kids profiles.\n(evidence: Data Sharing/Selling Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The Texas AG complaint and the April 2026 arbitration-clause addition are both dated and quantified in detail.", "Exposure Score (0-100)": 54, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_30d+3) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 5/20 (unilateral_modification+5) | Record 10/20 (severity3+8, litigation+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Netflix  <-  Netflix, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to a jury.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Netflix you gave up your personal data sold onward, your data shared corporate-wide, your right to sue, your right to join a class action, your right to a jury, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "2026-09-08T19:26:02Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Texas's May 2026 lawsuit alleges Netflix logged OVER 550 BILLION USER EVENTS PER DAY as early as 2015 — while publicly claiming it had 'zero interest' in advertising — and shared as many as 160,000 UNIQUE DATA POINTS PER 30 SECONDS of a single viewing session with data brokers like Experian and Acxiom and ad platforms including Google, Amazon, Yahoo, and The Trade Desk. On top of that, the lawsuit alleges Netflix tracks exactly what children click, how long they watch, what they skip, when they pause, and what they replay on Kids profiles — with autoplay left ON by default specifically because it 'overrides conscious decision-making' and keeps kids watching (and generating trackable data) longer. Texas is seeking $10,000 per violation, rising to $250,000 per violation for consumers 65 or older.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 102, "_entity_id": 155, "_entity_slug": "netflix", "_issuer": "Netflix, Inc.", "_issuer_slug": "netflix-inc", "_ticker": "NFLX", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "23andMe", "Category": "Health/Genetic Testing", "Terms & Conditions URL": "23andme.com/about/tos/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "23andme.com/legal/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CATASTROPHIC BREACH + REGULATORY + BANKRUPTCY CASCADE: a 2023 data breach (undisclosed until later) exposed the GENETIC and personal information of approximately 7 MILLION customers nationwide (855,000+ in California alone), including health, ancestry, ethnicity, genetic predispositions, and biological-relative information — among the most sensitive categories of personal data covered anywhere in this entire audit. California's AG sued in 2026 alleging 23andMe ignored warnings its systems were compromised and downplayed the breach's severity, seeking penalties under California's Genetic Information Privacy Act. 23andMe filed for BANKRUPTCY in 2025, which the company itself attributed partly to the breach and related litigation. A federal court approved a $30–$50 MILLION settlement fund for the consolidated customer litigation (claims deadline already passed as of early 2026).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. CRITICAL: 23andMe filed for Chapter 11 bankruptcy protection (March 2025) and its assets were sold to TTAM Technologies. The buyer stated it intends to 'honor the current privacy policy.' Whether the original arbitration clause survives a bankruptcy-sale asset transfer is a live legal question — 42 state attorneys general (including MD and VA) secured only non-binding assurances about data handling from the bankruptcy trustee, not enforceable court orders.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Given genetic data cannot be changed or reissued the way a password or credit card can, this is arguably the single highest-permanent-stakes breach in this entire audit — worth flagging with particular weight regardless of category, and worth monitoring for what happens to customer genetic data during/after the bankruptcy (who owns/controls it going forward is a live, unresolved question).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Sunnyvale", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://oag.maryland.gov/News/pages/Attorney-General-Brown-Announces-Multistate-Settlement-of----Bankruptcy-Claims-Against-23andMe-Over-Genetic-Data-Breach-.aspx", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "TTAM Technologies (acquired from bankruptcy, 2025)", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: TTAM Technologies (acquired from bankruptcy, 2025)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2023 breach exposed genetic data of ~7 million 23andMe customers; CA AG alleges warnings were ignored\nWHAT THE TERMS SAY: A 2023 data breach, undisclosed until later, exposed the genetic and personal information of approximately 7 million customers nationwide (855,000+ in California alone), including health, ancestry, ethnicity, genetic predispositions, and biological-relative information. California's AG sued in 2026 alleging 23andMe ignored warnings its systems were compromised and downplayed the breach's severity.\nWHY IT MATTERS: A federal court approved a $30-50 million settlement fund for the consolidated customer litigation, though genetic data, unlike a password, cannot be reissued once exposed.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SALE · FL-4] 23andMe's bankruptcy turned the genetic data of 15 million+ people, including the deceased, into a saleable asset\nWHAT THE TERMS SAY: When 23andMe went bankrupt in 2025, the genetic data of over 15 million people — including people who have since died — legally became a company asset to be liquidated and put up for auction, with pharmaceutical companies among the interested buyers; a bankruptcy judge approved the sale over a 28-state AG challenge, ruling it 'involves a sale of customer data only in a technical sense.'\nWHY IT MATTERS: Only 13 states require consent before genetic data changes hands in an acquisition like this, and family members of deceased customers have no formal channel to object to how a relative's genetic code — which is also partly their own — gets used going forward.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[PENDING_LITIGATION · FL-2] 42 state AGs secured only non-binding assurances, not enforceable orders, on 23andMe customer data after bankruptcy\nWHAT THE TERMS SAY: Whether the original arbitration clause survives the bankruptcy-sale asset transfer to buyer TTAM Technologies is a live legal question; 42 state attorneys general (including MD and VA) secured only non-binding assurances about data handling from the bankruptcy trustee, not enforceable court orders.\nWHY IT MATTERS: TTAM stated it intends to 'honor the current privacy policy,' but that commitment is not backed by a binding court order.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=Y; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The breach scope, bankruptcy sale terms, and state AG actions are all dated and detailed with specific figures.", "Exposure Score (0-100)": 61, "Exposure Band": "High", "Sub: Dispute Rights /30": 23, "Sub: Data Practices /30": 14, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 23/30 (forced_arbitration+12, class_action_waiver+9, optout_window_unverified+2) | Data 14/30 (data_sold_or_shared_for_value+8, biometric_collection+6) | Contract 4/20 (termination_or_confiscation+4) | Record 20/20 (severity5+20, litigation+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "23andMe  <-  TTAM Technologies (acquired from bankruptcy, 2025)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using 23andMe you gave up your personal data sold onward, your biometric identifiers, your right to sue, your right to join a class action, and your right to keep what you paid for. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "2026-09-08T19:26:06Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "When 23andMe went bankrupt in 2025, the genetic data of over 15 MILLION people — including people who have since DIED, whose DNA records remain active in the database — legally became a company ASSET to be liquidated, put up for auction to the highest bidder, with pharmaceutical companies among the interested buyers. A coalition of 28 state Attorneys General sued to stop it, arguing 23andMe never had the right to transfer customers' biological material without explicit new consent — but the bankruptcy judge approved the sale anyway, ruling it 'involves a sale of customer data only in a technical sense' because of how the deal was structured. Only 13 states require consent before genetic data changes hands in an acquisition like this — meaning for most Americans, whether their DNA can be sold without asking them again 'literally comes down to where you happen to live.' Family members of deceased customers have NO formal channel to object to how a dead relative's genetic code — which is also partly THEIR OWN genetic code — gets used going forward.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 103, "_entity_id": 157, "_entity_slug": "23andme", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "MyFitnessPal", "Category": "Health/Fitness", "Terms & Conditions URL": "myfitnesspal.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "myfitnesspal.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Active 2026 investigation (Milberg-backed) alleges the MyFitnessPal Android app violates California's Confidentiality of Medical Information Act by transmitting users' personal health information — including weight-loss goals, motivations, activity levels, meal frequency, lifestyle habits, and relevant health conditions — to third-party companies for advertising/marketing WITHOUT consent; affected California users could be owed hundreds of dollars if the investigation proceeds to a claim.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. MyFitnessPal was sold by Under Armour to Francisco Partners (PE firm) in 2020 for $345M (after a $150M write-down from the original acquisition). The 2018 breach exposed 150M accounts. The 2026 tracking-cookie suit (Shah v. MyFitnessPal, N.D. Cal.) names Meta, Google, TikTok, Amazon, and The Trade Desk as recipients of user data. Opt-out mechanism exists per standard practice but specific window not confirmed from text retrieved this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Health/fitness/wellness apps as a CATEGORY sit largely outside HIPAA's protections even though they collect equivalent sensitive data (see the broader FTC Health Breach Notification Rule findings below) — worth flagging this as a structural gap, not just a MyFitnessPal-specific issue.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Austin", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://cipaworld.com/2026/01/30/california-judge-puts-myfitnesspal-on-a-privacy-diet-key-privacy-claims-survive-as-court-weighs-in-on-cookie-consent-and-consumer-privacy-expectations/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Francisco Partners (private equity, acquired from Under Armour 2020)", "Years Referenced in Finding (heuristic)": "2026, 2018, 2014", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Francisco Partners (private equity, acquired from Under Armour 2020)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] MyFitnessPal's 2018 breach exposed 150 million accounts; a 2026 sister-app breach exposed a child's data\nWHAT THE TERMS SAY: The 2018 breach exposed 150 million MyFitnessPal accounts. In March 2026, sister app Cal AI (an AI calorie tracker acquired with, per the tracker, no real security review) was hit by a fresh breach exposing 3.2 million records of eating habits, body measurements, and fitness goals — including, per researchers, at least one record belonging to a child born in 2014.\nWHY IT MATTERS: Two confirmed breaches years apart, the second under a newly acquired app, suggest the underlying security posture did not improve despite the earlier incident.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] 2026 investigation alleges MyFitnessPal shared health data with advertisers without consent\nWHAT THE TERMS SAY: An active 2026 investigation (Milberg-backed) alleges the MyFitnessPal Android app violates California's Confidentiality of Medical Information Act by transmitting weight-loss goals, motivations, activity levels, meal frequency, lifestyle habits, and health conditions to third-party companies for advertising without consent.\nWHY IT MATTERS: California users could be owed hundreds of dollars if the investigation proceeds to a claim.\n(evidence: Data Sharing/Selling Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DARK_PATTERN_CONSENT · FL-2] A 'browse without being tracked' button reportedly doesn't stop Meta, Google, TikTok, and Amazon from tracking\nWHAT THE TERMS SAY: MyFitnessPal's cookie-consent banner offers a button to browse 'without being tracked'; a 2026 lawsuit (Shah v. MyFitnessPal, N.D. Cal.) alleges Meta, Google, ByteDance/TikTok, and Amazon keep tracking users anyway even after they click it.\nWHY IT MATTERS: Users who believe they've opted out of tracking may still have their fitness and health data collected by these named third parties.\n(evidence: Arbitration / Class Action Waiver; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2018 and 2026 breaches are confirmed, but the health-data-sharing and 'don't track me' claims rest on an active, unresolved investigation and lawsuit.", "Exposure Score (0-100)": 58, "Exposure Band": "High", "Sub: Dispute Rights /30": 23, "Sub: Data Practices /30": 15, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 23/30 (forced_arbitration+12, class_action_waiver+9, optout_window_unverified+2) | Data 15/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "MyFitnessPal  <-  Francisco Partners (private equity, acquired from Under Armour 2020)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using MyFitnessPal you gave up your personal data sold onward, your data shared corporate-wide, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "2026-09-08T19:26:09Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "MyFitnessPal's cookie-consent banner offers you a button to browse 'without being tracked' — a 2026 lawsuit alleges Meta, Google, ByteDance/TikTok, and Amazon keep tracking you anyway even after you click it. That's on top of the original 2018 breach that exposed 150 MILLION accounts. Then in March 2026, MyFitnessPal's newly-acquired sister app Cal AI (an AI calorie tracker) was hit by a fresh breach exposing 3.2 million records of eating habits, body measurements, and fitness goals — including, according to researchers, at least one record belonging to a CHILD BORN IN 2014. The acquisition reportedly happened with no real security review, despite MyFitnessPal's own history.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 104, "_entity_id": 159, "_entity_slug": "myfitnesspal", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "GoodRx / BetterHelp / Premom (health app category)", "Category": "Health/Fitness", "Terms & Conditions URL": "goodrx.com/terms-of-use ; betterhelp.com/terms-of-service ; premom.com (individual company terms not all individually captured this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "goodrx.com/privacy-policy ; betterhelp.com/privacy-policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "COMPLETED FTC ENFORCEMENT WAVE (2023, still highly relevant precedent as of 2026): the FTC settled with GoodRx, BetterHelp, Premom, and Vitagene collectively for nearly $9.5 MILLION over sharing sensitive health data (including PRESCRIPTION and MENTAL HEALTH information) with advertisers, violating the Health Breach Notification Rule, deceiving users about sharing practices, and retroactively changing privacy policies after the fact. A SEPARATE class action against GoodRx settled for $13 MILLION (2023) over disclosing personal health information via tracking technologies without consent.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. GoodRx's ToS. 30-day opt-out via written notice. The FTC's $1.5M GoodRx settlement (Health Breach Notification Rule, Feb 2023) and $7.8M BetterHelp settlement (March 2023) both happened while the arbitration clause was in effect — but the FTC as a regulator is not bound by private arbitration clauses, so it could bring these actions regardless. Individual consumers seeking their own remedies would face the clause.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This FTC enforcement wave is the clearest, most authoritative precedent in the entire health-app category for this audit — recommend treating GoodRx/BetterHelp/Premom/Vitagene as a linked cluster in any customer education material about health-app data sharing specifically.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Santa Monica", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.ftc.gov/news-events/news/press-releases/2023/03/ftc-ban-betterhelp-revealing-consumers-data-including-sensitive-mental-health-information-facebook", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "GoodRx Holdings, Inc. (this row covers a category: BetterHelp is owned by Teladoc Health, Premom is owned by Easy Healthcare Corporation)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: GoodRx Holdings, Inc. (this row covers a category: BetterHelp is owned by Teladoc Health, Premom is owned by Easy Healthcare Corporation)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] FTC found BetterHelp sent mental-health intake answers to Facebook and Snapchat for ad targeting\nWHAT THE TERMS SAY: The FTC found BetterHelp transmitted new users' intake answers about anxiety, depression, medication history, and emotional struggles, plus their email and IP address, to Facebook and Snapchat through an embedded tracking pixel for targeted advertising, while its site promised that information would only be used for counseling.\nWHY IT MATTERS: About 800,000 people are eligible for refunds from the resulting $7.8 million settlement; BetterHelp maintains it never shared 'clinical data from therapy sessions,' but the FTC's findings concerned the intake questionnaire answers specifically.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[UNILATERAL_CHANGES · FL-2] FTC's $9.5M enforcement wave found GoodRx and peers retroactively rewrote privacy policies after already sharing data\nWHAT THE TERMS SAY: The FTC settled with GoodRx, BetterHelp, Premom, and Vitagene collectively for nearly $9.5 million over sharing sensitive health data (including prescription and mental health information) with advertisers, violating the Health Breach Notification Rule, deceiving users about sharing practices, and retroactively changing privacy policies after the fact.\nWHY IT MATTERS: Changing a privacy policy after data has already been shared does not undo the exposure that already occurred under the earlier version.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[REGULATORY_PENALTY · FL-2] A separate class action against GoodRx settled for $13 million over disclosing health data via trackers.\nWHAT THE TERMS SAY: A separate class action against GoodRx settled for $13 million (2023) over disclosing personal health information via tracking technologies without consent.\nWHY IT MATTERS: This is a distinct action from the FTC's collective settlement, covering disclosure of personal health information via tracking technologies without consent.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Multiple named, dated, and dollar-quantified settlements document exactly what health data was shared and with whom.", "Exposure Score (0-100)": 50, "Exposure Band": "High", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 5/20 (unilateral_modification+5) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "GoodRx / BetterHelp / Premom (health app category)  <-  GoodRx Holdings, Inc. (this row covers a category: BetterHelp is owned by Teladoc Health, Premom is owned by Easy Healthcare Corporation)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using GoodRx / BetterHelp / Premom (health app category) you gave up your data shared corporate-wide, your right to sue, your right to join a class action, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:26:12Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "BetterHelp asks new users to answer intake questions about anxiety, depression, medication history, and emotional struggles — the exact vulnerable disclosures someone makes while reaching out for help for the first time. The FTC found BetterHelp then transmitted those specific answers, plus your email and IP address, to Facebook and Snapchat through an embedded tracking pixel, to fuel targeted ADVERTISING, while its own site promised that information would only be used to provide counseling. About 800,000 people are eligible for refunds from the resulting $7.8 million settlement. BetterHelp's own public statement insists it never shared 'clinical data from therapy sessions' — the FTC's findings were specifically about the intake questionnaire answers, a distinction that may be cold comfort to anyone who filled one out.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 105, "_entity_id": 162, "_entity_slug": "goodrx-betterhelp-premom-health-app-category", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "WhatsApp (Meta)", "Category": "Social/Messaging", "Terms & Conditions URL": "whatsapp.com/legal/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "whatsapp.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "See the Meta row (top of this tab) for the primary finding: a March 2026 case (Shirazi et al. v. Meta) alleges Meta and its contractor Accenture intercepted, read, and stored private WhatsApp messages DESPITE marketing the platform as end-to-end encrypted — if true, this would directly contradict WhatsApp's single most important, most-marketed privacy promise. As of May 2026, Meta had not yet filed a formal defense.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration — governed by Meta's terms. 30-day opt-out window.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is WhatsApp's OWN specific slice of the broader Meta litigation — worth flagging distinctly since 'end-to-end encrypted' is WhatsApp's core value proposition to users in a way it isn't for Facebook/Instagram.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Menlo Park", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Meta Platforms, Inc., ATTN: Privacy Operations, 1 Meta Way, Menlo Park, CA 94025, USA (corporate/SEC address: 1601 Willow Road, Menlo Park, CA 94025)", "Legal / Privacy Contact Email": "No published privacy email; Meta routes all requests through in-product privacy forms", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Meta Platforms, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Meta Platforms, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Lawsuit alleges Meta and contractor Accenture read and stored WhatsApp messages despite E2E encryption marketing\nWHAT THE TERMS SAY: A March 2026 case (Shirazi et al. v. Meta) alleges Meta and its contractor Accenture intercepted, read, and stored private WhatsApp messages despite the platform being marketed as end-to-end encrypted; as of May 2026, Meta had not yet filed a formal defense.\nWHY IT MATTERS: If true, this would directly contradict WhatsApp's single most important, most-marketed privacy promise to users.\n(evidence: Data Sharing/Selling Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] WhatsApp disputes are governed by Meta's mandatory arbitration terms with a 30-day opt-out\nWHAT THE TERMS SAY: WhatsApp is subject to mandatory binding arbitration governed by Meta's terms, with a 30-day opt-out window.\nWHY IT MATTERS: WhatsApp users give up default court access under the same arbitration terms that apply across Meta's platforms.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Most of WhatsApp's broader data-practice context is explicitly deferred to the separate Meta row in this tracker; this row's own text supports only the encryption-interception allegation and the arbitration clause as distinct, WhatsApp-specific items.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The interception allegation is an unresolved, contested lawsuit, and most other context is deferred to the separate Meta row rather than restated here.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "WhatsApp (Meta)  <-  Meta Platforms, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using WhatsApp (Meta) you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:26:15Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "WhatsApp's entire brand promise is 'end-to-end encrypted' — not even Meta can read your messages. A 2026 lawsuit alleges Meta and contractor Accenture read and stored those supposedly unreadable messages anyway. Meta publicly rejects this and insists the encryption works exactly as advertised; Telegram's leadership has publicly piled on, using the lawsuit to promote its own security — while Telegram's OWN default chats aren't end-to-end encrypted at all, meaning the loudest critic here has a real vulnerability of its own it's not drawing attention to.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 106, "_entity_id": 164, "_entity_slug": "whatsapp-meta", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Telegram", "Category": "Social/Messaging", "Terms & Conditions URL": "telegram.org/tos", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "telegram.org/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Telegram explicitly states it does NOT use collected data for ad targeting or commercial purposes (a genuine positive contrast to most other apps in this tracker), but its DEFAULT chats are NOT end-to-end encrypted — they use server-based encryption instead, meaning Telegram itself can technically access message content, and a server breach could expose chat data in a way true E2E-encrypted apps (Signal, WhatsApp when working as designed) are structurally protected against. Telegram requires a phone number to create an account, and contacts who already have that number saved will be notified/see the user on Telegram even if the account uses a pseudonym — a real anonymity leak for users trying to register privately. Telegram has also faced criticism for weak content moderation.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Telegram's Terms of Service (Dubai, UAE) do not include a US-style arbitration clause or class action waiver. Disputes governed by the laws of the British Virgin Islands (where Telegram is incorporated), with jurisdiction in the BVI courts. This is consistent with Telegram's non-US legal structure.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "SEPARATE 2026 GOVERNMENT ACTION: India's government restricted access to Telegram nationally during a national exam period, citing fraud/misinformation concerns, and India's Delhi High Court dismissed Telegram's legal challenge to that restriction — a government-access/platform-availability issue distinct from a customer-privacy finding, but relevant context on Telegram's regulatory relationships.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Dubai", "HQ State": "UAE", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ in Dubai, UAE (non-US)", "Parent / Ultimate Owner": "Telegram FZ-LLC (Dubai)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (UAE) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in UAE. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Telegram's default chats aren't end-to-end encrypted, meaning Telegram itself can technically read them\nWHAT THE TERMS SAY: Telegram's default 'cloud chats' use server-based encryption rather than end-to-end encryption, meaning Telegram can technically access message content; true end-to-end encryption requires manually starting a 'Secret Chat,' which most users never use.\nWHY IT MATTERS: A server breach could expose chat data in a way that true E2E-encrypted apps like Signal are structurally protected against.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-2] Telegram's phone-number requirement can leak a pseudonymous user's identity to contacts\nWHAT THE TERMS SAY: Telegram requires a phone number to create an account, and contacts who already have that number saved will be notified of or see the user on Telegram even if the account uses a pseudonym.\nWHY IT MATTERS: The tracker calls this a real anonymity leak for users trying to register privately.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[PENDING_LITIGATION · FL-3] Telegram is fighting Australia's online-safety regulator over its child-safety reporting position\nWHAT THE TERMS SAY: Telegram is currently fighting Australia's online-safety regulator in court over what the regulator calls an unclear, shifting legal position on how it responds to child-safety reporting requirements.\nWHY IT MATTERS: This is an active, unresolved regulatory dispute over Telegram's compliance obligations.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Telegram's non-US legal structure and no-arbitration stance are clearly stated, but the encryption and anonymity mechanics are described with technical hedging ('technically,' 'if compelled') rather than confirmed incidents.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "App / Service", "Ownership Path": "Telegram  <-  Telegram FZ-LLC (Dubai)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Telegram takes nothing from the list this tracker checks - but 10 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:26:18Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Telegram markets itself as the private alternative to WhatsApp — but ordinary 'cloud chats' are NOT end-to-end encrypted by default; they're only encrypted between your device and Telegram's own servers, meaning Telegram itself can technically read them if compelled to (true end-to-end encryption requires manually starting a 'Secret Chat' most users never use). Telegram is currently fighting Australia's online-safety regulator in court over what the regulator calls an unclear, shifting legal position on how it responds to child-safety reporting requirements.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 107, "_entity_id": 166, "_entity_slug": "telegram", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "LinkedIn (Microsoft)", "Category": "Social/Messaging (professional)", "Terms & Conditions URL": "linkedin.com/legal/user-agreement", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "linkedin.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MULTIPLE ACTIVE 2025-2026 CLASS ACTIONS: (1) a class action alleges LinkedIn uses hidden scripts to scan users' installed BROWSER EXTENSIONS and transmit that data to third parties — potentially revealing political views, religious beliefs, and employment status tied to real identities, done silently on every page load without disclosure in the privacy policy; (2) LinkedIn's own 'LinkedIn Insight Tag' tracking pixel has been named as a CO-DEFENDANT (alongside Meta's pixel) in multiple healthcare-website privacy lawsuits (e.g., J.S. v. Spring Fertility Holdings, Meta, and LinkedIn) for allegedly intercepting and transmitting sensitive patient information (e.g., fertility treatment type, sexual orientation) to LinkedIn/Meta for ad-targeting without consent — meaning LinkedIn's tracking infrastructure creates legal exposure even on THIRD-PARTY websites having nothing to do with LinkedIn itself; (3) a January 2025 class action alleged LinkedIn shared PAID PREMIUM subscribers' private messages (about employment, IP, and compensation) with third parties to train AI models, breaching a premium contract that promised heightened privacy — the plaintiff voluntarily DROPPED this specific suit 9 days after filing once LinkedIn showed evidence it had not actually used premium messages for AI training, illustrating that not every well-publicized privacy allegation holds up once challenged.", "Arbitration / Class Action Waiver": "Standard binding arbitration + class action waiver expected in the User Agreement (industry-standard for this category, not independently confirmed word-for-word this pass).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "SYSTEMIC FINDING WORTH FLAGGING ACROSS THE WHOLE TRACKER: LinkedIn's and Meta's tracking pixels appear as co-defendants on OTHER companies' websites throughout this research — including a separate April 2026 case naming Wells Fargo, PNC Bank, and Hilton for embedding LinkedIn/Meta/Pinterest/X pixels that allegedly captured browsing on financial pages and transmitted data for ad-profiling. This means the 'issue' isn't confined to using LinkedIn/Meta/Pinterest/X directly — it also follows from visiting ANY site (including a bank's own site, as documented in the Banks tab) that has quietly embedded these companies' tracking code.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Sunnyvale", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "PARENT ADDRESS ONLY — verify before using for legal notice. LinkedIn Corporation is a Sunnyvale, California-headquartered subsidiary with its own privacy policy and terms. Parent: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA", "Legal / Privacy Contact Email": "No published privacy email; Microsoft routes requests via microsoft.com/concern/privacy (30-day response commitment)", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R2) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Microsoft Corporation", "Years Referenced in Finding (heuristic)": "2026, 2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Microsoft Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] 'BrowserGate': LinkedIn silently scans for 6,000+ extensions, some tied to religion or activism.\nWHAT THE TERMS SAY: The 'BrowserGate' investigation (April 2026) found that every time LinkedIn loads on a Chrome-based browser, hidden code silently checks for over 6,000 specific browser extensions — including apps related to religion, political activism, and tools used by neurodivergent people — with zero visible indicator or consent request, and also collects roughly 48 device characteristics to fingerprint the machine.\nWHY IT MATTERS: Because LinkedIn ties every profile to a real name, employer, and job title, this scan can link a person's religious beliefs, political leanings, or disability-related tool use directly to their professional identity.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] LinkedIn's Insight Tag is named a co-defendant in lawsuits over sensitive patient data on third-party healthcare sites\nWHAT THE TERMS SAY: LinkedIn's own 'LinkedIn Insight Tag' tracking pixel has been named as a co-defendant, alongside Meta's pixel, in multiple healthcare-website privacy lawsuits (e.g., J.S. v. Spring Fertility Holdings, Meta, and LinkedIn) for allegedly intercepting and transmitting sensitive patient information, such as fertility treatment type and sexual orientation, to LinkedIn/Meta for ad-targeting without consent.\nWHY IT MATTERS: This means LinkedIn's tracking infrastructure creates legal exposure even on third-party websites that have nothing to do with LinkedIn itself.\n(evidence: Data Sharing/Selling Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[AI_TRAINING · FL-2] A 2025 lawsuit alleges LinkedIn opted Premium users into AI training on their private messages.\nWHAT THE TERMS SAY: The tracker describes a 2025 lawsuit alleging LinkedIn quietly opted Premium users into sharing their private messages for AI training, then rewrote its own FAQ afterward in a way the lawsuit calls an attempt to 'cover its tracks.' The tracker also records that the plaintiff in the January 2025 class action over premium messages and AI training voluntarily dropped that suit nine days after filing, once LinkedIn showed it had not actually used premium messages for AI training.\nWHY IT MATTERS: Even where LinkedIn now lets users opt out going forward, it has not offered to delete data from AI models already trained on it; the tracker notes not every well-publicized privacy allegation holds up once challenged.\n(evidence: SCARY; Tracker says unconfirmed (fidelity pass 1: Overstated corrected) (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are only assumed industry-standard and not confirmed, and the row's own text shows conflicting accounts of the AI-training allegation — one version says a related suit was dropped after being disproven.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 15, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 15/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "App / Service", "Ownership Path": "LinkedIn (Microsoft)  <-  Microsoft Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using LinkedIn (Microsoft) you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:26:21Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The 'BrowserGate' investigation (April 2026) found that every single time you load LinkedIn on a Chrome-based browser, hidden code silently checks for the presence of over 6,000 SPECIFIC BROWSER EXTENSIONS — including apps related to religion, political activism, and tools used by neurodivergent people — with zero visible indicator and zero consent request. It also collects roughly 48 device characteristics to fingerprint your machine. Because LinkedIn ties every profile to a REAL NAME, employer, and job title, this scan can link a person's religious beliefs, political leanings, or disability-related tool use directly to their professional identity. This sits on top of a SEPARATE 2025 lawsuit alleging LinkedIn quietly opted Premium users into sharing their PRIVATE MESSAGES for AI training, then rewrote its own FAQ afterward in a way the lawsuit calls an attempt to 'cover its tracks' — and even where LinkedIn now lets you opt out going forward, it has NOT offered to delete your data from AI models already trained on it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 108, "_entity_id": 168, "_entity_slug": "linkedin-microsoft", "_issuer": "Microsoft Corporation", "_issuer_slug": "microsoft-corporation", "_ticker": "MSFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Threads (Meta)", "Category": "Social/Messaging", "Terms & Conditions URL": "See Meta's Instagram Terms of Use (Threads operates under the same Meta account/terms framework)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "See Meta's privacy policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Threads is governed by the same overall Meta data practices, litigation exposure ($375M NM verdict, 45-state AG coalition, youth-addiction MDL), and privacy policy documented in the Meta row at the top of this tab — no distinct, separate legal framework identified this pass.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration — governed by Meta's terms. 30-day opt-out window.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "No standalone Threads-specific litigation identified this pass; treat as part of Meta's overall profile.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Menlo Park", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Meta Platforms, Inc., ATTN: Privacy Operations, 1 Meta Way, Menlo Park, CA 94025, USA (corporate/SEC address: 1601 Willow Road, Menlo Park, CA 94025)", "Legal / Privacy Contact Email": "No published privacy email; Meta routes all requests through in-product privacy forms", "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.ftc.gov/news-events/news/press-releases/2019/07/ftc-imposes-5-billion-penalty-sweeping-new-privacy-restrictions-facebook", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Meta Platforms, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Meta Platforms, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Signing up for Threads binds users to Meta's mandatory arbitration terms, regardless of using other Meta apps\nWHAT THE TERMS SAY: Threads is governed by mandatory binding arbitration under Meta's terms, with a 30-day opt-out window, and no standalone Threads-specific dispute framework.\nWHY IT MATTERS: Users who only download Threads still give up default court access under Meta's umbrella arbitration terms.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — This row's own text explicitly defers nearly all substantive findings (the $375M child-safety verdict, 45-state AG coalition, youth-addiction litigation) to the separate Meta row and states 'no standalone Threads-specific litigation identified this pass'; only the arbitration clause is a Threads-row-specific fact, and cross-referenced findings about Meta are not counted as findings about Threads itself.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The row explicitly states no standalone Threads-specific litigation was identified and defers nearly everything to the separate Meta row.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Threads (Meta)  <-  Meta Platforms, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Threads (Meta) you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:26:21Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Threads runs on the exact same underlying Meta infrastructure and data practices already documented for Facebook/Instagram elsewhere in this tracker — the $375M child-safety jury verdict, the 45-state AG coalition, the youth-addiction lawsuits — all apply here too, just under a different app icon. Signing up for Threads means agreeing to the same overall Meta terms you'd be bound by on Facebook or Instagram, whether or not you use either of those apps.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 109, "_entity_id": 169, "_entity_slug": "threads-meta", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "X (Twitter)", "Category": "Social/Messaging", "Terms & Conditions URL": "x.com/en/tos", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "x.com/en/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MAJOR COMPLETED FTC ACTION NOW UNDER ACTIVE CHALLENGE: in May 2022, Twitter paid a $150 MILLION civil penalty after the FTC found it asked 140+ MILLION users for phone numbers/emails 'for security purposes' (two-factor authentication) and then used that same data to sell targeted advertising — a textbook bait-and-switch on a security feature. The order required a comprehensive privacy/security program with third-party audits through 2042. On June 3, 2026, X Corp. (renamed after Musk's 2022 acquisition, later folded into xAI, then absorbed by SpaceX in Feb 2026) petitioned the FTC to set aside or shorten this order, arguing the company that committed the violation 'no longer exists' and that compliance has cost it ~$17 million in paperwork; the FTC opened a 30-day public comment period (closing July 2, 2026) and, notably, is controlled by a different political administration than the one that issued the original order — EFF and other advocacy groups have filed formal opposition arguing the order should stay in place. As of this writing the outcome is UNDECIDED.", "Arbitration / Class Action Waiver": "CLASS ACTION WAIVER with liability capped at $100 per covered dispute. X's ToS (effective Jan 15, 2026) split statute-of-limitations: 1 year for federal claims, 2 years for state claims. The 2026 update expanded 'Content' to include AI prompts and outputs. Separately, X Corp REFUSED to pay JAMS arbitration fees for former employees (2nd Circuit ruled in X's favor, Sept 2, 2025), demonstrating the company's willingness to exploit procedural arbitration costs. The FTC's existing $150M order against X (2022, 2FA phone numbers used for ads) remains in effect — X petitioned to terminate it early (June 2026), outcome pending.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is a live, contested regulatory rollback in progress — genuinely unusual to catch mid-decision rather than after the fact. Worth checking for a final outcome after July 2, 2026, since the resolution will directly determine whether X's federal privacy obligations continue, shrink, or disappear.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.ftc.gov/news-events/news/press-releases/2026/06/ftc-seeks-comment-x-corp-petition-set-aside-or-modify-ftc-order-concerning-twitter", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "X Corp. (Elon Musk, private)", "Years Referenced in Finding (heuristic)": "2022, 2011, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: X Corp. (Elon Musk, private)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[AI_TRAINING · FL-2] By default, X shares users' public posts and private conversations with Grok to train xAI's models\nWHAT THE TERMS SAY: By default, X shares your public posts and your private conversations with its own AI chatbot Grok with xAI, to train and improve Grok's models, with the opt-out buried in a 'Third-party Collaborators' settings menu.\nWHY IT MATTERS: Most users are unlikely to find the opt-out, meaning private conversations may be used for AI training without users realizing it.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[LIABILITY_CAP_INDEMNITY · FL-1] X caps its liability at $100 per dispute and has fought to avoid paying arbitration fees\nWHAT THE TERMS SAY: X's ToS (effective Jan 15, 2026) includes a class action waiver with liability capped at $100 per covered dispute; separately, X Corp refused to pay JAMS arbitration fees for former employees, and the 2nd Circuit ruled in X's favor (Sept 2, 2025).\nWHY IT MATTERS: The tracker frames this as demonstrating the company's willingness to exploit procedural arbitration costs against people bringing claims.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[REGULATORY_PENALTY · FL-2] X paid $150M after using 2FA phone numbers for ads, violating an earlier 2011 FTC order, and is now fighting to end oversight\nWHAT THE TERMS SAY: In May 2022, Twitter paid a $150 million civil penalty after the FTC found it asked 140+ million users for phone numbers/emails 'for security purposes' (two-factor authentication) and then used that data to sell targeted advertising, which itself violated an earlier 2011 FTC order for a similar broken privacy promise.\nWHY IT MATTERS: On June 3, 2026, X Corp petitioned the FTC to set aside or shorten the resulting oversight order, arguing the violating company 'no longer exists'; EFF has formally opposed this as a 'brazen attempt to escape accountability,' and the outcome was undecided as of this writing.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The FTC order, the pending petition to end it, and the Grok data-sharing default are all dated and documented with specific figures and named parties.", "Exposure Score (0-100)": 52, "Exposure Band": "High", "Sub: Dispute Rights /30": 9, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 9/30 (class_action_waiver+9) | Data 13/30 (data_sold_or_shared_for_value+8, ai_training_on_user_data+5) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 20/20 (severity5+20, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "X (Twitter)  <-  X Corp. (Elon Musk, private)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your content and your conversations, as raw material to train AI models.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using X (Twitter) you gave up your personal data sold onward, your content used as AI training data, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "2026-09-08T19:26:23Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Right now, by DEFAULT, X shares your public posts AND your private conversations with its own AI chatbot Grok with xAI, to train and improve Grok's models — the opt-out is buried in a 'Third-party Collaborators' settings menu most people will never find. This isn't X's first offense: the 2022 $150 million FTC penalty was for secretly using phone numbers/emails collected for TWO-FACTOR AUTHENTICATION SECURITY to sell targeted ads instead — and that itself violated an EARLIER 2011 FTC order for a similar broken privacy promise. In June 2026, X petitioned to end the FTC's oversight early, arguing (among other things) that being freed from the order is 'critical to advancing American leadership in artificial intelligence' — in plain terms, X wants out of privacy oversight partly so it can feed more of your data into Grok without restriction. The Electronic Frontier Foundation's formal opposition brief calls this a 'brazen attempt to escape accountability at the expense of the American people.' As of this writing, the outcome is still undecided.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 110, "_entity_id": 171, "_entity_slug": "x-twitter", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "BeReal", "Category": "Social/Messaging", "Terms & Conditions URL": "bereal.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "bereal.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or FTC action; BeReal's core feature (simultaneous front/back camera capture at a random daily time) inherently collects more candid, less-curated imagery than most social apps, which is worth noting as a structurally distinct risk profile even without a confirmed specific incident this pass.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — BeReal (Paris, France) ToS governed by French law. No US-style arbitration clause or class action waiver. Disputes go to the courts of Paris. Consistent with EU consumer-protection norms. BeReal was acquired by Voodoo (French mobile gaming company) in June 2024 for ~$500M.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Queued for a dedicated follow-up; thin verification this session, typical of smaller/newer apps not yet subject to the same volume of litigation as larger platforms in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Paris", "HQ State": "France", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ in Paris, France (non-US)", "Parent / Ultimate Owner": "Voodoo (Paris, acquired June 2024)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (France) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in France. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] BeReal's simultaneous front/back camera feature structurally captures unusually candid, unposed imagery\nWHAT THE TERMS SAY: The tracker notes BeReal's simultaneous front-and-back camera capture at a random daily moment inherently collects more candid, unposed imagery of users and their surroundings than most social apps, though no specific lawsuit or FTC action was independently confirmed this pass.\nWHY IT MATTERS: Because users can't prepare or pose for the capture, the app structurally collects more candid, unposed imagery of people and their surroundings than most social apps, even without a confirmed specific incident this pass.\n(evidence: SCARY; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one substantive finding was located: data sharing is explicitly not independently confirmed this pass, and BeReal's terms state there is no mandatory arbitration clause (consumer-favorable, not a troubling item); Notes flag thin verification typical of smaller apps.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data-sharing practices are explicitly not independently confirmed and Notes flag thin verification this pass.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "App / Service", "Ownership Path": "BeReal  <-  Voodoo (Paris, acquired June 2024)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, BeReal takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:26:23Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "BeReal's entire premise — a simultaneous front-and-back camera capture at a random moment each day — collects more candid, unposed imagery of you and your surroundings than almost any other app in this tracker, precisely because you can't prepare or pose for it the way you would for a typical photo post.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 111, "_entity_id": 173, "_entity_slug": "bereal", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "eBay", "Category": "Shopping/Retail", "Terms & Conditions URL": "ebay.com/help/policies/member-behaviour-policies/user-agreement?id=4259", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "ebay.com/help/policies/member-behaviour-policies/user-privacy-notice-privacy-policy?id=4260", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Active arbitration demands (Levi & Korsinsky / Labaton Keller Sucharow, 2025-2026): allege eBay shared California users' private information via third-party trackers without consent, seeking statutory damages up to $5,000/violation under California law — same CIPA-driven pixel-tracking pattern seen at Etsy, LinkedIn, Pinterest, and other companies in this tracker.", "Arbitration / Class Action Waiver": "Binding arbitration confirmed directly from the current User Agreement (effective June 28, 2026 update): requires a MANDATORY 45-day 'Informal Dispute Resolution' notice period before either party can start arbitration or small-claims court; a Feb 2026 update explicitly EXPANDED the arbitration clause to cover disputes involving AI 'buy for me' shopping agents and LLM bots, and separately banned such bots from scraping the site — a genuinely novel, AI-era update to a legal terms document not seen elsewhere in this tracker.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "eBay is the only company found in this entire 185-company audit to have proactively updated its legal terms specifically to address AI shopping agents/LLM bots (Feb 2026) — worth flagging as a leading indicator of a terms-of-service trend likely to spread to other e-commerce companies in this tracker.", "Industry (Fortune 500)": "Internet Services and Retailing", "Revenue (Fortune 500)": "$11.1B", "Market Cap": "$49.3B", "Employees": "11,500", "HQ City": "San Jose", "HQ State": "California", "CEO": "Jamie Iannone", "Ticker": "EBAY", "Website (Corporate)": "ebay.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (EBAY). Service route: c/o General Counsel / Corporate Secretary, San Jose, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Arbitration demands allege eBay shared California users' private information via third-party trackers\nWHAT THE TERMS SAY: Levi & Korsinsky / Labaton Keller Sucharow arbitration demands (2025-2026) allege eBay shared California users' private information via third-party trackers without consent, seeking statutory damages up to $5,000 per violation under California law.\nWHY IT MATTERS: If the allegations hold, California users' private information was shared via third-party trackers without consent, with statutory damages sought of up to $5,000 per violation under California law.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] eBay requires a 45-day pre-arbitration notice; a Feb 2026 update extended arbitration to AI shopping agents\nWHAT THE TERMS SAY: The June 2026 User Agreement update requires a mandatory 45-day 'Informal Dispute Resolution' notice before either side can start arbitration or small-claims court, and a February 2026 update expanded the arbitration clause to cover disputes involving AI 'buy for me' agents and LLM bots (while separately banning such bots from scraping the site).\nWHY IT MATTERS: The mandatory 45-day notice period delays a consumer's ability to start arbitration or small-claims court, and the February 2026 update extends the clause to disputes involving AI 'buy for me' shopping agents and LLM bots — a novel AI-era update the tracker says is not seen elsewhere in this tracker.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The row's third notable detail — eBay quietly removing Chief Compliance Officer references from its risk-committee charter the day after a harassment lawsuit settled — is governance context without a stated direct consumer-facing harm, so only two distinct consumer-facing items are included.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated from the current User Agreement, but the data-sharing allegations remain pending, unadjudicated claims.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 5/20 (unilateral_modification+5) | Record 10/20 (severity3+8, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "eBay  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using eBay you gave up your data shared corporate-wide, your right to sue, and your right to be consulted before terms change. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:26:53Z (HTTP 200, CHANGED)", "SCARY (most astonishing T&C item)": "eBay's security team once tormented a couple who publicly criticized the company — sending them live spiders, a bloody pig mask, and funeral wreaths, among other things — in a scandal so severe it generated a federal criminal case AND a 5-YEAR civil lawsuit. That civil case FINALLY settled on February 25, 2026. The very next day, eBay quietly rewrote its own board oversight rules, removing any mention of a dedicated Chief Compliance Officer position from its risk committee charter — timed so precisely that, had the change happened while the case was still active, it could have been used as evidence against the company.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 112, "_entity_id": 174, "_entity_slug": "ebay", "_issuer": "eBay", "_issuer_slug": "ebay", "_ticker": "EBAY", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Etsy", "Category": "Shopping/Retail", "Terms & Conditions URL": "etsy.com/legal/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "etsy.com/legal/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ACTIVE CLASS ACTION (2025): a California Invasion of Privacy Act (CIPA) lawsuit alleges Etsy let third parties like Meta and Google secretly track users via hidden pixel trackers embedded on its site, without adequate consent — part of a broader nationwide wave of 'tracking pixel' litigation (4,000+ wiretap-based class actions filed against website operators since 2022, per industry tracking) that treats CIPA's $5,000-per-violation statutory damages as a major driver of settlement pressure, since damages can be multiplied across every visitor rather than requiring individual proof of harm.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out via written notice to Etsy Inc., Legal Department, 117 Adams Street, Brooklyn, NY 11201. Covers both buyer and seller disputes. Etsy's marketplace creates a three-way relationship (buyer, seller, platform) — the arbitration clause governs the buyer-Etsy and seller-Etsy relationships but NOT buyer-seller disputes directly.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This 'pixel tracking' litigation wave is a genuinely cross-cutting pattern worth flagging as its own category across this whole tracker — it already appears here for Etsy, LinkedIn, Pinterest, PNC Bank, Wells Fargo, and Hilton (see LinkedIn row) and likely applies to many more companies in this audit that simply haven't been individually named in a lawsuit yet.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Brooklyn", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Etsy, Inc.", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Etsy, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] 2025 lawsuit alleges Etsy fed shoppers' data to Google, Meta, TikTok, and Microsoft via hidden tracking pixels for ad auctions\nWHAT THE TERMS SAY: A 2025 California Invasion of Privacy Act class action alleges Etsy let third parties like Meta and Google secretly track users via hidden pixel trackers without adequate consent, part of a nationwide wave of tracking-pixel wiretap litigation carrying CIPA's $5,000-per-violation statutory damages.\nWHY IT MATTERS: If proven, a shopper's browsing behavior on Etsy could feed real-time ad-bidding auctions across major ad networks without informed consent, and the per-violation damages structure multiplies potential exposure across every visitor.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Etsy imposes mandatory arbitration with a class-action waiver and only a 30-day opt-out window\nWHAT THE TERMS SAY: Etsy's terms include mandatory binding arbitration with a class action waiver; consumers must send written opt-out notice to Etsy's Brooklyn legal department within 30 days, and the clause governs buyer-Etsy and seller-Etsy disputes but not buyer-seller disputes directly.\nWHY IT MATTERS: Users who miss the narrow 30-day opt-out window are locked into individual arbitration and lose the ability to join a class action against Etsy.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees/Billing was not itemized this pass, and the Notes' cross-company pixel-litigation pattern references other companies (LinkedIn, Pinterest, PNC, Wells Fargo, Hilton) rather than a separate Etsy-specific finding, leaving two distinct items.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly documented, but the data-sharing claims remain an active, unresolved lawsuit.", "Exposure Score (0-100)": 46, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Etsy  <-  Etsy, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Etsy you gave up your personal data sold onward, your data shared corporate-wide, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A 2025 lawsuit alleges Etsy secretly shared shoppers' data with Google, Meta, TikTok, AND Microsoft simultaneously through hidden tracking pixels, feeding real-time digital AD-BIDDING AUCTIONS on nearly every visit — turning a simple browse through handmade candles or vintage jewelry into a live behavioral-profiling event across four of the biggest ad networks in the world at once.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 113, "_entity_id": 176, "_entity_slug": "etsy", "_issuer": "Etsy, Inc.", "_issuer_slug": "etsy-inc", "_ticker": "ETSY", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Wish", "Category": "Shopping/Retail", "Terms & Conditions URL": "wish.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "wish.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same general discount-marketplace risk category as Temu/Shein documented elsewhere in this tracker (counterfeit goods, data practices scrutiny) though no Wish-specific lawsuit was independently confirmed this pass — Wish predates Temu/Shein's rise and has faced its own historical scrutiny over counterfeit/unsafe products (not independently verified with a specific case this pass).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. ContextLogic (Wish parent, San Francisco) ToS, AAA rules. 30-day opt-out. Wish delisted from NASDAQ in 2023 after its stock dropped 97% from IPO; the company was acquired by Qoo10 (Singapore) in 2024. The arbitration clause may or may not survive the acquisition — check current terms.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend grouping with Temu/Shein for a consolidated discount-marketplace category review if useful.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Qoo10 Pte. Ltd. (Singapore, acquired 2024)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Qoo10 Pte. Ltd. (Singapore, acquired 2024)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Wish binds shoppers to mandatory arbitration with a class-action waiver, with unclear status after its 2024 Qoo10 acquisition\nWHAT THE TERMS SAY: ContextLogic's (Wish's parent) terms impose mandatory binding arbitration with a class action waiver under AAA rules and a 30-day opt-out, though the tracker notes the clause's survival after Wish's 2024 acquisition by Qoo10 is unconfirmed.\nWHY IT MATTERS: Consumers who don't opt out within 30 days lose the ability to sue collectively, and the ownership change adds uncertainty about which entity's terms currently govern disputes.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-2] Wish shares the same unverified counterfeit-goods/data-practice risk profile as Temu and Shein\nWHAT THE TERMS SAY: The tracker notes Wish faces the same general discount-marketplace scrutiny (counterfeit goods, data practices) documented for Temu/Shein elsewhere, and has its own history of counterfeit/unsafe-product criticism, but no Wish-specific lawsuit was independently confirmed this pass.\nWHY IT MATTERS: Shoppers face the same category-wide counterfeit and data-practice risks associated with ultra-discount marketplaces, even though no confirmed case ties directly to Wish this pass.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two items were found: the data-sharing/counterfeit-goods risk is explicitly unconfirmed for Wish specifically, and Fees/Billing was not itemized, leaving no third distinct company-specific harm.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No Wish-specific lawsuit was independently confirmed and the arbitration clause's post-acquisition status is unverified.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Wish  <-  Qoo10 Pte. Ltd. (Singapore, acquired 2024)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Wish you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Wish built its early business on ultra-cheap goods shipped directly from Chinese manufacturers with minimal vetting — the same discount-marketplace model now under active state AG lawsuits and FTC scrutiny for Temu and Shein elsewhere in this tracker (counterfeit goods, malware allegations, mass-arbitration strategies). Wish got there first and drew similar counterfeit/unsafe-product criticism years before its newer competitors became household names.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 114, "_entity_id": 178, "_entity_slug": "wish", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Best Buy", "Category": "Shopping/Retail", "Terms & Conditions URL": "bestbuy.com/site/help-topics/terms-conditions/pcmcat204400050000.c", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "bestbuy.com/site/help-topics/privacy-policy/pcmcat204400050001.c", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ACTIVE CLASS ACTION (filed April 27, 2026, Case No. 0:26-cv-02381): alleges Best Buy builds a 'comprehensive' unique profile on every customer from the moment they interact with the company — online, via app, or in a physical store — and then SELLS that data (including purchase histories and contact details) to third-party brands through its own retail media network ('Best Buy Ads') and a third-party 'data clean room,' allegedly without adequate consent, allegedly violating state privacy laws.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. AAA rules. 30-day opt-out via written notice to Best Buy Legal Department, 7601 Penn Avenue South, Richfield MN 55423. Best Buy was one of the first major retailers to adopt mandatory arbitration (2007) and has defended the clause successfully in multiple courts.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The 'retail media network' business model (using in-house shopping data to sell targeted ads to brands) is increasingly common among large retailers — worth checking whether Target, Walmart, and other retailers in this tracker have similar 'Ads network' + 'data clean room' structures, since this may be a category-wide pattern rather than a Best-Buy-specific one.", "Industry (Fortune 500)": "Specialty Retailers: Other", "Revenue (Fortune 500)": "$41.7B", "Market Cap": "$16.3B", "Employees": "85,000", "HQ City": "Richfield", "HQ State": "Minnesota", "CEO": "Corie Barry", "Ticker": "BBY", "Website (Corporate)": "bestbuy.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (BBY). Service route: c/o General Counsel / Corporate Secretary, Richfield, Minnesota — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Minnesota' is a non-DMV US state", "Parent / Ultimate Owner": "Best Buy Co., Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Best Buy Co., Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SALE · FL-2] 2026 class action alleges Best Buy sells customer profiles via 'Best Buy Ads' and a data clean room\nWHAT THE TERMS SAY: A class action filed April 27, 2026 (Case No. 0:26-cv-02381) alleges Best Buy builds a comprehensive profile on every customer from online, app, and in-store interactions, then sells that data — including purchase histories and contact details — to third-party brands through Best Buy Ads and a third-party data clean room, allegedly without adequate consent.\nWHY IT MATTERS: If true, customers' purchase histories and contact details are being monetized to outside brands without clear consent; the lawsuit further alleges Best Buy's own advertising arm boasts, in its own marketing materials, that it tracks 15,000 unique attributes per customer and can tie 93% of all transactional revenue back to a specific, identifiable individual.\n(evidence: Data Sharing, SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Best Buy requires mandatory arbitration with a class-action waiver and only a 30-day opt-out window\nWHAT THE TERMS SAY: Best Buy's terms impose mandatory binding arbitration under AAA rules with a class action waiver and a 30-day opt-out via written notice to its Minnesota legal department; Best Buy was one of the first major retailers to adopt mandatory arbitration (2007) and has defended it successfully in court.\nWHY IT MATTERS: The clause blocks class litigation for consumers who don't affirmatively opt out within 30 days, and its established court record makes it harder to challenge.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees/Billing was not itemized, and the retail-media-network note speculates about other retailers (Target, Walmart) rather than describing a separate Best Buy-specific finding, leaving two distinct items.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly documented and the data-sale allegations are detailed, but remain an unresolved lawsuit.", "Exposure Score (0-100)": 46, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Best Buy  <-  Best Buy Co., Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Best Buy you gave up your personal data sold onward, your data shared corporate-wide, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:27:26Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "A 2026 lawsuit alleges Best Buy's own advertising arm boasts, in its OWN marketing materials, that it tracks 15,000 UNIQUE ATTRIBUTES per customer and can tie 93% OF ALL TRANSACTIONAL REVENUE back to a specific, identifiable individual — following you from the moment you click a targeted social media ad through every purchase and repair afterward. A named plaintiff specifically says nowhere in Best Buy's own privacy policy, and nowhere during checkout, was she ever told her data was being sold this precisely.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 115, "_entity_id": 180, "_entity_slug": "best-buy", "_issuer": "Best Buy Co., Inc.", "_issuer_slug": "best-buy-co-inc", "_ticker": "BBY", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Wayfair", "Category": "Shopping/Retail (furniture/home goods)", "Terms & Conditions URL": "wayfair.com/v/terms_conditions/terms_of_use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "wayfair.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not itemized this pass.", "Arbitration / Class Action Waiver": "A 2019 federal court case (Gorny v. Wayfair, N.D. Ill.) already UPHELD Wayfair's web-based arbitration agreement against a class action challenge, rejecting the plaintiff's arguments that (1) his claims fell outside the clause's scope, (2) no binding agreement was ever formed by browsing/clicking, and (3) the clause didn't extend to Wayfair's parent company — establishing this specific clause as legally tested and enforceable precedent, unlike many other companies' clauses in this tracker which remain untested in court. The court specifically noted the checkout page displayed the arbitration-notice language in bold, same-size font directly below the purchase button — a design choice later courts may look to as a model for what makes a web arbitration clause enforceable.", "Fees / Billing Flags": "Separate, unrelated 2026 class action alleges Wayfair's '30-day returns' policy applies to items that are, in practice, non-returnable — flagged briefly in earlier research alongside a Best Buy-style retail-data class action (not independently verified in detail this pass).", "Notes": "The Gorny precedent is useful context for understanding why arbitration clauses on retail websites are so hard to challenge once a court has specifically validated the exact wording/placement used.", "Industry (Fortune 500)": "Internet Services and Retailing", "Revenue (Fortune 500)": "$12.5B", "Market Cap": "$12.6B", "Employees": "12,100", "HQ City": "Boston", "HQ State": "Massachusetts", "CEO": "Niraj Shah", "Ticker": "W", "Website (Corporate)": "wayfair.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (W). Service route: c/o General Counsel / Corporate Secretary, Boston, Massachusetts — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Massachusetts' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Massachusetts SOC Corporate Search — corp.sec.state.ma.us/corpweb/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Wayfair's web-based arbitration clause was tested and upheld in federal court, making it especially hard for customers to challenge\nWHAT THE TERMS SAY: In Gorny v. Wayfair (N.D. Ill., 2019), a federal court upheld Wayfair's web-based arbitration agreement against a class-action challenge, rejecting arguments that the claims fell outside its scope, that browsing/clicking didn't form a binding agreement, and that it didn't extend to Wayfair's parent company; the court noted the checkout page displayed the arbitration notice in bold, same-size font directly below the purchase button.\nWHY IT MATTERS: Because this specific clause and its checkout placement have already survived a legal challenge, it is tested precedent that makes it harder for a Wayfair customer to avoid arbitration and pursue a class action.\n(evidence: Arbitration, SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] Separate 2026 class action alleges Wayfair's '30-day returns' policy covers items that are non-returnable\nWHAT THE TERMS SAY: A 2026 class action, flagged briefly and not independently verified in detail this pass, alleges Wayfair's advertised '30-day returns' policy applies to items that are, in practice, non-returnable.\nWHY IT MATTERS: If accurate, shoppers relying on the advertised return window may find they can't actually return certain items, though this claim is not independently verified in detail.\n(evidence: Fees; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data Sharing/Selling was not itemized this pass, leaving only the arbitration-precedent finding and the not-independently-verified returns-policy class action.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause is clearly documented and court-tested, but the returns-policy class action is only briefly flagged and not independently verified in detail.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Wayfair  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Wayfair you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A federal court has already tested and UPHELD Wayfair's web-based arbitration clause against a customer's challenge — specifically because the checkout page displayed the arbitration notice in bold text directly below the purchase button. That design choice, once validated by a real court, effectively became a template other companies can point to for making their own clickwrap arbitration clauses harder to challenge — a single retailer's checkout page layout quietly raising the bar for what counts as 'you agreed to this' everywhere else.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 116, "_entity_id": 181, "_entity_slug": "wayfair", "_issuer": "Wayfair", "_issuer_slug": "wayfair", "_ticker": "W", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Poshmark", "Category": "Shopping/Retail (resale marketplace)", "Terms & Conditions URL": "poshmark.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "poshmark.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Active mass-arbitration investigation (2026): attorneys believe Poshmark uses tracking technology to secretly collect user interaction data and share it with PAYPAL regardless of whether the customer actually uses PayPal to check out or makes any purchase at all — i.e., the data sharing is alleged to occur just from browsing, not from any transaction.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Poshmark ToS, AAA rules. 30-day opt-out. Poshmark was acquired by Naver (South Korean internet conglomerate) in Jan 2023 for $1.2B. The arbitration clause survived the acquisition.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The 'shares data with a payment processor even if you never use that payment method' pattern is worth flagging distinctly from typical ad-pixel tracking — it implicates a financial-services third party (PayPal) rather than just an advertiser.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Redwood City", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Naver Corporation (Seoul, acquired Jan 2023)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Naver Corporation (Seoul, acquired Jan 2023)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Poshmark allegedly shares browsing data with PayPal even when shoppers never use PayPal to check out\nWHAT THE TERMS SAY: A 2026 mass-arbitration investigation alleges Poshmark uses tracking technology to collect user interaction data and share it with PayPal regardless of whether the customer uses PayPal to check out or makes any purchase at all.\nWHY IT MATTERS: Users could have their browsing activity handed to a financial-services third party just from scrolling the app, with no transaction or PayPal use ever occurring.\n(evidence: Data Sharing, SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Poshmark requires mandatory arbitration with a class-action waiver and a 30-day opt-out that survived its 2023 Naver acquisition\nWHAT THE TERMS SAY: Poshmark's terms impose mandatory binding arbitration under AAA rules with a class action waiver and a 30-day opt-out; the clause survived Poshmark's January 2023 acquisition by Naver.\nWHY IT MATTERS: Consumers who miss the 30-day window lose the ability to bring or join a class action against Poshmark.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees/Billing was not itemized this pass, leaving only the PayPal data-sharing allegation and the arbitration clause as distinct items.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated, but the PayPal data-sharing claim is an active investigation, not a confirmed finding.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Poshmark  <-  Naver Corporation (Seoul, acquired Jan 2023)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Poshmark you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:27:43Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Attorneys allege Poshmark shares your browsing activity with PAYPAL even if you never once use PayPal to check out or buy anything on the app — the data-sharing is alleged to trigger just from scrolling, not from any actual transaction. You could browse for secondhand clothes with zero intention of paying through PayPal and still have your activity handed to PayPal anyway.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 117, "_entity_id": 183, "_entity_slug": "poshmark", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Mercari", "Category": "Shopping/Retail (resale marketplace)", "Terms & Conditions URL": "mercari.com (Terms of Service — direct URL not individually captured this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "mercari.com (privacy notice not individually located this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "ACTIVE MASS ARBITRATION (2026): attorneys allege Mercari violates Illinois's Biometric Information Privacy Act (BIPA) by requiring users to upload a SELFIE AND A GOVERNMENT-ISSUED ID PHOTO for identity verification — collecting FACIAL GEOMETRY DATA (a unique, unchangeable biometric identifier) without first notifying users or obtaining the written consent Illinois law specifically requires for this category of data. BIPA provides for $1,000 per negligent violation and up to $5,000 per willful violation — among the highest per-violation statutory damages found anywhere in this tracker.", "Arbitration / Class Action Waiver": "Mercari's Terms of Service contain an arbitration clause; attorneys are pursuing this specific claim as MASS ARBITRATION (not a class action) given that structure, following the by-now-familiar pattern of using individual arbitration filings at scale to create settlement pressure.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is the most serious BIOMETRIC-specific privacy finding in the shopping/retail category of this tracker — worth flagging alongside the Kia/Nissan/Tesla biometric findings in the Auto Apps tab as part of a broader cross-industry pattern of companies collecting face/biometric data for verification purposes without the heightened consent some states (Illinois specifically) require.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Palo Alto", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] Mercari allegedly collects facial geometry via selfie-plus-ID verification without the written consent Illinois' BIPA requires\nWHAT THE TERMS SAY: Attorneys allege Mercari requires users to upload a selfie and a government-issued ID photo for identity verification, collecting facial geometry data without first notifying users or obtaining the written consent Illinois' Biometric Information Privacy Act requires; BIPA allows $1,000 per negligent violation and up to $5,000 per willful violation.\nWHY IT MATTERS: Facial geometry is a biometric identifier that can't be changed if exposed, and BIPA's per-violation statutory damages create substantial exposure if the allegations hold.\n(evidence: Data Sharing, SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Mercari's arbitration clause is now the basis for a mass-arbitration campaign over its alleged biometric-consent violations\nWHAT THE TERMS SAY: Mercari's Terms of Service contain an arbitration clause, and attorneys are pursuing the biometric-collection claim as mass arbitration — filing many individual arbitration claims at scale — rather than a class action.\nWHY IT MATTERS: The same arbitration clause meant to individualize disputes is being used at scale to create settlement pressure, though it also means affected users can't easily join a single collective case.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees/Billing was not itemized this pass and the arbitration opt-out window is not stated, leaving the biometric-collection allegation and the arbitration-clause mechanism as the only two distinct items.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The biometric-collection allegation is detailed and specific, but remains an active, unadjudicated mass-arbitration claim.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 6/30 (biometric_collection+6) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Mercari  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Mercari you gave up your biometric identifiers and your right to sue. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "To sell or buy on Mercari, attorneys allege you may be required to upload BOTH a selfie AND a photo of your government-issued ID — collecting your exact facial geometry, a biometric identifier that, unlike a password, can never be changed if it's ever exposed. Illinois law specifically requires written consent before collecting this, with penalties up to $5,000 PER VIOLATION for a willful failure to get it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 118, "_entity_id": 184, "_entity_slug": "mercari", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "OfferUp", "Category": "Shopping/Retail (local marketplace)", "Terms & Conditions URL": "offerup.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "offerup.com/privacy (referenced, not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass.", "Arbitration / Class Action Waiver": "Binding arbitration explicitly applies RETROACTIVELY — the Terms state that amended arbitration provisions (including 'consolidation of disputes' rules) apply to ANY dispute arising before a customer even agreed to the amended terms, 'whether or not notice of such dispute was provided, or arbitration was initiated, prior to your agreement to the amended Terms.' This retroactive-application language is more aggressive than most other arbitration clauses in this tracker, which typically apply going forward from acceptance rather than reaching back to cover disputes that arose under a PRIOR version of the terms. Also explicitly bars 'class action refund claims brought by a class of taxpayers... related to taxes collected and remitted' — an unusually specific carve-out suggesting past tax-related disputes with customers.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The retroactive arbitration-amendment language is worth flagging as one of the more customer-unfavorable structural mechanisms found in this tracker — it means OfferUp can potentially change the rules for a dispute that already exists before a customer has agreed to the change.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Bellevue", "HQ State": "Washington", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[UNILATERAL_CHANGES · FL-3] OfferUp's arbitration terms apply retroactively to disputes that existed before a customer agreed to the amended terms\nWHAT THE TERMS SAY: OfferUp's Terms state that amended arbitration provisions, including consolidation-of-disputes rules, apply to any dispute arising before a customer agreed to the amended terms, 'whether or not notice of such dispute was provided, or arbitration was initiated, prior to your agreement to the amended Terms.'\nWHY IT MATTERS: OfferUp can change arbitration rules and apply them backward to a dispute a customer already has, a more aggressive posture than most arbitration clauses in this tracker, which apply only going forward from acceptance.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] OfferUp's terms specifically bar class-action tax-refund claims, an unusually narrow carve-out suggesting past tax disputes\nWHAT THE TERMS SAY: The Terms explicitly bar 'class action refund claims brought by a class of taxpayers... related to taxes collected and remitted' — an unusually specific carve-out compared to other arbitration clauses in this tracker.\nWHY IT MATTERS: This narrow, specific exclusion suggests OfferUp has faced past tax-related customer disputes and preemptively blocked a collective route to challenge them.\n(evidence: Arbitration; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data Sharing and Fees/Billing were not confirmed or itemized this pass, leaving only the two arbitration-related structural findings.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The retroactive arbitration language is clearly quoted from the Terms, but data-sharing and fee practices were not confirmed this pass.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 5/20 (unilateral_modification+5) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "OfferUp  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using OfferUp you gave up your right to sue, your right to join a class action, and your right to be consulted before terms change. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:27:43Z (HTTP 200, CHANGED)", "SCARY (most astonishing T&C item)": "OfferUp's arbitration clause explicitly applies RETROACTIVELY — the company can update its arbitration terms and apply them to a dispute that already existed BEFORE you ever agreed to the new version, 'whether or not' you'd already started a dispute. Most companies' arbitration clauses only apply going forward from when you agree to them; this one can reach backward.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 119, "_entity_id": 185, "_entity_slug": "offerup", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Target", "Category": "Shopping/Retail", "Terms & Conditions URL": "target.com/c/terms-conditions/-/N-4sr7p", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "target.com/c/privacy-policy/-/N-4sr7t", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ONE OF THE LARGEST RETAIL BREACHES IN US HISTORY: the 2013 Target breach exposed credit/debit card data of ~40 MILLION customers plus personal information of up to 70 MILLION additional shoppers — hackers gained access through a THIRD-PARTY HVAC VENDOR and installed malware on Target's point-of-sale systems during the peak holiday shopping season. Target paid a $10 million consumer settlement fund (capped at $10,000/claimant, but the average payout after fees was reportedly only ~$30) plus a SEPARATE $18.5 million settlement with 47 state attorneys general (2017). New state privacy laws (2022–2025) have reopened DERIVATIVE claims in California and Illinois for consumers who can trace delayed identity-theft harm back to the original 2013 breach — meaning this 13-year-old breach still generates active litigation in 2026.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Target.com Terms of Use. 30-day opt-out window. AAA rules. Given the 2013 breach (41M payment cards + 60M contacts, $18.5M multistate settlement including DC) and the severity-5 rating in this tracker, the arbitration clause directly affects the largest consumer data-breach class in Target's history.", "Fees / Billing Flags": "SEPARATE 2026 SETTLEMENT: Target paid up to $2.225 million to resolve claims it violated Washington State's Equal Pay and Opportunities Act by failing to disclose salary ranges/benefits in job postings (2023–2025 postings) — an employment-law issue, not a customer-privacy issue, but relevant if this audit also considers labor practices.", "Notes": "The 'breach originated through a third-party HVAC vendor' finding is a useful, concrete illustration of the supply-chain/vendor-access risk pattern noted elsewhere in this tracker (e.g., the Booking.com/Expedia/Eurail travel-industry vendor breaches).", "Industry (Fortune 500)": "General Merchandisers", "Revenue (Fortune 500)": "$104.8B", "Market Cap": "$59.2B", "Employees": "440,000", "HQ City": "Minneapolis", "HQ State": "Minnesota", "CEO": "Michael Fiddelke", "Ticker": "TGT", "Website (Corporate)": "target.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (TGT). Service route: c/o General Counsel / Corporate Secretary, Minneapolis, Minnesota — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://oag.dc.gov/release/attorney-general-racine-announces-185-million", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Minnesota' is a non-DMV US state", "Parent / Ultimate Owner": "Target Corporation", "Years Referenced in Finding (heuristic)": "2013, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Target Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Target's 2013 breach (~40M cards, up to 70M shoppers) still draws derivative litigation in 2026\nWHAT THE TERMS SAY: The 2013 Target breach, which entered through a third-party HVAC vendor, exposed payment-card data of ~40 million customers and personal information of up to 70 million shoppers; Target paid a $10 million consumer settlement fund (average payout after fees reportedly only ~$30) plus a separate $18.5 million settlement with 47 state AGs (2017), and new 2022-2025 state privacy laws have reopened derivative claims in California and Illinois for consumers tracing delayed identity-theft harm back to the original breach.\nWHY IT MATTERS: More than a decade later, consumers whose delayed identity-theft harm surfaces late can still pursue claims, while the average payout from the original consumer settlement was reportedly only about $30 after fees.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Target's mandatory arbitration clause with a 30-day opt-out directly governs the largest data-breach class in its history\nWHAT THE TERMS SAY: Target.com's Terms of Use impose mandatory binding arbitration with a class action waiver under AAA rules and a 30-day opt-out window, which the tracker notes directly affects the 2013 breach class (41M payment cards + 60M contacts, $18.5M multistate settlement).\nWHY IT MATTERS: Customers affected by the historic breach who don't opt out within 30 days are limited to individual arbitration rather than collective litigation.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DISCRIMINATORY_PRACTICE · FL-1] Target paid up to $2.225M in 2026 to resolve claims it violated Washington's pay-transparency law\nWHAT THE TERMS SAY: Target paid up to $2.225 million to resolve claims it violated Washington State's Equal Pay and Opportunities Act by failing to disclose salary ranges and benefits in 2023-2025 job postings; the tracker notes this is an employment-law issue, not a customer-privacy issue.\nWHY IT MATTERS: This finding concerns Target as an employer rather than as a data handler, but is included as it's directly stated in this row's record and is relevant if labor practices are considered.\n(evidence: Fees; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The 2013 breach, settlements, and arbitration terms are all clearly documented with specific figures and dates.", "Exposure Score (0-100)": 44, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Target  <-  Target Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Target you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:27:48Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Target's landmark 2013 breach — 40 million cards, 70 million shoppers' personal data, entered through a THIRD-PARTY HVAC VENDOR'S credentials — is STILL generating fresh lawsuits in 2026, more than a decade later, from people whose delayed identity-theft harm is only now surfacing. On top of that decade-old wound, Target faces a completely separate active 2026 case alleging its coffee creamer contains FEWER SERVINGS than advertised on the label — a reminder that for a retailer this size, litigation genuinely never fully clears; new complaints just keep arriving behind the old ones.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 120, "_entity_id": 187, "_entity_slug": "target", "_issuer": "Target Corporation", "_issuer_slug": "target-corporation", "_ticker": "TGT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Postmates (DoorDash)", "Category": "Delivery", "Terms & Conditions URL": "postmates.com/legal/terms-of-service-us", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "postmates.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Postmates was acquired by and is now operated under DoorDash — see the DoorDash row for primary findings, including the NY AG's $16.75M settlement over tip-transparency practices, which likely extends to Postmates-branded orders processed on DoorDash's underlying platform.", "Arbitration / Class Action Waiver": "Likely governed by DoorDash's broader Terms following the acquisition; not independently confirmed whether Postmates retains a fully separate legal agreement this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Treat as effectively a DoorDash-owned brand for purposes of this audit rather than a fully independent company.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://ag.ny.gov/press-release/2025/attorney-general-james-secures-1675-million-doordash-cheating-delivery-workers", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "DoorDash, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: DoorDash, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — This row is a cross-reference to the DoorDash row for primary findings (the $16.75M NY AG tip-transparency settlement belongs to DoorDash, not independently to Postmates), and Notes state Postmates is treated as a DoorDash-owned brand rather than an independent company; arbitration terms are also not independently confirmed, leaving no company-specific finding to report this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No terms or findings are independently confirmed for Postmates; the row defers entirely to the DoorDash row.", "Exposure Score (0-100)": 14, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Postmates (DoorDash)  <-  DoorDash, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Postmates (DoorDash) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "2026-09-08T19:27:50Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Postmates now runs on DoorDash's underlying platform — meaning DoorDash's $16.75 million NY AG settlement over using customer tips to subsidize workers' base pay (documented elsewhere in this tracker) plausibly extends to every Postmates-branded order too, even though the app you opened still says 'Postmates.'", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 121, "_entity_id": 188, "_entity_slug": "postmates-doordash", "_issuer": "DoorDash, Inc.", "_issuer_slug": "doordash-inc", "_ticker": "DASH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Seamless (Grubhub)", "Category": "Delivery", "Terms & Conditions URL": "seamless.com/corporate/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "seamless.com/corporate/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Seamless is owned by and operates under Grubhub — Grubhub itself paid a $25 MILLION FTC settlement (referenced in the Uber/DoorDash research earlier in this tracker) for deceptive fee/subscription practices, and was specifically cited by a competitor (H&R Block-style comparison, see DoorDash row) as a model for proactively extending its post-settlement transparency reforms industry-wide — the only major delivery company to do so in the 2026 FTC food-delivery-fee rulemaking comment period.", "Arbitration / Class Action Waiver": "Likely governed by Grubhub's broader Terms following the acquisition.", "Fees / Billing Flags": "See Grubhub's $25M FTC settlement, referenced under the DoorDash row.", "Notes": "Grubhub (Seamless's parent) is arguably the most PROACTIVE of the major delivery platforms on fee transparency post-settlement — a genuine point of contrast worth noting against DoorDash/Uber Eats/Instacart's more contested records in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Chicago", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.ftc.gov/news-events/news/press-releases/2024/12/ftc-illinois-attorney-general-take-action-against-grubhub-harming-diners-workers-small-businesses", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Just Eat Takeaway.com (Amsterdam, acquired 2021)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Just Eat Takeaway.com (Amsterdam, acquired 2021)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — This row is essentially a cross-reference to Grubhub's $25M FTC settlement (documented under the DoorDash row) rather than an independent Seamless-specific finding; arbitration terms are only presumed to follow Grubhub's broader Terms, and Notes frame Grubhub/Seamless as comparatively proactive on fee transparency, leaving no distinct troubling item to report for Seamless itself this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No Seamless-specific terms or findings are independently confirmed; the row defers to Grubhub's settlement and terms.", "Exposure Score (0-100)": 14, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Seamless (Grubhub)  <-  Just Eat Takeaway.com (Amsterdam, acquired 2021)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Seamless (Grubhub) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "2026-09-08T19:27:54Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Seamless runs on Grubhub's infrastructure, meaning Grubhub's own $25 million FTC settlement over deceptive fees and subscription practices applies to the same underlying system powering Seamless orders — the brand name changes, the company handling your money and data doesn't.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 122, "_entity_id": 190, "_entity_slug": "seamless-grubhub", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Domino's", "Category": "Delivery/Restaurant", "Terms & Conditions URL": "dominos.com/en/tou/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "dominos.com/en/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit — recommend direct follow-up given the general delivery-industry fee-transparency scrutiny (Uber Eats, DoorDash, Instacart, McDonald's, Chick-fil-A) already well-documented elsewhere in this tracker; worth checking whether Domino's proprietary delivery/ordering app faces similar allegations.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Domino's Terms of Use, AAA rules. 30-day opt-out via written notice. Covers online ordering, the Domino's app, and Piece of the Pie Rewards. Given Domino's heavy app/digital ordering model (~80% of US orders are digital), the Terms of Use govern the primary consumer relationship.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Queued for a dedicated follow-up given the strong pattern already established across the delivery/restaurant-app category in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Ann Arbor", "HQ State": "Michigan", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Michigan' is a non-DMV US state", "Parent / Ultimate Owner": "Domino's Pizza, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Michigan LARA Business Entity Search — cofs.lara.state.mi.us/SearchApi/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Domino's Pizza, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Domino's mandatory arbitration and class-action waiver cover its digital ordering (~80% of US orders)\nWHAT THE TERMS SAY: Domino's Terms of Use impose mandatory binding arbitration with a class action waiver under AAA rules, a 30-day opt-out via written notice, and cover online ordering, the Domino's app, and Piece of the Pie Rewards — governing the primary consumer relationship given that roughly 80% of US orders are digital.\nWHY IT MATTERS: Because roughly 80% of US orders are digital, this arbitration clause governs the primary consumer relationship for customers who don't opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data Sharing/Selling and Fees were not itemized or independently confirmed this pass; the SCARY item and Notes describe an industry-wide delivery-fee-transparency pattern documented for other companies (Uber Eats, DoorDash, Instacart, McDonald's, Chick-fil-A) rather than a confirmed Domino's-specific finding, leaving only the arbitration clause as a distinct item.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly documented, but data-sharing and fee practices were not confirmed or itemized this pass.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Domino's  <-  Domino's Pizza, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Domino's you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Domino's operates in the exact same delivery-fee-transparency landscape already documented for Uber Eats, DoorDash, Instacart, McDonald's, and Chick-fil-A elsewhere in this tracker — no Domino's-specific enforcement action was independently confirmed, but the industry-wide pattern of hidden delivery markups makes it worth checking your own Domino's delivery total against ordering the same items for pickup.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 123, "_entity_id": 192, "_entity_slug": "domino-s", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Starbucks", "Category": "Restaurant/Loyalty App", "Terms & Conditions URL": "starbucks.com/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "starbucks.com/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED 2026 DATA BREACH: on Feb 6, 2026, Starbucks discovered unauthorized access to 'Partner Central' (an EMPLOYEE-facing system, not the customer rewards app) after a third party obtained login credentials via phishing websites impersonating the real Partner Central login page. Reported to the Maine AG (March 12, 2026); 889 individuals nationwide affected (5 in Maine specifically) — a relatively small-scale, contained breach compared to many other findings in this tracker, and again employee-facing rather than customer-facing.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out via written notice. AAA Consumer Arbitration Rules. Small claims court exception. Separately, a March 2025 LA County jury awarded $50M to a delivery driver (Garcia v. Starbucks) in a tort case — Starbucks has stated it will appeal. The arbitration clause would not have covered this case (tort, not contract), but it would cover billing/rewards disputes.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This particular breach targeted EMPLOYEES via credential phishing, not customers directly through the Starbucks Rewards app — worth being precise about this distinction if referencing it, since it's a different risk category (employee-system phishing) than the customer-data-sharing findings that dominate most of this tracker.", "Industry (Fortune 500)": "Food Services", "Revenue (Fortune 500)": "$37.2B", "Market Cap": "$118.5B", "Employees": "361,000", "HQ City": "Seattle", "HQ State": "Washington", "CEO": "Brian Niccol", "Ticker": "SBUX", "Website (Corporate)": "starbucks.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (SBUX). Service route: c/o General Counsel / Corporate Secretary, Seattle, Washington — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.aol.com/news/jury-awarded-delivery-driver-burned-222405732.html", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Starbucks Corporation", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Starbucks Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] 2026 lawsuit alleges Starbucks' '100% Ethical Sourcing' claim is false and some decaf contains undisclosed VOC chemicals\nWHAT THE TERMS SAY: A 2026 consumer lawsuit alleges Starbucks' '100% Ethical Sourcing' marketing claim is false, and that certain decaf products contain measurable VOC (volatile organic compound) chemicals not disclosed in the marketing.\nWHY IT MATTERS: If true, consumers relying on Starbucks' ethical-sourcing marketing and choosing decaf may be consuming undisclosed chemicals while paying for a sourcing claim that isn't accurate.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] Confirmed 2026 phishing breach compromised Starbucks' employee-facing Partner Central system, affecting 889 people nationwide\nWHAT THE TERMS SAY: On Feb 6, 2026, Starbucks discovered unauthorized access to Partner Central — an employee-facing system, not the customer rewards app — after a third party obtained login credentials via phishing sites impersonating the real login page; it was reported to the Maine AG (889 individuals nationwide, 5 in Maine).\nWHY IT MATTERS: Though contained and employee-facing rather than customer-facing, it is a confirmed credential-phishing breach that exposed real individuals' data.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Starbucks' mandatory arbitration and class-action waiver cover billing/rewards disputes but not tort claims like the $50M hot-tea verdict\nWHAT THE TERMS SAY: Starbucks' terms impose mandatory binding arbitration with a class action waiver under AAA Consumer Arbitration Rules, a 30-day opt-out, and a small-claims exception; the tracker notes the clause would not have covered the March 2025 $50M Garcia v. Starbucks tort verdict (a delivery driver burned by 180-190°F spilled tea) but would cover billing/rewards disputes.\nWHY IT MATTERS: Rewards and billing disputes are pushed into individual arbitration, while more serious injury claims can still reach a jury, as the $50M verdict shows.\n(evidence: Arbitration, SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Partner Central breach and arbitration terms are clearly confirmed, but the ethical-sourcing/VOC and tip-pooling claims remain allegations.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Starbucks  <-  Starbucks Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Starbucks you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:28:00Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "A Los Angeles jury awarded a delivery driver $50 MILLION after 180-190°F tea spilled in his lap at a drive-thru, causing severe burns — a stark reminder of just how hot Starbucks serves its drinks. Separately, a 2026 consumer lawsuit alleges Starbucks' '100% Ethical Sourcing' marketing claim is false, and that certain decaf products contain measurable VOC (volatile organic compound) chemicals the marketing doesn't disclose. And baristas in California allege the company's tip-pooling system quietly diverts money away from the employees actually earning those tips — with the math on a busy location adding up to real money missing from workers' pockets week after week.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 124, "_entity_id": 194, "_entity_slug": "starbucks", "_issuer": "Starbucks Corporation", "_issuer_slug": "starbucks-corporation", "_ticker": "SBUX", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Chipotle", "Category": "Restaurant/Loyalty App", "Terms & Conditions URL": "chipotle.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "chipotle.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "An October 2025 breach compromised EMPLOYEE Workday payroll accounts (not the customer-facing rewards app) — attackers gained 'unauthorized logins' and attempted to CHANGE DIRECT-DEPOSIT BANKING INFORMATION to divert employee paychecks to themselves, in addition to exposing names, Social Security numbers, birthdates, and bank account/routing numbers. A resulting employee class action (Jasso v. Chipotle, seeking to represent 'thousands' of employees, ~$5M+ at stake) was filed in Jan 2026 alleging 'wrongful, reckless, and grossly negligent' data security — but the named plaintiff voluntarily DISMISSED the suit in Feb 2026 (without prejudice, meaning it could theoretically be refiled), leaving the underlying breach's legal resolution unclear as of this research.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for the customer-facing app specifically.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is an EMPLOYEE-facing breach (payroll diversion attempt), not a customer-facing privacy issue — worth being precise about this distinction, similar to the Starbucks Partner Central breach elsewhere in this tracker, if referencing it in customer-facing material.", "Industry (Fortune 500)": "Food Services", "Revenue (Fortune 500)": "$11.9B", "Market Cap": "$44.9B", "Employees": "130,504", "HQ City": "Newport Beach", "HQ State": "California", "CEO": "Scott Boatwright", "Ticker": "CMG", "Website (Corporate)": "chipotle.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (CMG). Service route: c/o General Counsel / Corporate Secretary, Newport Beach, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] October 2025 breach of Chipotle's employee Workday payroll system exposed SSNs and bank data, with attempted paycheck diversion\nWHAT THE TERMS SAY: An October 2025 breach compromised employee Workday payroll accounts (not the customer rewards app); attackers gained unauthorized logins and attempted to change direct-deposit banking information to divert employee paychecks, exposing names, Social Security numbers, birthdates, and bank account/routing numbers. A resulting employee class action (Jasso v. Chipotle) was filed in January 2026 but voluntarily dismissed without prejudice in February 2026, leaving the breach's legal resolution unclear.\nWHY IT MATTERS: Affected employees had highly sensitive financial and identity data exposed and were at risk of having paychecks redirected to attackers; the dismissal without prejudice means the case could still be refiled.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-1] Chipotle reportedly charges up to 13% more for delivery orders than identical in-store items, beyond the disclosed delivery fee\nWHAT THE TERMS SAY: Per industry reporting cited in the tracker, Chipotle has been specifically tested for charging more for delivery orders than in-store pickup — sometimes 13% higher on the same menu items — even as the delivery fee is marketed separately as if it's the only added cost.\nWHY IT MATTERS: Customers ordering delivery may pay a hidden markup on the menu items themselves, beyond the disclosed delivery fee, inflating the true cost of the order.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration/class-action terms are not independently confirmed for Chipotle's customer-facing app (only 'standard... expected'), leaving the confirmed employee payroll breach and the delivery-markup pattern as the two distinct items.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=Y; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration terms are unconfirmed, and the employee breach's related lawsuit was dismissed without a clear resolution.", "Exposure Score (0-100)": 8, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 5/20 (severity2+2, breach+3) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "App / Service", "Ownership Path": "Chipotle  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Chipotle you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:28:02Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The exact same practice under scrutiny across the restaurant industry — charging MORE for delivery orders than in-store pickup, sometimes 13% higher on the same menu items — has been specifically tested by Chipotle, per industry reporting, even as the underlying delivery FEE is marketed separately as if it's the only added cost.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 125, "_entity_id": 195, "_entity_slug": "chipotle", "_issuer": "Chipotle", "_issuer_slug": "chipotle", "_ticker": "CMG", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "McDonald's", "Category": "Restaurant/Loyalty App", "Terms & Conditions URL": "mcdonalds.com/us/en-us/legal/terms-and-conditions.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "mcdonalds.com/us/en-us/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "$50 MILLION BIPA SETTLEMENT: Illinois McDonald's restaurants agreed to pay $50 million to employees (not customers) who were required to log into restaurant systems using biometric data (fingerprints) without the disclosures/consent Illinois' Biometric Information Privacy Act requires — an employee-facing rather than customer-facing finding, but relevant if this audit also considers how companies in this tracker treat frontline workers, not just customers.", "Arbitration / Class Action Waiver": "Named in an active mass-arbitration investigation (with Chick-fil-A, Grubhub, Uber Eats, TurboTax, StubHub, and others) over allegedly hiding delivery/service/small-order fees until late in the checkout process; separately, McDonald's SETTLED a related class action over drive-through/ordering fees, returning $26+ million to consumers collectively — though individual payouts averaged only about $38 per person, illustrating how large aggregate settlement totals can still mean modest amounts for any one customer.", "Fees / Billing Flags": "See arbitration column — the $26M drive-through settlement is the customer-facing fee finding specifically.", "Notes": "McDonald's has BOTH an employee-facing biometric settlement ($50M) and a customer-facing fee settlement ($26M+) — worth distinguishing clearly in any summary since they involve completely different people (workers vs. customers) and different underlying laws (BIPA vs. general consumer protection/fee-disclosure law).", "Industry (Fortune 500)": "Food Services", "Revenue (Fortune 500)": "$26.9B", "Market Cap": "$191.4B", "Employees": "150,000", "HQ City": "Chicago", "HQ State": "Illinois", "CEO": "Christopher Kempczinski", "Ticker": "MCD", "Website (Corporate)": "mcdonalds.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (MCD). Service route: c/o General Counsel / Corporate Secretary, Chicago, Illinois — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] Illinois McDonald's paid a $50 million BIPA settlement over unconsented fingerprint logins for employees\nWHAT THE TERMS SAY: Illinois McDonald's restaurants agreed to pay $50 million to employees who were required to log into restaurant systems using fingerprint biometric data without the disclosures and consent Illinois' BIPA requires; this is an employee-facing rather than customer-facing finding.\nWHY IT MATTERS: While this settlement addresses workers rather than customers, it shows McDonald's collected biometric data without required consent, the same category of harm tracked for customer-facing biometric findings elsewhere in this audit.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[AUTO_RENEWAL_FEES · FL-1] McDonald's faces a mass-arbitration probe over allegedly hidden fees; paid $26M+ (avg ~$38/person)\nWHAT THE TERMS SAY: McDonald's is named in an active mass-arbitration investigation (with Chick-fil-A, Grubhub, Uber Eats, TurboTax, StubHub, and others) over allegedly hiding delivery/service/small-order fees until late in checkout, and separately settled a related class action over drive-through/ordering fees, returning $26+ million to consumers collectively — though individual payouts averaged only about $38 per person.\nWHY IT MATTERS: Consumers may pay hidden fees revealed only late in checkout, and even when McDonald's settles, individual compensation is modest relative to the aggregate settlement size.\n(evidence: Arbitration, Fees; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The SCARY item's franchisee wage-theft and chicken-supplier price-fixing details concern labor practices and McDonald's as a plaintiff against suppliers respectively, not McDonald's own consumer-facing terms or data practices, leaving two distinct company-specific items.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The BIPA and fee settlements are clearly documented with figures, but the mass-arbitration delivery-fee investigation is still active and unresolved.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 6/30 (biometric_collection+6) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 10/20 (severity3+8, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "App / Service", "Ownership Path": "McDonald's  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using McDonald's you gave up your biometric identifiers, your right to sue, and your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "McDonald's franchisees systematically underpaid hourly workers through off-the-clock prep time and missed breaks — the kind of small-per-shift shortfall that adds up to real money across thousands of shifts nationwide. Separately, McDonald's has joined OTHER restaurant chains suing chicken suppliers for allegedly fixing prices through secret phone and text communication — meaning the cost of your Chicken McNuggets may have been artificially inflated by a supplier conspiracy the restaurant itself is now suing over.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 126, "_entity_id": 196, "_entity_slug": "mcdonald-s", "_issuer": "McDonald's", "_issuer_slug": "mcdonald-s", "_ticker": "MCD", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Chick-fil-A (One app)", "Category": "Restaurant/Loyalty App", "Terms & Conditions URL": "chick-fil-a.com/legal/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "chick-fil-a.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "TWO SEPARATE, DISTINCT PRIVACY ISSUES: (1) a confirmed DATA BREACH (first disclosed 2023, litigation still active in 2026) exposed the Chick-fil-A One loyalty app, where customers who stored payment methods and personal information (encouraged via rewards incentives) had accounts compromised — loyalty points were stolen and fraudulently redeemed, some customers lost real money, and the app did not require two-factor authentication by default; the lawsuit specifically argues Chick-fil-A created the conditions for harm by incentivizing customers to store sensitive data without adequate security. Chick-fil-A settled this data-breach suit (per a 2023 Georgia federal case). (2) SEPARATELY, a Video Privacy Protection Act (VPPA) class action alleges Chick-fil-A used the Meta Pixel on its 'Stories of Evergreen Hills' animated content site to transmit video-viewing data (URL, video title) tied to a visitor's Facebook ID, allowing Facebook to determine which specific individuals watched which specific videos — part of the same VPPA/tracking-pixel litigation wave affecting many other companies in this tracker.", "Arbitration / Class Action Waiver": "Named in an active mass-arbitration investigation (with McDonald's, Grubhub, Uber Eats, TurboTax, StubHub, and others) over allegedly illegal 'junk fees' and 'drip pricing' added late in the ordering process for delivery orders placed through the Chick-fil-A website/app.", "Fees / Billing Flags": "See arbitration column — the delivery junk-fee investigation is fee-related, distinct from the data-breach and VPPA issues above.", "Notes": "Chick-fil-A now has THREE separate, distinct issue categories documented in this tracker (data breach, video-tracking/VPPA, and delivery junk fees) — among the most multi-faceted findings for any single company in the apps category.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "College Park", "HQ State": "Georgia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Georgia' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2023, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Georgia SOS eCorp — ecorp.sos.ga.gov/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Chick-fil-A's loyalty app was breached in 2023, settled, then breached again the same way in June 2026 because MFA is still optional\nWHAT THE TERMS SAY: Chick-fil-A's 2023 loyalty-app breach (customers who stored payment info and personal data had accounts compromised, loyalty points stolen and fraudulently redeemed, no two-factor authentication by default) was settled in a 2023 Georgia federal case; the tracker states the same app was breached again in June 2026 via reused stolen credentials, because Chick-fil-A offers but still doesn't require multi-factor authentication.\nWHY IT MATTERS: The exact security gap the company already settled a lawsuit over remained unfixed three years later, exposing customers to a repeat of the same type of account compromise and loyalty-point theft.\n(evidence: Data Sharing, SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] A VPPA class action alleges Chick-fil-A's Meta Pixel let Facebook identify which specific individuals watched which of its videos\nWHAT THE TERMS SAY: A Video Privacy Protection Act class action alleges Chick-fil-A used the Meta Pixel on its 'Stories of Evergreen Hills' animated content site to transmit video-viewing data (URL, video title) tied to a visitor's Facebook ID, letting Facebook determine which specific individuals watched which specific videos.\nWHY IT MATTERS: If true, watching branded video content could be linked to a person's Facebook identity without clear consent, revealing individual viewing habits to a third-party ad platform.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[AUTO_RENEWAL_FEES · FL-1] Chick-fil-A is under mass-arbitration investigation for allegedly hiding delivery fees until late in checkout\nWHAT THE TERMS SAY: Chick-fil-A is named in an active mass-arbitration investigation (with McDonald's, Grubhub, Uber Eats, TurboTax, StubHub, and others) over allegedly illegal junk fees and drip pricing added late in the ordering process for delivery orders placed through its website/app.\nWHY IT MATTERS: Customers ordering delivery may be quoted a lower price upfront only to have additional fees added late in checkout, inflating the final total beyond what was initially advertised.\n(evidence: Arbitration, Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2023 and 2026 breaches are clearly confirmed, but the VPPA pixel-tracking claim and delivery-fee investigation remain active, unresolved allegations.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "App / Service", "Ownership Path": "Chick-fil-A (One app)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Chick-fil-A (One app) you gave up your data shared corporate-wide, your right to sue, and your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Chick-fil-A's loyalty app was breached in 2023 for 'utter failure to implement basic cybersecurity policies,' and the company settled that lawsuit. Then in June 2026, the SAME app was breached AGAIN, the same way — stolen login credentials from elsewhere getting reused, because Chick-fil-A OFFERS multi-factor authentication but still doesn't REQUIRE it. The exact security gap the company already got sued over once was still sitting there, unfixed, three years later.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 127, "_entity_id": 197, "_entity_slug": "chick-fil-a-one-app", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Booking.com", "Category": "Travel", "Terms & Conditions URL": "booking.com/content/terms.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "booking.com/content/privacy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Booking.com has disclosed at least two separate data-exposure incidents: (1) a breach where 'unauthorized parties' accessed customer details (financial information reportedly NOT compromised, per the company's own statement); (2) a 2024 third-party vendor exposure (Prestige Software, which processes reservations for Booking.com/Expedia and others) that briefly left large volumes of reservation data unsecured — illustrating a broader travel-industry pattern where breaches increasingly originate from third-party vendors/supply-chain partners rather than the travel company's own systems directly (the same source article notes similar third-party-caused breaches at Eurail, KLM/Air France, and Hertz/Dollar/Thrifty in 2025–2026).", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION for consumer disputes — Booking.com (HQ: Amsterdam, Netherlands) is governed by Dutch law and does not include a US-style arbitration clause in its consumer-facing terms. Disputes go to the competent courts in Amsterdam. This is consistent with EU consumer protection norms, which generally disfavor mandatory arbitration.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "SEPARATE, UNRELATED LEGAL NOTE: a July 2024 federal jury found Booking.com violated the Computer Fraud and Abuse Act by improperly accessing Ryanair's protected computer systems — this is Booking.com as a DEFENDANT in a dispute with an airline PARTNER, not a customer-privacy issue, but relevant corporate-conduct context; the dispute was later settled with a data-access agreement between the two companies.", "Industry (Fortune 500)": "Internet Services and Retailing", "Revenue (Fortune 500)": "$26.9B", "Market Cap": "$137.8B", "Employees": "24,179", "HQ City": "Norwalk", "HQ State": "Connecticut", "CEO": "Glenn Fogel", "Ticker": "BKNG", "Website (Corporate)": "bookingholdings.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (BKNG). Service route: c/o General Counsel / Corporate Secretary, Norwalk, Connecticut — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Connecticut' is a non-DMV US state", "Parent / Ultimate Owner": "Booking Holdings Inc. (Norwalk, CT)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Connecticut SOTS CONCORD — service.ct.gov/business/s/onlinebusinesssearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Booking Holdings Inc. (Norwalk, CT)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Booking.com disclosed two separate data-exposure incidents, including a 2024 third-party vendor (Prestige Software) leak of reservation data\nWHAT THE TERMS SAY: Booking.com disclosed a breach where unauthorized parties accessed customer details (financial information reportedly not compromised, per the company), plus a 2024 exposure via third-party vendor Prestige Software, which processes reservations for Booking.com and others, briefly leaving large volumes of reservation data unsecured.\nWHY IT MATTERS: Customer reservation and personal data were exposed through both a direct breach and a vendor's unsecured systems, illustrating how travel bookings can be compromised even when the platform's own systems aren't directly at fault.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[LIABILITY_CAP_INDEMNITY · FL-1] Consumer-legal guides warn Booking.com's terms are 'pretty one-sided' and strictly limit customers' right to recourse\nWHAT THE TERMS SAY: Legal guides advising consumers on suing online travel sites describe Booking.com's own Terms as 'pretty one-sided' and say they 'strictly limit your right to any recourse,' with disclaimers that courts have historically enforced.\nWHY IT MATTERS: A customer harmed by a Booking.com transaction may find contractual disclaimers stand in the way of holding the company accountable, per third-party legal guidance cited in the tracker.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees/Billing was not itemized, and the Ryanair CFAA case and hoteliers' commission lawsuit noted in this row are business-to-business disputes rather than consumer-facing terms issues, leaving two distinct consumer-relevant items; Booking.com's lack of a mandatory arbitration clause is consumer-favorable and not counted as troubling.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Two data-exposure incidents are confirmed, but the company's own statements minimize financial-data impact and full details remain limited.", "Exposure Score (0-100)": 18, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Booking.com  <-  Booking Holdings Inc. (Norwalk, CT)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to be made whole. Their liability is capped, often at what you paid.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Booking.com you gave up your right to meaningful compensation. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "European hoteliers have banded together to sue Booking.com over 'excessive commissions' baked into restrictive pricing clauses — seeking BILLIONS in compensation. Meanwhile, legal guides advising ordinary consumers on suing online travel sites warn plainly that Booking.com's own Terms are 'pretty one-sided' and 'strictly limit your right to any recourse,' with disclaimers that courts have historically enforced. The same booking platform under fire from hotels for unfair commissions has terms that make it just as hard for the CUSTOMER on the other end to fight back.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 128, "_entity_id": 199, "_entity_slug": "booking-com", "_issuer": "Booking Holdings Inc.", "_issuer_slug": "booking-holdings-inc", "_ticker": "BKNG", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Expedia", "Category": "Travel", "Terms & Conditions URL": "expedia.com/service/termsandconditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "expedia.com/service/privacypolicy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "A 2020 data breach involving Expedia.com and a third-party vendor (Amazon Web Services / AWS-hosted infrastructure operated by a business partner) exposed tens of millions of personal records, leading to a class action — consistent with the broader travel-industry third-party-vendor breach pattern already documented in the Booking.com row (Prestige Software, Eurail, KLM/Air France, Hertz/Dollar/Thrifty).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Expedia Group ToS, AAA rules, Washington state law. 30-day opt-out via email to arboptout@expedia.com. Covers Expedia, Hotels.com, Vrbo, Orbitz, Travelocity, and all Expedia Group brands.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Add to the Booking.com row's cross-reference list of travel companies affected by the same 'breach originates from a third-party vendor, not the travel company's own systems' pattern.", "Industry (Fortune 500)": "Internet Services and Retailing", "Revenue (Fortune 500)": "$14.7B", "Market Cap": "$31.3B", "Employees": "16,500", "HQ City": "Seattle", "HQ State": "Washington", "CEO": "Ariane Gorin", "Ticker": "EXPE", "Website (Corporate)": "expediagroup.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (EXPE). Service route: c/o General Counsel / Corporate Secretary, Seattle, Washington — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Expedia Group, Inc.", "Years Referenced in Finding (heuristic)": "2020", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Expedia Group, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Expedia's 2020 data breach, traced to a third-party vendor's AWS-hosted infrastructure, exposed tens of millions of records\nWHAT THE TERMS SAY: A 2020 data breach involving Expedia.com and a third-party vendor (AWS-hosted infrastructure operated by a business partner) exposed tens of millions of personal records, leading to a class action.\nWHY IT MATTERS: Tens of millions of customers had personal data exposed through a partner's infrastructure rather than Expedia's own systems, yet Expedia customers bore the consequences.\n(evidence: Data Sharing, SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Expedia's mandatory arbitration and class-action waiver cover all Expedia Group brands, with only a 30-day opt-out by email\nWHAT THE TERMS SAY: Expedia Group's Terms of Service impose mandatory binding arbitration with a class action waiver under AAA rules and Washington state law, with a 30-day opt-out via email to arboptout@expedia.com, covering Expedia, Hotels.com, Vrbo, Orbitz, Travelocity, and all Expedia Group brands.\nWHY IT MATTERS: A single arbitration clause blocks class litigation across the entire Expedia Group portfolio of brands unless a customer affirmatively opts out by email within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[LIABILITY_CAP_INDEMNITY · FL-1] Consumer-legal guides describe Expedia's terms as nearly as one-sided as Booking.com's, with disclaimers courts have enforced\nWHAT THE TERMS SAY: Expedia's Terms are described by consumer-legal guides as nearly identical in one-sidedness to Booking.com's — heavy disclaimers and strict limits on recourse that courts have historically enforced against travelers.\nWHY IT MATTERS: Combined with mandatory arbitration, these disclaimers make it harder for a harmed Expedia customer to hold the company accountable through the courts.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Arbitration terms, the opt-out mechanism, and the 2020 breach are all clearly and specifically documented.", "Exposure Score (0-100)": 42, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Expedia  <-  Expedia Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Expedia you gave up your right to sue, your right to join a class action, and your right to meaningful compensation. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Expedia's Terms are described by consumer-legal guides as nearly identical in one-sidedness to Booking.com's (this same tab) — heavy disclaimers, strict limits on recourse, courts historically enforcing them against travelers. Separately, Expedia's own 2020 breach traced back to a THIRD-PARTY VENDOR'S infrastructure, exposing tens of millions of records — the same 'it wasn't technically our system' pattern found at Marriott, Booking.com, and Target elsewhere in this tracker.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 129, "_entity_id": 201, "_entity_slug": "expedia", "_issuer": "Expedia Group, Inc.", "_issuer_slug": "expedia-group-inc", "_ticker": "EXPE", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Delta Air Lines", "Category": "Travel (airline)", "Terms & Conditions URL": "delta.com/us/en/legal/contract-of-carriage", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "delta.com/us/en/privacy-policy/overview", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "STRUCTURAL FLAG APPLIES TO ALL US AIRLINES: airlines are largely EXEMPT from FTC privacy enforcement (the 1978 Airline Deregulation Act preempts state privacy/consumer-protection lawsuits against airlines, and the FTC's authority 'specifically excludes domestic and foreign airline activities') — instead, the Department of Transportation (DOT) is the primary enforcer, and per EPIC's research, DOT has historically 'sparsely used' this authority compared to the FTC's decades of active enforcement. This means airline customers have meaningfully WEAKER practical privacy-enforcement recourse than customers of virtually every other company in this entire audit. Delta specifically discloses sharing customer data with 'data centers, biometric verification services, and online tools,' airline partners, and promotional partners; collects biometric data (fingerprints, face, voice, or eye scans) and discloses it to business partners; and announced 'surveillance pricing' (AI-driven personalized pricing based on customer data) that consumer attorneys argue may violate deception/fairness standards and could create discriminatory pricing effects via proxy variables correlated with protected characteristics, even without discriminatory intent.", "Arbitration / Class Action Waiver": "CLASS ACTION WAIVER in Contract of Carriage. NO mandatory arbitration — like most US airlines, Delta uses a class action waiver WITHOUT an arbitration clause, meaning disputes go to court but only individually. Part of the 2020-2023 mass-adoption wave (8 of 10 largest US airlines). Delta is one of two defendants (with United) still litigating the domestic airline price-fixing MDL.", "Fees / Billing Flags": "ACTIVE $5 MILLION CLASS ACTION (filed May 2026, NY): alleges Delta's website is deceptively designed to push customers toward accepting 'inferior' electronic travel credits (usable only on Delta, ~1-year expiration) instead of clearly offering the FULL CASH REFUNDS customers are entitled to on fully-refundable fares — the complaint states Delta itself internally values a cash refund at 2X the value of an e-credit, while its own website pre-selects the e-credit option and hides the cash-refund option elsewhere on the page.", "Notes": "The airline-industry-wide FTC exemption (via the Airline Deregulation Act) is arguably the single most important STRUCTURAL finding in this whole audit — it applies identically to United, American, Southwest, and every other US airline, meaning customers of ALL airlines have less regulatory recourse than customers of virtually any other company category in this entire tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Atlanta", "HQ State": "Georgia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.hausfeld.com/news/hausfeld-wins-significant-victory-on-behalf-of-class-of-domestic-airline-ticket-purchasers-in-antitrust-lawsuit-against-major-us-carriers", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Delta Air Lines, Inc.", "Years Referenced in Finding (heuristic)": "2026, 2020", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Georgia SOS eCorp — ecorp.sos.ga.gov/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Delta Air Lines, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[SURVEILLANCE_PRICING · FL-2] Delta discloses biometric data to partners and announced AI-driven 'surveillance pricing'\nWHAT THE TERMS SAY: Delta discloses sharing customer data with data centers, biometric verification services, online tools, airline partners, and promotional partners; it collects biometric data (fingerprints, face, voice, or eye scans) and discloses it to business partners; and it announced AI-driven personalized 'surveillance pricing' based on customer data that consumer attorneys argue may violate deception/fairness standards and could create discriminatory pricing effects via proxy variables correlated with protected characteristics, even without discriminatory intent.\nWHY IT MATTERS: Customer data could be used to set individualized prices, and consumer attorneys argue this may violate deception/fairness standards and could create discriminatory pricing effects via proxy variables correlated with protected characteristics, even without discriminatory intent.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-3] Airlines including Delta are structurally exempt from FTC privacy enforcement, leaving a regulator that historically acts rarely\nWHAT THE TERMS SAY: The 1978 Airline Deregulation Act preempts state privacy/consumer-protection lawsuits against airlines and specifically excludes airline activities from FTC authority; the Department of Transportation is the primary enforcer instead, and per EPIC's research, DOT has historically used this authority sparsely compared to the FTC's decades of active enforcement.\nWHY IT MATTERS: Delta customers have meaningfully weaker practical privacy-enforcement recourse than customers of virtually any other company in this tracker, since the primary regulator rarely acts.\n(evidence: Data Sharing, Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DARK_PATTERN_CONSENT · FL-1] A May 2026 lawsuit alleges Delta's cancellation page pre-selects a lesser e-credit over the cash refund customers are owed\nWHAT THE TERMS SAY: A $5 million class action filed May 2026 in New York alleges Delta's website deceptively pushes customers toward accepting 'inferior' e-credits (usable only on Delta, ~1-year expiration) instead of clearly offering full cash refunds on fully-refundable fares; the complaint states Delta internally values a cash refund at twice the value of an e-credit, while its website pre-selects the e-credit option, filling the screen, and hides the cash-refund option elsewhere on the page, requiring scrolling and manual deselection.\nWHY IT MATTERS: Customers entitled to a full cash refund may unknowingly accept a lesser, Delta-only credit that expires in about a year and is worth half as much by Delta's own internal valuation.\n(evidence: Fees, SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Data-sharing and pricing practices are clearly disclosed by Delta itself, but the discriminatory-pricing and refund-dark-pattern claims remain active, unresolved allegations.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 9, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 9/30 (class_action_waiver+9) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Delta Air Lines  <-  Delta Air Lines, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Delta Air Lines you gave up your biometric identifiers, your data shared corporate-wide, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "2026-09-08T19:31:41Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "A May 2026 lawsuit alleges Delta's own internal pricing values a CASH REFUND at TWICE the value of an e-credit — and then designs its cancellation page so the LESSER e-credit option is PRE-SELECTED and fills the entire visible screen, while the cash refund you actually paid extra for is hidden below, requiring you to scroll and manually deselect the pre-picked choice. The suit calls this exactly what the FTC defines as an illegal 'dark pattern.' Separately, Delta paid $78.75 MILLION to settle claims it dumped jet fuel over a Southern California neighborhood during a 2020 emergency landing — residents reported fumes and physical symptoms from fuel raining down on homes and schools below.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 130, "_entity_id": 203, "_entity_slug": "delta-air-lines", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Marriott (Bonvoy)", "Category": "Travel/Loyalty", "Terms & Conditions URL": "marriott.com/en-us/terms-of-use.mi", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "marriott.com/en-us/privacy-statement.mi", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ONE OF THE LARGEST DATA BREACHES IN THIS ENTIRE AUDIT: the 2018 Starwood breach (discovered after Marriott's acquisition of Starwood) exposed approximately 133.7 MILLION guest records by Marriott's own admission (other sources cite up to 500 million total affected globally), including ~5.25 million UNENCRYPTED passport numbers and 20.3 million encrypted passport numbers — the breach reportedly went undiscovered for more than 4 YEARS after it began. A second, separate breach hit another 5.2 million guests in 2020. Marriott paid $52 MILLION to settle US state-level litigation (with 20 years of mandatory third-party cybersecurity monitoring) and separately paid a $24 MILLION fine to UK data protection authorities under GDPR for the same 2018 breach. A federal judge (Maryland, 2025) granted class certification for a subset of ~45 million affected consumers in CA/CT/FL/GA/MD/NY, allowing that litigation to proceed. SEPARATELY, Marriott faces active resort-fee class actions (advertised one price, charged another) and an Illinois BIPA lawsuit over fingerprint-based EMPLOYEE timekeeping systems.", "Arbitration / Class Action Waiver": "Class-action lawyers specifically 'questioned an arbitration clause in Marriott's free internet monitoring program' offered to breach-affected customers — i.e., the very remediation program Marriott offered to breach victims may itself have contained an arbitration clause limiting those victims' ability to sue over the breach that prompted the offer in the first place. A federal appeals court (Aug 2023) specifically VACATED an earlier class-certification win and sent the case back for further consideration of a class-action waiver signed by hotel guests — showing arbitration/waiver clauses remain a live, unresolved battleground in this specific litigation years after the breach.", "Fees / Billing Flags": "Separate active resort-fee class actions allege Marriott advertised one room price and charged a different, higher price once mandatory resort fees were added.", "Notes": "This is one of the largest, most consequential, and most legally complex breaches found in this entire 185-company audit — spanning passport data, multiple countries' regulators, an 8-figure US settlement and a separate 8-figure UK fine, ongoing class certification fights, AND a potentially self-serving arbitration clause in the very monitoring program offered to victims.", "Industry (Fortune 500)": "Hotels, Casinos, Resorts", "Revenue (Fortune 500)": "$26.2B", "Market Cap": "$97.1B", "Employees": "155,000", "HQ City": "Bethesda", "HQ State": "Maryland", "CEO": "Anthony Capuano", "Ticker": "MAR", "Website (Corporate)": "marriott.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation + Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-06", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded | Corrected 2026-08-06 (dollar-figure/date precision, sources re-verified via web search)", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (MAR). Service route: c/o General Counsel / Corporate Secretary, Bethesda, Maryland — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": "https://www.ftc.gov/legal-library/browse/cases-proceedings/192-3022-marriott-international-inc-starwood-hotels-resorts-worldwide-llc-matter", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Maryland' is DC/MD/VA", "Parent / Ultimate Owner": "Marriott International, Inc.", "Years Referenced in Finding (heuristic)": "2018, 2020", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Maryland SDAT Business Entity Search — egov.maryland.gov/businessexpress/entitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Marriott International, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2018 Starwood breach exposed ~133.7M guest records including 5.25M unencrypted passport numbers\nWHAT THE TERMS SAY: The tracker states the 2018 Starwood breach, discovered after Marriott's acquisition, exposed approximately 133.7 million guest records including ~5.25 million unencrypted and 20.3 million encrypted passport numbers, and reportedly went undiscovered for more than 4 years; a second breach in 2020 hit another 5.2 million guests.\nWHY IT MATTERS: Unencrypted passport numbers and years-long undetected exposure put millions of guests' most sensitive identity documents at risk with no timely warning.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-2] Marriott paid $52M to US states and a separate $24M UK GDPR fine over the same 2018 breach\nWHAT THE TERMS SAY: The tracker states Marriott paid $52 million to settle US state-level litigation (with 20 years of mandatory third-party cybersecurity monitoring) and separately paid a $24 million fine to UK data protection authorities under GDPR for the same breach; a federal judge in Maryland (2025) granted class certification for a subset of ~45 million affected consumers.\nWHY IT MATTERS: Two separate eight-figure penalties across two countries, plus ongoing class certification fights, show the breach's consequences are still unfolding years later for affected guests.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] The free monitoring program offered to breach victims may itself have contained an arbitration clause limiting their ability to sue\nWHAT THE TERMS SAY: Class-action lawyers questioned an arbitration clause in Marriott's free internet monitoring program offered to breach-affected customers; a federal appeals court in August 2023 vacated an earlier class-certification win and sent the case back for further consideration of a class-action waiver signed by hotel guests.\nWHY IT MATTERS: If confirmed, breach victims accepting free remediation may have unknowingly limited their own ability to pursue collective legal action over the same breach.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Settlements and fines are well documented, but the arbitration opt-out window and full scope of the self-serving arbitration clause remain unclear.", "Exposure Score (0-100)": 56, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 6/30 (biometric_collection+6) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 20/20 (severity5+20, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Marriott (Bonvoy)  <-  Marriott International, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Marriott (Bonvoy) you gave up your biometric identifiers, your right to sue, your right to join a class action, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "2026-09-08T19:31:44Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Marriott's combined litigation — the 2018 breach, a separate 2020 breach, resort-fee deception, and biometric employee timekeeping violations — has collectively touched OVER 500 MILLION PEOPLE WORLDWIDE. The FTC's related order — which carries no monetary penalty and requires Marriott to let US customers request deletion of data tied to their Bonvoy account — is a SEPARATE settlement from the $52 million Marriott paid; that money went to a 49-state-plus-DC Attorney General coalition (District of Columbia among them) over the same breaches, not to the FTC. Both the deletion right and the $52 million exist only because of these settlements, not because Marriott offered either voluntarily. Multiple federal courts have separately DISMISSED versions of the data-breach class actions for lack of legal 'standing,' illustrating how hard it can be for an individual guest to even get their case heard, regardless of how large the underlying breach was.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 131, "_entity_id": 205, "_entity_slug": "marriott-bonvoy", "_issuer": "Marriott International, Inc.", "_issuer_slug": "marriott-international-inc", "_ticker": "MAR", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Disney+ / Hulu (Disney)", "Category": "Streaming", "Terms & Conditions URL": "disneytermsofuse.com", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "disneyprivacycenter.com", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "$10 MILLION FTC/DOJ COPPA SETTLEMENT (finalized Dec 2025): Disney Worldwide Services and Disney Entertainment Operations were found to have mislabeled children-directed videos as NOT 'Made for Kids' (MFK) when uploading them to YOUTUBE — the mislabeling let YouTube collect personal data from children under 13 who watched and use that data to target advertising to them. This is a distinct 'issue' from Disney's own Disney+ streaming platform: it arose from how Disney's CONTENT was labeled on a third-party platform (YouTube/Google), illustrating that even a well-resourced company with a long public commitment to child-safety compliance (as Disney stated in response) can still trigger federal enforcement through content-labeling practices on someone else's platform.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Disney's Subscriber Agreement covers Disney+, Hulu, ESPN+, and Star+. AAA rules. 30-day opt-out via written notice. Disney's $2.75M CA AG settlement (Feb 2026) for CCPA opt-out non-compliance + separate $10M FTC COPPA settlement (Dec 2025) both happened AFTER the arbitration clause was in effect.", "Fees / Billing Flags": "Disney is required going forward to review whether videos should be labeled MFK UNLESS YouTube implements its own age-assurance technology that can determine viewer age across all users — a forward-looking provision that ties Disney's compliance obligations to Google/YouTube's own future technology choices.", "Notes": "Cross-reference this with the YouTube/Google row above — the same underlying incident implicates both companies, but for different reasons (Disney for mislabeling, Google/YouTube for the platform's overall child-data practices already noted in the youth-addiction litigation).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Burbank", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.dataprotectionreport.com/2026/02/partial-compliance-is-noncompliance-lessons-from-californias-2-75-million-settlement-with-disney/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "The Walt Disney Company", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: The Walt Disney Company). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] $10M FTC/DOJ settlement: Disney mislabeled kids' content on YouTube, letting the platform collect children's data for ad targeting\nWHAT THE TERMS SAY: The tracker states Disney Worldwide Services and Disney Entertainment Operations were found to have mislabeled children-directed videos as not 'Made for Kids' when uploading them to YouTube, which let YouTube collect personal data from children under 13 who watched and use that data to target ads to them; the settlement was finalized Dec 2025 for $10 million.\nWHY IT MATTERS: Mislabeling allowed a third-party platform to collect and monetize young children's viewing data in violation of federal child-privacy law.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DARK_PATTERN_CONSENT · FL-2] California AG fined Disney $2.75M for ignoring customers' own data opt-out requests across Disney+, Hulu, and ESPN+\nWHAT THE TERMS SAY: The tracker states California's Attorney General secured a $2.75 million penalty against Disney in Feb 2026 specifically for failing to honor customers' own opt-out requests across Disney+, Hulu, and ESPN+.\nWHY IT MATTERS: Consumers who actively tried to stop their data from being shared were, per the settlement, ignored anyway, undermining the basic function of an opt-out right.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with a class-action waiver covers Disney+, Hulu, ESPN+ and Star+, with only a 30-day opt-out window\nWHAT THE TERMS SAY: Disney's Subscriber Agreement imposes mandatory binding arbitration with a class-action waiver under AAA rules, covering Disney+, Hulu, ESPN+, and Star+, with a 30-day opt-out via written notice.\nWHY IT MATTERS: Subscribers who don't act within 30 days give up their right to sue Disney collectively, including over the privacy violations described above.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=Y; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Multiple settlements are confirmed and dated, but some specifics, such as the Hulu price-hike claims, are only referenced, not detailed.", "Exposure Score (0-100)": 51, "Exposure Band": "High", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 8/30 (data_sold_or_shared_for_value+8) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 16/20 (severity4+14, litigation+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "App / Service", "Ownership Path": "Disney+ / Hulu (Disney)  <-  The Walt Disney Company", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Disney+ / Hulu (Disney) you gave up your personal data sold onward, your right to sue, your right to join a class action, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "2026-09-08T19:31:47Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "California's Attorney General secured a $2.75 MILLION penalty against Disney (Feb 2026) specifically for FAILING TO HONOR customers' own opt-out requests across Disney+, Hulu, and ESPN+ — meaning people who took the time to click 'stop sharing my data' were allegedly ignored anyway. Hulu separately faces active claims over how it timed price-hike notices and over what it discloses in its ad-supported tier's data sharing. This is the SAME corporate family whose theme parks separately face a facial-recognition lawsuit (see the Walt Disney row) — across streaming AND physical parks, Disney's consent mechanisms are under simultaneous legal challenge.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 132, "_entity_id": 207, "_entity_slug": "disney-hulu-disney", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Max (HBO Max, Warner Bros. Discovery)", "Category": "Streaming", "Terms & Conditions URL": "max.com/us/en/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "max.com/us/en/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same general VPPA/tracking-pixel litigation risk category as other streaming/video platforms in this tracker (see AMC Networks' settled VPPA pixel case, and BuzzFeed's mass-arbitration pixel claims, both documented elsewhere) — no Max/HBO Max-specific lawsuit independently confirmed this pass.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Warner Bros. Discovery's Terms of Use, AAA Consumer Arbitration Rules. 30-day opt-out via written notice. Covers Max, Discovery+, and all WBD streaming properties.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a dedicated follow-up given the broader streaming-industry VPPA pixel-litigation wave documented for other platforms in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Warner Bros. Discovery, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Warner Bros. Discovery, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration and a class-action waiver cover Max, Discovery+, and all WBD streaming properties, with a 30-day opt-out\nWHAT THE TERMS SAY: Warner Bros. Discovery's Terms of Use impose mandatory binding arbitration with a class-action waiver under AAA Consumer Arbitration Rules, covering Max, Discovery+, and all WBD streaming properties, with a 30-day opt-out via written notice.\nWHY IT MATTERS: Subscribers who miss the 30-day window lose the ability to bring or join a class action against WBD over disputes involving Max.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the arbitration clause is company-specific and confirmed for Max; the Data Sharing and SCARY fields describe an industry-wide VPPA tracking-pixel litigation wave affecting other streaming platforms, with no Max-specific case independently confirmed this pass.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly documented, but no Max-specific data-sharing or litigation claim was independently confirmed this pass.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Max (HBO Max, Warner Bros. Discovery)  <-  Warner Bros. Discovery, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Max (HBO Max, Warner Bros. Discovery) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:31:48Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Max sits inside the same broader video-privacy litigation wave (Video Privacy Protection Act tracking-pixel cases) already confirmed against other streaming and video-content sites throughout this tracker — no Max-specific case was independently confirmed, but the underlying tracking technology is common across the whole streaming industry.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 133, "_entity_id": 209, "_entity_slug": "max-hbo-max-warner-bros-discovery", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Apple Music", "Category": "Streaming (music)", "Terms & Conditions URL": "apple.com/legal/internet-services/itunes/us/terms.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "apple.com/legal/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or FTC action for Apple Music specifically; Apple's overall privacy positioning is generally regarded as more restrictive toward third-party data sharing than many other companies in this tracker, though this was not independently verified against a primary source this pass.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Apple's Media Services Terms (covering App Store, Apple Music, Apple TV, Apple Books, Podcasts, Arcade, Fitness+, last updated Sept 15 2025) contain no arbitration clause and no class action waiver. Disputes governed by California law, Santa Clara County courts. Apple is the ONLY major consumer tech company in this tracker with no mandatory arbitration. iCloud has separate terms also lacking an arbitration clause.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Queued for a dedicated follow-up; thin verification this session.", "Industry (Fortune 500)": "Computers, Office Equipment", "Revenue (Fortune 500)": "$416.2B", "Market Cap": "$4.8T", "Employees": "164,000", "HQ City": "Cupertino", "HQ State": "California", "CEO": "Tim Cook", "Ticker": "AAPL", "Website (Corporate)": "apple.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AAPL). Service route: c/o General Counsel / Corporate Secretary, Cupertino, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Apple Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Apple Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — No specific troubling practice is confirmed for Apple Music this pass; data-sharing exposure is explicitly unverified, and Apple's Media Services Terms notably lack any mandatory arbitration clause or class-action waiver, which is a positive rather than a troubling finding.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The absence of an arbitration clause is clearly documented, but data-sharing practices and any litigation remain unconfirmed this pass.", "Exposure Score (0-100)": 8, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "App / Service", "Ownership Path": "Apple Music  <-  Apple Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Apple Music takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:31:50Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Apple's overall privacy stance is generally stronger than most companies in this tracker, but no specific Apple Music consumer lawsuit was independently confirmed this pass — worth a direct follow-up specifically on what listening-history data is shared with music labels/rights-holders for royalty and analytics purposes.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 134, "_entity_id": 211, "_entity_slug": "apple-music", "_issuer": "Apple Inc.", "_issuer_slug": "apple-inc", "_ticker": "AAPL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Amazon Prime Video", "Category": "Streaming", "Terms & Conditions URL": "See Amazon's Conditions of Use (amazon.com/gp/help/customer/display.html?nodeId=508088)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "See Amazon's Privacy Notice (amazon.com/privacy)", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Governed by the same overall Amazon account/Conditions of Use framework documented in the Amazon row at the top of this tracker — MOST DIRECTLY RELEVANT: the $2.5 BILLION FTC Amazon Prime settlement (documented in that row) covers the Prime MEMBERSHIP sign-up/cancellation practices that Prime Video is bundled under, meaning this is likely the single most relevant finding for Prime Video specifically, even though it's filed under Amazon's general Prime program rather than Prime Video as a standalone service.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — governed by Amazon's Conditions of Use, which removed arbitration in July 2021.", "Fees / Billing Flags": "See the $2.5B Amazon Prime settlement in the Amazon row.", "Notes": "Treat as part of Amazon's overall Prime-membership profile rather than a fully standalone entity for purposes of this audit.", "Industry (Fortune 500)": "Internet Services and Retailing", "Revenue (Fortune 500)": "$716.9B", "Market Cap": "$2.6T", "Employees": "1,556,000", "HQ City": "Seattle", "HQ State": "Washington", "CEO": "Andrew R. Jassy", "Ticker": "AMZN", "Website (Corporate)": "amazon.com", "Main Mailing Address (legal/privacy notices)": "Amazon.com, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210, USA", "Legal / Privacy Contact Email": "Not verified this pass — Amazon routes privacy requests through its in-account privacy portal", "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-06", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded | Corrected 2026-08-06 (dollar-figure/date precision, sources re-verified via web search)", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AMZN). Service route: c/o General Counsel / Corporate Secretary, Seattle, Washington — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.ftc.gov/legal-library/browse/cases-proceedings/2123050-amazoncom-inc-rosca-ftc-v", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Amazon.com, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Amazon.com, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-4] Prime Video is bundled under the $2.5B FTC settlement over deceptive Prime sign-up and cancellation practices\nWHAT THE TERMS SAY: The tracker states Prime Video is bundled under the same Amazon Prime membership for which the FTC secured a $2.5 billion settlement ($1 billion civil penalty plus $1.5 billion in consumer redress) over dark-pattern sign-up and cancellation practices.\nWHY IT MATTERS: Consumers subscribing to watch Prime Video are enrolled through the exact subscription structure regulators found used deceptive tactics to sign people up and make cancellation difficult.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the bundled Prime dark-pattern settlement is a company-specific, confirmed finding for Prime Video; Amazon's Conditions of Use notably contain no mandatory arbitration (a positive, not a troubling finding), and no separate Prime Video-specific privacy issue is stated.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The finding is confirmed but filed under Amazon's general Prime program rather than a Prime Video-specific disclosure.", "Exposure Score (0-100)": 23, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 20/20 (severity5+20) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "App / Service", "Ownership Path": "Amazon Prime Video  <-  Amazon.com, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Amazon Prime Video you gave up your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "2026-09-08T19:32:22Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Prime Video is bundled under the same Amazon Prime membership the FTC secured a $2.5 BILLION settlement over ($1 billion civil penalty plus $1.5 billion in consumer redress, per the stipulated order) for dark-pattern sign-up and cancellation practices (documented elsewhere in this tracker) — meaning the video service you actually watch is wrapped inside the exact subscription structure regulators found deceptive.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 135, "_entity_id": 213, "_entity_slug": "amazon-prime-video", "_issuer": "Amazon.com, Inc.", "_issuer_slug": "amazon-com-inc", "_ticker": "AMZN", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Peacock (NBCUniversal/Comcast)", "Category": "Streaming", "Terms & Conditions URL": "peacocktv.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "peacocktv.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Owned by Comcast/NBCUniversal — relevant to note Comcast's own Xfinity brands are documented elsewhere in this tracker (Carriers and Internet Providers tabs) for a separate $117.5 MILLION data-breach settlement (referenced in the Zoom row's comparison context) — not independently confirmed whether that breach specifically touched Peacock account data, though shared corporate infrastructure makes it worth a direct follow-up check.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Comcast's subscriber agreements govern Peacock alongside Xfinity broadband. The Oct 2023 CitrixBleed breach (31-36M customers, $117.5M preliminary settlement Jan 2026) means the arbitration clause directly affects breach victims' ability to pursue collective relief. Comcast's arbitration clause is one of the most litigated in consumer law — the Supreme Court's AT&T v. Concepcion (2011) and Comcast's own Italian Colors decision both shaped the enforceability of class waivers industry-wide.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Cross-reference with Comcast/Xfinity's $117.5M breach settlement (Carriers/ISP tabs) to confirm whether Peacock account data was included in that incident's scope.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.masonllp.com/blog/hasson-v-comcast-cable-communications/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Comcast Corporation", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Comcast Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration under Comcast's subscriber agreement limits Peacock users tied to the $117.5M CitrixBleed breach relief\nWHAT THE TERMS SAY: Comcast's subscriber agreements, which govern Peacock alongside Xfinity broadband, impose mandatory binding arbitration with a class-action waiver; the tracker notes the Oct 2023 CitrixBleed breach (31-36 million customers, $117.5 million preliminary settlement Jan 2026) means this clause directly affects breach victims' ability to pursue collective relief.\nWHY IT MATTERS: Peacock subscribers bound by the same Comcast arbitration clause as breach victims may be limited in how they can seek redress collectively.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] Peacock's parent Comcast paid $117.5M over a breach affecting 35.8M Xfinity customers; unconfirmed whether Peacock accounts were included\nWHAT THE TERMS SAY: The tracker states Comcast paid $117.5 million to settle a 2023 data breach (CitrixBleed) affecting 35.8 million Xfinity customers, but explicitly notes it is not confirmed whether Peacock accounts specifically were included in that incident's scope.\nWHY IT MATTERS: Given shared corporate infrastructure between Comcast/Xfinity and Peacock, the breach's reach into Peacock account data remains an open, unresolved question.\n(evidence: Data Sharing | SCARY | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only arbitration terms and the unconfirmed breach-overlap question are documented; no separate Peacock-specific fee or data-sharing practice is stated this pass.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clear, but whether the CitrixBleed breach touched Peacock accounts specifically remains unconfirmed.", "Exposure Score (0-100)": 44, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Peacock (NBCUniversal/Comcast)  <-  Comcast Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Peacock (NBCUniversal/Comcast) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:32:26Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Peacock's parent Comcast separately paid $117.5 MILLION to settle a 2023 data breach affecting 35.8 million Xfinity customers — not confirmed whether Peacock accounts specifically were caught up in that breach, but the shared corporate infrastructure makes it worth checking directly.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 136, "_entity_id": 214, "_entity_slug": "peacock-nbcuniversal-comcast", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Paramount+", "Category": "Streaming", "Terms & Conditions URL": "paramountplus.com/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "paramountplus.com/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same general VPPA/tracking-pixel litigation risk category as other streaming platforms in this tracker; a separate ClassAction.org note found earlier in this research mentions 'Paramount seeks dismissal of data-sharing class action' as an active, ongoing matter, though specific case details were not independently confirmed this pass.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Paramount Global's ToS, AAA rules. 30-day opt-out via mail to Paramount Global, Attn: Legal Department, 1515 Broadway, New York NY 10036. Covers Paramount+, Pluto TV, and Showtime.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up on the specific data-sharing class action referenced above.", "Industry (Fortune 500)": "Entertainment", "Revenue (Fortune 500)": "$29.2B", "Market Cap": "$9.8B", "Employees": "20,350", "HQ City": "New York", "HQ State": "New York", "CEO": "David Ellison", "Ticker": "PSKY", "Website (Corporate)": "paramount.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (PSKY). Service route: c/o General Counsel / Corporate Secretary, New York, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Paramount Global", "Years Referenced in Finding (heuristic)": "2024, 2025, 1988", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Paramount Global). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Cho v. Paramount Global alleges Paramount+ shared users' watched video titles with Meta and TikTok via tracking pixels\nWHAT THE TERMS SAY: The tracker states Cho v. Paramount Global (SDNY, Nov 2024) alleges Paramount+ embedded Meta and TikTok pixels that transmitted the titles of videos watched alongside unique user identifiers, with VPPA statutory damages of up to $2,500 per person; Paramount moved to dismiss on the ground that the plaintiff consented to the disclosures.\nWHY IT MATTERS: If proven, viewers' specific watch history was sent to ad platforms without adequate disclosure, exposing potentially sensitive viewing habits and, per the statute, large per-person liability across a class.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with a class-action waiver covers Paramount+, Pluto TV, and Showtime, with a 30-day mail-in opt-out\nWHAT THE TERMS SAY: Paramount Global's Terms of Service impose mandatory binding arbitration with a class-action waiver under AAA rules, covering Paramount+, Pluto TV, and Showtime, with a 30-day opt-out via mail to Paramount's Legal Department.\nWHY IT MATTERS: Subscribers who don't mail an opt-out within 30 days waive their right to sue Paramount collectively, including over the pixel-sharing allegations above.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only the Cho v. Paramount Global pixel-sharing allegation and the arbitration clause are distinct, company-specific findings; the additional ClassAction.org reference appears to describe the same or related underlying dispute rather than a third distinct harm.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Cho litigation and arbitration terms are well documented, but the separate ClassAction.org data-sharing note lacks independently confirmed case details.", "Exposure Score (0-100)": 41, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Paramount+  <-  Paramount Global", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Paramount+ you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Paramount is the clearest illustration in this tracker that identical conduct produces opposite legal outcomes depending on which court hears it. Cho v. Paramount Global, filed in the Southern District of New York in November 2024, alleges Paramount+ embedded Meta and TikTok pixels that transmitted the titles of videos watched alongside unique user identifiers — with VPPA statutory damages of up to $2,500 per person. Paramount moved to dismiss on the ground that the plaintiff consented to the exact disclosures he complains of. Meanwhile in Salazar v. Paramount Global the Sixth Circuit AFFIRMED dismissal of a materially similar claim in April 2025, while the Second Circuit had gone the other way weeks earlier in the NBA case — a live circuit split over who even counts as a 'consumer' under a 1988 statute written for video rental stores. Same company, same conduct, different federal circuits, opposite results.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 137, "_entity_id": 216, "_entity_slug": "paramount", "_issuer": "Paramount Global", "_issuer_slug": "paramount-global", "_ticker": "PSKY", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google / Alphabet", "Category": "Productivity/Utility (search, email, cloud, Android, ads)", "Terms & Conditions URL": "policies.google.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "LIKELY THE LARGEST TOTAL LEGAL/REGULATORY EXPOSURE OF ANY COMPANY IN THIS ENTIRE 185-COMPANY AUDIT: (1) $1.375 BILLION settlement with Texas (2025) — the largest privacy settlement ever obtained by a single US state against a tech company; (2) €2.95 BILLION EU antitrust fine (2025) for distorting competition in ad-tech; (3) a 2024 settlement requiring Google to DESTROY BILLIONS of data records after being sued for secretly tracking users who believed they were browsing privately in Chrome's Incognito mode, plus letting Incognito users block third-party cookies for 5 years; (4) a March 2026 court-approved settlement (In re: Google RTB Consumer Privacy Litigation) resolving claims that Google shared personal data with hundreds of third parties through Real-Time Bidding ad auctions BILLIONS OF TIMES A DAY despite explicitly telling users 'Google does not sell your personal information to anyone' — plaintiffs' counsel described this RTB practice as potentially 'the biggest data breach the world has ever seen'; (5) a separate 2025 $350 million settlement (unrelated matter, details not captured this pass); (6) 2 completed federal DOJ antitrust wins finding Google illegally maintained monopolies in BOTH general search AND digital advertising — both currently under appeal as of mid-2026, with the DOJ and state AGs separately appealing that the search-case remedies (which stopped short of ordering a Chrome divestiture) didn't go far enough.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass for Google's own consumer Terms of Service — standard binding arbitration + class action waiver expected industry-wide, though note many of the above cases proceeded as class actions/government suits rather than individual arbitration, suggesting either opt-outs, government-suit exceptions (governments generally aren't bound by consumer arbitration clauses), or claims that predate/exceed the scope of Google's arbitration terms.", "Fees / Billing Flags": "Google Ads customers (2016-2023) and Google Play Store purchasers (2016-2024) are separately eligible for over $2.3 BILLION in additional 2026 settlement funds across an antitrust/app-store-fee case wave distinct from the privacy cases above.", "Notes": "Given the sheer scale (multiple billion-dollar-plus settlements/fines across privacy, antitrust, and ad-tech in the last 2 years alone), Google/Alphabet likely deserves the single most extensive dedicated deep-dive of any company in this entire tracker if your audit is prioritizing companies by total regulatory/legal exposure rather than by category.", "Industry (Fortune 500)": "Internet Services and Retailing", "Revenue (Fortune 500)": "$402.8B", "Market Cap": "$4.2T", "Employees": "183,323", "HQ City": "Mountain View", "HQ State": "California", "CEO": "Sundar Pichai", "Ticker": "GOOGL", "Website (Corporate)": "abc.xyz", "Main Mailing Address (legal/privacy notices)": "Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (GOOGL). Service route: c/o General Counsel / Corporate Secretary, Mountain View, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alphabet Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] Google's $1.375B Texas settlement (2025) is the largest US state privacy settlement against a tech company\nWHAT THE TERMS SAY: The tracker states Google reached a $1.375 billion settlement with Texas in 2025, described as the largest privacy settlement ever obtained by a single US state against a tech company.\nWHY IT MATTERS: The tracker calls it the largest privacy settlement ever obtained by a single US state against a tech company, one of multiple billion-dollar-plus settlements and fines recorded for Google across privacy, antitrust, and ad-tech in the last two years.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[DATA_SALE · FL-2] RTB litigation alleges Google shared personal data with hundreds of third parties billions of times a day despite saying it 'does not sell' data\nWHAT THE TERMS SAY: The tracker states a March 2026 court-approved settlement (In re: Google RTB Consumer Privacy Litigation) resolved claims that Google shared personal data with hundreds of third parties through Real-Time Bidding ad auctions billions of times a day despite telling users 'Google does not sell your personal information to anyone'; plaintiffs' counsel described the practice as potentially 'the biggest data breach the world has ever seen.'\nWHY IT MATTERS: If the allegations reflect actual practice, users' data was broadcast to hundreds of parties at massive scale while Google's own public statement said otherwise.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DARK_PATTERN_CONSENT · FL-2] A 2025 lawsuit alleges Chrome fingerprints children in a way that persists even after schools disable cookies or anti-tracking tools\nWHAT THE TERMS SAY: The tracker states a 2025 lawsuit alleges Google's Chrome browser secretly builds a unique fingerprint of children that keeps working even after a school administrator disables cookies or turns on anti-tracking tools, allegedly feeding Google's ad products and being sold onward to other education-technology companies.\nWHY IT MATTERS: If proven, the tracking would defeat the specific privacy controls schools use to protect children, and monetize that tracking through sale to other companies.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Multiple major settlements and lawsuits are well documented, but Google's own consumer arbitration terms and opt-out details are not independently confirmed this pass.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Google / Alphabet  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Google / Alphabet you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:32:31Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "A 2025 lawsuit alleges Google's Chrome browser secretly builds a unique 'fingerprint' of CHILDREN specifically, one that keeps working even after a school administrator disables cookies or turns on anti-tracking tools — with that fingerprint allegedly feeding Google's own ad products and getting sold onward to other education-technology companies. Separately, and far more serious: in March 2026, a Florida father filed the first wrongful-death lawsuit involving Google's Gemini AI chatbot, alleging prolonged conversations with the chatbot contributed to his adult son's death by suicide following a mental health crisis — the case remains in early litigation and the allegations are unproven, but it sits alongside a separate 2025 suit (Robby Starbuck) alleging Gemini generated and spread false, seriously damaging claims about a real person to millions of users. Given the sensitivity of these specific matters, this entry deliberately stays at the level of the documented legal filings rather than describing the alleged content itself. All of this comes as Google pours unprecedented capital into AI development, which shareholder advocates argue is FAR outpacing any corresponding growth in privacy safeguards.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 138, "_entity_id": 217, "_entity_slug": "google-alphabet", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Microsoft (Outlook/365)", "Category": "Productivity/Utility", "Terms & Conditions URL": "microsoft.com/en-us/servicesagreement/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "privacy.microsoft.com/en-us/privacystatement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Active class action (Russo v. Microsoft Corp., N.D. Cal.) alleges Microsoft 365/Exchange BUSINESS customers' contacts and data are shared with Facebook and other third parties WITHOUT CONSENT, despite Microsoft marketing these products as 'secure and private' — the complaint further alleges Microsoft shares customer emails, documents, and calendars with 'unauthorized third parties for unauthorized purposes' and uses customer data to develop its own products, allegedly violating the Wiretap Act and Stored Communications Act. This is a BUSINESS/PROFESSIONAL customer issue (relevant to BMHC's own Microsoft 365 usage, if any) rather than a purely consumer-facing one.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Microsoft Services Agreement, same clause as Xbox. 30-day opt-out via mail to One Microsoft Way, Redmond WA 98052 or email optout@microsoft.com. Covers Outlook.com, Microsoft 365, OneDrive, Teams, Bing, Copilot, and all Microsoft consumer services.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "SEPARATE, UNRELATED 2026 DEVELOPMENT: Slack/Salesforce filed an ANTITRUST lawsuit against Microsoft in a UK court (April 2026) alleging illegal tying/bundling of Microsoft Teams with Office — Microsoft is a DEFENDANT in a business-to-business competition dispute here, not a customer-privacy issue, but relevant corporate-conduct context if useful.", "Industry (Fortune 500)": "Computer Software", "Revenue (Fortune 500)": "$281.7B", "Market Cap": "$2.9T", "Employees": "228,000", "HQ City": "Redmond", "HQ State": "Washington", "CEO": "Satya Nadella", "Ticker": "MSFT", "Website (Corporate)": "microsoft.com", "Main Mailing Address (legal/privacy notices)": "Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA", "Legal / Privacy Contact Email": "No published privacy email; Microsoft routes requests via microsoft.com/concern/privacy (30-day response commitment)", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (MSFT). Service route: c/o General Counsel / Corporate Secretary, Redmond, Washington — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Microsoft Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Microsoft Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Russo v. Microsoft alleges 365/Exchange business customers' data went to Facebook and other third parties\nWHAT THE TERMS SAY: The tracker states Russo v. Microsoft Corp. (N.D. Cal.) alleges Microsoft 365/Exchange business customers' contacts and data are shared with Facebook and other third parties without consent, and that Microsoft shares customer emails, documents, and calendars with 'unauthorized third parties for unauthorized purposes' and uses customer data to develop its own products, allegedly violating the Wiretap Act and Stored Communications Act.\nWHY IT MATTERS: If proven, businesses paying for a security-branded product had confidential communications shared with outside parties and repurposed to build Microsoft's own offerings.\n(evidence: Data Sharing | SCARY; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with a class-action waiver covers Outlook.com, 365, OneDrive, Teams, Bing, and Copilot, with a 30-day opt-out\nWHAT THE TERMS SAY: The Microsoft Services Agreement imposes mandatory binding arbitration with a class-action waiver, the same clause used for Xbox, covering Outlook.com, Microsoft 365, OneDrive, Teams, Bing, Copilot, and all Microsoft consumer services, with a 30-day opt-out via mail or email.\nWHY IT MATTERS: Users across nearly all Microsoft consumer products, including those implicated in the Russo allegations, must opt out within 30 days or lose the right to sue collectively.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only the Russo data-sharing allegation and the arbitration clause are documented; the row itself notes the Russo case is a business/professional-customer issue rather than purely consumer-facing, and the Slack/Salesforce UK antitrust suit against Microsoft is unrelated business-conduct context, not a consumer-privacy finding.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause is clearly stated, but the Russo data-sharing allegations remain an active, unconfirmed lawsuit primarily concerning business customers.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Microsoft (Outlook/365)  <-  Microsoft Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Microsoft (Outlook/365) you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "2026-09-08T19:32:32Z (HTTP 200, CHANGED)", "SCARY (most astonishing T&C item)": "A business-customer lawsuit alleges Microsoft shares Exchange/365 customers' emails, documents, and calendars with 'unauthorized third parties for unauthorized purposes' and uses that data to develop Microsoft's OWN products — while marketing 365 as 'secure and private.' If proven, this means businesses paying for a premium, security-branded product may have had their confidential internal communications quietly repurposed to improve the same company's other commercial offerings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 139, "_entity_id": 218, "_entity_slug": "microsoft-outlook-365", "_issuer": "Microsoft Corporation", "_issuer_slug": "microsoft-corporation", "_ticker": "MSFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Dropbox", "Category": "Productivity/Utility (cloud storage)", "Terms & Conditions URL": "dropbox.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "dropbox.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Named in a proposed class action alleging failure to properly safeguard user personal data that was exposed in a breach (specific incident details/date not independently confirmed this pass — recommend direct follow-up on the specific breach referenced).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. AAA rules, California law. 30-day opt-out via email to arbitration-opt-out@dropbox.com. Covers Dropbox, HelloSign, DocSend, and all Dropbox products.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up pass to confirm the specific breach details and current litigation status given the thin detail captured here.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Proposed class action alleges Dropbox failed to protect user data that was later exposed in a breach\nWHAT THE TERMS SAY: The tracker states Dropbox is named in a proposed class action alleging failure to properly safeguard user personal data that was exposed in a breach; specific incident details and date are not independently confirmed this pass.\nWHY IT MATTERS: Because users store highly sensitive files like tax documents, medical records, and photos on Dropbox, any confirmed breach would carry outsized personal risk.\n(evidence: Data Sharing | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with a class-action waiver covers Dropbox, HelloSign, and DocSend, with a 30-day email opt-out\nWHAT THE TERMS SAY: Dropbox's terms impose mandatory binding arbitration with a class-action waiver under AAA rules and California law, covering Dropbox, HelloSign, DocSend, and all Dropbox products, with a 30-day opt-out via email to arbitration-opt-out@dropbox.com.\nWHY IT MATTERS: Users affected by the alleged breach above would need to opt out within 30 days to preserve their right to pursue collective legal action.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Breach details are thin and explicitly unconfirmed per the tracker's own notes; only the allegation itself and the arbitration clause are documented, with a recommended follow-up to confirm specifics.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The breach itself is only alleged in a proposed class action with no confirmed date or scope; the tracker recommends direct follow-up.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Dropbox  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Dropbox you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:32:35Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "A proposed class action alleges Dropbox failed to properly protect user data that was later exposed in a breach — for a service millions use specifically to STORE their most sensitive personal files (tax documents, medical records, photos), any breach carries outsized risk simply because of what people choose to keep there.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 140, "_entity_id": 219, "_entity_slug": "dropbox", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Slack (Salesforce)", "Category": "Productivity/Utility", "Terms & Conditions URL": "slack.com/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "slack.com/trust/privacy/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a Slack-specific consumer privacy finding.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Salesforce's Master Subscription Agreement governs Slack since the $27.7B acquisition (2021). 30-day opt-out. Given the Salesloft Drift OAuth breach (Aug 2025, 700+ organizations affected via stolen tokens), the arbitration clause directly affects enterprise and individual users whose data was compromised through Salesforce's integration ecosystem.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "NOTABLE 2026 DEVELOPMENT: Slack and parent company Salesforce filed an ANTITRUST lawsuit AGAINST Microsoft in a UK court (April 2026), accusing Microsoft of illegally tying/bundling Teams with Office to disadvantage Slack — Slack here is a PLAINTIFF in a competitor dispute, not a defendant in a customer-privacy matter; also worth noting Bumble's Jan 2026 corporate breach (documented in the Bumble row) occurred via compromise of Bumble's internal Slack workspace — illustrating that Slack itself can become an attack vector into OTHER companies' systems even when Slack's own infrastructure isn't directly breached.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Salesforce, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Salesforce, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Aug 2025 Salesloft Drift OAuth breach hit 700+ organizations via tokens stolen in Salesforce's ecosystem\nWHAT THE TERMS SAY: The tracker states the Salesloft Drift OAuth breach (Aug 2025) affected 700+ organizations via stolen tokens within Salesforce's integration ecosystem, and that Slack's arbitration clause directly affects enterprise and individual users whose data was compromised through that ecosystem.\nWHY IT MATTERS: The tracker states no Slack-specific privacy finding was independently confirmed this pass, but notes Slack's Salesforce-governed arbitration clause would directly apply to any enterprise or individual users whose data was compromised through Salesforce's integration ecosystem via the Aug 2025 Salesloft Drift OAuth breach (700+ organizations affected), limiting their ability to pursue collective claims.\n(evidence: Arbitration; Stated in tracker (fidelity pass 1: Overstated corrected) (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with a class-action waiver has governed Slack since Salesforce's $27.7B acquisition, with a 30-day opt-out\nWHAT THE TERMS SAY: Salesforce's Master Subscription Agreement, which has governed Slack since the $27.7 billion acquisition in 2021, imposes mandatory binding arbitration with a class-action waiver, with a 30-day opt-out.\nWHY IT MATTERS: Slack users must opt out within 30 days or give up the right to pursue collective claims, including those tied to the Salesloft Drift breach above.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No Slack-specific consumer privacy finding is independently confirmed this pass; the Bumble breach that used a compromised Slack workspace as an entry point is documented as a finding about Bumble, not Slack, per the tracker's own framing, and the Microsoft antitrust suit is an unrelated competition matter.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and the Salesloft Drift ecosystem breach are documented, but no Slack-specific consumer privacy claim is confirmed this pass.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Slack (Salesforce)  <-  Salesforce, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Slack (Salesforce) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:32:37Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Slack and its parent Salesforce filed a lawsuit against Microsoft in a LONDON court (April 2026), accusing it of illegally bundling Teams with Office to squeeze out competition — the same underlying conduct that got Microsoft investigated for antitrust violations decades earlier with Internet Explorer. Meanwhile, Slack's own infrastructure has been the ENTRY POINT for at least one other major breach documented in this tracker (Bumble's Jan 2026 corporate breach happened via a compromised internal Slack workspace) — the workplace chat tool millions of employees use daily can become the way into an entirely different company's systems.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 141, "_entity_id": 221, "_entity_slug": "slack-salesforce", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Zoom", "Category": "Productivity/Utility (video conferencing)", "Terms & Conditions URL": "zoom.com/en/trust/terms/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "zoom.com/en/trust/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "COMPLETED FTC SETTLEMENT (still governing precedent): the FTC found Zoom marketed its platform as providing 'end-to-end encryption' for meeting content when, in practice, Zoom used only TRANSPORT LAYER encryption — meaning Zoom's own SERVERS could access unencrypted meeting data, directly contradicting its own marketing (the same 'claimed encryption doesn't match reality' pattern already documented for WhatsApp/Meta elsewhere in this tracker). Separately, the FTC found Zoom installed a PERSISTENT LOCAL WEB SERVER on Mac devices (to let users skip a browser security prompt when joining meetings) that REMAINED ACTIVE even after Zoom itself was uninstalled — a mechanism the FTC concluded circumvented user consent and introduced unnecessary, ongoing security risk on customers' own devices.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. AAA rules. Terms govern all Zoom products including Zoom Workplace, Zoom Phone, Zoom Rooms. FTC required a comprehensive security program (2020 order, no monetary penalty) after false 'end-to-end 256-bit encryption' claims. Opt-out mechanism exists but specific window not confirmed from the text retrieved this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The persistent background web server surviving uninstallation is a genuinely alarming, concrete finding — worth flagging distinctly from the more common 'marketing overstated encryption' pattern seen elsewhere, since this is a case of software behaving in a way the user couldn't detect or remove through normal means.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Jose", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.ftc.gov/news-events/news/press-releases/2020/11/ftc-requires-zoom-enhance-its-security-practices-part-settlement", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Zoom Communications, Inc. (fmr. Zoom Video Communications)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Zoom Communications, Inc. (fmr. Zoom Video Communications)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] FTC found Zoom's fake 'end-to-end encryption' claim hid that its servers could access meetings, and a hidden web server survived uninstalling\nWHAT THE TERMS SAY: The tracker states the FTC found Zoom marketed 'end-to-end encryption' for meetings when it actually used only transport-layer encryption, meaning Zoom's own servers could access unencrypted meeting data; separately, the FTC found Zoom installed a persistent local web server on Mac devices, to let users skip a browser security prompt, that remained active even after Zoom itself was uninstalled, which the FTC concluded circumvented user consent.\nWHY IT MATTERS: Users believed their meetings were end-to-end encrypted when Zoom could access the content, and a hidden server persisted on their computers even after they removed the app, creating an ongoing security risk they couldn't detect or remove through normal means.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Zoom paid $85M to settle claims it secretly shared user data with Facebook, Google, and LinkedIn\nWHAT THE TERMS SAY: The tracker states Zoom paid $85 million to settle claims it secretly shared users' personal data with Facebook, Google, and LinkedIn; paying customers received 15% of what they spent (or $25, whichever was more), while free users received just $15.\nWHY IT MATTERS: Free users, who never paid Zoom, received the smallest compensation despite having their data shared without their knowledge.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration covers all Zoom products, with an opt-out mechanism whose window is not confirmed\nWHAT THE TERMS SAY: Zoom's terms impose mandatory binding arbitration with a class-action waiver under AAA rules, governing Zoom Workplace, Zoom Phone, and Zoom Rooms; an opt-out mechanism exists but the specific window was not confirmed from the text retrieved this pass.\nWHY IT MATTERS: Users seeking to sue Zoom collectively over the encryption or data-sharing issues above must navigate an opt-out process whose deadline isn't clearly documented.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The FTC findings and $85M settlement are clearly documented, but the arbitration opt-out window is not confirmed.", "Exposure Score (0-100)": 41, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 23, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 23/30 (forced_arbitration+12, class_action_waiver+9, optout_window_unverified+2) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Zoom  <-  Zoom Communications, Inc. (fmr. Zoom Video Communications)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Zoom you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:32:41Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Zoom already paid $85 MILLION to settle claims it secretly shared users' personal data with Facebook, Google, and LinkedIn — on TOP of the separate FTC finding (documented elsewhere in this tracker) that Zoom marketed 'end-to-end encryption' it didn't actually have, and installed a hidden local web server on Mac computers that survived even after Zoom itself was uninstalled. Paying customers got back 15% of what they'd spent (or $25, whichever was more); free users got just $15 — meaning the people who never paid Zoom a dime got the smallest compensation for having their data shared anyway.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 142, "_entity_id": 223, "_entity_slug": "zoom", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google Maps", "Category": "Productivity/Utility (navigation)", "Terms & Conditions URL": "See Google's overall Terms of Service (policies.google.com/terms)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "See Google's overall Privacy Policy (policies.google.com/privacy)", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Governed by the same overall Google privacy framework and litigation exposure documented in the Google row at the top of this tab (the $1.375B Texas settlement, RTB 'biggest data breach' case, Incognito-tracking settlement, and $425M Firebase-tracking judgment) — no separate, Maps-specific legal action independently confirmed this pass, though location history/Timeline data specifically collected through Maps is a recurring subject of the broader Google location-tracking scrutiny noted in that row (e.g., the '2 billion users' location data collected despite privacy settings' finding).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration for Google Devices (Nest, Pixel, etc.) with 30-day opt-out from device activation. Google is ALSO currently defending against 69,507 individual arbitration demands in In re Google Assistant Privacy Litigation (N.D. Cal., Feb 2025 ruling) — the court REJECTED Google's attempt to block the mass opt-out.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Treat as part of Google's overall profile rather than a standalone entity.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-finalizes-historic-settlement-google-and-secures-1375-billion-big-tech", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alphabet Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Google's location-tracking scrutiny includes reports that 2 billion users' location data was collected despite privacy settings\nWHAT THE TERMS SAY: The tracker states Google Maps' location history/Timeline data is a recurring subject of broader Google location-tracking scrutiny, including a finding that location data was collected from 2 billion users despite privacy settings meant to prevent it.\nWHY IT MATTERS: Users who configured privacy settings believing they had turned off location tracking may have had their location collected anyway.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Google Maps location data sits inside the same $1.375B Texas settlement, RTB case, and $425M Firebase-tracking judgment as the rest of Google's ecosystem\nWHAT THE TERMS SAY: The tracker states Google Maps is governed by the same overall Google privacy framework as the $1.375 billion Texas settlement, the RTB litigation researchers called potentially 'the biggest data breach the world has ever seen,' and the $425 million Firebase-tracking judgment, meaning turn-by-turn location history is part of the same data ecosystem those cases concern.\nWHY IT MATTERS: Location data collected through everyday navigation use is implicated in the same large-scale privacy litigation and settlements affecting the rest of Google's products.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Google is defending 69,507 individual arbitration demands over Assistant privacy, after a court rejected its bid to block the mass opt-out\nWHAT THE TERMS SAY: The tracker states Google Devices (Nest, Pixel, etc.) carry mandatory arbitration with a 30-day opt-out from device activation, and that Google is currently defending against 69,507 individual arbitration demands in In re Google Assistant Privacy Litigation (N.D. Cal.), after a Feb 2025 ruling rejected Google's attempt to block the mass opt-out.\nWHY IT MATTERS: The sheer volume of individual arbitration demands shows how many users are pursuing privacy claims against Google's connected devices, which include hardware many use for Maps navigation.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Google's broader privacy settlements are well documented, but no separate, Maps-specific legal action was independently confirmed this pass.", "Exposure Score (0-100)": 54, "Exposure Band": "High", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 19, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 19/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Google Maps  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Google Maps you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, and your right to sue. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "2026-09-08T19:32:41Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Google Maps sits inside the SAME $1.375 billion Texas settlement, the RTB case researchers called potentially 'the biggest data breach the world has ever seen,' and the $425 million Firebase-tracking judgment documented for Google/Alphabet elsewhere in this tracker — your turn-by-turn location history is part of the exact same data ecosystem those cases are about.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 143, "_entity_id": 224, "_entity_slug": "google-maps", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fitbit (Google)", "Category": "Health/Fitness (wearable)", "Terms & Conditions URL": "fitbit.com/global/us/legal/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "fitbit.com/global/us/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "STRUCTURAL FLAG: HIPAA does NOT apply to Fitbit (or any consumer wearable maker) since HIPAA only covers hospitals, health plans, and their business associates — not consumer apps, even though wearables collect equivalent sensitive data (heart rate, sleep, location, reproductive-health-adjacent metrics). A Duke University study found 79% of popular health/fitness apps share data with third parties. Fitbit specifically was named in a multidistrict class action alleging it shared heart-rate/sleep data with advertisers and research partners beyond what a reasonable consumer would expect; separately, a 2021 unsecured database (belonging to third-party company GetHealth, not Fitbit directly) exposed 61 million Apple/Fitbit user records including names, birthdates, weight, height, and location — illustrating how data can leak through companies users have never heard of, buried in a device maker's own terms and conditions. Google acquired Fitbit for $2.1B (2019) and pledged not to use Fitbit data for advertising; precedent is mixed since Google initially kept Nest data separate after its 2014 acquisition, then merged it into Google's broader ecosystem within a year.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration — governed by Google's device arbitration clause since Google completed the Fitbit acquisition (Jan 2021, $2.1B). 30-day opt-out from device activation. A Fitbit user who activated their device without opting out is bound by the same terms as Nest and Google Assistant users, including the In re Google Assistant mass arbitration (69,507 demands).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The 'HIPAA doesn't cover this' structural gap applies to EVERY wearable/health app in this category (Fitbit, Strava, Peloton, Headspace, Calm, Noom, Oura, WHOOP, Garmin) — worth stating once as a category-wide finding rather than repeating per-app.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alphabet Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] HIPAA does not cover Fitbit at all, leaving heart-rate, sleep, and location data with no federal health-privacy protection\nWHAT THE TERMS SAY: The tracker states HIPAA only covers hospitals, health plans, and their business associates, not consumer wearables like Fitbit, even though Fitbit collects heart rate, sleep, and location data as sensitive as what a doctor's office gathers.\nWHY IT MATTERS: Users may assume health-adjacent data collected by a wearable is protected the way medical records are, when in fact it isn't.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Fitbit is named in a multidistrict class action alleging heart-rate and sleep data was shared with advertisers beyond reasonable expectations\nWHAT THE TERMS SAY: The tracker states Fitbit was named in a multidistrict class action alleging it shared heart-rate/sleep data with advertisers and research partners beyond what a reasonable consumer would expect, and separately notes a Duke University study found 79% of popular health/fitness apps share data with third parties.\nWHY IT MATTERS: If proven, users' physiological data was distributed to advertisers or research partners without expected limits.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Fitbit users are bound by Google's device arbitration clause, including the 69,507-demand Google Assistant mass arbitration\nWHAT THE TERMS SAY: The tracker states Fitbit is governed by mandatory binding arbitration under Google's device arbitration clause since the acquisition closed in Jan 2021, with a 30-day opt-out from device activation; a Fitbit user who didn't opt out is bound by the same terms as Nest and Google Assistant users, including the In re Google Assistant mass arbitration (69,507 demands).\nWHY IT MATTERS: Fitbit users who didn't opt out within 30 days of activation are limited to arbitration for disputes, including those over the data-sharing allegations above.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=Y; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The HIPAA gap and GetHealth breach are clearly stated, but the multidistrict class action's specific allegations and current status are only summarized.", "Exposure Score (0-100)": 47, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 25, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 7, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 25/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, biometric_collection+6, precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 7/20 (severity2+2, breach+3, litigation+2) | flags stated 9/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Fitbit (Google)  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. A continuous record of everywhere you physically go.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Fitbit (Google) you gave up your personal data sold onward, your biometric identifiers, your physical movements, your data shared corporate-wide, and your right to sue. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "2026-09-08T19:32:44Z (HTTP 200, CHANGED)", "SCARY (most astonishing T&C item)": "HIPAA — the law most people assume protects their health data — does NOT cover Fitbit at all, because it only applies to hospitals, health plans, and their direct business associates, not consumer wearables. Fitbit collects heart rate, sleep, and location data just as sensitive as what a doctor's office gathers, with none of the same federal legal protection.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 144, "_entity_id": 225, "_entity_slug": "fitbit-google", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Strava", "Category": "Health/Fitness (GPS activity tracking)", "Terms & Conditions URL": "strava.com/legal/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "strava.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "GENUINE NATIONAL-SECURITY-SCALE PRIVACY FAILURE, repeated across multiple years: Strava's public 'Global Heatmap' (built from aggregated user workout GPS data) has repeatedly exposed sensitive locations — in 2018 it revealed secret US/allied military base layouts in Syria, Afghanistan, and Djibouti because soldiers logged runs on base without realizing routes were public; in 2022 an Israeli NGO used planted fake Strava segments to identify over 100 individuals, including intelligence personnel, at six secret military facilities; in 2025, French nuclear submarine crew members leaked patrol positions through logged Strava workouts; in March 2026, a sailor revealed a French aircraft carrier's location by logging an on-deck run. Separately, Le Monde reporting found the movements of world leaders' bodyguards could be tracked via their own public Strava accounts near meeting venues. Strava's 'Metro' program also sells de-identified but highly granular aggregated movement data to city governments and transportation agencies; more than 700 third-party apps can access a connected user's GPS routes, heart rate, and performance data via Strava's API.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Strava Subscriber Agreement, AAA rules. 30-day opt-out via email to legal@strava.com. Strava's heat maps (aggregated GPS data from all users) have previously revealed the locations of military bases and intelligence installations. The arbitration clause covers disputes over GPS/location data handling.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is arguably the most striking 'aggregated consumer data creates a national security problem' finding in this entire audit — a genuinely different category of harm from typical advertiser data-sharing, since the harm here comes from PUBLIC-BY-DEFAULT aggregation of ordinary fitness data rather than any deliberate misuse by Strava itself.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R4) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Strava, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Strava, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Strava's public Global Heatmap has repeatedly exposed secret military base layouts and personnel locations\nWHAT THE TERMS SAY: The tracker states Strava's public Global Heatmap, built from aggregated user workout GPS data, revealed secret US/allied military base layouts in Syria, Afghanistan, and Djibouti in 2018; helped an Israeli NGO identify over 100 individuals including intelligence personnel at six secret facilities in 2022; leaked French nuclear submarine crew patrol positions in 2025; and revealed a French aircraft carrier's location via a sailor's on-deck run in March 2026.\nWHY IT MATTERS: Ordinary users' individually innocuous workout data, aggregated by default into a public map, can inadvertently expose classified locations and put personnel at risk, a harm distinct from deliberate data misuse.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[DATA_SALE · FL-2] Strava's Metro sells de-identified aggregated movement data; 700+ apps can reach user GPS via its API\nWHAT THE TERMS SAY: The tracker states Strava's Metro program sells de-identified but highly granular aggregated movement data to city governments and transportation agencies, and that more than 700 third-party apps can access a connected user's GPS routes, heart rate, and performance data via Strava's API.\nWHY IT MATTERS: Even 'de-identified' aggregated movement data can be granular enough to be sensitive, and hundreds of third-party apps having API access widens the number of parties handling users' location and health data.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with a class-action waiver covers Strava disputes, including over GPS/location data handling, with a 30-day opt-out\nWHAT THE TERMS SAY: Strava's Subscriber Agreement imposes mandatory binding arbitration with a class-action waiver under AAA rules, with a 30-day opt-out via email to legal@strava.com; the tracker notes this clause covers disputes over GPS/location data handling.\nWHY IT MATTERS: Users affected by location-data exposure must opt out within 30 days to preserve the right to pursue collective claims.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=Y; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Strava's own privacy policy and the public heatmap incidents are clearly documented, but the harm arises from aggregation rather than a single confirmed misuse, making the risk diffuse.", "Exposure Score (0-100)": 48, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 22, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 22/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, biometric_collection+6, precise_location_tracking+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 9/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Strava  <-  Strava, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. A continuous record of everywhere you physically go.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to take them to court. Disputes go to private arbitration.\n  6. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (7 of 13): your content used as AI training data; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Strava you gave up your personal data sold onward, your biometric identifiers, your physical movements, your data shared corporate-wide, your right to sue, and your right to join a class action. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "2026-09-08T19:32:46Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Strava's own current privacy policy candidly confirms it pulls in data from whatever you connect — your Peloton account, Garmin device, or Apple Health — including heart rate, sleep, HRV, and VO2max. Strava says it won't sell or advertise with that specific health data. But the company's own aggregated public 'Global Heatmap' has repeatedly done something no advertiser ever could: reveal secret military base layouts in active conflict zones, expose intelligence personnel at hidden facilities, and leak a French aircraft carrier's real-time position — all just from soldiers and sailors logging ordinary runs. The privacy risk here isn't a company selling your data on purpose; it's that thousands of individually-innocent workout logs, aggregated together, can accidentally reveal exactly what a nation's military is trying hardest to hide.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 145, "_entity_id": 227, "_entity_slug": "strava", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Peloton", "Category": "Health/Fitness (connected equipment)", "Terms & Conditions URL": "peloton.com/legal-policies/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "peloton.com/legal-policies/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "A 2021 API vulnerability exposed personal data of approximately 3 MILLION users (full names, emails, ages, workout stats) — Peloton reportedly took over 90 DAYS to fix the vulnerability after being notified, a notably slow remediation timeline compared to other breaches in this tracker. Separately, security researchers found Peloton's connected treadmill runs an outdated, unpatched Android OS version with known security flaws, and that attackers with physical device access could potentially deploy malware or steal data through the hardware itself — a hardware-level vulnerability distinct from the typical software/data-sharing issues found elsewhere in this tracker.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. Peloton ToS, AAA rules, New York law. Peloton collects heart rate, workout intensity, calorie burn, and body metrics — the arbitration clause covers disputes over how this health-adjacent fitness data is handled. Peloton's $1.25B debt restructuring (2024) raises questions about data-asset handling in a potential bankruptcy/acquisition scenario, similar to 23andMe.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The customer-service-chat-to-AI-marketing-firm pipeline is a notably specific and unusual finding — worth flagging since it's not about workout data at all, but about ordinary customer support interactions being repurposed for marketing/AI training.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R4) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Peloton Interactive, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Peloton Interactive, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] A 2021 API vulnerability exposed ~3M Peloton users' data; Peloton reportedly took over 90 days to fix\nWHAT THE TERMS SAY: The tracker states a 2021 API vulnerability exposed personal data of approximately 3 million users (full names, emails, ages, workout stats), and that Peloton reportedly took over 90 days to fix the vulnerability after being notified, a notably slow remediation timeline.\nWHY IT MATTERS: A reported three-month delay in fixing a known vulnerability left approximately 3 million users' data exposed longer than necessary.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] A California lawsuit alleges Peloton recorded customer-service chats and gave them to an AI marketing firm without telling users\nWHAT THE TERMS SAY: The tracker states a California lawsuit alleges Peloton recorded live customer-service chat conversations, the ones used to troubleshoot a bike or resolve a billing issue, and handed that data to an AI-focused marketing firm without telling users.\nWHY IT MATTERS: If proven, routine support conversations, not workout data, were repurposed for marketing without consumer knowledge or consent.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with a class-action waiver covers Peloton disputes over health-adjacent fitness data, with a 30-day opt-out\nWHAT THE TERMS SAY: Peloton's Terms of Service, under AAA rules and New York law, impose mandatory binding arbitration with a class-action waiver and a 30-day opt-out; the tracker notes this covers disputes over how Peloton's collected heart rate, workout intensity, calorie burn, and body metrics are handled.\nWHY IT MATTERS: Users must opt out within 30 days or lose the ability to bring a class action over the breach or chat-sharing allegations described above.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2021 breach and remediation delay are clearly documented, but the chat-sharing lawsuit's allegations and outcome remain unconfirmed.", "Exposure Score (0-100)": 47, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Peloton  <-  Peloton Interactive, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Peloton you gave up your biometric identifiers, your data shared corporate-wide, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A California lawsuit alleges Peloton recorded live customer-service CHAT conversations — the ones you'd have troubleshooting your bike or resolving a billing issue — and handed that data to an AI-focused MARKETING FIRM without telling you. On top of that, Peloton's connected treadmill has been found running an outdated, unpatched version of Android with known security holes, meaning someone with physical access to the hardware in your own home could potentially install malware or extract data through the machine itself — a hardware-level vulnerability that has nothing to do with what workout data you actually agreed to share.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 146, "_entity_id": 229, "_entity_slug": "peloton", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Headspace", "Category": "Health/Fitness (mental wellness)", "Terms & Conditions URL": "headspace.com/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "headspace.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same HIPAA-gap category issue as Fitbit/Strava above; independent research found Headspace shares 7 of 9 collected data points with third parties (78% — among the highest share-rates of any meditation/wellness app tested); Headspace's own privacy policy explicitly lists RESPONDING TO SUBPOENAS AND COURT ORDERS as a stated use of retained personal data, and does not commit to deleting data after a defined retention period — meaning conversations/mood logs a user shares with a meditation app could later be subpoenaed in unrelated legal proceedings (e.g., divorce, custody, criminal cases), a genuinely under-appreciated risk for a mental-wellness product.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Headspace ToS, AAA rules. 30-day opt-out. Headspace merged with Ginger (mental health provider) in 2021 to form Headspace Health. Given the mental-health context, the arbitration clause covers disputes over therapeutic content and therapist-matching services, not just billing.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The subpoena-exposure risk applies to the whole mental-wellness app category (Headspace, Calm, Talkspace, BetterHelp) — worth a single consolidated flag rather than repeating per-app.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Santa Monica", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Headspace Health (fmr. Headspace Inc. + Ginger)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Headspace Health (fmr. Headspace Inc. + Ginger)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Independent testing found Headspace shares 7 of 9 collected data points with third parties, 78%, among the highest of meditation apps tested\nWHAT THE TERMS SAY: The tracker states independent research found Headspace shares 7 out of 9 data points it collects with third parties (78%), among the highest share-rates of any meditation/wellness app tested.\nWHY IT MATTERS: Users sharing mood logs and meditation habits with a wellness app may not expect the large majority of that data to reach outside parties.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[RETENTION_PERIOD · FL-2] Headspace's privacy policy names responding to subpoenas as a use of your data and sets no defined retention limit\nWHAT THE TERMS SAY: The tracker states Headspace's own privacy policy explicitly lists responding to subpoenas and court orders as a stated use of retained personal data, and does not commit to deleting data after a defined retention period.\nWHY IT MATTERS: Conversations or mood logs shared with a meditation app could later be subpoenaed in unrelated legal proceedings such as divorce, custody, or criminal cases, with no stated limit on how long that data is kept.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration covers disputes over Headspace's therapeutic content and therapist-matching, not just billing, with a 30-day opt-out\nWHAT THE TERMS SAY: Headspace's Terms of Service impose mandatory binding arbitration with a class-action waiver under AAA rules, with a 30-day opt-out; the tracker notes that given the mental-health context following the 2021 Ginger merger, the clause covers disputes over therapeutic content and therapist-matching services, not just billing.\nWHY IT MATTERS: Users with disputes over the quality or handling of mental-health services, not just charges, are limited to individual arbitration unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Headspace's own privacy policy language and independent third-party testing results are both directly cited and specific.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Headspace  <-  Headspace Health (fmr. Headspace Inc. + Ginger)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Headspace you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Independent testing found Headspace shares 7 OUT OF 9 data points it collects with third parties — 78%, among the highest share rates of any meditation app tested — and its own privacy policy lists RESPONDING TO SUBPOENAS as a stated use of your data, with no defined limit on how long it's kept. A meditation app meant to help you decompress can also become evidence in a legal proceeding you have nothing to do with.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 147, "_entity_id": 232, "_entity_slug": "headspace", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Calm", "Category": "Health/Fitness (mental wellness)", "Terms & Conditions URL": "calm.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "calm.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same HIPAA-gap issue as Headspace above; Calm's data retention policy does not define a clear length of time after which data or cookies are deleted, per independent research — an open-ended retention practice distinct from apps that at least specify a retention window.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Calm ToS, AAA rules. 30-day opt-out via email to legal@calm.com. Calm processes sleep, meditation, and mood-tracking data — the arbitration clause covers disputes over how this sensitive wellness data is handled.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Pair with the Headspace/Talkspace/BetterHelp findings for a consolidated mental-wellness-app category summary if useful.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Calm.com, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Calm.com, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[RETENTION_PERIOD · FL-2] Calm's privacy policy does not specify how long it retains user data or cookies\nWHAT THE TERMS SAY: The tracker states independent research found Calm's data retention policy does not define a clear length of time after which data or cookies are deleted, an open-ended practice distinct from apps that at least specify a retention window.\nWHY IT MATTERS: Users have no way to know how long their meditation, sleep, and mood data will be kept.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Plaintiffs' firms are soliciting mass arbitration against Calm over alleged Meta pixel sharing of in-app video watch history\nWHAT THE TERMS SAY: The tracker states plaintiffs' firms are soliciting mass arbitration (not a class action) against Calm over alleged Meta pixel sharing of in-app video watch history under the VPPA, but flags this as solicited claims from lead-generation-style sources rather than an adjudicated finding.\nWHY IT MATTERS: If the underlying sharing occurred, a meditation app's watch history can reveal what a person is anxious about, grieving, or unable to sleep through, though the tracker cautions this specific claim is not independently verified.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with a class-action waiver covers Calm's sleep, meditation, and mood-tracking data disputes, with a 30-day opt-out\nWHAT THE TERMS SAY: Calm's Terms of Service impose mandatory binding arbitration with a class-action waiver under AAA rules, with a 30-day opt-out via email to legal@calm.com; the tracker notes this covers disputes over how Calm's sleep, meditation, and mood-tracking data is handled.\nWHY IT MATTERS: Users must opt out within 30 days or be limited to individual arbitration, including for claims like the pixel-sharing allegations above.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The retention-policy gap is independently confirmed, but the Meta pixel mass-arbitration claim is explicitly flagged in the tracker as solicited rather than adjudicated.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Calm  <-  Calm.com, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Calm you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:32:54Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Two separate problems. First, Calm's privacy policy does not specify how long it retains your data or cookies — an open-ended retention window, where competitors at least commit to a period. Second, plaintiffs' firms are soliciting MASS ARBITRATION (not a class action) against Calm over alleged Meta pixel sharing of in-app video watch history under the VPPA — and mass arbitration is the tactic documented in the Lowe's and Newegg rows, used precisely because arbitration clauses killed the class action. Treat the arbitration campaign as solicited claims rather than an adjudicated finding: the most visible sources on it are lead-generation sites of exactly the kind this tracker's research standard warns against. What makes the underlying category serious is content: a meditation app's watch history is a record of what a person is anxious about, grieving, or unable to sleep through.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 148, "_entity_id": 234, "_entity_slug": "calm", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Noom", "Category": "Health/Fitness (weight loss)", "Terms & Conditions URL": "noom.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "noom.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Named in a London-based Privacy International study (alongside BetterMe Meal Plan, Fullstory, VShred) reviewing diet/weight-loss apps found to be sharing sensitive dieting/weight data with third-party marketers or failing to adequately protect it; same general HIPAA-gap issue as other health apps in this tracker.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Noom Subscription Agreement, AAA rules. 30-day opt-out. Noom has faced multiple FTC complaints and class actions over auto-renewal practices and the difficulty of canceling subscriptions — the arbitration clause is Noom's primary defense in these disputes. A 2022 class settlement required Noom to improve cancellation disclosures.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Given prior BMHC/Gazette context around eating and body-image-related editorial sensitivity, this category (diet/weight-loss apps sharing sensitive dieting data) may warrant a more careful, dedicated review rather than a generic pass if it's ever referenced in customer-facing material.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Noom, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Noom, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Noom is named in a Privacy International study of diet apps sharing sensitive dieting and weight data with third-party marketers\nWHAT THE TERMS SAY: The tracker states Noom is named in a London-based Privacy International study, alongside BetterMe Meal Plan, Fullstory, and VShred, reviewing diet/weight-loss apps found to be sharing sensitive dieting/weight data with third-party marketers or failing to adequately protect it.\nWHY IT MATTERS: Information about a user's body and eating habits, among the most personal data people track, may flow to advertisers outside the app.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[AUTO_RENEWAL_FEES · FL-1] Noom has faced multiple FTC complaints and class actions over auto-renewal and cancellation difficulty, with arbitration as its primary defense\nWHAT THE TERMS SAY: The tracker states Noom has faced multiple FTC complaints and class actions over auto-renewal practices and the difficulty of canceling subscriptions, that the arbitration clause is Noom's primary defense in these disputes, and that a 2022 class settlement required Noom to improve cancellation disclosures.\nWHY IT MATTERS: Subscribers who struggled to cancel and later sought recourse may be steered into individual arbitration rather than court, even though a prior settlement already found cancellation disclosures needed improvement.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with a class-action waiver covers Noom's Subscription Agreement, with a 30-day opt-out\nWHAT THE TERMS SAY: Noom's Subscription Agreement imposes mandatory binding arbitration with a class-action waiver under AAA rules, with a 30-day opt-out.\nWHY IT MATTERS: Users must opt out within 30 days or lose the ability to bring or join a class action against Noom.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Privacy International study and FTC/class-action history are documented, but specific case names and settlement figures beyond the 2022 cancellation-disclosure case are not detailed.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 4/20 (severity2+2, litigation+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Noom  <-  Noom, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Noom you gave up your data shared corporate-wide, your right to sue, your right to join a class action, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Noom is named alongside other diet/weight-loss apps in independent research finding these apps share sensitive dieting and weight data with third-party marketers — information about your body and eating habits, arguably some of the most personal data anyone tracks, flowing to advertisers outside the app's own walls.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 149, "_entity_id": 236, "_entity_slug": "noom", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "WebMD", "Category": "Health/Fitness (health information)", "Terms & Conditions URL": "webmd.com/about-webmd-policies/about-terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "webmd.com/about-webmd-policies/about-privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "As a symptom-checker/health-information site rather than a data-collecting wearable, WebMD's primary privacy exposure is typically through tracking pixels/ad-tech on its pages (same general category as the LinkedIn/Meta pixel findings elsewhere in this tracker) rather than device-level biometric collection; not independently confirmed with a specific named lawsuit this pass.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. WebMD ToS, AAA rules. 30-day opt-out. WebMD was acquired by Internet Brands (a KKR portfolio company) in 2017 for $2.8B. Health-search queries are commercially valuable — the arbitration clause covers disputes over how WebMD uses and shares search/symptom data with advertisers.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up specifically checking whether WebMD uses health-topic-specific ad targeting (e.g., serving ads based on which condition/symptom pages a user viewed) — a practice flagged by HHS/FTC guidance elsewhere in this research as a particular risk area for health-adjacent websites.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Internet Brands (Apollo Global Management portfolio)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Internet Brands (Apollo Global Management portfolio)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] WebMD's tracking pixels could reveal which specific symptom or health condition a visitor looked up to ad networks\nWHAT THE TERMS SAY: The tracker states WebMD's primary privacy exposure is through tracking pixels/ad-tech on its pages, the same general pattern documented for LinkedIn and Meta elsewhere, and that which specific symptom or condition page a user viewed could theoretically be shared with ad networks the moment they visit.\nWHY IT MATTERS: Health-topic browsing is sensitive; sharing it with ad networks could reveal a person's medical concerns the same way visiting a mortgage page reveals financial situation, though no specific WebMD lawsuit was independently confirmed this pass.\n(evidence: Data Sharing | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration covers disputes over how WebMD shares valuable health-search and symptom data with advertisers, with a 30-day opt-out\nWHAT THE TERMS SAY: WebMD's Terms of Service impose mandatory binding arbitration with a class-action waiver under AAA rules, with a 30-day opt-out; the tracker notes health-search queries are commercially valuable and that the clause covers disputes over how WebMD uses and shares this data with advertisers.\nWHY IT MATTERS: Users disputing how their symptom searches are shared with advertisers are limited to individual arbitration unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No WebMD-specific lawsuit or named incident was independently confirmed this pass; only the general tracking-pixel exposure pattern and the arbitration clause are documented.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=N; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No specific WebMD lawsuit or confirmed incident exists this pass; the tracking-pixel exposure is inferred by analogy to other companies' documented cases.", "Exposure Score (0-100)": 33, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "WebMD  <-  Internet Brands (Apollo Global Management portfolio)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your biometric identifiers.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using WebMD you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:32:59Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "As a health-symptom-checker site, WebMD's biggest privacy risk is the SAME tracking-pixel pattern already documented for LinkedIn, Meta, and health-adjacent sites throughout this tracker — which specific symptom or condition page you looked up could theoretically be shared with ad networks the moment you visit, the same way browsing a mortgage page reveals your financial situation.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 150, "_entity_id": 238, "_entity_slug": "webmd", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CVS Health / CVS app", "Category": "Health/Pharmacy", "Terms & Conditions URL": "cvs.com/content/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "cvs.com/content/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "A 2021 CVS Health DATABASE LEAK exposed OVER ONE BILLION RECORDS — including search queries for specific medications and vaccines — one of the largest-scale exposures found anywhere in this entire 185-company audit by raw record count, though the search-query nature of the exposed data (rather than full medical records) may limit per-person severity relative to, e.g., the 23andMe genetic-data breach elsewhere in this tracker.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. CVS Health's Terms of Use, AAA rules. 30-day opt-out via written notice. As parent of Aetna (whose arbitration clause preserves class/jury waivers even after opt-out) and CVS Caremark (PBM), CVS Health's arbitration terms span pharmacy, insurance, and PBM services — one of the most vertically integrated dispute-resolution regimes in consumer healthcare.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Worth directly verifying details of this 2021 breach given the extraordinary scale claimed (1 billion+ records) before citing it in any customer-facing material — confirm scope, what was actually exposed, and whether CVS disclosed/settled this specific incident.", "Industry (Fortune 500)": "Health Care: Pharmacy and Other Services", "Revenue (Fortune 500)": "$402.1B", "Market Cap": "$137.9B", "Employees": "259,500", "HQ City": "Woonsocket", "HQ State": "Rhode Island", "CEO": "David Joyner", "Ticker": "CVS", "Website (Corporate)": "cvshealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (CVS). Service route: c/o General Counsel / Corporate Secretary, Woonsocket, Rhode Island — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Rhode Island' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): RI SOS Corporate Database — business.sos.ri.gov/CorpWeb/CorpSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2021 database leak exposed 1B+ records including medication and vaccine search queries\nWHAT THE TERMS SAY: A 2021 CVS Health database leak reportedly exposed over one billion records, including search queries for specific medications and vaccines.\nWHY IT MATTERS: The tracker itself flags this as needing direct verification of scope and disclosure before being cited, so the true scale and consumer impact are not yet confirmed.\n(evidence: Data Sharing | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with class waiver spans CVS pharmacy, Aetna insurance, and Caremark PBM\nWHAT THE TERMS SAY: CVS Health's Terms of Use require mandatory binding arbitration under AAA rules with a class action waiver and a 30-day written-notice opt-out; as parent of Aetna and CVS Caremark, the clause spans pharmacy, insurance, and PBM services.\nWHY IT MATTERS: A single, vertically integrated arbitration regime can limit a consumer's ability to bring or join a collective claim across pharmacy, insurance, and drug-benefit disputes alike.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[REGULATORY_PENALTY · FL-1] CVS Caremark is accused by the FTC of helping inflate insulin prices via a rebate scheme\nWHAT THE TERMS SAY: CVS Caremark, CVS Health's own pharmacy-benefits arm, is one of three companies the FTC accused of artificially inflating insulin prices through a rebate scheme.\nWHY IT MATTERS: If accurate, the accusation means the same corporate family millions rely on for prescriptions is also alleged to have helped make an essential medication more expensive.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2021 breach's scale is asserted but the tracker itself calls for verification before it's cited, while arbitration terms are clearly stated.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "CVS Health / CVS app  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using CVS Health / CVS app you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:33:01Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "CVS Caremark (CVS's own pharmacy-benefits arm) is one of three companies the FTC accused of artificially inflating INSULIN prices through a rebate scheme documented elsewhere in this tracker — meaning the pharmacy chain millions rely on for prescriptions is also the entity accused of helping make one of the most essential, life-sustaining medications more expensive than it needed to be.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 151, "_entity_id": 239, "_entity_slug": "cvs-health-cvs-app", "_issuer": "CVS Health / CVS app", "_issuer_slug": "cvs-health-cvs-app", "_ticker": "CVS", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Walgreens app", "Category": "Health/Pharmacy", "Terms & Conditions URL": "walgreens.com/topic/help/policies/termsofuse.jsp", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "walgreens.com/topic/help/policies/privacypolicy.jsp", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Walgreens processes prescription data (HIPAA-covered when acting as a pharmacy), loyalty-program purchase history (myWalgreens, NOT HIPAA-covered), photo-service data, and health-clinic data (VillageMD, majority-owned by Walgreens). The app combines pharmacy and retail data streams — prescription pickup reminders alongside front-store purchase tracking — creating a health-and-consumer hybrid profile. The DOJ opioid settlement (up to $350M) arose from Walgreens' dispensing data.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Walgreens' ToS covers the app, walgreens.com, and photo services. Given the DOJ opioid settlement (up to $350M, False Claims Act) and the app's role as a pharmacy interface handling prescription data (HIPAA-covered), the arbitration clause affects disputes over both data handling and prescription-service quality.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Pair with the CVS row for a consolidated pharmacy-app category review, given the shared prescription-data risk profile.", "Industry (Fortune 500)": "Food & Drug Stores", "Revenue (Fortune 500)": "$147.7B", "Market Cap": "Non-public", "Employees": "252,500", "HQ City": "Deerfield", "HQ State": "Illinois", "CEO": "Timothy Wentworth", "Ticker": "Non-public", "Website (Corporate)": "walgreensbootsalliance.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (Non-public). Service route: c/o General Counsel / Corporate Secretary, Deerfield, Illinois — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.healthcaredive.com/news/walgreens-settles-department-justice-opioid-lawsuit-350-million/746018/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Walgreens Boots Alliance, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Walgreens Boots Alliance, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] Walgreens paid ~$5.5B in the national opioid settlement and up to $350M to DOJ over alleged unlawful fills\nWHAT THE TERMS SAY: Walgreens agreed to pay roughly $5.5 billion as part of the national opioid settlement and separately paid up to $350 million to the DOJ over allegations it filled millions of unlawful opioid prescriptions and billed federal healthcare programs for them.\nWHY IT MATTERS: Consumers and taxpayers may have effectively helped fund prescriptions the government itself says should never have been filled.\n(evidence: SCARY | Data Sharing; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Walgreens combines pharmacy and retail data streams into a health-and-consumer hybrid profile\nWHAT THE TERMS SAY: Walgreens processes prescription data (HIPAA-covered when acting as a pharmacy), loyalty-program purchase history (myWalgreens, NOT HIPAA-covered), photo-service data, and health-clinic data (VillageMD, majority-owned by Walgreens); the app combines pharmacy and retail data streams - prescription pickup reminders alongside front-store purchase tracking - creating a health-and-consumer hybrid profile.\nWHY IT MATTERS: Blending regulated prescription data with unregulated retail and loyalty tracking can expose more about a person's health than either data stream would alone.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration and class waiver cover the app, walgreens.com, and photo services\nWHAT THE TERMS SAY: Walgreens' Terms of Service impose mandatory binding arbitration with a class action waiver across the app, walgreens.com, and photo services.\nWHY IT MATTERS: Given the app's role handling prescription data and the DOJ opioid findings, this clause can limit how consumers challenge both data-handling and prescription-service issues.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The opioid settlements are clearly documented, but fees are not itemized and the arbitration opt-out window is stated as unverified.", "Exposure Score (0-100)": 47, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 23, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 23/30 (forced_arbitration+12, class_action_waiver+9, optout_window_unverified+2) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Walgreens app  <-  Walgreens Boots Alliance, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Walgreens app you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:33:04Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Walgreens agreed to pay roughly $5.5 BILLION as part of the national opioid settlement, and SEPARATELY paid up to $350 MILLION to the DOJ over allegations it filled MILLIONS of unlawful opioid prescriptions and then billed federal healthcare programs for them — meaning taxpayers may have helped fund prescriptions the government itself says should never have been filled in the first place.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 152, "_entity_id": 241, "_entity_slug": "walgreens-app", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Bumble", "Category": "Dating", "Terms & Conditions URL": "bumble.com/en/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "bumble.com/en/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "TWO DISTINCT 2026 BREACHES: (1) A January 2026 breach (disclosed by hacking group ShinyHunters) compromised Bumble's INTERNAL corporate systems (Slack, Google Drive) via a 'vishing' (voice phishing) attack on a contractor account, leaking 30GB of internal corporate files; Bumble states member profiles/messages were NOT exposed in this specific incident, though the scale of internal document theft raises questions about what sensitive business/employee data was included. (2) A SEPARATE class action (Omirin v. Bumble, W.D. Texas, filed Feb 2026) alleges a different 'massive and preventable' cyberattack exposed actual USER data — names, dates of birth, addresses, phone numbers, SOCIAL SECURITY NUMBERS, account numbers, AND highly sensitive context-rich dating data (chat history, dating history) — alleging Bumble failed to encrypt data adequately and failed to follow required security protocols. The combination of financial identifiers (SSNs) with intimate dating-app content is a particularly high-risk data combination for identity theft AND personal/reputational harm.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver and jury trial waiver. 30-day opt-out via email to arbitration_optout@bumble.com. AAA rules, Texas law (Bumble HQ: Austin TX). Covers Bumble, Bumble BFF, and Bumble Bizz.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Two SEPARATE Bumble breaches in the same short window (corporate-systems breach + user-data breach) is worth noting as a pattern of security lapses rather than a single isolated incident.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Austin", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Bumble Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Bumble Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Class action alleges a breach exposed users' SSNs alongside chat and dating history\nWHAT THE TERMS SAY: The Omirin v. Bumble class action (W.D. Texas, filed Feb 2026) alleges a cyberattack exposed names, dates of birth, addresses, phone numbers, Social Security numbers, account numbers, and chat/dating history, and that Bumble failed to encrypt data adequately.\nWHY IT MATTERS: Combining financial identifiers like SSNs with intimate dating-app content creates unusually high risk for both identity theft and personal or reputational harm, though this remains an unproven allegation.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] January 2026 vishing attack on a contractor leaked 30GB of Bumble's internal corporate files\nWHAT THE TERMS SAY: Hacking group ShinyHunters disclosed a breach of Bumble's internal corporate systems (Slack, Google Drive) via a voice-phishing attack on a contractor account, leaking 30GB of internal files; Bumble states member profiles and messages were not exposed in this incident.\nWHY IT MATTERS: Even though Bumble says user profiles weren't exposed, the scale of internal document theft raises questions about what sensitive business or employee data was included, and shows a pattern alongside the separate user-data breach allegation.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DISCRIMINATORY_PRACTICE · FL-1] Bumble settled a lawsuit alleging its 'women message first' feature illegally discriminates by sex\nWHAT THE TERMS SAY: Bumble's core 'women message first' feature was the subject of a lawsuit alleging it illegally discriminates by sex under California civil rights law, and Bumble settled rather than fight it, setting aside tens of millions of dollars in accrued legal reserves for this and related cases.\nWHY IT MATTERS: The company chose to settle rather than defend the app's defining design choice in court, with tens of millions of dollars in accrued legal reserves covering this and related cases.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "One breach is confirmed by the company itself, while the more severe user-data breach remains an unproven allegation in active litigation.", "Exposure Score (0-100)": 43, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Bumble  <-  Bumble Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to a jury.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Bumble you gave up your right to sue, your right to join a class action, and your right to a jury. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:33:06Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Bumble's own 'women message first' feature — the entire premise of the app — was itself the SUBJECT OF A LAWSUIT alleging it illegally discriminates by sex under California civil rights law; Bumble settled rather than fight it, setting aside tens of millions of dollars in accrued legal reserves for this and related cases. This is on top of the Jan 2026 corporate breach documented elsewhere in this tracker, which happened via a compromised internal Slack workspace — meaning the app built around putting women in control of the first move has had to defend that exact design choice in court.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 153, "_entity_id": 243, "_entity_slug": "bumble", "_issuer": "Bumble Inc.", "_issuer_slug": "bumble-inc", "_ticker": "BMBL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Hinge (Match Group)", "Category": "Dating", "Terms & Conditions URL": "hinge.co/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "hinge.co/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "See the Match Group row for the primary findings: $14M FTC settlement over fake 'love interest' ads (that settlement covered Match.com specifically, though Match Group's broader practices affect all its brands including Hinge); a 2024 lawsuit specifically names Tinder/Hinge together alleging both apps are designed to be addictive using dark-pattern techniques.", "Arbitration / Class Action Waiver": "Same Match Group-wide mandatory arbitration + class action waiver noted in that row — a ban on one Match Group app can extend across ALL Match Group platforms (Hinge, Tinder, OkCupid) simultaneously.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See Match Group row for full detail; Hinge shares the same parent-company risk profile.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.upguard.com/news/match-data-breach-2026-01-29", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Match Group, Inc.", "Years Referenced in Finding (heuristic)": "2026, 2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Match Group, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] January 2026 breach via vendor AppsFlyer exposed 10M+ records across Hinge, Match, and OkCupid\nWHAT THE TERMS SAY: The ShinyHunters group breached Hinge, Match, and OkCupid through third-party analytics vendor AppsFlyer, exposing over 10 million records of dating-app usage data and personal information.\nWHY IT MATTERS: As Malwarebytes noted, exposed dating-app activity can reveal who someone was interested in, when, and how -- a more personal exposure than a stolen loyalty number.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[BIOMETRICS · FL-2] Illinois attorneys are investigating whether Hinge's selfie verification illegally collected facial geometry\nWHAT THE TERMS SAY: Illinois attorneys are investigating whether Hinge's selfie-verification feature collected users' facial geometry without the consent required under the state's biometric privacy law.\nWHY IT MATTERS: If confirmed, this would mean a routine identity-verification feature captured legally protected biometric data without the required consent.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DARK_PATTERN_CONSENT · FL-2] A 2024 lawsuit alleges Hinge is engineered to make users 'compulsively' keep swiping and paying\nWHAT THE TERMS SAY: A 2024 lawsuit alleges Hinge (together with Tinder) is deliberately designed using dark-pattern techniques to be addictive, making users compulsively keep swiping and paying rather than helping them find a relationship and leave.\nWHY IT MATTERS: If accurate, the app's design would work against its own stated purpose, keeping users engaged and spending rather than helping them succeed and exit.\n(evidence: SCARY | Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "A cross-platform breach is confirmed, but the biometric-consent investigation and the addictive-design lawsuit are both still unresolved allegations.", "Exposure Score (0-100)": 52, "Exposure Band": "High", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 4/20 (termination_or_confiscation+4) | Record 20/20 (severity5+20, litigation+2) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Hinge (Match Group)  <-  Match Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Hinge (Match Group) you gave up your biometric identifiers, your data shared corporate-wide, your right to sue, and your right to keep what you paid for. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:33:09Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "In January 2026, the same ShinyHunters group that hit Panera, Amtrak, and dozens of others (documented throughout this tracker) breached Hinge, Match, and OkCupid via a third-party analytics vendor (AppsFlyer), exposing over 10 million records of dating-app USAGE DATA and personal information. Malwarebytes specifically singled this out against the same-week Panera breach: 'when your activity on a dating app is compromised, the impact can be deeply personal' — unlike a stolen loyalty-rewards number, exposed dating-app activity can reveal who you were interested in, when, and how. Separately, Illinois attorneys are investigating whether Hinge's selfie-verification feature illegally collected users' FACIAL GEOMETRY without the consent the state's biometric law requires, and a 2024 lawsuit alleges Hinge is deliberately engineered to make users 'compulsively' keep swiping and paying, rather than actually help them find a relationship and leave.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 154, "_entity_id": 244, "_entity_slug": "hinge-match-group", "_issuer": "Match Group, Inc.", "_issuer_slug": "match-group-inc", "_ticker": "MTCH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "OkCupid (Match Group)", "Category": "Dating", "Terms & Conditions URL": "okcupid.com/legal/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "okcupid.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SEPARATE, SPECIFIC FTC ACTION (March 30, 2026): 'FTC Takes Action Against Match and OkCupid for Deceiving Users by Sharing Personal Data with Third Party' — a more recent and OkCupid-SPECIFIC enforcement action distinct from the 2019 fake-ads case that only named Match.com. This confirms OkCupid has its OWN, separate, recent (2026) FTC finding about improper third-party data sharing, not just inherited exposure from its parent company's other issues.", "Arbitration / Class Action Waiver": "Same Match Group-wide mandatory arbitration + cross-platform ban policy as Hinge/Tinder.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is a genuinely DISTINCT, recent (2026) FTC action specific to OkCupid — worth flagging as its own finding rather than folding entirely into the general Match Group summary, since it's more current than the 2019 Match.com case.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation + Data breach", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.upguard.com/news/match-data-breach-2026-01-29", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Match Group, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Match Group, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] March 2026 FTC action found OkCupid deceived users by sharing personal data with a third party\nWHAT THE TERMS SAY: A March 30, 2026 FTC action, 'FTC Takes Action Against Match and OkCupid for Deceiving Users by Sharing Personal Data with Third Party,' is a distinct, OkCupid-specific finding separate from the 2019 Match.com fake-ads case.\nWHY IT MATTERS: This confirms OkCupid has its own recent, company-specific finding about improper third-party data sharing, not just inherited exposure from its parent.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] OkCupid was named alongside Hinge and Match in the January 2026 breach of 10M+ usage records\nWHAT THE TERMS SAY: OkCupid was named in the same January 2026 breach as Hinge and Match, exposing over 10 million records via a third-party vendor.\nWHY IT MATTERS: Users of OkCupid had dating-app usage data and personal information exposed in a breach affecting multiple Match Group platforms at once.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DARK_PATTERN_CONSENT · FL-1] FTC found OkCupid sent 'fake love interest' emails from accounts it already knew were fraudulent\nWHAT THE TERMS SAY: OkCupid is part of the FTC's $14 million settlement over 'fake love interest' emails, in which the agency found the company knowingly sent messages from accounts it had already identified as fraudulent to trick people into paying for a subscription to respond to a match that was never real.\nWHY IT MATTERS: Consumers were induced to pay for subscriptions based on contact from accounts the company itself already knew were fake.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=Y; penalty=Y; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Multiple confirmed FTC findings and a breach are clearly documented, though arbitration opt-out terms are not specified.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 4/20 (termination_or_confiscation+4) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "OkCupid (Match Group)  <-  Match Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using OkCupid (Match Group) you gave up your data shared corporate-wide, your right to sue, and your right to keep what you paid for. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:33:11Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "OkCupid was named in the SAME January 2026 breach as Hinge and Match (10+ million records via a third-party vendor) — and is separately part of the FTC's $14 million settlement over 'fake love interest' emails, where the agency found the company knowingly sent messages from accounts it had ALREADY IDENTIFIED as fraudulent, specifically to trick people into paying for a subscription to respond to a match that was never real.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 155, "_entity_id": 245, "_entity_slug": "okcupid-match-group", "_issuer": "Match Group, Inc.", "_issuer_slug": "match-group-inc", "_ticker": "MTCH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Roblox", "Category": "Gaming (child-oriented)", "Terms & Conditions URL": "roblox.com/info/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "roblox.com/info/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SEVERE, ACTIVE CHILD-SAFETY LITIGATION (2026): Roblox faces 140+ federal lawsuits over alleged child-safety failures, plus separate lawsuits from Attorneys General in Texas, Louisiana, Florida, Kentucky, Iowa, Tennessee, Nebraska, and Arkansas, and a Georgia investigation specifically into adult contact with minors originating on the platform. In May 2026, child-safety advocacy groups (Fairplay and the National Center on Sexual Exploitation) formally asked the FTC to investigate Roblox under Section 5 of the FTC Act, citing documented test findings that accounts registered to young children could access chat features with strangers with no meaningful age verification, and citing a family whose teenage son died after alleged online grooming that began on the platform. Roblox settled with Alabama, Nevada, and West Virginia (April 2026) on related youth-safety/consumer-protection matters and is negotiating with additional states. The platform's virtual-currency system (Robux) is separately alleged to obscure real-world costs from children through fluctuating conversion rates, and 'loot box'-style randomized reward mechanics are alleged to function like gambling aimed at minors.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. Roblox ToS, AAA rules, California law. Roblox's user base is predominantly children (over 50% under 13 per the company's own disclosures). The FTC has investigated Roblox's child-safety practices. The arbitration clause binds the parents/guardians of child users who accept the ToS on their behalf — the child cannot exercise the opt-out independently.", "Fees / Billing Flags": "Not itemized separately from the above.", "Notes": "Given the severity of the underlying allegations (child grooming, a reported death), this deserves the most serious, careful treatment of any company in this entire audit. If any customer/parent-facing material references Roblox, stick to citing the FTC complaint and state AG actions as established regulatory facts rather than restating graphic specifics.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Mateo", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R2) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Roblox Corporation", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Roblox Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-2] 140+ federal suits and multiple state AG suits allege Roblox let adults contact children with weak checks\nWHAT THE TERMS SAY: Roblox faces 140+ federal lawsuits (85+ consolidated into MDL 3166) plus separate suits from Attorneys General in Texas, Louisiana, Florida, Kentucky, Iowa, Tennessee, Nebraska, and Arkansas, alleging the platform's chat and communication features let adults contact children with insufficient age verification or moderation; Florida's AG says its investigators created test accounts posing as children as young as 7 to evaluate the platform's actual safety controls.\nWHY IT MATTERS: The scale of consolidated litigation and the state-level investigative response are themselves the clearest signal of how seriously the alleged child-safety failures are being treated by regulators and courts, on a platform whose user base is over 50% under 13 per the company's own disclosures.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[DARK_PATTERN_CONSENT · FL-4] Robux's fluctuating conversion rates and loot-box mechanics are alleged to obscure real costs from kids\nWHAT THE TERMS SAY: Roblox's Robux virtual-currency system is alleged to obscure real-world costs from children through fluctuating conversion rates, and its loot-box-style randomized reward mechanics are alleged to function like gambling aimed at minors.\nWHY IT MATTERS: If accurate, children may be spending real money without a clear sense of what it actually costs, encouraged by gambling-like reward mechanics.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration binds parents who accept the ToS, and children cannot opt out independently\nWHAT THE TERMS SAY: Roblox's Terms require mandatory binding arbitration with a class action waiver and a 30-day opt-out; the clause binds the parents or guardians who accept the ToS on a child's behalf, and the child cannot exercise the opt-out independently.\nWHY IT MATTERS: Because Roblox's user base is majority under 13 by the company's own disclosures, this structure removes the child's own ability to preserve a right to sue.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=Y; litigation=Y; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated, but the child-safety allegations remain in active, unresolved litigation and investigation.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Roblox  <-  Roblox Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Roblox you gave up your right to sue, your right to join a class action, and your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Roblox now faces more than 85 federal lawsuits consolidated into a single multidistrict litigation (MDL 3166) plus separate state Attorney General lawsuits (including Florida, Oklahoma, and Kentucky in 2026), all alleging the platform's chat and communication features let adults contact children with insufficient age verification or moderation. Florida's Attorney General has stated its own investigators created test accounts posing as children as young as 7 to evaluate the platform's actual safety controls in practice, rather than relying on Roblox's own safety claims. Child-safety advocacy groups have formally asked the FTC to investigate whether Roblox's engagement-driven design and virtual-currency system take advantage of children's developmental vulnerabilities. Given the severity and sensitivity of the underlying allegations, this entry deliberately stays at the level of documented regulatory/legal facts rather than describing specific incidents — the scale of consolidated litigation and the state-level investigative response are themselves the clearest signal of how seriously this is being treated by regulators and courts.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 156, "_entity_id": 247, "_entity_slug": "roblox", "_issuer": "Roblox Corporation", "_issuer_slug": "roblox-corporation", "_ticker": "RBLX", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Candy Crush / King (Microsoft-owned, via Activision Blizzard)", "Category": "Gaming (mobile)", "Terms & Conditions URL": "king.com/termsAndConditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "king.com/privacyPolicy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "King's privacy policy explicitly confirms use of player data for TARGETED ADVERTISING in partnership with third-party advertising partners, and explicitly frames continued use of its games as acceptance of that targeted-advertising data use — i.e., there is no way to play Candy Crush and opt out of data collection entirely, only an opt-in/opt-out for the advertising-targeting USE of already-collected data. Academic research (Fordham CLIP, 'Privacy in Gaming') specifically names Candy Crush Saga among mobile games analyzed for child-relevant privacy practices, given its broad, cross-generational player base that includes many children despite not being explicitly marketed as a kids' game — a 'mixed-audience' risk category the FTC has specifically flagged as an enforcement priority for 2026 COPPA compliance.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration — governed by Microsoft Services Agreement since the Activision Blizzard acquisition closed Oct 2023. Same 30-day opt-out as all Microsoft consumer services. King (Candy Crush developer) was acquired by Activision Blizzard in 2016.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "King (owned by Activision Blizzard, which Microsoft acquired in 2023) is a good example of the 'mixed-audience' COPPA risk category the FTC is now specifically targeting — a game not marketed exclusively to children but played by many of them, where age-gating is weak and behavioral/ad-tech tracking may begin before any age verification occurs.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Stockholm", "HQ State": "Sweden", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "PARENT ADDRESS ONLY — verify before using for legal notice. King is a Stockholm-based studio held through Activision Blizzard (Santa Monica, CA). Parent: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA", "Legal / Privacy Contact Email": "No published privacy email; Microsoft routes requests via microsoft.com/concern/privacy (30-day response commitment)", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ in Stockholm, Sweden (non-US)", "Parent / Ultimate Owner": "Microsoft Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Sweden) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Sweden. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] Candy Crush offers no way to stop underlying data collection, only opt-out of ad targeting\nWHAT THE TERMS SAY: King's privacy policy confirms player data is used for targeted advertising with third-party partners and frames continued use of its games as acceptance of that data use -- there is no way to play Candy Crush and opt out of the underlying data collection, only an opt-in/opt-out for how already-collected data is used for ad targeting.\nWHY IT MATTERS: Players who want to avoid data collection entirely have no option but to stop playing, since only the advertising use of the data -- not its collection -- can be limited.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-1] Lawsuit alleges a $250,000 Candy Crush tournament secretly let 'super users' cheat undetected\nWHAT THE TERMS SAY: A lawsuit alleges King/Activision Blizzard ran a Candy Crush tournament promising a $250,000 grand prize while secretly allowing 'super users' with unfair advantages and letting some players cheat by playing offline to hide their real scores, without disclosing any of this to paying, competing entrants.\nWHY IT MATTERS: If accurate, players spent real money and time chasing a prize under conditions the company allegedly knew were rigged.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Candy Crush disputes now run through Microsoft's mandatory arbitration since the ABK acquisition\nWHAT THE TERMS SAY: Candy Crush disputes are now governed by mandatory binding arbitration under the Microsoft Services Agreement, with the same 30-day opt-out as other Microsoft consumer services, following the Activision Blizzard acquisition.\nWHY IT MATTERS: Players' dispute rights over a mobile game are now folded into the same arbitration regime covering all of Microsoft's consumer products.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Ad-targeting opt-out is described but the underlying data collection cannot be avoided while playing, and the tournament-rigging claim remains an unproven allegation.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Candy Crush / King (Microsoft-owned, via Activision Blizzard)  <-  Microsoft Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Candy Crush / King (Microsoft-owned, via Activision Blizzard) you gave up your data shared corporate-wide and your right to sue. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:33:16Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "A lawsuit alleges King/Activision Blizzard ran a Candy Crush tournament promising a $250,000 grand prize while secretly allowing 'super users' with unfair advantages, letting some players cheat by playing offline to hide their real scores, and never disclosing any of this to the people spending real money and countless hours chasing the prize — the complaint alleges the company knew about the rigged conditions and let them continue anyway.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 157, "_entity_id": 248, "_entity_slug": "candy-crush-king-microsoft-owned-via-activision-blizzard", "_issuer": "Microsoft Corporation", "_issuer_slug": "microsoft-corporation", "_ticker": "MSFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "PlayStation Network (Sony)", "Category": "Gaming", "Terms & Conditions URL": "playstation.com/en-us/legal/psn-terms-of-service/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "playstation.com/en-us/legal/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ONE OF THE MOST HISTORICALLY SIGNIFICANT BREACHES IN GAMING: the 2011 PlayStation Network breach exposed personal data (name, address, email, birthdate, login credentials) of 77.1 MILLION accounts, cost Sony ~$171 MILLION, took the network offline for 3+ weeks, and triggered Congressional scrutiny and 65 separate class actions (later consolidated, settled for $15 million in games/currency/identity-theft reimbursement). The ACLU specifically criticized Sony for a slow, incomplete breach notification (learned of the breach April 19, didn't disclose full extent until a week later) — a communications failure pattern that recurs across several other breaches in this tracker. SEPARATELY, a 2023 MOVEit third-party software vulnerability (exploited by the Cl0p ransomware group, affecting 2,700+ organizations broadly) also exposed Sony employee data including detailed MEDICAL DIAGNOSES (cancer, kidney failure, liver disease) for ~50,000 current/former employees — employee-facing, not customer-facing, but illustrates the same company's repeated exposure to major breaches across a decade. A CURRENT (2026) social-engineering vulnerability lets attackers hijack PSN accounts using only an email address and a purchase date (inferable from public trophy data), by convincing sympathetic customer-service reps to disable two-factor authentication and change account emails — not a network hack, but a customer-service-process weakness.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Sony Interactive Entertainment's ToS, AAA rules. 30-day opt-out via mail to Sony Interactive Entertainment LLC, 2207 Bridgepointe Parkway, San Mateo CA 94404. The $7.85M antitrust settlement (Caccuri v. Sony, N.D. Cal.) is itself being paid as PlayStation Store credit, not cash — meaning the settlement reinforces the ecosystem the lawsuit challenged.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Sony/PlayStation now has THREE separate documented security failure categories across 15 years (2011 mega-breach, 2023 employee medical-data exposure via third-party vendor, 2026 ongoing customer-service social-engineering vulnerability) — among the most persistent multi-incident security track records found in this entire audit.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Mateo", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R4) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.classaction.org/news/7.85m-sony-antitrust-settlement-over-alleged-digital-playstation-games-monopoly-approved-by-court", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Sony Interactive Entertainment LLC (Sony Group)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Sony Interactive Entertainment LLC (Sony Group)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2011 PSN breach exposed 77.1M accounts and cost Sony ~$171M amid criticized slow disclosure\nWHAT THE TERMS SAY: The 2011 PlayStation Network breach exposed personal data -- name, address, email, birthdate, login credentials -- for 77.1 million accounts, cost Sony roughly $171 million, took the network offline for three-plus weeks, and triggered Congressional scrutiny and 65 consolidated class actions settled for $15 million in reimbursement.\nWHY IT MATTERS: The ACLU specifically criticized Sony for slow, incomplete breach notification, a pattern the tracker notes recurs across other breaches.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] Court found Sony illegally blocked retailers from selling PSN vouchers, forcing its own store\nWHAT THE TERMS SAY: A federal court found Sony violated antitrust law by illegally blocking Amazon, Best Buy, GameStop, Target, and Walmart from selling PlayStation game vouchers, forcing digital purchases through its own store; the resulting $7.85 million settlement averages just $1.14 per person, paid only as store credit spendable back inside Sony's own ecosystem.\nWHY IT MATTERS: The settlement meant to remedy the harm pays consumers in credit they must spend inside the very ecosystem the lawsuit challenged, while a separate UK case seeks billions for the same conduct.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] A 2026 vulnerability lets attackers hijack PSN accounts by tricking support reps into disabling 2FA\nWHAT THE TERMS SAY: A current 2026 social-engineering vulnerability lets attackers hijack PSN accounts using only an email address and a purchase date (inferable from public trophy data), by convincing customer-service reps to disable two-factor authentication and change account emails.\nWHY IT MATTERS: This is not a network hack but a customer-service process weakness, meaning an account can be taken over without any technical breach at all.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2011 breach and antitrust findings are well documented, but the current account-hijack vulnerability rests on an undisclosed customer-service process weakness.", "Exposure Score (0-100)": 43, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "PlayStation Network (Sony)  <-  Sony Interactive Entertainment LLC (Sony Group)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using PlayStation Network (Sony) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:33:19Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Sony spent years illegally blocking Amazon, Best Buy, GameStop, Target, and Walmart from selling PlayStation game vouchers, forcing every digital purchase through its own store instead — a federal court found this violated antitrust law. The resulting $7.85 million settlement works out to an average of just $1.14 PER PERSON (individual payouts range $0.91 to $33.66), paid only as store credit you have to spend back inside Sony's own ecosystem. Meanwhile in the UK, a SEPARATE lawsuit nicknamed 'PlayStation You Owe Us' is seeking BILLIONS in compensation for the same category of overpricing — the exact same conduct, radically different scale of consequence depending which side of the Atlantic you're on.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 158, "_entity_id": 251, "_entity_slug": "playstation-network-sony", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Xbox (Microsoft)", "Category": "Gaming", "Terms & Conditions URL": "microsoft.com/en-us/servicesagreement/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "privacy.microsoft.com/en-us/privacystatement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "$20 MILLION FTC/DOJ COPPA SETTLEMENT (2023, still governing precedent): Microsoft was found to have knowingly collected personal information (including phone numbers) from children under 13 signing up for Xbox Live WITHOUT parental notice/consent; separately, even when Microsoft DID provide some parent notice, the FTC found it was incomplete and failed to meet COPPA's specific disclosure requirements; AND when children started but did not finish creating an Xbox Live account, Microsoft retained their personal information LONGER than COPPA permits. The FTC's Samuel Levine specifically stated the resulting order 'makes clear that kids' avatars, biometric data, and health information are not exempt from COPPA' — an explicit statement that in-game avatars and biometric data collected via gaming hardware (e.g., Kinect-style sensors, controllers) count as protected children's data. ADDITIONAL CONTEXT: this $20 million COPPA fine represented just 0.03% of Microsoft's revenue for the SINGLE QUARTER it was announced in — a penalty so small relative to Microsoft's overall business that critics questioned whether it functioned as a real deterrent at all.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out via mail to Microsoft Corporation, ATTN: CELA Arbitration, One Microsoft Way, Redmond WA 98052 or email to optout@microsoft.com. $20M COPPA settlement (2023) for collecting data from under-13 users without consent. Microsoft's arbitration clause also covers LinkedIn, Outlook, OneDrive, and all other Microsoft consumer services.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is the clearest, most authoritative precedent establishing that GAME AVATARS and BIOMETRIC DATA collected through gaming hardware count as protected children's data under COPPA — a useful reference point if this audit ever needs to explain why gaming-console data practices matter as much as social media data practices for child privacy.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Redmond", "HQ State": "Washington", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA", "Legal / Privacy Contact Email": "No published privacy email; Microsoft routes requests via microsoft.com/concern/privacy (30-day response commitment)", "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R4) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.ftc.gov/news-events/news/press-releases/2023/06/ftc-will-require-microsoft-pay-20-million-over-charges-it-illegally-collected-personal-information", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Microsoft Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Microsoft Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] $20M FTC/DOJ settlement found Microsoft collected under-13 kids' data on Xbox Live without consent\nWHAT THE TERMS SAY: The FTC/DOJ found Microsoft knowingly collected personal information, including phone numbers, from children under 13 signing up for Xbox Live without parental notice or consent, gave incomplete notice even when some was provided, and retained incomplete signups' data longer than COPPA permits.\nWHY IT MATTERS: The $20 million settlement amounted to just 0.03% of Microsoft's revenue for the single quarter it was announced in, leading critics to question whether it functions as a real deterrent.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[BIOMETRICS · FL-2] FTC says kids' avatars and biometric data from gaming hardware count as protected COPPA data\nWHAT THE TERMS SAY: The FTC's Samuel Levine stated the settlement order 'makes clear that kids' avatars, biometric data, and health information are not exempt from COPPA,' establishing that in-game avatars and biometric data collected via gaming hardware count as protected children's data.\nWHY IT MATTERS: This confirms gaming-console data practices carry the same child-privacy stakes as social media data practices.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration for Xbox disputes also covers LinkedIn, Outlook, and OneDrive\nWHAT THE TERMS SAY: Microsoft's mandatory binding arbitration clause with class action waiver, with a 30-day opt-out, covers Xbox alongside LinkedIn, Outlook, OneDrive, and all other Microsoft consumer services.\nWHY IT MATTERS: A single arbitration regime spanning gaming, email, cloud storage, and professional-networking accounts concentrates a large share of a user's digital life under one dispute-resolution clause.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The FTC settlement, its specific findings, and its consequences are clearly and specifically documented.", "Exposure Score (0-100)": 44, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 6/30 (biometric_collection+6) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Xbox (Microsoft)  <-  Microsoft Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Xbox (Microsoft) you gave up your biometric identifiers, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:33:20Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Microsoft's $20 million COPPA fine for collecting children's data on Xbox Live without parental consent worked out to just 0.03% of Microsoft's revenue for the SINGLE QUARTER the settlement was announced in — a fraction so small that critics questioned whether it could function as any real deterrent to a company Microsoft's size. The FTC specifically said the case established that kids' AVATARS and BIOMETRIC DATA collected through a game console count as protected children's data just like a name or email address would.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 159, "_entity_id": 252, "_entity_slug": "xbox-microsoft", "_issuer": "Microsoft Corporation", "_issuer_slug": "microsoft-corporation", "_ticker": "MSFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "TurboTax (Intuit)", "Category": "Finance/Tax", "Terms & Conditions URL": "turbotax.intuit.com/legal/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "turbotax.intuit.com/privacy-security", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Separate, still-early-stage class actions allege TurboTax shared user data with advertisers (no approved settlement as of Feb 2026); a Canadian class action (Foreman & Company v. Intuit, filed May 2025) is separately gaining momentum as more taxpayers report notices from the Canada Revenue Agency.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver and jury trial waiver. AAA rules, California law. Nuclear clause: if class waiver unenforceable, entire Disputes Section voids. CONTESTED: a federal judge (Judge Breyer, N.D. Cal.) found the clause too inconspicuous to bind users (2020) — the 9th Circuit REVERSED, ruling the 'Sign In' button constituted agreement despite the terms being 15,000+ words. Intuit then faced 100,000+ individual arbitration demands. The $141M multistate settlement (May 2022) was a SEPARATE proceeding from the FTC administrative action (which the 5th Circuit vacated in 2026).", "Fees / Billing Flags": "TWO COMPLETED SETTLEMENTS totaling $141 MILLION (2022): (1) a 50-state-AG multistate settlement, and (2) a parallel FTC action — both over Intuit's years-long 'free, free, free' advertising campaign for TurboTax Free Edition, which excluded roughly two-thirds of filers (gig workers with 1099 income, student-loan-interest filers, even simple unemployment income) who were then upsold mid-filing to paid products costing $60–$120. ~4.4 million consumers received ~$30 checks. MAJOR 2026 LEGAL TWIST: the 5th Circuit Court of Appeals VACATED the FTC's related 20-year cease-and-desist order in March 2026, ruling (citing the Supreme Court's SEC v. Jarkesy decision) that deceptive-advertising claims are similar enough to common-law fraud that they must be tried in a federal court with a jury, NOT decided internally by the FTC's own administrative law judges — a major, still-unresolved separation-of-powers ruling that could reshape how the FTC enforces consumer protection law against many other companies in this audit going forward, not just Intuit.", "Notes": "This is one of the most legally significant developments in the entire tracker: if the 5th Circuit's reasoning holds and spreads to other circuits, it could weaken the FTC's ability to quickly resolve deceptive-advertising cases against ANY company without a full federal court trial — worth monitoring as a cross-cutting regulatory development, not just a TurboTax issue.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R4) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Intuit Inc.", "Years Referenced in Finding (heuristic)": "2024, 2023, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Intuit Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] After a 2024 breach, a plaintiff got a fake IRS letter containing his real SSN and exact tax owed\nWHAT THE TERMS SAY: After the 2024 TurboTax/Credit Karma breach, one named plaintiff received a fraudulent letter impersonating the IRS that contained his actual Social Security number and the exact amount he owed on his 2023 taxes -- details precise enough that the real IRS had to confirm the letter wasn't genuine.\nWHY IT MATTERS: Breached tax data can be weaponized into scams precise enough to be mistaken for genuine government correspondence.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-1] $141M settlement resolved a years-long 'free, free, free' ad campaign that excluded 2/3 of filers\nWHAT THE TERMS SAY: A $141 million multistate-AG and FTC settlement resolved Intuit's years-long 'free, free, free' advertising for TurboTax Free Edition, which excluded roughly two-thirds of filers who were then upsold mid-filing to paid products costing $60-$120; about 4.4 million consumers received roughly $30 checks.\nWHY IT MATTERS: Roughly two-thirds of filers were excluded from the advertised 'free' product and were upsold mid-filing to paid products costing $60-$120, while about 4.4 million consumers received roughly $30 checks.\n(evidence: Fees; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[CLASS_ACTION_WAIVER · FL-3] A 'nuclear clause' voids the entire disputes section if the class action waiver is ever struck down\nWHAT THE TERMS SAY: TurboTax's arbitration clause includes a 'nuclear clause' voiding the entire Disputes Section if the class action waiver is found unenforceable; a federal judge found the clause too inconspicuous to bind users in 2020, but the 9th Circuit reversed, ruling that clicking 'Sign In' constituted agreement despite 15,000-plus words of terms, after which Intuit faced 100,000+ individual arbitration demands.\nWHY IT MATTERS: Courts have actively disagreed over whether users meaningfully agreed to this clause at all, yet the ruling that stood treats a login click as binding consent to a lengthy, unread document.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=Y; penalty=Y; litigation=Y; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Major settlements and a breach are well documented, but current data-sharing-with-advertisers allegations remain unresolved.", "Exposure Score (0-100)": 46, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_30d+3) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 16/20 (severity3+8, breach+3, penalty+3, litigation+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "TurboTax (Intuit)  <-  Intuit Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to a jury.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using TurboTax (Intuit) you gave up your right to sue, your right to join a class action, your right to a jury, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "After the 2024 TurboTax/Credit Karma breach, one named plaintiff received a FRAUDULENT LETTER impersonating the IRS — the fake letter contained his ACTUAL Social Security number and the exact amount he really owed on his 2023 taxes, details precise enough that the real IRS had to confirm the letter wasn't genuine. As of 2026, there are THREE separate active TurboTax lawsuits running at once (free-filing deception, tax-fraud facilitation, and privacy violations), and the confusion has spawned a wave of social-media scams: fake TikTok and Facebook posts promise an immediate '$2,500 TurboTax payout' — a real number, but one that's just a plaintiff-side legal estimate from an UNRELATED, still-pending case, not money anyone can actually claim right now.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 160, "_entity_id": 254, "_entity_slug": "turbotax-intuit", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "H&R Block", "Category": "Finance/Tax", "Terms & Conditions URL": "hrblock.com/online-tax-filing/legal.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "hrblock.com/online-tax-filing/privacy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not itemized separately from the FTC finding below.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out via hrblock.com/goto/optout OR signed letter to H&R Block Arbitration Opt-Out, PO Box 32818, Kansas City MO 64171. Unique feature: a BELLWETHER PROCEDURE for mass arbitration — when 25+ claimants with coordinated counsel raise similar claims, only a limited number of test cases proceed at a time, which slows the mass-arbitration weapon that forced Amazon to drop arbitration entirely. ACTIVELY LITIGATED: Rios v. HRB Digital (N.D. Cal., appeal to 9th Circuit filed July 20, 2026) — Judge Chen found the clause procedurally unconscionable due to the bellwether provision and refused to compel arbitration. H&R Block is appealing, arguing a separate case (Pabon, E.D.N.Y.) found the 30-day opt-out cured unconscionability. The underlying claim: H&R Block's online tax software used tracking pixels to transmit confidential tax return data (names, income, dependents, credits) to Meta and Google without consent.", "Fees / Billing Flags": "$7 MILLION FTC SETTLEMENT (finalized 2025, following a Feb 2024 complaint): the FTC found H&R Block engaged in unfair/deceptive practices by making customers who wanted to DOWNGRADE to a cheaper product contact customer service unnecessarily, and then, once the downgrade succeeded, WIPING THEIR PREVIOUSLY ENTERED TAX DATA — forcing them to start over from scratch. The FTC found this data-wiping penalty led some customers to just stick with the more expensive product rather than lose their work, effectively trapping them in an upsell. H&R Block must stop this data-wiping-on-downgrade practice by 2026 and must now disclose either the percentage of taxpayers eligible for its 'free' products or state plainly that most taxpayers don't qualify.", "Notes": "The 'wipe your data if you try to downgrade' mechanism is a distinctive and clever dark pattern worth flagging on its own — it doesn't block the downgrade outright, it just makes the downgrade prohibitively costly in time/effort, which is arguably more insidious than a blocked button.\n\nDATA-QUALITY CORRECTION (Aug 2026): the Fortune 500 metadata columns on this row previously held data for BLOCK, INC. (the Jack Dorsey company formerly named Square, HQ Oakland CA, ticker XYZ/SQ) — a fuzzy-match error from the F500 population script, which matched the string 'Block'. H&R Block is a wholly unrelated tax preparation company headquartered in Kansas City, Missouri. The incorrect metadata has been CLEARED rather than replaced, because correct H&R Block figures were not independently verified this pass. Repopulate from a primary source before relying on this row's metadata. TRACKER-LEVEL WARNING: this is the failure mode the project guide's fuzzy-match dedup discipline is meant to catch, and it ran in the opposite direction — not merging two rows for one company, but assigning one company's data to a different company with a similar name. Any future F500 repopulation should validate matches on ticker or website, not on name string similarity alone.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Kansas City", "HQ State": "Missouri", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Missouri' is a non-DMV US state", "Parent / Ultimate Owner": "H&R Block, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Missouri SOS Business Search — bsd.sos.mo.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: H&R Block, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] RICO class action alleges H&R Block, Meta, and Google illegally harvested and shared people's tax data\nWHAT THE TERMS SAY: A class action invoking the federal RICO Act alleges H&R Block, Meta, and Google worked together to illegally harvest and share people's tax data (income, deductions, filing details) without consent. Separately, the arbitration case Rios v. HRB Digital centers on an underlying claim that H&R Block's online tax software used tracking pixels to transmit confidential tax return data to Meta and Google, and a separate mass-arbitration investigation alleges H&R Block's website shared customers' financial information with Facebook through embedded tracking tools.\nWHY IT MATTERS: If accurate, some of a person's most sensitive financial details would have been routed to advertising companies without their knowledge while they filed taxes.\n(evidence: Arbitration | SCARY; Tracker says unconfirmed (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "[DARK_PATTERN_CONSENT · FL-1] $7M FTC settlement found H&R Block wiped customers' entered tax data if they tried to downgrade\nWHAT THE TERMS SAY: The FTC found H&R Block made customers who wanted to downgrade to a cheaper product contact customer service unnecessarily, then wiped their previously entered tax data once the downgrade succeeded, forcing them to start over; the FTC found this led some customers to stay with the pricier product rather than lose their work.\nWHY IT MATTERS: The company must stop this practice by 2026 and now must disclose either the percentage of taxpayers eligible for its 'free' products or state plainly that most don't qualify.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] A federal judge found H&R Block's arbitration clause procedurally unconscionable over its bellwether rule\nWHAT THE TERMS SAY: H&R Block's arbitration clause includes a bellwether procedure that lets only a limited number of test cases proceed when 25 or more claimants raise similar claims; in Rios v. HRB Digital, a federal judge found this procedurally unconscionable and refused to compel arbitration, a ruling H&R Block is now appealing.\nWHY IT MATTERS: The bellwether provision slows the mass-arbitration weapon that forced Amazon to drop arbitration entirely, and Judge Chen found the clause procedurally unconscionable because of it - a ruling H&R Block is appealing, arguing a separate case (Pabon, E.D.N.Y.) found the 30-day opt-out cured unconscionability.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=Y; litigation=Y; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The FTC settlement and downgrade dark pattern are clearly confirmed, but the tracking-pixel tax-data-sharing claims remain contested allegations in ongoing litigation.", "Exposure Score (0-100)": 47, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "H&R Block  <-  H&R Block, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using H&R Block you gave up your data shared corporate-wide, your right to sue, your right to join a class action, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A class action filed against H&R Block, Meta, AND Google invokes the federal RICO Act — the law originally built to prosecute organized crime — alleging the three companies worked together to illegally harvest and share people's actual TAX DATA (income, deductions, filing details) without consent. Separately, a mass-arbitration investigation alleges H&R Block's website secretly shared customers' financial information with Facebook through embedded tracking tools. And the same 'if you try to downgrade to a cheaper product, we wipe your entered data and make you start over' design already documented for H&R Block elsewhere in this tracker means even customers who tried to avoid this exact privacy exposure by switching plans could be penalized with lost work for trying.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 161, "_entity_id": 256, "_entity_slug": "h-r-block", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Credit Karma (Intuit)", "Category": "Finance", "Terms & Conditions URL": "creditkarma.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "creditkarma.com/about/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not itemized separately from the FTC finding below.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver — governed by Intuit's Website ToS, same clause as TurboTax. Credit Karma was acquired by Intuit in 2020 for $8.1B. A July 2024 class action (N.D. Cal.) alleges Intuit failed to prevent TurboTax AND Credit Karma data breaches — the arbitration clause is the likely defense.", "Fees / Billing Flags": "COMPLETED FTC SETTLEMENT ($3 million, 2022/2023, FTC Docket C-4781): the FTC found Credit Karma sent consumers marketing emails with subject lines like 'Congrats! You're pre-approved for an American Express Card' when, according to the FTC, Credit Karma KNEW many recipients did NOT actually qualify for those cards — with one credit-card-company partner explicitly stating it does not 'preapprove, prequalify, or preselect' consumers the way Credit Karma's marketing implied. Consumers who clicked through and applied, believing approval was all but guaranteed, sometimes had their credit scores dinged by the resulting hard inquiry despite being denied — a real, quantifiable harm from the deceptive marketing (a hard credit inquiry that doesn't result in approval still affects a credit score).", "Notes": "Credit Karma is owned by Intuit (same parent as TurboTax, also documented elsewhere in this tracker for its own FTC 'free' advertising issues) — both companies under Intuit have now been separately cited by the FTC for structurally similar 'implied guarantee that isn't real' marketing patterns (free tax filing vs. pre-approved credit cards).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Oakland", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Intuit Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Intuit Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] $3M FTC settlement found Credit Karma sent 'pre-approved' emails to people it knew didn't qualify\nWHAT THE TERMS SAY: The FTC found Credit Karma sent marketing emails like 'Congrats! You're pre-approved' for credit cards when it knew many recipients did not actually qualify, per the $3 million FTC settlement (Docket C-4781); a partner explicitly stated it does not 'preapprove, prequalify, or preselect' consumers as Credit Karma's marketing implied.\nWHY IT MATTERS: Consumers who applied believing approval was all but guaranteed sometimes had their credit scores dinged by a hard inquiry despite being denied -- a real, quantifiable harm from the deceptive marketing.\n(evidence: Fees | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] A 2024 class action alleges Intuit failed to prevent breaches at both TurboTax and Credit Karma\nWHAT THE TERMS SAY: A July 2024 class action in N.D. Cal. alleges Intuit failed to prevent data breaches affecting both TurboTax and Credit Karma.\nWHY IT MATTERS: If accurate, Credit Karma users' data may have been exposed alongside TurboTax's in incidents Intuit allegedly could have prevented.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Credit Karma's mandatory arbitration clause is the likely defense against the 2024 breach suit\nWHAT THE TERMS SAY: Credit Karma's mandatory binding arbitration with class action waiver, governed by Intuit's Website ToS (the same clause as TurboTax), is described as the likely defense against the 2024 class action over the alleged breach failures.\nWHY IT MATTERS: The same arbitration clause that covers everyday disputes may also be used to block a collective claim over the breach allegations themselves.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The $3M FTC settlement is clearly documented, but the 2024 breach-related class action allegations are not independently confirmed this pass.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Credit Karma (Intuit)  <-  Intuit Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Credit Karma (Intuit) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:33:40Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The FTC found Credit Karma sent people emails saying 'Congrats! You're pre-approved' for credit cards it KNEW many of them didn't actually qualify for — people who applied anyway, believing approval was all but guaranteed, sometimes got a HARD CREDIT INQUIRY that dinged their score, on top of being denied the card they were told they'd already been pre-approved for.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 162, "_entity_id": 257, "_entity_slug": "credit-karma-intuit", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Mint (Intuit)", "Category": "Finance", "Terms & Conditions URL": "mint.intuit.com/legal/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "mint.intuit.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same parent company (Intuit) as TurboTax and Credit Karma, both documented elsewhere in this tracker for their own FTC actions ($141M TurboTax 'free' advertising settlement; $3M Credit Karma 'pre-approved' settlement) — no Mint-specific lawsuit independently confirmed this pass.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver — governed by Intuit's ToS. NOTE: Intuit SHUT DOWN Mint on March 23, 2024, and migrated users to Credit Karma. The arbitration clause survived the product shutdown and governs any remaining disputes over the transition, including questions about what happened to Mint users' financial data after the shutdown.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "IMPORTANT STATUS NOTE: Intuit has been SUNSETTING Mint and migrating users to Credit Karma — if this audit is meant to reflect currently-active apps, confirm Mint's current operational status directly, since it may no longer be accepting new users or may have already shut down by the time this tracker is used.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.attorneygeneral.gov/taking-action/attorney-general-henry-announces-141-million-settlement-for-millions-of-americans-decieved-by-turbotax-owner-intuit/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Intuit Inc. (Mint shut down March 23, 2024; users migrated to Credit Karma)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Intuit Inc. (Mint shut down March 23, 2024; users migrated to Credit Karma)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-4] Mint's arbitration clause outlived the app itself and now governs disputes over its shutdown\nWHAT THE TERMS SAY: Intuit shut down Mint on March 23, 2024 and migrated users to Credit Karma, but the mandatory binding arbitration clause survived the shutdown and now governs any remaining disputes over the transition, including questions about what happened to Mint users' financial data afterward.\nWHY IT MATTERS: Users seeking answers about what became of their financial data after a product's discontinuation must go through arbitration rather than court, even though the product itself no longer exists.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[UNILATERAL_CHANGES · FL-4] Mint users were migrated to Credit Karma when the app was sunset, with no lawsuit specific to Mint\nWHAT THE TERMS SAY: Intuit has been sunsetting Mint and migrating its users to Credit Karma; the tracker notes no Mint-specific lawsuit was independently confirmed this pass, and recommends confirming Mint's current operational status and whether user accounts and data were simply folded into Credit Karma.\nWHY IT MATTERS: Users who still think of Mint as active may not realize their account and data have already been absorbed into a different product.\n(evidence: Notes | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two Mint-specific items are supported; the $141M TurboTax and $3M Credit Karma settlements referenced in this row belong to sibling companies under the same Intuit umbrella, not to Mint itself, and no Mint-specific lawsuit was independently confirmed this pass.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Mint has no independently confirmed lawsuit of its own, and what happened to migrated users' data after the shutdown is not explained.", "Exposure Score (0-100)": 53, "Exposure Band": "High", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 9, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 9/20 (unilateral_modification+5, termination_or_confiscation+4) | Record 20/20 (severity5+20) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Mint (Intuit)  <-  Intuit Inc. (Mint shut down March 23, 2024; users migrated to Credit Karma)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Mint (Intuit) you gave up your right to sue, your right to join a class action, your right to keep what you paid for, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:33:46Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Mint shares Intuit's corporate family with TurboTax ($141M FTC settlement over 'free' filing deception) and Credit Karma ($3M settlement over fake pre-approval offers) — and is now being SUNSET by Intuit entirely, with users pushed toward Credit Karma instead. If you're one of the many people who still think of Mint as active, it's worth confirming your account and data haven't simply been quietly folded into a different product.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 163, "_entity_id": 258, "_entity_slug": "mint-intuit", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ticketmaster / Live Nation", "Category": "Events/Ticketing", "Terms & Conditions URL": "ticketmaster.com/legal-info/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "ticketmaster.com/legal-info/privacy-information", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Active data breach class action still moving through federal court as of 2026 (details not independently confirmed in full this pass) — one of three parallel legal 'rings' facing the company alongside hidden-fees litigation and the antitrust case below.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. Live Nation Entertainment ToS, AAA rules. Given the DOJ's May 2024 antitrust lawsuit alleging Live Nation/Ticketmaster maintains an illegal monopoly over live events (the case is ongoing), the arbitration clause directly affects consumers' ability to pursue individual claims over monopoly pricing. The class action waiver is the company's primary defense against coordinated consumer relief.", "Fees / Billing Flags": "MAJOR VERDICT (April 15, 2026): after a 5-week federal trial, a jury found Live Nation/Ticketmaster UNLAWFULLY MONOPOLIZED the live entertainment market — Ticketmaster controls ~86% of primary ticketing at major venues, Live Nation's promotion arm handles ~70% of promotion, and the two together used a 'flywheel' of vertically integrated market power (artist management + venues + promotion + ticketing) to shut out competitors. Internal company communications entered as evidence included references to using a 'velvet hammer' against competitors and language about 'robbing [concert-goers] blind.' Mid-trial, the DOJ settled with Live Nation for BEHAVIORAL remedies only (permitting multi-vendor ticketing, opening some amphitheaters to outside promoters, capping some fees at 15%) rather than the structural breakup (Ticketmaster divestiture) originally sought — but a coalition of 33+ state attorneys general REJECTED that settlement and continued litigating independently, arguing it 'does not adequately remedy the harm' to consumers.", "Notes": "The 'robbing them blind' internal quote, entered as evidence in a federal antitrust trial the company LOST, is about as damning and quotable a finding as exists anywhere in this entire 185-company audit — worth flagging prominently. Also notable that state AGs are actively pushing for MORE than what the federal government settled for, an unusual dynamic worth watching for final resolution.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Beverly Hills", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Live Nation Entertainment, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Live Nation Entertainment, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Jury found Live Nation/Ticketmaster illegally monopolized live entertainment via a 'flywheel' of control\nWHAT THE TERMS SAY: After a 5-week federal trial, a jury found Live Nation/Ticketmaster unlawfully monopolized the live entertainment market -- Ticketmaster controls about 86% of primary ticketing at major venues, Live Nation's promotion arm handles about 70% of promotion -- using a vertically integrated 'flywheel' of artist management, venues, promotion, and ticketing; internal communications entered as evidence referenced a 'velvet hammer' against competitors and 'robbing [concert-goers] blind.'\nWHY IT MATTERS: A jury has already found the company's market dominance illegal, based partly on internal language describing tactics against fans in strikingly blunt terms.\n(evidence: Fees | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] 33+ state AGs rejected the DOJ's behavioral-only settlement as inadequate and kept litigating\nWHAT THE TERMS SAY: Mid-trial, the DOJ settled with Live Nation for behavioral remedies only -- permitting multi-vendor ticketing, opening some amphitheaters to outside promoters, capping some fees at 15% -- rather than the structural breakup originally sought; a coalition of 33-plus state attorneys general rejected that settlement and continued litigating independently, arguing it 'does not adequately remedy the harm.'\nWHY IT MATTERS: The federal government and a majority of states disagree on whether the remedy actually fixes the harm to consumers, leaving the ultimate outcome unresolved.\n(evidence: Fees | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration and a class waiver limit individual claims over the monopoly's pricing\nWHAT THE TERMS SAY: Live Nation Entertainment's Terms of Service require mandatory binding arbitration under AAA rules with a class action waiver and a 30-day opt-out; given the DOJ's antitrust suit, the clause directly affects consumers' ability to pursue individual claims over monopoly pricing, with the class waiver as the company's primary defense against coordinated relief.\nWHY IT MATTERS: Even where a jury has found illegal monopolization, individual consumers face an arbitration-only path with no ability to band together in court.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The antitrust verdict and its aftermath are clearly documented, but the separate data breach class action's details are not independently confirmed this pass.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Ticketmaster / Live Nation  <-  Live Nation Entertainment, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ticketmaster / Live Nation you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Internal Live Nation/Ticketmaster communications, entered as evidence in the federal antitrust trial the company LOST in April 2026, reportedly included staff describing tactics as a 'velvet hammer' against competitors and talking about 'robbing [concert-goers] blind.' A jury found the company illegally monopolized live entertainment, controlling roughly 86% of primary ticketing at major venues. The DOJ settled for behavioral fixes rather than breaking the company up — and more than 33 state Attorneys General REJECTED that settlement outright, arguing it doesn't come close to fixing the harm to ordinary fans.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 164, "_entity_id": 260, "_entity_slug": "ticketmaster-live-nation", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "StubHub", "Category": "Events/Ticketing", "Terms & Conditions URL": "stubhub.com/legal-notices/user-agreement/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "stubhub.com/legal-notices/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not itemized separately from the FTC finding below.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. StubHub User Agreement, AAA rules. 30-day opt-out. StubHub was sold from eBay to viagogo in Feb 2020; the combined entity is now the world's largest ticket resale marketplace. Given the Ticketmaster antitrust DOJ lawsuit (2024), ticket-marketplace T&C is an increasingly scrutinized area.", "Fees / Billing Flags": "$10 MILLION FTC SETTLEMENT (April 2026): the nation's largest ticket resale platform was found to have violated the FTC's new 'Fees Rule' (effective May 12, 2025, requiring upfront total-price disclosure) by advertising ticket prices without clearly disclosing mandatory fees — specifically over a 3-day period right when the rule took effect (May 12–14, 2025). Separate, still-active state-specific mass-arbitration investigations (e.g., New York) allege StubHub's ticket-selection pages show one price (e.g., $405) that jumps significantly higher ($522) only after a ticket is selected, allegedly violating New York's Arts and Cultural Affairs Law requiring total-cost disclosure before selection.", "Notes": "This is one of the first enforcement actions under the FTC's brand-new Fees Rule — useful precedent since it shows the rule has real teeth almost immediately after taking effect, unlike the still-pending food-delivery fee rulemaking noted elsewhere in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "viagogo Entertainment Inc. (acquired 2020)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: viagogo Entertainment Inc. (acquired 2020)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] $10M FTC settlement found StubHub hid mandatory fees right as the new Fees Rule took effect\nWHAT THE TERMS SAY: The FTC's $10 million settlement (April 2026) found StubHub violated the FTC's new Fees Rule (effective May 12, 2025) by advertising ticket prices without clearly disclosing mandatory fees over a 3-day window (May 12-14, 2025) right when the rule took effect; StubHub's service fees have reportedly added 22% to 45% on top of the listed price, revealed only deep into checkout.\nWHY IT MATTERS: Consumers select tickets based on a price that can rise by nearly half before checkout, the exact 'drip pricing' the new Fees Rule was designed to stop.\n(evidence: Fees | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DARK_PATTERN_CONSENT · FL-1] New York investigation alleges StubHub's ticket pages show one price, then a higher one after selection\nWHAT THE TERMS SAY: A separate, active New York mass-arbitration investigation alleges StubHub's ticket-selection pages show one price (e.g., $405) that jumps significantly higher ($522) only after a ticket is selected, allegedly violating New York's Arts and Cultural Affairs Law requiring total-cost disclosure before selection.\nWHY IT MATTERS: If accurate, consumers commit to a ticket before learning its real, higher price.\n(evidence: Fees; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-1] Lawsuit alleges StubHub's own CEO has an ownership stake in a large-scale ticket-reselling operation\nWHAT THE TERMS SAY: A July 2026 lawsuit alleges StubHub CEO Eric Baker has an ownership stake in a large-scale professional ticket-reselling operation that has sold inventory through StubHub for years, while the company markets itself to ordinary customers as a simple 'fan-to-fan' marketplace; StubHub says the relationship was disclosed in SEC filings, just not to customers.\nWHY IT MATTERS: If accurate, the platform's leadership may personally profit from the professional resellers competing against ordinary fans for the same tickets, without customers ever being told.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=Y; litigation=Y; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The FTC fee-disclosure settlement is clearly confirmed, but the CEO conflict-of-interest allegation and the New York price-jump investigation remain unresolved.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "StubHub  <-  viagogo Entertainment Inc. (acquired 2020)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using StubHub you gave up your right to sue, your right to join a class action, and your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A July 2026 lawsuit alleges StubHub's OWN CEO, Eric Baker, has an ownership stake in a large-scale professional ticket-reselling operation that has sold inventory through StubHub for YEARS — while the company markets itself to ordinary customers as a simple 'fan-to-fan' marketplace, not a platform where the person running it may personally profit from the professional scalpers competing against regular fans for the same tickets. StubHub says the relationship was disclosed in SEC filings, just not to the customers actually buying tickets. Separately, StubHub's service fees have reportedly added 22% to 45% on top of the listed ticket price, revealed only deep into checkout — the same 'drip pricing' the FTC's new Fees Rule was specifically designed to stop.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 165, "_entity_id": 262, "_entity_slug": "stubhub", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Waze (Google)", "Category": "Navigation", "Terms & Conditions URL": "waze.com/legal/tos", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "waze.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Owned by Google since 2013; governed largely by Google's overall privacy framework, though Waze maintains its own separate Terms/Privacy documents. Waze's core feature (crowdsourced, real-time location sharing with other drivers to report traffic/hazards/police locations) inherently involves more granular, real-time location broadcasting than typical mapping apps — not independently confirmed with a specific named lawsuit this pass, but worth flagging as a structurally higher-location-exposure product than Google Maps' more passive navigation model.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration — governed by Google's terms since Waze's acquisition (2013, $1.15B). 30-day opt-out. Waze collects continuous real-time GPS location data while driving — the arbitration clause covers disputes over this location tracking, which is among the most granular location data any consumer app collects.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up specifically on Waze's real-time location-sharing defaults, given the app's crowdsourced design is structurally different from passive-navigation apps like Google Maps.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R4) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alphabet Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Waze's 'Invisible Mode' hides your icon from others but does not stop location data collection\nWHAT THE TERMS SAY: Waze collects continuous real-time GPS location data while driving, among the most granular location data any consumer app collects; its 'Invisible Mode' only hides a user's car icon from other users on the map and does not stop the underlying location data collection, which Waze researchers describe as continuing even in the background when not actively navigating.\nWHY IT MATTERS: A privacy feature that sounds like it stops tracking actually only changes what other users can see, not what the company itself continues to collect.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-3] Waze's disputes run through Israeli courts while sibling app Google Maps uses US courts\nWHAT THE TERMS SAY: Waze's Terms specify Israeli law and Israeli courts govern any dispute, while Google Maps, under the same parent company, uses California law and US courts -- a difference that has persisted for thirteen years since Google's 2013 acquisition of Waze.\nWHY IT MATTERS: Academic research cited in the tracker finds barely 0.05% to 0.22% of consumers ever open and read a privacy policy, which is precisely why a jurisdiction clause like this can go unnoticed for over a decade.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration under Google's terms covers disputes over Waze's continuous GPS tracking\nWHAT THE TERMS SAY: Since Google's 2013 acquisition, Waze disputes are governed by mandatory binding arbitration under Google's terms with a 30-day opt-out, covering disputes over Waze's continuous real-time GPS location tracking.\nWHY IT MATTERS: Disputes over some of the most granular location data any consumer app collects are funneled into arbitration rather than court.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Location-tracking and jurisdiction terms are clearly described, but no specific lawsuit or enforcement action has been independently confirmed.", "Exposure Score (0-100)": 21, "Exposure Band": "Low", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Waze (Google)  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Waze (Google) you gave up your physical movements and your right to sue. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "2026-09-08T19:33:54Z (HTTP 200, CHANGED)", "SCARY (most astonishing T&C item)": "Waze and Google Maps are both owned by Google — but Waze's Terms specify ISRAELI LAW and ISRAELI COURTS govern any dispute, while Google Maps uses California law and US courts. Same parent company, two completely different legal systems depending which of its map apps you happen to use, thirteen years after Google bought Waze. On top of that, Waze's own 'Invisible Mode' only hides your car icon from OTHER USERS on the map — it does NOT stop the underlying location data collection itself, which Waze researchers describe as continuing even in the background when you're not actively navigating. Academic research also finds barely 0.05% to 0.22% of consumers ever actually open and read a privacy policy like this one — which is precisely why a jurisdiction clause like this can sit in plain sight for over a decade without most users ever knowing it's there.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 166, "_entity_id": 263, "_entity_slug": "waze-google", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Nextdoor", "Category": "Social/Local", "Terms & Conditions URL": "nextdoor.com/about/tou/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "nextdoor.com/privacy_policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Active mass arbitration investigation (2026): attorneys believe Nextdoor uses tracking technology to share users' PRECISE LOCATION DATA with Microsoft, potentially violating state/federal privacy law — notable specifically because Nextdoor is a NEIGHBORHOOD-based platform where precise location is inherently more sensitive/identifying than on a general social network, since users' posts are already implicitly tied to a small geographic radius. Nextdoor's current privacy policy (effective Jan 1, 2026) does explicitly bar children under 13 from using the platform and does offer opt-outs for targeted advertising in certain states.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. Nextdoor ToS, AAA rules, California law. Nextdoor's hyperlocal model means the arbitration clause covers disputes over neighborhood-level data (verified home addresses, neighborhood crime reports, local business reviews) — among the most geographically precise consumer data any social platform collects.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The 'shares location with Microsoft' finding is notable since Microsoft (via Xbox, Nextdoor, and its own 365/Outlook products) now appears in THREE separate rows of this tracker with distinct privacy findings — worth flagging Microsoft's cross-product data-sharing footprint as a pattern.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R4) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Nextdoor Holdings, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Nextdoor Holdings, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Nextdoor's hyperlocal model ties verified home addresses and reviews to a small geographic radius\nWHAT THE TERMS SAY: Nextdoor's hyperlocal model means its arbitration clause covers disputes over neighborhood-level data -- verified home addresses, neighborhood crime reports, and local business reviews -- among the most geographically precise consumer data any social platform collects.\nWHY IT MATTERS: Because posts are already tied to a small geographic radius, this location data is inherently more identifying than on a general social network.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Attorneys are investigating whether Nextdoor secretly shares precise location data with Microsoft\nWHAT THE TERMS SAY: An active 2026 mass-arbitration investigation examines whether Nextdoor uses tracking technology to share users' precise location data with Microsoft, potentially violating state or federal privacy law.\nWHY IT MATTERS: If confirmed, simply having both a Nextdoor account and a Microsoft account could mean a user's neighborhood-app location history feeds a separate tech giant's advertising business.\n(evidence: Data Sharing | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with a 30-day opt-out covers Nextdoor's hyperlocal data disputes\nWHAT THE TERMS SAY: Nextdoor's Terms of Service require mandatory binding arbitration under AAA rules and California law, with a class action waiver and a 30-day opt-out.\nWHY IT MATTERS: This limits how neighborhood-level data disputes, including the Microsoft-sharing investigation, can be pursued collectively.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The hyperlocal data model is clearly described, but whether Nextdoor actually shares location data with Microsoft remains an open, unconfirmed investigation.", "Exposure Score (0-100)": 42, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Nextdoor  <-  Nextdoor Holdings, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Nextdoor you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, and your right to join a class action. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "As of March 2026, attorneys are actively investigating whether Nextdoor secretly shares your LOCATION DATA with Microsoft for advertising purposes — meaning simply having BOTH a Nextdoor account and a Microsoft Outlook/Office account could mean your neighborhood-app location history is quietly feeding an entirely separate tech giant's ad business. Nextdoor's own 2026 investor filings confirm it now reaches 1 IN 3 US HOUSEHOLDS and is actively expanding AI-driven content personalization — growth funded largely through the same advertising platform this investigation is questioning.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 167, "_entity_id": 265, "_entity_slug": "nextdoor", "_issuer": "Nextdoor Holdings, Inc.", "_issuer_slug": "nextdoor-holdings-inc", "_ticker": "KIND", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Yelp", "Category": "Local/Reviews", "Terms & Conditions URL": "yelp.com/static?p=tos", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "yelp.com/static?p=privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or FTC action — recommend direct follow-up given Yelp's business model relies heavily on location data and business-review behavioral profiling.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver and jury trial waiver. AAA rules, California law. 30-day opt-out via email to arbitration-opt-out@yelp.com. Covers both consumer users and business owner accounts.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Queued for a dedicated follow-up pass; thin verification this session relative to most other companies in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Yelp Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Yelp Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Yelp's entire business model runs on location data and behavioral profiling of user activity\nWHAT THE TERMS SAY: Yelp's business model relies on location data and behavioral profiling of where users go and what they think of it.\nWHY IT MATTERS: The tracker describes this as a genuinely under-researched privacy profile relative to how much real-world movement and opinion data the app has access to.\n(evidence: SCARY | Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with class and jury waivers covers both consumer and business-owner accounts\nWHAT THE TERMS SAY: Yelp's Terms require mandatory binding arbitration with a class action waiver and jury trial waiver under AAA rules and California law, with a 30-day opt-out via email, covering both consumer users and business owner accounts.\nWHY IT MATTERS: Both ordinary users and the businesses reviewed on the platform give up their right to a jury trial and to band together in a lawsuit.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two items are supported; the row states Yelp's specific data practices were not independently confirmed with a named lawsuit or FTC action this pass, leaving the structural location/behavioral-profiling business model and the arbitration clause as the substantive findings.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No specific lawsuit, breach, or regulatory action has been confirmed for Yelp; the row itself flags this as thin, follow-up-pending verification.", "Exposure Score (0-100)": 39, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_30d+3) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Yelp  <-  Yelp Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to a jury.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Yelp you gave up your physical movements, your right to sue, your right to join a class action, and your right to a jury. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Yelp's entire business model runs on location data and behavioral profiling of where you go and what you think of it — a genuinely under-researched privacy profile relative to how much of your real-world movement and opinions the app has access to, worth a direct follow-up given how little public litigation has actually tested Yelp's specific practices compared to peers.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 168, "_entity_id": 267, "_entity_slug": "yelp", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "OpenTable", "Category": "Restaurant Reservations", "Terms & Conditions URL": "opentable.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "opentable.com/c/legal/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. OpenTable (Booking Holdings subsidiary) ToS. OpenTable tracks dining frequency, cuisine preferences, spending patterns, and party size — the arbitration clause covers disputes over how this dining-behavior data is shared with restaurant partners and advertisers.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Not itemized this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Booking Holdings Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Booking Holdings Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] OpenTable's own materials describe arbitration only as a conditional 'possibility,' not a firm clause\nWHAT THE TERMS SAY: OpenTable's own privacy materials describe only 'the possibility, under certain conditions,' of binding arbitration, notably vaguer language than the hard, unambiguous arbitration clauses most other companies in the tracker use.\nWHY IT MATTERS: This leaves real uncertainty about what actually happens if a dispute over a reservation or data ever arises.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] OpenTable tracks dining frequency, cuisine preferences, and spending, shared with restaurant partners\nWHAT THE TERMS SAY: OpenTable tracks dining frequency, cuisine preferences, spending patterns, and party size, and its arbitration clause covers disputes over how this dining-behavior data is shared with restaurant partners and advertisers.\nWHY IT MATTERS: A detailed behavioral profile of a user's dining habits and spending is shared beyond OpenTable itself, to restaurant partners and advertisers.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two items are supported; no specific lawsuit or breach was confirmed for OpenTable this pass, leaving the vague arbitration language and the dining-behavior data sharing as the substantive findings.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "OpenTable's own materials describe arbitration only as a conditional possibility, and no specific lawsuit or breach is confirmed.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "OpenTable  <-  Booking Holdings Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using OpenTable you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "OpenTable's own privacy materials describe only 'the possibility, under certain conditions,' of binding arbitration — notably vaguer language than the hard, unambiguous arbitration clauses most other companies in this tracker use, leaving real uncertainty about what actually happens if a dispute over your reservation or data ever arises.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 169, "_entity_id": 268, "_entity_slug": "opentable", "_issuer": "Booking Holdings Inc.", "_issuer_slug": "booking-holdings-inc", "_ticker": "BKNG", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Duolingo", "Category": "Education", "Terms & Conditions URL": "duolingo.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "duolingo.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "v59 REWRITE. The v58 row rested on a single third-party finding (Duolingo named among apps whose embedded Firebase SDK fed the Google judgment) and a SCARY entry about AI-generated story quality that is a product-quality story, not a terms or data finding. Both are superseded here.\n\nTHE MATERIAL FINDING IS A POLICY THAT SHRANK. Per ConductAtlas change tracking, Duolingo's privacy policy was updated on 27 MAY 2026 and the update REMOVED material: (1) the explicit statement that Duolingo shares user information with social media, advertising and analytics partners; (2) the 'Do Not Sell My Personal Information' control; (3) the explicit disclosure describing VOICE DATA COLLECTION; and (4) the explicit carve-out stating that Android and web users were NOT subject to audio collection for product-improvement purposes -- previously audio collection was authorised for iOS users only. The replacement language states that all users may choose not to share audio in Settings, which implies audio collection may now occur ACROSS ALL PLATFORMS unless the user opts out. ConductAtlas notes, and this tracker repeats, that these are changes to the DISCLOSURE and that actual practices may be unchanged.\n\nOther tracked changes: a Math Tutor feature processes audio through Apple for transcription, with audio deleted but text transcripts potentially retained and shared with AI vendors; IP addresses may be retained beyond 30 days for paying subscribers for payment processing and fraud prevention; the Video Call feature was reworded from an offering to a possible offering; and FullStory session-replay activity recording is disableable via a Tracking toggle in Settings, which means it is ON unless switched off.\n\nSEQUENCE WORTH NOTING, WITHOUT ASSERTING CAUSATION: The amended COPPA Rule, adopted January 2025 with a compliance date of 22 April 2026, added VOICEPRINTS and other biometric identifiers to the categories of protected children’s personal information, requires SEPARATE verifiable parental consent before a child’s data is disclosed for advertising or AI training, requires operators to name the specific recipients rather than referring to partners generically, and bans indefinite retention. The removal of the explicit voice-data disclosure is dated roughly five weeks AFTER that compliance date. This tracker does not claim the two are connected and has no evidence that they are. It records the sequence because the POLICY CHANGES tab exists to capture exactly this: a privacy policy that got shorter on a sensitive category shortly after that category became more regulated.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver and jury trial waiver. AAA rules, Pennsylvania law (Duolingo HQ: Pittsburgh). 30-DAY OPT-OUT by email to legal@duolingo.com -- one of the shorter windows in this workbook and the single most actionable item on this row. The clause applies to all users regardless of age; Duolingo reports 88 million-plus monthly active users, a substantial share of them minors. Duolingo went public in 2021 (NASDAQ: DUOL).", "Fees / Billing Flags": "Not itemized this pass beyond the freemium and Super/Max subscription structure. Note that IP retention now differs between free and paying users per the tracked policy change, which makes payment status a data-retention variable rather than only a billing one.", "Notes": "Carried forward from v58 and still true: the Firebase exposure is Google's collection occurring THROUGH Duolingo's app via an embedded third-party SDK, and Duolingo itself may have no direct fault in it. See the new Google Firebase + AdMob row, which now documents that SDK layer properly so rows like this one can point at it rather than re-explaining it.\n\nThe v58 SCARY entry (the CEO's admission that roughly a fifth of AI-generated stories were unusable, and the 2025 AI-first memo backlash) has been MOVED OUT of the SCARY field and is retained here in Notes, because per the SCHEMA & EXTENSION GUIDE §7 a product-quality and labour story is not a consumer terms or data-privacy harm and should not occupy the row's most prominent finding slot. That reclassification is logged in CORRECTIONS LOG.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Pittsburgh", "HQ State": "Pennsylvania", "CEO": null, "Ticker": "DUOL", "Website (Corporate)": "duolingo.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (DUOL). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://conductatlas.com/platform/duolingo/duolingo-privacy-policy/voice-data-collection/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Duolingo, Inc.", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Duolingo, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[UNILATERAL_CHANGES · FL-1] The privacy policy SHRANK on 27 May 2026, removing the voice-collection disclosure and the do-not-sell control\nWHAT THE TERMS SAY: Per ConductAtlas change tracking, the 27 May 2026 update removed the explicit statement that Duolingo shares information with social media, advertising and analytics partners, removed the Do Not Sell My Personal Information control, and removed the explicit voice-data collection disclosure.\nWHY IT MATTERS: This workbook’s POLICY CHANGES tab names a shrinking privacy policy as the single highest-value alert the system can produce, because rights and disclosures rarely get shorter by accident.\n(evidence: ConductAtlas platform/duolingo change history, retrieved 2026-09-06)", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-1] The carve-out protecting Android and web users from audio collection was removed\nWHAT THE TERMS SAY: The prior policy authorised audio collection for product improvement from iOS users with an explicit carve-out for Android and web users; the revised language states all users may choose not to share audio in Settings.\nWHY IT MATTERS: A protection that existed for two platforms was replaced by an opt-out, which reverses the default for those users.\n(evidence: ConductAtlas voice-and-audio change history, retrieved 2026-09-06)", "Top Troubling #3": "[FORCED_ARBITRATION · FL-2] A 30-day arbitration opt-out by email binds 88 million-plus users including many minors\nWHAT THE TERMS SAY: Duolingo requires binding arbitration with class and jury waivers under AAA rules and Pennsylvania law, with a 30-day opt-out sent to legal@duolingo.com, applying to all users regardless of age.\nWHY IT MATTERS: It is short, it is by email, and it is the only step on this row a household can complete today — see ACTION - OPT-OUT KIT.\n(evidence: Duolingo Terms of Service; carried forward from v58 and not re-fetched this pass)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=?; affiliates=Y; biometric=Y; aitrain=Y; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The 27 May 2026 changes are individually dated and itemised by an independent change-tracking service, which is a stronger evidentiary position than most rows in this workbook enjoy.", "Exposure Score (0-100)": 58, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 18, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_30d+3) | Data 18/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, ai_training_on_user_data+5, sensitive_exposure_tag+3) | Contract 5/20 (unilateral_modification+5) | Record 8/20 (severity3+8) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "CHILDREN’S DATA → Federal COPPA (amended rule, compliance 2026-04-22) now requires SEPARATE verifiable parental consent before a child’s data goes to advertisers or AI training, and bans indefinite retention; MD bars targeted advertising to consumers a controller knows are under 18; state AGs have express COPPA parens patriae standing (confirmed in the Roku ruling)\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Duolingo  <-  Duolingo, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n  6. Your right to a jury.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your personal data sold onward; your physical movements; a broad licence to your own content; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Duolingo you gave up your content used as AI training data, your biometric identifiers, your data shared corporate-wide, your right to sue, your right to join a class action, your right to a jury, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "2026-09-08T19:35:09Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "On 27 MAY 2026 Duolingo's privacy policy got SHORTER. It removed the explicit statement that it shares your data with advertising and analytics partners. It removed the 'Do Not Sell My Personal Information' button. It removed the disclosure describing VOICE DATA COLLECTION. And it removed the carve-out that had protected Android and web users from audio collection entirely — previously that applied to iOS only — replacing it with an opt-out buried in Settings. Five weeks earlier, on 22 April 2026, the amended federal COPPA Rule took effect and added VOICEPRINTS to the list of protected children's data. This tracker asserts NO connection between those two events and has no evidence of one. It records the sequence because a privacy policy that quietly shrinks on a sensitive category is the loudest signal this system is built to catch — and Duolingo has 88 million-plus monthly users, a great many of them children, recording their voices.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 170, "_entity_id": 270, "_entity_slug": "duolingo", "_issuer": "Duolingo, Inc.", "_issuer_slug": "duolingo-inc", "_ticker": "DUOL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Grammarly", "Category": "Productivity (writing assistant)", "Terms & Conditions URL": "grammarly.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "grammarly.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "STRUCTURAL FLAG WORTH NOTING: Grammarly's core function requires reading and analyzing the FULL TEXT of whatever a user is writing (emails, documents, messages) to provide suggestions — meaning by design, Grammarly's servers process a uniquely broad, often highly personal/sensitive slice of a user's written communications (medical questions to a doctor via a patient portal, legal correspondence, personal emails, etc.) compared to apps that only see metadata or limited inputs. Not independently confirmed with a specific named lawsuit this pass, but the category of risk (full-content analysis, not just metadata) is structurally distinct from most other apps in this tracker.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. AAA rules, California law. 30-day opt-out via email to arbitration-opt-out@grammarly.com. Grammarly processes substantial keystroke data — every word typed in the browser extension — making the arbitration clause relevant to data-handling disputes, not just billing.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a dedicated follow-up specifically on what Grammarly retains/uses analyzed text FOR (e.g., AI model training) given how much sensitive content the product structurally has access to by design.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Grammarly, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Grammarly, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Grammarly's AI 'Expert Review' put fabricated editing advice in the names of Stephen King, Carl Sagan and journalist Julia Angwin without asking them\nWHAT THE TERMS SAY: In March 2026 Grammarly's premium 'Expert Review' feature offered AI-generated editing feedback explicitly attributed to real, named people including Stephen King, Carl Sagan, Kara Swisher, and Julia Angwin, without asking any of them first.\nWHY IT MATTERS: Angwin's lawsuit alleges the AI advice attributed to her was low quality and didn't reflect how she actually edits, meaning Grammarly put professional judgment in her mouth she never gave; Grammarly pulled the feature after backlash but the lawsuit continues.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Grammarly's core function requires its servers to read the full text of whatever a user is writing, not just metadata\nWHAT THE TERMS SAY: By design, Grammarly's servers process the full text of user writing (emails, documents, messages), which can include highly personal or sensitive content like medical questions to a doctor or legal correspondence, a structurally broader intake than apps that only see metadata.\nWHY IT MATTERS: A user's sensitive written communications pass through Grammarly's servers as a basic condition of using the product, though the tracker notes this is not tied to a confirmed named lawsuit this pass.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Grammarly requires binding arbitration with a class action waiver, with a 30-day opt-out window\nWHAT THE TERMS SAY: Grammarly's terms impose mandatory binding arbitration with a class action waiver under AAA rules and California law, with a 30-day opt-out available via email to arbitration-opt-out@grammarly.com.\nWHY IT MATTERS: Because Grammarly processes substantial keystroke data from every word typed in its browser extension, the tracker notes this clause is relevant to data-handling disputes, not just billing.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The structural full-text-access risk is described but not tied to a confirmed lawsuit, while the Angwin case is a live, unresolved suit and fees/data-retention detail are explicitly not itemized.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Grammarly  <-  Grammarly, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Grammarly you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:35:11Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "In March 2026, Grammarly's 'Expert Review' feature offered premium users AI-generated editing feedback explicitly attributed to REAL, NAMED people — including Stephen King, Carl Sagan, Kara Swisher, and journalist Julia Angwin — without asking ANY of them first. Angwin's lawsuit alleges the AI-generated advice put in her name was actually LOW QUALITY and didn't even reflect how she really edits, meaning Grammarly wasn't just using her name without permission, it was putting words and professional judgment in her mouth that she never said and might not even agree with. Grammarly pulled the feature after the backlash, but the lawsuit continues. Separately, a January 2026 independent privacy study flagged Grammarly's own browser extension as one of the most privacy-concerning AI tools tested, collecting website content, personal communications, and activity data across whatever you're writing — not just inside Grammarly itself.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 171, "_entity_id": 272, "_entity_slug": "grammarly", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Life360", "Category": "Family Safety/Location Tracking", "Terms & Conditions URL": "life360.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "life360.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MAJOR FTC ENFORCEMENT ACTION (Jan 2025): the FTC formally ordered Life360 to STOP SELLING sensitive location data collected from users — part of a broader FTC campaign against the location-data industry that also caught data brokers InMarket, X-Mode, Gravy Analytics, and Mobilewalla. A 2023 class action (E.S. et al. v. Life360) alleged the company sold geolocation data — including CHILDREN'S LOCATIONS — to data brokers; that case was voluntarily dismissed with prejudice in Nov 2023 (cannot be refiled), but attorneys shifted to individual arbitration claims instead. SEPARATE, ONGOING ISSUE: Life360's driving-behavior data has reportedly been shared via ARITY (an Allstate subsidiary) with insurers, and law firms are actively investigating whether Life360 users saw unexplained car-insurance premium increases (2022–2025) tied to this secret data-sharing pipeline — the Texas AG has separately sued Allstate/Arity directly over this practice. A 2024 DATA BREACH exposed personal information of approximately 443,000 users (contact information, not financial credentials — Life360 did not treat it as a full account compromise, though exposed data is sufficient for targeted phishing).", "Arbitration / Class Action Waiver": "A related but distinct case (Ireland-Gordy v. Tile, Life360, Amazon) alleges Life360's Tile tracker product enables STALKING through design flaws — one plaintiff found a hidden Tile in her car that had been used by an ex-partner to track her over 16,000 TIMES, exploiting a 'Anti-Theft Mode' feature that makes trackers invisible to scanning apps meant to help victims detect covert tracking devices. In Aug 2025 a court dismissed some claims as time-barred but kept core negligence/privacy claims alive; the Ninth Circuit then sent the remaining claims to ARBITRATION in March 2026 — the case remains active but stayed, with no resolution yet.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "GIVEN THIS APP IS SPECIFICALLY MARKETED FOR FAMILY/CHILD SAFETY, this is one of the most concerning 'issue pertaining to customers' findings in the entire audit — a product sold explicitly on a safety promise has (1) an FTC order for selling children's location data, (2) an insurance-data-sharing pipeline affecting customer costs, AND (3) a related product (Tile) allegedly enabling real-world stalking via a specific 'anti-theft' feature. Recommend treating this as a priority flag given the product's explicit safety positioning.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R2) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-sues-allstate-and-arity-unlawfully-collecting-using-and-selling-over-45", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Life360, Inc.", "Years Referenced in Finding (heuristic)": "2026, 2023", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Life360, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[DATA_SALE · FL-2] FTC formally ordered Life360 to stop selling sensitive location data, including children's locations\nWHAT THE TERMS SAY: In January 2025 the FTC ordered Life360 to stop selling sensitive location data it collected from users, part of a broader FTC campaign against the location-data industry; a 2023 class action separately alleged the company sold geolocation data including children's locations to data brokers.\nWHY IT MATTERS: A family-safety app parents use to track their kids was, per a federal regulator, selling that same location data; the 2023 private suit was dismissed with prejudice and cannot be refiled, though attorneys shifted to individual arbitration claims.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] A suit alleging Tile's design enables stalking was sent to arbitration by the Ninth Circuit in 2026\nWHAT THE TERMS SAY: A related case (Ireland-Gordy v. Tile, Life360, Amazon) alleges Life360's Tile product's 'Anti-Theft Mode' makes trackers invisible to scanning apps meant to detect covert tracking, and one plaintiff found a hidden Tile used by an ex-partner to track her over 16,000 times; in March 2026 the Ninth Circuit sent the remaining claims to arbitration.\nWHY IT MATTERS: A plaintiff alleging real-world stalking enabled by a product design choice had her claims moved out of open court and into arbitration, where the case remains active but stayed with no resolution yet.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #3": "[SURVEILLANCE_PRICING · FL-2] Life360 was reportedly paid millions to funnel users' driving data to insurer-linked Arity without disclosure\nWHAT THE TERMS SAY: Life360's driving-behavior data has reportedly been shared via Arity, an Allstate subsidiary, with insurers, feeding what Arity itself called 'the world's largest driving behavior database'; law firms are investigating whether this tie to unexplained car-insurance premium increases (2022-2025) occurred with no disclosure to users.\nWHY IT MATTERS: As of mid-2026 there is no active settlement or claim form for affected Life360 users specifically — the Texas AG case targets Allstate/Arity directly, not Life360, leaving no formal path for an ordinary customer to be compensated even though their data allegedly fed the pricing system.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The FTC order and 2024 breach are confirmed with figures, but the arbitration opt-out window and the insurance-pricing connection remain unconfirmed or under investigation.", "Exposure Score (0-100)": 54, "Exposure Band": "High", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Life360  <-  Life360, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Life360 you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, and your right to sue. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "2026-09-08T19:35:14Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Life360 reportedly received MILLIONS OF DOLLARS to embed Allstate subsidiary Arity's tracking software inside its app — meaning the family-safety app parents use to check on their kids was PAID to secretly funnel braking, acceleration, speed, and route data into what Arity itself called 'the world's largest driving behavior database,' later sold to insurers to help justify premium increases for over 45 million Americans. You opened Life360 to check on your teenager; Arity was allegedly reading your driving habits in real time, with no pop-up ever telling you that's what was happening. As of mid-2026, there's no active settlement or claim form for affected users — the original 2023 class action was dismissed outright, and the live Texas Attorney General case is against Allstate and Arity directly, not Life360 itself, so there's currently no formal path for an ordinary Life360 customer to be compensated even though their data allegedly fueled the whole system.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 172, "_entity_id": 274, "_entity_slug": "life360", "_issuer": "Life360, Inc.", "_issuer_slug": "life360-inc", "_ticker": "LIF", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ring (Amazon)", "Category": "Smart Home/Security", "Terms & Conditions URL": "ring.com/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "ring.com/privacy-notice", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "DEEPLY CONCERNING SUBSTANTIATED FTC FINDING (2023 settlement, still the governing precedent): the FTC's complaint found Ring gave EMPLOYEES UNRESTRICTED ACCESS to customers' home camera footage before September 2017 — including a documented instance where a Ring employee viewed THOUSANDS of video recordings from at least 81 FEMALE users' cameras (assigned to bathrooms and bedrooms) over a three-month period; a coworker's initial misconduct report was not taken seriously until a supervisor noticed the employee was 'only viewing videos of pretty girls.' Separately, Ring's inadequate security (no multi-factor authentication until 2019) let hackers access customer camera feeds and sexually proposition people, call children racial slurs, and threaten families for ransom through hacked two-way video/audio — roughly 55,000 US customer accounts were compromised.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Ring is an Amazon subsidiary governed by Amazon's Conditions of Use post-July 2021 removal.", "Fees / Billing Flags": "$5.8 MILLION settlement paid as customer refunds; Ring required to delete pre-2018 videos/facial data and can no longer use products/features built from that improperly-collected data.", "Notes": "This is arguably the most severe INDIVIDUAL HARM finding (as opposed to systemic data-sharing) anywhere in this entire audit — a documented employee using access to spy on women in their bathrooms/bedrooms is qualitatively different from a data-sharing or billing complaint. Worth flagging with particular seriousness given the in-home, intimate nature of the devices involved.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Santa Monica", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R3) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.ftc.gov/news-events/news/press-releases/2024/04/ftc-sends-refunds-ring-customers-stemming-2023-settlement-over-charges-company-failed-block", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Amazon.com, Inc.", "Years Referenced in Finding (heuristic)": "2025, 2026, 2023, 2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Amazon.com, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] FTC found a Ring employee viewed thousands of videos from at least 81 female users' bathrooms and bedrooms\nWHAT THE TERMS SAY: The FTC's 2023 complaint found Ring gave employees unrestricted access to customers' home camera footage before September 2017, including a documented instance of an employee viewing thousands of recordings from at least 81 female users' cameras assigned to bathrooms and bedrooms over three months; a coworker's initial report was dismissed until a supervisor noticed the employee was 'only viewing videos of pretty girls.'\nWHY IT MATTERS: Ring's own employees had effectively unsupervised access to intimate, in-home footage, and internal reporting failed to stop it for months; Ring paid a $5.8 million FTC settlement and must delete pre-2018 videos and facial data.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[BIOMETRICS · FL-2] Ring's 'Familiar Faces' facial recognition allegedly scans anyone who approaches a door, not just registered users\nWHAT THE TERMS SAY: Ring's 'Familiar Faces' feature, launched December 2025, uses AI facial recognition to build a database of up to 50 people per household; a June 2026 lawsuit alleges it captures and stores the face of anyone who walks up to the door, including delivery drivers or passersby, none of whom consented.\nWHY IT MATTERS: People who never bought or agreed to a Ring device can have their face captured and stored simply by approaching a Ring-equipped door, according to the pending lawsuit.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-4] Ring still hands footage to police without a warrant or homeowner consent in emergencies, and rebuilt police partnerships via Flock Safety\nWHAT THE TERMS SAY: Ring provides footage to police in emergencies without a warrant or the homeowner's consent; after ending its direct police-footage-request program in 2024, it reversed course in 2026, rebuilding police partnerships through Axon and Flock Safety, a company whose surveillance network has separately been linked to federal immigration enforcement.\nWHY IT MATTERS: Homeowners' camera footage can reach law enforcement, including through a surveillance network tied to immigration enforcement, without the homeowner's warrant-backed consent.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The FTC settlement, breach scale (~55,000 accounts), and the current Familiar Faces lawsuit are all specifically documented with dates and figures.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 13/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Ring (Amazon)  <-  Amazon.com, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ring (Amazon) you gave up your biometric identifiers and your data shared corporate-wide. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:35:16Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Ring's new 'Familiar Faces' feature (launched Dec 2025) uses AI facial recognition to build a database of up to 50 people per household — and a June 2026 lawsuit alleges it captures and stores the FACE OF ANYONE who walks up to that door, including a friend visiting, a delivery driver, or a stranger simply passing by, none of whom ever consented. This comes after Ring's OWN 2023 FTC settlement ($5.8M) for a documented case of an employee spying on women through their in-home cameras in bathrooms and bedrooms. Ring had actually ENDED its direct police-footage-request program in 2024 after public backlash — but reversed course in 2026, rebuilding police partnerships through Axon (Taser's parent company) and Flock Safety, a company whose surveillance network has separately been linked to federal immigration enforcement accessing location data. Ring still provides footage to police in emergencies WITHOUT a warrant or the homeowner's consent. Internally, Ring's own CEO has reportedly told staff the company's 'lost dog' Search Party feature was really designed to help 'zero out crime' — confirming what looks like a pet-finding tool is also understood internally as surveillance infrastructure.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 173, "_entity_id": 275, "_entity_slug": "ring-amazon", "_issuer": "Amazon.com, Inc.", "_issuer_slug": "amazon-com-inc", "_ticker": "AMZN", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Nest (Google)", "Category": "Smart Home/Security", "Terms & Conditions URL": "store.google.com/us/gp/nest_terms_of_service (governed by Google's overall Terms)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "store.google.com/us/gp/nest_privacy_notice", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Referenced directly in the Fitbit row's acquisition-precedent discussion: when Google acquired Nest (2014), it initially kept Nest data SEPARATE from Google's broader ecosystem, then merged it in within about a year — explicitly cited by researchers as a cautionary precedent for how Google's 2019 promise to keep Fitbit data separate/ad-free might not hold indefinitely either. Nest's core products (smart cameras, thermostats, smoke detectors) collect in-home audio/video/presence data, placing it in the same 'in-home surveillance device' risk category as Ring/Amazon Alexa documented elsewhere in this tracker, though no Nest-specific lawsuit was independently confirmed this pass.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration for Google Devices with 30-day opt-out from device activation. Subject to the same In re Google Assistant Privacy Litigation mass arbitration (69,507 individual demands).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The 'kept data separate, then merged it a year later' pattern is a useful, concrete illustration of why 'we won't combine this data' promises (also made about Fitbit) deserve some skepticism over a multi-year horizon.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R4) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.classaction.org/news/google-lawsuit-claims-nest-cameras-doorbells-collect-facial-data-without-consent", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alphabet Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[BIOMETRICS · FL-2] Google reportedly disables Nest's facial recognition only in Illinois, where biometric consent law applies, leaving it active elsewhere\nWHAT THE TERMS SAY: Google disables Nest's 'Familiar Faces' facial-recognition feature specifically in Illinois, the one state with a strong biometric consent law, while leaving it fully active everywhere else; as of July 2026 this is at least the third lawsuit alleging Nest cameras scan the face of anyone who walks into view, mapping facial geometry into a permanent biometric template with no warning and no opt-out, even for children.\nWHY IT MATTERS: With Nest holding roughly a quarter of the US doorbell-camera market and 33 million American households owning a smart camera, Google can reportedly build biometric profiles of people who never bought a Nest device, simply by living near one.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Google kept Nest data separate after its 2014 acquisition, then merged it into its broader ecosystem about a year later\nWHAT THE TERMS SAY: When Google acquired Nest in 2014 it initially kept Nest data separate from Google's broader ecosystem, then merged it in within about a year, a pattern researchers cite as a cautionary precedent for whether Google's 2019 promise to keep Fitbit data separate might hold.\nWHY IT MATTERS: A company's promise to keep newly acquired user data siloed may not hold over a multi-year horizon, based on Google's own prior handling of Nest data; no Nest-specific lawsuit over this merge was independently confirmed this pass.\n(evidence: Notes; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Nest's mandatory arbitration is swept into a mass arbitration action of over 69,000 individual demands against Google Devices\nWHAT THE TERMS SAY: Nest is covered by mandatory binding arbitration for Google Devices with a 30-day opt-out from device activation, and is subject to the same In re Google Assistant Privacy Litigation mass arbitration involving 69,507 individual demands.\nWHY IT MATTERS: Consumer disputes over Nest devices are funneled into a mass arbitration process rather than open court or a single class action.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Facial-recognition litigation is well documented but the Google data-merger concern is precedent-based inference rather than a confirmed Nest-specific incident.", "Exposure Score (0-100)": 45, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Nest (Google)  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Nest (Google) you gave up your biometric identifiers, your data shared corporate-wide, and your right to sue. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:35:19Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Google DISABLES its Nest 'Familiar Faces' facial-recognition feature specifically in Illinois — the one state with a strong biometric consent law — while leaving it fully active everywhere else. That's effectively Google admitting the feature wouldn't survive a state that actually requires consent for facial scanning, and choosing not to fix that everywhere, only where it's legally forced to. As of July 2026, this is now at least the THIRD separate lawsuit over the same feature: Nest cameras reportedly scan the face of ANYONE who walks into view — a neighbor out for a walk, a delivery driver, a friend visiting next door — mapping their exact facial geometry into a permanent biometric template, with no warning and no way to opt out, even for children. With Nest holding roughly a quarter of the US doorbell-camera market and 33 million American households now owning a smart camera, Google can build biometric profiles of people who never bought a Nest device themselves, simply by living in a neighborhood that has one.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 174, "_entity_id": 276, "_entity_slug": "nest-google", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "ADT", "Category": "Home Security", "Terms & Conditions URL": "adt.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "adt.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED APRIL 2026 BREACH + EXTORTION ATTEMPT: a hacker infiltrated ADT's network (~April 20, 2026) and exfiltrated customer names, phone numbers, addresses, birthdates, last-4 SSN digits, and tax IDs; the hacker then posted a 'PAY OR LEAK' ultimatum threatening to release the stolen data and cause further 'digital problems' unless ADT responded by a set deadline (April 27, 2026) — a direct extortion attempt, not merely passive data theft. A class action (James v. ADT) alleges ADT knowingly kept customer PII on systems it knew were vulnerable and failed to meet FTC data-security guidelines, and separately failed to fully disclose the breach's scope to affected individuals and regulators.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. ADT's Terms of Service cover all monitoring and smart-home services. Given the April 2026 ShinyHunters breach (5.5M records, vishing attack via Okta SSO → Salesforce), the arbitration clause directly affects breach victims' legal options.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The active extortion/'pay or leak' threat is a distinct and more acute harm pattern than the typical passive-exposure breaches found elsewhere in this tracker — worth flagging given ADT is a HOME SECURITY company, where a breach carries an ironic, heightened trust-violation dimension.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Boca Raton", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R3) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.bankinfosecurity.com/home-security-firm-adt-breach-55m-customers-data-exposed-a-31511", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "ADT Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: ADT Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] April 2026 hacker took ADT customers' last-4 SSN digits and tax IDs, then issued a 'pay or leak' ultimatum\nWHAT THE TERMS SAY: A hacker infiltrated ADT's network around April 20, 2026 and exfiltrated customer names, phone numbers, addresses, birthdates, last-4 SSN digits, and tax IDs, then posted a 'pay or leak' ultimatum with an April 27, 2026 deadline threatening to release the data.\nWHY IT MATTERS: This was an active extortion attempt, not passive data theft, against a home-security company; a class action alleges ADT knowingly kept customer PII on systems it knew were vulnerable and failed to meet FTC data-security guidelines.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] ADT's mandatory arbitration clause directly limits breach victims' legal options after the April 2026 hack\nWHAT THE TERMS SAY: ADT's terms impose mandatory binding arbitration with a class action waiver covering all monitoring and smart-home services; the tracker notes this directly affects the legal options of victims of the April 2026 ShinyHunters breach (5.5 million records) that began with a vishing attack through Okta SSO into Salesforce.\nWHY IT MATTERS: Customers whose data was exposed in the breach face individual arbitration rather than a class remedy for pursuing ADT.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[PENDING_LITIGATION · FL-2] A lawsuit alleges ADT still hasn't told most affected customers what data of theirs was actually taken\nWHAT THE TERMS SAY: The James v. ADT class action alleges ADT knowingly kept customer PII on vulnerable systems and failed to fully disclose the breach's scope to affected individuals and regulators; ADT's only public acknowledgment came four days after the extortion deadline.\nWHY IT MATTERS: Customers may not know the full extent of what personal data was exposed about them, according to the pending suit, even as the underlying breach affected 5.5 million records.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach mechanics and extortion threat are well documented, but the lawsuit alleges ADT still hasn't disclosed the full scope to affected customers.", "Exposure Score (0-100)": 39, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 23, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 23/30 (forced_arbitration+12, class_action_waiver+9, optout_window_unverified+2) | Data 0/30 (none) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "ADT  <-  ADT Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using ADT you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:35:23Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "ADT — a company literally in the business of protecting people's homes — has suffered THREE CONFIRMED BREACHES IN UNDER TWELVE MONTHS. In the most recent (April 2026), a single employee fell for a voice-phishing call, handing attackers an Okta login that pivoted straight into a Salesforce database holding 5.5 million customer records — names, phone numbers, addresses, and for some, birthdates and partial Social Security numbers. The ShinyHunters extortion group gave ADT a 'pay or leak' deadline; ADT's only public acknowledgment came four days later, and the lawsuit alleges the company still hasn't told most affected customers exactly what of their data was taken. The one genuine silver lining, confirmed by ADT itself: no payment cards, no alarm-system access codes, and no actual camera audio/video were part of this specific breach.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 175, "_entity_id": 278, "_entity_slug": "adt", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Chime", "Category": "Fintech/Banking (neobank)", "Terms & Conditions URL": "chime.com/legal/terms-of-service/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "chime.com/legal/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED APRIL 2026 DATA BREACH: a class action alleges Chime Financial 'lost control' over customers' highly sensitive financial data during an April 2026 breach that plaintiffs argue could have been prevented with adequate security measures — specific data types exposed and total customer count not independently confirmed this pass; recommend direct follow-up given Chime's status as a neobank handling checking/savings-equivalent accounts for potentially financially vulnerable customers (Chime markets itself partly toward underbanked/lower-income consumers), making a financial-data breach here potentially more consequential per-customer than at a typical retailer.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Chime's ToS, AAA rules. 60-day opt-out — Chime is one of only two companies in this tracker (along with Aetna) offering a 60-day window. Written notice required. Chime is a financial technology company, not a bank — banking services provided by Bancorp Bank or Stride Bank, N.A.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Chime's target demographic (often underbanked/lower-income customers seeking an alternative to traditional banks) makes this breach worth a closer, dedicated look given potential overlap with BMHC's own audience — recommend direct follow-up on breach scope/severity.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R4) — review status not recorded", "Arbitration Opt-Out Window (Days)": 60, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Chime Financial, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Chime Financial, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] An Iran-linked group allegedly breached Chime, locking 16,000+ people out of their accounts at the peak\nWHAT THE TERMS SAY: A group calling itself 'Team 313' allegedly breached Chime's servers on April 1, 2026, locking more than 16,000 people out of their accounts at the peak, blocking balance checks, transfers, and rent payments; Chime says no member data was compromised and blames only its marketing website, while plaintiffs in three federal lawsuits dispute this, alleging SSNs and login credentials were exposed and that the group threatened to publish stolen data.\nWHY IT MATTERS: For customers whose paycheck sits at Chime instead of a traditional bank, being locked out means no access to their own money, and the scope of any data exposure is directly disputed between Chime and its plaintiffs.\n(evidence: SCARY; Tracker says unconfirmed (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[TERMINATION_CONFISCATION · FL-4] Consolidated litigation alleges Chime closes accounts and freezes customer funds without notice or explanation\nWHAT THE TERMS SAY: Predating the April 2026 breach, Chime has faced years of complaints, now consolidated litigation, alleging it closes customer accounts and freezes funds without notice or explanation, affecting a base of 22 million account holders.\nWHY IT MATTERS: Customers of a neobank marketed partly toward underbanked consumers can reportedly wake up locked out of their own money with no explanation.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Chime requires mandatory arbitration but offers a longer-than-typical 60-day opt-out window\nWHAT THE TERMS SAY: Chime's terms impose mandatory binding arbitration with a class action waiver under AAA rules, with a 60-day opt-out via written notice — one of only two companies in this tracker (with Aetna) offering a 60-day window.\nWHY IT MATTERS: Disputes over the April 2026 breach or account-freeze pattern are subject to individual arbitration unless a customer affirmatively opts out within 60 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Chime and its plaintiffs directly dispute what data was exposed, and the tracker notes specific data types and total customer count are not independently confirmed this pass.", "Exposure Score (0-100)": 39, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 22, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 22/30 (forced_arbitration+12, class_action_waiver+9, optout_60d+1) | Data 0/30 (none) | Contract 4/20 (termination_or_confiscation+4) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Chime  <-  Chime Financial, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Chime you gave up your right to sue, your right to join a class action, and your right to keep what you paid for. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "An IRAN-LINKED hacktivist group calling itself 'Team 313' allegedly breached Chime's servers on April 1, 2026, locking more than 16,000 people (at the outage's peak) out of their own bank accounts — no balance checks, no transfers, no rent payments for people whose paycheck sits at Chime instead of a traditional bank. Chime publicly maintains no member data was actually compromised and blames only its marketing website; the plaintiffs in three separate federal lawsuits dispute that directly, alleging Social Security numbers and login credentials were exposed and that the group has threatened to publish stolen data. SEPARATELY, and predating this breach: Chime has faced years of complaints (now their own consolidated litigation) alleging it closes customer accounts and freezes funds WITHOUT NOTICE OR EXPLANATION — with 22 million account holders, a company positioning itself as the friendly alternative to traditional banking has generated a persistent pattern of people simply waking up locked out of their own money.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 176, "_entity_id": 280, "_entity_slug": "chime", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Klarna / Afterpay / Affirm (Buy Now, Pay Later apps)", "Category": "Fintech (installment payments)", "Terms & Conditions URL": "affirm.com/terms ; afterpay.com/en-US/terms-of-service ; klarna.com/us/legal/", "T&C Direct PDF?": "NO (HTML only for all three)", "Privacy Policy URL": "affirm.com/privacy-policy ; afterpay.com/en-US/privacy-policy ; klarna.com/us/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only for all three)", "Data Sharing/Selling Flags": "COMPREHENSIVE INDEPENDENT STUDY (Incogni, 2025) of 8 major BNPL apps found aggressive data collection with limited transparency: Afterpay gathers and shares up to 20 DIFFERENT DATA TYPES with third parties (including CREDIT SCORES), sharing 17 of those types onward; Klarna collects in-app MESSAGES; apps like Sezzle and Zip collect full web-BROWSING HISTORIES; Affirm, Afterpay, and Zip collectively share PRECISE LOCATION DATA potentially affecting up to 53 MILLION DEVICES; Afterpay/Klarna's combined in-app interaction tracking reaches ~52 million users. On AVERAGE, a BNPL app in the study collected 14 distinct data types and shared 5 of them onward, often citing multiple vague purposes (functionality, fraud prevention, advertising, analytics) per data point — making it hard for users to know which purpose actually drives any given sharing decision. Klarna had a 2021 security incident letting users view OTHER USERS' accounts; Afterpay's parent Block (also documented elsewhere in this tracker for its Cash App CFPB action) suffered a breach exposing 8.2 million people's data.", "Arbitration / Class Action Waiver": "Affirm-specific active class action (Shepard v. Affirm, NY): alleges Affirm's marketing encourages consumers into BNPL plans that make RETURNS practically pointless — specifically, Affirm allegedly does not refund/adjust installment payments even after a customer successfully returns the purchased item to the retailer, meaning customers keep paying installments on a product they no longer have. Separately, a CFPB investigation into BNPL risks/benefits was opened across Affirm, Afterpay, Klarna, PayPal, and Zip collectively — an industry-wide regulatory inquiry rather than a single-company action.", "Fees / Billing Flags": "Affirm ALSO faces a completed, SETTLED data-breach claim tied to a THIRD-PARTY vendor (Evolve Bank and Trust, Feb/May 2024 breach) — payouts ranged up to $3,000 with documented losses or a flat $20 without documentation, illustrating the typically modest per-person payout even in a settled case.", "Notes": "This is one of the richest, most quantified 'issue pertaining to customers' findings in the entire audit for a company CATEGORY (BNPL) rather than a single company — the 'keep paying installments on a returned item' Affirm allegation is a particularly clear, concrete, easily-explained consumer harm.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Stockholm", "HQ State": "Sweden", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R4) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": "https://www.consumerfinance.gov/data-research/research-reports/the-buy-now-pay-later-market/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ in Stockholm, Sweden (non-US)", "Parent / Ultimate Owner": "Klarna Bank AB (Stockholm, Sweden) — this row covers multiple BNPL companies; Afterpay is owned by Block Inc., Affirm is independent (Affirm Holdings, Inc.)", "Years Referenced in Finding (heuristic)": "2023, 2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Sweden) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Sweden. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] An independent study found Afterpay shares up to 20 data types with third parties, including credit scores, with vague purposes cited\nWHAT THE TERMS SAY: A 2025 Incogni study of 8 BNPL apps found Afterpay gathers and shares up to 20 different data types with third parties, including credit scores, sharing 17 of those types onward; on average a BNPL app in the study collected 14 distinct data types and shared 5 onward, often citing multiple vague purposes per data point.\nWHY IT MATTERS: Users of BNPL apps can't easily tell which stated purpose (functionality, fraud prevention, advertising, analytics) actually drives any given instance of their data being shared onward.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[AUTO_RENEWAL_FEES · FL-1] A lawsuit alleges Affirm keeps charging installment payments even after a customer successfully returns the purchased item\nWHAT THE TERMS SAY: Shepard v. Affirm (NY) alleges Affirm's marketing encourages consumers into BNPL plans that make returns practically pointless, because Affirm allegedly does not refund or adjust installment payments even after a customer successfully returns the item to the retailer.\nWHY IT MATTERS: A customer can end up continuing to pay installments on a product they no longer have, according to the pending suit.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[LOCATION_TRACKING · FL-2] Affirm, Afterpay, and Zip collectively share precise location data potentially affecting up to 53 million devices\nWHAT THE TERMS SAY: Per the same Incogni study, Affirm, Afterpay, and Zip collectively share precise location data potentially affecting up to 53 million devices, while apps like Sezzle and Zip also collect full web-browsing histories.\nWHY IT MATTERS: Precise location data from tens of millions of BNPL users' devices is shared onward, according to the independent study, on top of the browsing and messaging data the same apps collect.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=Y; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Findings are drawn from an aggregate third-party study across multiple BNPL apps and an industry-wide CFPB inquiry rather than any single company's own terms, and no arbitration clause is confirmed for this row.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 7, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 7/20 (termination_or_confiscation+4, auto_renewal_or_fee_trap+3) | Record 20/20 (severity5+20, litigation+2) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Klarna / Afterpay / Affirm (Buy Now, Pay Later apps)  <-  Klarna Bank AB (Stockholm, Sweden) — this row covers multiple BNPL companies; Afterpay is owned by Block Inc., Affirm is independent (Affirm Holdings, Inc.)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Klarna / Afterpay / Affirm (Buy Now, Pay Later apps) you gave up your physical movements, your data shared corporate-wide, your right to keep what you paid for, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:35:27Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "CFPB research found 41% of Buy Now Pay Later users missed at least one payment in 2023, and outstanding BNPL debt in the US has now topped $30 BILLION, growing roughly 30% per year. Afterpay specifically FREEZES your account the moment you miss a single payment. And here's the part most shoppers never realize at checkout: even though the button says 'Afterpay' or 'Klarna,' the actual LOAN is often legally owned by a different, unnamed partner lender — meaning if you ever end up in bankruptcy, you may not even know which company to list as your real creditor. On top of all that, Klarna is simultaneously facing a SECURITIES class action from its own INVESTORS alleging it misrepresented loan quality around its 2025 IPO — the same company managing millions of ordinary shoppers' installment debt is separately accused of misleading Wall Street about how risky that debt actually is.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 177, "_entity_id": 283, "_entity_slug": "klarna-afterpay-affirm-buy-now-pay-later-apps", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Discord", "Category": "Social/Messaging (gaming-oriented)", "Terms & Conditions URL": "discord.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "discord.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "$49 MILLION FTC SETTLEMENT (2023) for COPPA violations: the FTC found Discord collected personal information from children under 13 without parental consent, and that internal company documents showed Discord KNEW about predatory adult behavior toward minors on the platform and moved slowly to address it. Age verification remains effectively symbolic — children under 13 can create accounts simply by lying about their age, with no meaningful verification in place, and default privacy settings for ALL users (not just minors) were found to be weak. As of 2026, this has expanded into a broader wave of litigation: a children's-privacy class action, a general privacy class action, and multiple individual WRONGFUL DEATH cases alleging the platform failed to protect minors from predators — among the most severe harm categories found anywhere in this audit.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. AAA rules. 30-day opt-out via email to arbitration-opt-out@discord.com with subject line 'Arbitration Opt-Out.' $49M FTC COPPA settlement (2023) + active state lawsuits (NJ, NV, IN, AR, TX — Texas won a TRO 7 weeks after filing). Discord's TRO loss in Texas means a court found probable cause that its terms violate the state's child-privacy law.", "Fees / Billing Flags": "The completed $49M FTC settlement went to the U.S. government, NOT to individual users/families; the separate private class actions and wrongful-death suits are the only path to direct payouts, and as of 2026 no final settlement amounts have been reached in those cases.", "Notes": "Combined with the Meta/TikTok/Snapchat/YouTube youth-safety findings elsewhere in this tracker, Discord rounds out a remarkably consistent, multi-platform pattern: weak age verification, default-weak privacy settings, and documented internal knowledge of the resulting harms preceding external enforcement. Worth treating all five platforms as one connected youth-safety narrative in any customer/parent-facing materials.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R3) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-secures-historic-legal-victory-forcing-discord-protect-texas-children", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Discord Inc.", "Years Referenced in Finding (heuristic)": "2023, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Discord Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] Discord paid a $49 million FTC settlement after internal documents showed it knew about predatory adult behavior toward minors\nWHAT THE TERMS SAY: The FTC found Discord collected personal information from children under 13 without parental consent, and internal company documents showed Discord knew about predatory adult behavior toward minors on the platform and moved slowly to address it; age verification remained effectively symbolic and default privacy settings for all users were found to be weak.\nWHY IT MATTERS: The $49 million settlement went to the U.S. government, not to individual users or families; the only path to direct payouts is the separate, unresolved private litigation.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-2] Multiple wrongful-death lawsuits allege Discord's platform failed to protect minors from predators\nWHAT THE TERMS SAY: As of 2026, litigation against Discord has expanded into a children's-privacy class action, a general privacy class action, and multiple individual wrongful-death cases alleging the platform failed to protect minors from predators, alongside active state lawsuits in NJ, NV, IN, AR, and TX.\nWHY IT MATTERS: Texas won a temporary restraining order seven weeks after filing, meaning a court found probable cause that Discord's terms violate the state's child-privacy law; no final settlement amounts have been reached in the wrongful-death or privacy suits as of 2026.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DARK_PATTERN_CONSENT · FL-2] Nevada alleges Discord delayed rolling out stricter age verification after seeing 'a hit to the company's bottom line'\nWHAT THE TERMS SAY: Nevada's lawsuit alleges that when Discord first announced stricter age checks it then quietly delayed the rollout after seeing a hit to the company's bottom line, which the state calls 'damage control,' not genuine safety reform; the platform reportedly didn't require any age verification until 2026.\nWHY IT MATTERS: A safety feature Discord had already announced was allegedly held back for financial reasons, according to Nevada's suit, leaving the under-13 age-verification gap open longer than it needed to be.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The FTC settlement amount, the Texas TRO ruling, and the named state lawsuits are all specifically documented with dates and outcomes.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Discord  <-  Discord Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Discord you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:35:29Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Discord already paid a $49 million FTC settlement in 2023 over child-privacy violations — and by 2026 faced fresh state lawsuits from Nevada, New Jersey, and Texas alleging its private servers and direct messages remain effectively unmonitored (moderation relies on unpaid volunteers) and that the platform didn't require any age verification until 2026. Nevada's lawsuit specifically alleges that when Discord first announced stricter age checks, it then quietly DELAYED the rollout after seeing 'a hit to the company's bottom line' — the state calls this 'damage control,' not genuine safety reform. Given how serious the underlying allegations are, this entry deliberately stays at the level of documented regulatory and legal facts rather than describing specific incidents.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 178, "_entity_id": 285, "_entity_slug": "discord", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Reddit", "Category": "Social/Messaging", "Terms & Conditions URL": "redditinc.com/policies/user-agreement", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "redditinc.com/policies/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Reddit has publicly licensed large volumes of user-generated content to AI companies (e.g., Google, OpenAI) for model training under paid data-licensing deals — a practice distinct from most other platforms in this audit in that Reddit is monetizing USER POSTS/COMMENTS themselves (not just behavioral/location data) as a core revenue line; specific consumer lawsuit/settlement details not independently confirmed this pass.", "Arbitration / Class Action Waiver": "Standard binding arbitration + class action waiver expected (not independently confirmed word-for-word this pass).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Worth a dedicated follow-up pass given Reddit's fairly unique 'user content as AI training data product' business model relative to the other social platforms in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.pbs.org/newshour/nation/reddit-sues-ai-company-over-alleged-industrial-scale-scraping-of-its-users-comments", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Reddit, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Reddit, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[AI_TRAINING · FL-2] Reddit earns about $130 million a year licensing user posts and comments to Google and OpenAI for AI training\nWHAT THE TERMS SAY: Reddit has publicly licensed large volumes of user-generated content to AI companies including Google and OpenAI for model training under paid data-licensing deals, earning roughly $130 million a year, about 10% of total revenue.\nWHY IT MATTERS: User posts and comments become a revenue-generating training-data product for Reddit itself, distinct from most platforms in this tracker that monetize behavioral or location data rather than the content users wrote.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONTENT_LICENSE · FL-4] Reddit sues Anthropic and Perplexity for scraping the same user comments it separately sells licenses to\nWHAT THE TERMS SAY: Reddit's own lawyer describes the AI industry's data scraping as an 'industrial-scale data laundering economy,' while Reddit itself sells licenses to Google and OpenAI for the same user comments it is suing Anthropic and Perplexity for taking without paying.\nWHY IT MATTERS: Reddit frames its lawsuits as protecting users' privacy and deletion rights, but the tracker notes the underlying dispute is over who gets to pay for access to users' words, not whether those words end up training an AI at all.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms are explicitly described as only 'expected' and not independently confirmed word-for-word this pass, fees are not itemized, and no consumer-specific lawsuit against Reddit is confirmed; only the content-licensing/AI-training practice is substantively documented for this row.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=?; liabcap=?; contentlic=Y; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration terms are only 'expected' and explicitly unconfirmed, fees aren't itemized, and no consumer-specific lawsuit or settlement against Reddit is confirmed this pass.", "Exposure Score (0-100)": 36, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 13/30 (data_sold_or_shared_for_value+8, ai_training_on_user_data+5) | Contract 3/20 (broad_content_license+3) | Record 20/20 (severity5+20) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use", "Entity Type": "App / Service", "Ownership Path": "Reddit  <-  Reddit, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your content and your conversations, as raw material to train AI models.\n  3. A licence to your own photos, writing and uploads, on their terms.\n\nNOT YET DETERMINED (10 of 13): your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Reddit you gave up your personal data sold onward, your content used as AI training data, and a broad licence to your own content. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:35:32Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Reddit's own lawyer describes the AI industry's data scraping as an 'industrial-scale data laundering economy' — while Reddit ITSELF earns roughly $130 MILLION a year (about 10% of total revenue) selling licenses to Google and OpenAI for the exact same user comments it's suing Anthropic and Perplexity for taking without paying. Reddit frames its lawsuits as protecting users' privacy and deletion rights — but the underlying business model is unmistakable: your posts and comments have become a commercial product Reddit sells to AI companies, and the legal fight is really over who's allowed to pay for access, not whether your words end up training an AI at all.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 179, "_entity_id": 287, "_entity_slug": "reddit", "_issuer": "Reddit, Inc.", "_issuer_slug": "reddit-inc", "_ticker": "RDDT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Pinterest", "Category": "Social/Messaging (visual/shopping)", "Terms & Conditions URL": "policy.pinterest.com/en/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policy.pinterest.com/en/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Pinterest's own tracking pixel appears as a named third-party tracker in multiple OTHER companies' class actions in this research (e.g., alongside LinkedIn/Meta/X on PNC Bank's site, and on retail sites like Boot Barn) — same 'pixel follows you to other companies' sites' pattern flagged under LinkedIn above.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. Pinterest ToS, AAA rules, California law. Pinterest's visual search and recommendation algorithms process image data that can reveal interests, aesthetics, and purchasing intent — the arbitration clause covers disputes over how this visual-preference data is used for targeted advertising.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the LinkedIn row's systemic tracking-pixel finding — Pinterest is part of the same cross-company pattern.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Pinterest, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Pinterest, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Pinterest's tracking pixel appears on unrelated third-party sites named in other companies' suits\nWHAT THE TERMS SAY: Pinterest's own tracking pixel appears embedded on other companies' websites, showing up as a named third-party tracker in other companies' class actions over site tracking (for example on a bank's site and a retail site).\nWHY IT MATTERS: Pinterest's tracking code can quietly follow a visitor around the internet on sites that have nothing to do with pinning recipes or home decor, and its pixel shows up as a named third party in other companies' class actions.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Wrong corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Pinterest requires mandatory arbitration with a class action waiver covering disputes over how visual-preference data is used\nWHAT THE TERMS SAY: Pinterest's terms impose mandatory binding arbitration with a class action waiver, 30-day opt-out, under AAA rules and California law; the clause covers disputes over how Pinterest's visual search and recommendation algorithms process image data revealing interests, aesthetics, and purchasing intent for targeted advertising.\nWHY IT MATTERS: Disputes over how Pinterest uses a user's visual-preference data for ad targeting go to individual arbitration rather than a class action, unless the user opts out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only the cross-site tracking-pixel practice and the arbitration clause are stated for Pinterest itself; the named lawsuits referenced are against other companies (a bank, a retailer), not Pinterest, per the cross-reference rule.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Pinterest's own tracking-pixel practice is documented only via its appearance in other companies' lawsuits, not through a Pinterest-specific case or settlement.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Pinterest  <-  Pinterest, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Pinterest you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:35:34Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Pinterest's own tracking pixel shows up as a named THIRD-PARTY defendant in OTHER companies' lawsuits throughout this tracker — alongside LinkedIn and Meta on a bank's website, and on retail sites elsewhere — meaning Pinterest's tracking code can be quietly following you around the internet on sites that have nothing to do with pinning recipes or home decor.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 180, "_entity_id": 289, "_entity_slug": "pinterest", "_issuer": "Pinterest, Inc.", "_issuer_slug": "pinterest-inc", "_ticker": "PINS", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Spotify", "Category": "Streaming (music)", "Terms & Conditions URL": "spotify.com/legal/end-user-agreement/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "spotify.com/legal/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Active 2026 class action alleges data privacy violations (sharing subscriber data with third parties without consent) — case is still in litigation with no consumer claim form open as of early 2026; a separate claims process for the privacy case specifically may open by mid-2026 per legal-news tracking, but nothing has been finalized. A separate, unrelated ongoing dispute concerns songwriter/publisher royalty payments (a rights-holder issue, not a subscriber-data issue).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver and jury trial waiver. 30-day opt-out via email to tounotice@spotify.com. Unique feature: after two mediation sessions, a user can opt out of arbitration entirely and sue in court — this is better than a pure class-action ban because it prevents indefinite stonewalling. AAA Consumer Arbitration Rules. Terms last updated Aug 26, 2025. A federal court (S.D.N.Y., Judge Koeltl, April 30 2026) upheld the clause against a payola-playlist challenge, finding the plaintiff's continued use after 2023 and 2025 terms updates constituted agreement.", "Fees / Billing Flags": "Not itemized this pass beyond the billing-practices class action noted above.", "Notes": "Both the privacy and billing cases remain UNRESOLVED as of mid-2026 — worth a follow-up check once either settlement finalizes, since neither has an open claim form yet.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Stockholm", "HQ State": "Sweden", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R6) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ in Stockholm, Sweden (non-US)", "Parent / Ultimate Owner": "Spotify Technology S.A.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Sweden) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Sweden. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] A lawsuit alleges Spotify's 'personalized' recommendations are secretly pay-for-play, not based on a listener's actual taste\nWHAT THE TERMS SAY: A lawsuit alleges that through a program called 'Discovery Mode,' artists who accept lower royalty payments get pushed into user recommendations and playlists more often, described in the complaint as reviving 'pay-for-play' in an algorithmic form.\nWHY IT MATTERS: A song that feels like the app 'gets you' may actually be one whose artist agreed to earn less per stream in exchange for a recommendation boost; a federal judge already granted Spotify's motion to force a similar claim into arbitration.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Spotify requires mandatory arbitration and a jury trial waiver, though users can escape it after two mediation sessions\nWHAT THE TERMS SAY: Spotify's terms impose mandatory binding arbitration with a class action waiver and jury trial waiver, 30-day opt-out via email, under AAA rules; uniquely, after two mediation sessions a user can opt out of arbitration entirely and sue in court instead.\nWHY IT MATTERS: A federal court (S.D.N.Y., April 30, 2026) upheld the clause against a payola-playlist challenge, finding that continued use of Spotify after the 2023 and 2025 terms updates constituted agreement to it.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] An active 2026 class action alleges Spotify shared subscriber data with third parties without consent\nWHAT THE TERMS SAY: A 2026 class action alleges data privacy violations, specifically sharing subscriber data with third parties without consent; the case remains in litigation with no consumer claim form open as of early 2026, though a separate claims process may open by mid-2026.\nWHY IT MATTERS: Affected subscribers currently have no way to file a claim, since neither the privacy nor the related billing case has an open claim form as of mid-2026.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The privacy class action remains unresolved with no open claim form, and the Discovery Mode pay-for-play practice is an unproven allegation in active litigation.", "Exposure Score (0-100)": 41, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Spotify  <-  Spotify Technology S.A.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to a jury.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Spotify you gave up your data shared corporate-wide, your right to sue, your right to join a class action, and your right to a jury. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:35:37Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "A lawsuit alleges Spotify's 'personalized' recommendations aren't actually based on YOUR listening taste at all — through a program called 'Discovery Mode,' artists who accept LOWER royalty payments get pushed into your recommendations and playlists more often, described in the complaint as reviving 'the industry's oldest deception — pay-for-play — in a modern, algorithmic form.' The song that feels like the app 'gets you' may really just be one whose artist agreed to earn less money per stream in exchange for Spotify boosting it. A federal judge already granted Spotify's motion to force a similar claim into arbitration instead of open court. Separately, copyright disputes allege Spotify streamed OVER 175 MILLION SONGS without proper licensing agreements.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 181, "_entity_id": 291, "_entity_slug": "spotify", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Amazon Alexa", "Category": "Smart Home/Voice Assistant", "Terms & Conditions URL": "amazon.com/alexa-terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "amazon.com/alexa-privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "$25 MILLION COPPA SETTLEMENT (2023, still governing precedent): the FTC found Amazon kept children's Alexa voice recordings and transcripts INDEFINITELY by default (until Sept 2019) despite explicitly promising in a 'Children's Privacy Disclosure' that parents could have data deleted on request; even when Amazon DID delete audio recordings after a parent's request, it separately retained WRITTEN TRANSCRIPTS of the same children's conversations in an internal database accessible to employees, without disclosing this retention to parents. Amazon also allegedly used undeleted children's voice/geolocation data to improve its own algorithms — which the settlement now explicitly bars going forward.", "Arbitration / Class Action Waiver": "Standard binding arbitration + class action waiver expected (not independently confirmed word-for-word this pass).", "Fees / Billing Flags": "As part of the settlement, Amazon must delete previously-requested-but-retained data, remove inactive child Alexa profiles after 18 months (unless a parent opts to keep them), and cannot train algorithms on data flagged for deletion.", "Notes": "The 'we deleted the recording but kept a written transcript of the same content' finding is a subtle but important distinction worth flagging — deleting one data FORMAT doesn't necessarily delete the underlying information if it exists in another format the company didn't disclose.", "Industry (Fortune 500)": "Internet Services and Retailing", "Revenue (Fortune 500)": "$716.9B", "Market Cap": "$2.6T", "Employees": "1,556,000", "HQ City": "Seattle", "HQ State": "Washington", "CEO": "Andrew R. Jassy", "Ticker": "AMZN", "Website (Corporate)": "amazon.com", "Main Mailing Address (legal/privacy notices)": "Amazon.com, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210, USA", "Legal / Privacy Contact Email": "Not verified this pass — Amazon routes privacy requests through its in-account privacy portal", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AMZN). Service route: c/o General Counsel / Corporate Secretary, Seattle, Washington — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[AI_TRAINING · FL-2] Amazon kept written transcripts of children's Alexa conversations even after deleting the audio a parent requested removed\nWHAT THE TERMS SAY: The FTC found Amazon kept children's Alexa voice recordings and transcripts indefinitely by default until September 2019 despite promising parents could have data deleted on request; even when Amazon deleted the audio, it separately retained written transcripts of the same conversations in an internal database accessible to employees, undisclosed to parents, and allegedly used undeleted children's voice and geolocation data to improve its own algorithms.\nWHY IT MATTERS: Deleting one data format, like audio, didn't necessarily delete the underlying information if it existed in another undisclosed format; the 2023 $25 million settlement now bars Amazon from training algorithms on data flagged for deletion.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] A federal judge ruled tens of millions of Alexa users can sue as a group over alleged surreptitious interception of billions of conversations\nWHAT THE TERMS SAY: A federal judge ruled that tens of millions of Alexa users can sue Amazon as a group over allegations the device was designed to 'illegally and surreptitiously intercept billions of private conversations' far beyond the specific commands people meant for Alexa to hear.\nWHY IT MATTERS: The scale alleged, billions of intercepted conversations, goes well beyond intentional voice commands, according to the litigation that a judge allowed to proceed as a group action.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-3] The same judge refused to let non-account-holders who simply lived with an Alexa owner join the group lawsuit\nWHAT THE TERMS SAY: The judge specifically refused to let a separate group join the case: people who never personally registered an Alexa device but simply lived in the same house as someone who did, even though those roommates' and family members' voices were just as likely to have been picked up and stored.\nWHY IT MATTERS: Only the person whose name is on the account has clear legal standing to pursue a remedy; everyone else in the household potentially recorded the same way has a much harder road to any remedy at all.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are explicitly unconfirmed ('expected'), though the COPPA settlement and the ongoing mass litigation are well documented with specific figures.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (ai_training_on_user_data+5, precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nAI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Amazon Alexa  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Amazon Alexa you gave up your content used as AI training data and your physical movements. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A federal judge ruled that TENS OF MILLIONS of Alexa users can sue Amazon as a group over allegations the device was designed to 'illegally and surreptitiously intercept BILLIONS of private conversations' — far beyond the specific commands people actually meant for Alexa to hear. But the same judge specifically REFUSED to let a separate group join the case: people who never personally registered an Alexa device but simply LIVED IN THE SAME HOUSE as someone who did. Even though those roommates' and family members' voices were just as likely to have been picked up and stored, only the person whose name is on the account has clear legal standing — everyone else in the room, potentially recorded the same way, has a much harder road to any remedy at all.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 182, "_entity_id": 292, "_entity_slug": "amazon-alexa", "_issuer": "Amazon Alexa", "_issuer_slug": "amazon-alexa", "_ticker": "AMZN", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "United Airlines", "Category": "Travel (airline)", "Terms & Conditions URL": "united.com/en/us/fly/contract-of-carriage.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "united.com/en/us/fly/privacy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same FTC-exemption/DOT-jurisdiction structural issue as Delta (see Delta row) applies identically to United; airlines broadly collect extensive data including biometric information, travel patterns, in-flight Wi-Fi browsing history, and meal/seat preferences per EPIC's cross-airline research.", "Arbitration / Class Action Waiver": "CLASS ACTION WAIVER in Contract of Carriage. NO mandatory arbitration. United uses an alternate force-majeure form (per the Glazebrook study) that specifically authorizes future travel credits in lieu of cash refunds — structurally different from Delta/American/Southwest. Still litigating the price-fixing MDL with Delta.", "Fees / Billing Flags": "United was among the airlines (with Delta, American, JetBlue, Hawaiian, Alaska) that jointly SUED the DOT (via trade group Airlines for America) to block a 2024 rule requiring upfront disclosure of baggage/change/cancellation fees before final purchase — arguing the rule would 'greatly confuse consumers.' As of late 2025, that fee-disclosure rule remains on hold pending court review, and a subsequent administration change has made full enforcement of the rule less certain going forward.", "Notes": "See Delta row for the shared structural FTC-exemption finding across the whole airline category.", "Industry (Fortune 500)": "Airlines", "Revenue (Fortune 500)": "$59.1B", "Market Cap": "$38.1B", "Employees": "107,300", "HQ City": "Chicago", "HQ State": "Illinois", "CEO": "Scott Kirby", "Ticker": "UAL", "Website (Corporate)": "united.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (UAL). Service route: c/o General Counsel / Corporate Secretary, Chicago, Illinois — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.hausfeld.com/news/hausfeld-wins-significant-victory-on-behalf-of-class-of-domestic-airline-ticket-purchasers-in-antitrust-lawsuit-against-major-us-carriers", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "United Airlines Holdings, Inc.", "Years Referenced in Finding (heuristic)": "2011, 2018, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: United Airlines Holdings, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-1] United is still fighting a consolidated lawsuit alleging it coordinated with rival airlines for years to keep ticket prices high\nWHAT THE TERMS SAY: Delta, United, Southwest, and American have been accused in one consolidated lawsuit of secretly coordinating for years (2011-2018) to deliberately limit how many seats they offered on shared routes, keeping ticket prices artificially high rather than competing on capacity; Southwest and American already settled their portion for $60 million combined, while Delta and United are still fighting the case as of 2026, having lost their bid to get it dismissed.\nWHY IT MATTERS: United customers may have paid artificially inflated fares for years as a result of the alleged coordination, and the case against United remains unresolved.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[AUTO_RENEWAL_FEES · FL-1] United joined other airlines suing the DOT to block a rule requiring upfront disclosure of baggage and change fees\nWHAT THE TERMS SAY: United was among the airlines that jointly sued the DOT via trade group Airlines for America to block a 2024 rule requiring upfront disclosure of baggage, change, and cancellation fees before final purchase, arguing the rule would 'greatly confuse consumers'; as of late 2025 the rule remains on hold pending court review, with enforcement less certain after an administration change.\nWHY IT MATTERS: Consumers may not see the full fee picture before completing a ticket purchase, since the airline industry itself sued to keep that upfront-disclosure requirement from taking effect.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[LIABILITY_CAP_INDEMNITY · FL-1] United's force-majeure terms authorize future travel credits instead of cash refunds\nWHAT THE TERMS SAY: United uses an alternate force-majeure form that specifically authorizes future travel credits in lieu of cash refunds, structurally different from Delta, American, and Southwest.\nWHY IT MATTERS: A customer affected by a force-majeure disruption may be limited to a travel credit rather than getting their money back, under United's specific contract language.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The price-fixing MDL remains ongoing, the fee-disclosure rule is on hold pending court review, and a related greenwashing claim was dismissed on procedural rather than merits grounds.", "Exposure Score (0-100)": 39, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 9, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 8, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 9/30 (class_action_waiver+9) | Data 6/30 (biometric_collection+6) | Contract 8/20 (liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 16/20 (severity4+14, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "United Airlines  <-  United Airlines Holdings, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using United Airlines you gave up your biometric identifiers, your right to join a class action, your right to meaningful compensation, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "2026-09-08T19:36:51Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "United's marketing around 'sustainable aviation fuel' was challenged as GREENWASHING in a class action (later dismissed by a federal court on procedural grounds, not because the underlying claims were proven false). Delta, United, Southwest, and American have all been accused, in one consolidated lawsuit, of secretly coordinating with each other for YEARS (2011-2018) to deliberately LIMIT how many seats they offered on shared routes, specifically to keep ticket prices artificially high across the industry — not competing on capacity the way customers assume rival airlines would. Southwest and American already settled their portion for $60 million combined; Delta and United are still fighting the case as of 2026, having lost their bid to get it dismissed.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 183, "_entity_id": 294, "_entity_slug": "united-airlines", "_issuer": "United Airlines Holdings, Inc.", "_issuer_slug": "united-airlines-holdings-inc", "_ticker": "UAL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "American Airlines", "Category": "Travel (airline)", "Terms & Conditions URL": "aa.com/i18n/customer-service/support/conditions-of-carriage.jsp", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "aa.com/i18n/customer-service/support/privacy-policy.jsp", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same FTC-exemption/DOT-jurisdiction structural issue as Delta/United applies identically.", "Arbitration / Class Action Waiver": "CLASS ACTION WAIVER in Contract of Carriage (confirmed from aa.com, retrieved 2026-08-06): 'any lawsuit you bring against us...will be brought only in your individual capacity, and may not be brought in or asserted as part of a class action proceeding.' NO mandatory arbitration — disputes go to court, but only individually. American adopted its class action waiver during the 2020-2023 wave when 8 of the 10 largest US airlines added waivers to their contracts of carriage (per the Glazebrook study, NW J. Int'l L. & Bus., 2023). American settled the price-fixing MDL for $45M (2019, no admission).", "Fees / Billing Flags": "Co-plaintiff (with Delta, United, JetBlue, and others) in the joint lawsuit against the DOT's fee-disclosure rule described in the United row above.", "Notes": "See Delta row for the shared structural FTC-exemption finding across the whole airline category.", "Industry (Fortune 500)": "Airlines", "Revenue (Fortune 500)": "$54.6B", "Market Cap": "$9.8B", "Employees": "133,300", "HQ City": "Fort Worth", "HQ State": "Texas", "CEO": "Robert Isom", "Ticker": "AAL", "Website (Corporate)": "aa.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AAL). Service route: c/o General Counsel / Corporate Secretary, Fort Worth, Texas — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.hausfeld.com/news/hausfeld-wins-significant-victory-on-behalf-of-class-of-domestic-airline-ticket-purchasers-in-antitrust-lawsuit-against-major-us-carriers", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "American Airlines Group, Inc.", "Years Referenced in Finding (heuristic)": "2011, 2018, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: American Airlines Group, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] American settled the price-fixing MDL for $45 million in 2019, with no admission of wrongdoing\nWHAT THE TERMS SAY: American settled the price-fixing MDL for $45 million in 2019 with no admission; American is one of four carriers (with Delta, United, Southwest) accused in a consolidated lawsuit of coordinating for years (2011-2018) to limit seats on shared routes and keep ticket prices artificially high.\nWHY IT MATTERS: American's own settlement, reached without admitting wrongdoing, resolved its portion of an allegation that customers paid inflated fares due to coordinated capacity limits across the industry.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] American's Contract of Carriage bars customers from bringing claims as part of a class action, confirmed directly from its own site\nWHAT THE TERMS SAY: American's Contract of Carriage, confirmed from aa.com as retrieved 2026-08-06, states 'any lawsuit you bring against us...will be brought only in your individual capacity, and may not be brought in or asserted as part of a class action proceeding'; American adopted this waiver during a 2020-2023 wave in which 8 of the 10 largest US airlines added similar waivers.\nWHY IT MATTERS: A customer must pursue any claim against American individually, in court, since there is no arbitration clause but the class-action path is explicitly closed off.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[AUTO_RENEWAL_FEES · FL-1] American co-sued the DOT to block a rule requiring upfront disclosure of baggage and change fees\nWHAT THE TERMS SAY: American was a co-plaintiff, with Delta, United, JetBlue and others, in the joint lawsuit against the DOT's fee-disclosure rule requiring upfront disclosure of fees before final purchase.\nWHY IT MATTERS: Consumers may not see the full fee picture before completing a ticket purchase, since American joined the industry effort to keep the upfront-disclosure rule from taking effect.\n(evidence: Fees; Stated in tracker (firewall-edited: unverifiable figure removed) (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The class-action-waiver language is directly quoted from American's own site with a retrieval date, and the price-fixing settlement figure is specific and dated.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 9, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 9/30 (class_action_waiver+9) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "American Airlines  <-  American Airlines Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to join with other people harmed the same way. You must sue alone.\n  2. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using American Airlines you gave up your right to join a class action and your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:36:54Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "American Airlines is one of the four carriers named in the price-fixing conspiracy allegation. Delta, United, Southwest, and American have all been accused, in one consolidated lawsuit, of secretly coordinating with each other for YEARS (2011-2018) to deliberately LIMIT how many seats they offered on shared routes, specifically to keep ticket prices artificially high across the industry — not competing on capacity the way customers assume rival airlines would. Southwest and American already settled their portion for $60 million combined; Delta and United are still fighting the case as of 2026, having lost their bid to get it dismissed.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 184, "_entity_id": 296, "_entity_slug": "american-airlines", "_issuer": "American Airlines Group, Inc.", "_issuer_slug": "american-airlines-group-inc", "_ticker": "AAL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Southwest Airlines", "Category": "Travel (airline)", "Terms & Conditions URL": "southwest.com/legal/contract-of-carriage.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "southwest.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same FTC-exemption/DOT-jurisdiction structural issue as Delta/United/American applies identically; per EPIC's research, Southwest specifically collects customers' 'social media account information' and even more sensitive categories including 'present and future health status, and genetic information' — an unusually broad data-collection scope for an airline, worth independently verifying directly given how sensitive genetic/health data categories are treated elsewhere in this audit (see 23andMe row).", "Arbitration / Class Action Waiver": "CLASS ACTION WAIVER adopted in Contract of Carriage in 2022 (previously Southwest argued its website T&C waiver extended to the CC, but a court in Bombin rejected that argument). Southwest settled the price-fixing MDL for $15M (2018, no admission). NO mandatory arbitration.", "Fees / Billing Flags": "Not itemized separately this pass.", "Notes": "The genetic/health-data collection claim for Southwest specifically deserves direct verification against Southwest's actual current privacy policy before repeating it in any customer-facing material — it's a striking claim relative to what one would expect an airline to collect.", "Industry (Fortune 500)": "Airlines", "Revenue (Fortune 500)": "$28.1B", "Market Cap": "$23.3B", "Employees": "72,450", "HQ City": "Dallas", "HQ State": "Texas", "CEO": "Robert Jordan", "Ticker": "LUV", "Website (Corporate)": "southwest.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (LUV). Service route: c/o General Counsel / Corporate Secretary, Dallas, Texas — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.hausfeld.com/news/hausfeld-wins-significant-victory-on-behalf-of-class-of-domestic-airline-ticket-purchasers-in-antitrust-lawsuit-against-major-us-carriers", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Southwest Airlines Co.", "Years Referenced in Finding (heuristic)": "2026, 2011, 2018", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Southwest Airlines Co.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Research flags Southwest as collecting genetic and health-status data, an unusually broad scope for an airline\nWHAT THE TERMS SAY: Per EPIC's research, Southwest specifically collects customers' social media account information and even more sensitive categories including present and future health status and genetic information, an unusually broad data-collection scope for an airline.\nWHY IT MATTERS: The tracker itself flags this claim as needing direct, independent verification against Southwest's actual current privacy policy before it is repeated in customer-facing material.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-1] The DOJ itself dropped its lawsuit against Southwest over chronically delayed flights before it reached a resolution\nWHAT THE TERMS SAY: The US government filed a lawsuit against Southwest for illegally operating 'chronically delayed' flights on two specific routes, then the Justice Department itself dropped that lawsuit in 2026 under a new administration, before it ever reached a resolution.\nWHY IT MATTERS: A federal enforcement action meant to address chronic flight delays was withdrawn without any finding on the merits, leaving the underlying delay allegation unresolved.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CLASS_ACTION_WAIVER · FL-3] Southwest added a class action waiver to its Contract of Carriage in 2022 after a court rejected its earlier website-terms argument\nWHAT THE TERMS SAY: Southwest adopted a class action waiver in its Contract of Carriage in 2022, after previously arguing its website terms' waiver extended to the Contract of Carriage, an argument a court in Bombin rejected; Southwest settled the price-fixing MDL for $15 million in 2018 with no admission.\nWHY IT MATTERS: Southwest closed the gap a court had identified in its earlier waiver argument, meaning customers now face an explicit class-action bar in the carriage contract itself.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The genetic/health-data collection claim is explicitly flagged in the tracker as unverified, and the DOJ delay lawsuit was dropped without ever reaching a resolution.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 9, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 9/30 (class_action_waiver+9) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Southwest Airlines  <-  Southwest Airlines Co.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Southwest Airlines you gave up your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:36:57Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The US government actually FILED a lawsuit against Southwest for illegally operating 'chronically delayed' flights on two specific routes — then the Justice Department itself DROPPED that same lawsuit in 2026 under a new administration, before it ever reached a resolution. Separately, Southwest faces a SEPARATE securities fraud lawsuit from its own investors. Delta, United, Southwest, and American have all been accused, in one consolidated lawsuit, of secretly coordinating with each other for YEARS (2011-2018) to deliberately LIMIT how many seats they offered on shared routes, specifically to keep ticket prices artificially high across the industry — not competing on capacity the way customers assume rival airlines would. Southwest and American already settled their portion for $60 million combined; Delta and United are still fighting the case as of 2026, having lost their bid to get it dismissed.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 185, "_entity_id": 298, "_entity_slug": "southwest-airlines", "_issuer": "Southwest Airlines Co.", "_issuer_slug": "southwest-airlines-co", "_ticker": "LUV", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fortnite / Epic Games", "Category": "Gaming", "Terms & Conditions URL": "epicgames.com/site/en-US/tos", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "epicgames.com/site/en-US/privacypolicy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "LARGEST SINGLE FINE FOUND ANYWHERE IN THIS ENTIRE 185-COMPANY AUDIT: Epic Games (maker of Fortnite) paid a $275 MILLION FTC penalty for COPPA violations, far exceeding every other completed settlement found across carriers, banks, brokerages, ISPs, autos, and every other app researched in this tracker.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Epic Games ToS, AAA rules, North Carolina law (Epic HQ: Cary, NC). 30-day opt-out via written notice to Epic Games, Inc., Legal Department, Box 254, 2474 Walnut Street, Cary, NC 27518. Given Fortnite's younger-skewing user base, the arbitration clause affects a population that is less likely to understand or exercise the opt-out.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The $275M figure alone makes this the single largest completed monetary penalty in the whole tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cary", "HQ State": "North Carolina", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written earlier session (R5) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'North Carolina' is a non-DMV US state", "Parent / Ultimate Owner": "Epic Games, Inc. (Tencent holds ~40%)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NC SOS Business Registration Search — sosnc.gov/online_services/search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Epic Games, Inc. (Tencent holds ~40%)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] Epic paid a $275 million FTC penalty for COPPA violations, the largest single fine found anywhere in this 185-company audit\nWHAT THE TERMS SAY: Epic Games paid a $275 million FTC penalty for COPPA violations, far exceeding every other completed settlement found across carriers, banks, brokerages, ISPs, autos, and every other app researched in this tracker.\nWHY IT MATTERS: This is the single largest completed monetary penalty in the whole tracker, tied to Fortnite's handling of children's data.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Epic requires mandatory arbitration with a 30-day mail-in opt-out, for a player base that skews younger\nWHAT THE TERMS SAY: Epic's terms impose mandatory binding arbitration with a class action waiver under AAA rules and North Carolina law, with a 30-day opt-out via written notice to Epic's legal department in Cary, NC.\nWHY IT MATTERS: Given Fortnite's younger-skewing user base, the tracker notes this population is less likely to understand or exercise the mail-in opt-out.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-2] SAG-AFTRA is suing Epic over an AI Darth Vader chatbot that mimicked James Earl Jones's voice without full consent safeguards\nWHAT THE TERMS SAY: Fortnite added an AI-powered Darth Vader chatbot NPC using voice lines mimicking James Earl Jones's iconic voice; players found ways to make the AI say things Jones himself never would have agreed to, triggering a SAG-AFTRA lawsuit against Epic over unauthorized use of a deceased actor's voice and likeness.\nWHY IT MATTERS: A deceased actor's voice was used in a product feature that players could manipulate into saying things he never said, prompting union litigation still pending against Epic.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The FTC penalty amount, the arbitration mechanics, and the SAG-AFTRA lawsuit are all specifically documented.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Fortnite / Epic Games  <-  Epic Games, Inc. (Tencent holds ~40%)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Fortnite / Epic Games you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Fortnite added an AI-powered Darth Vader chatbot NPC using voice lines mimicking James Earl Jones's iconic voice — players quickly found ways to make the AI say things Jones himself never would have agreed to, triggering a SAG-AFTRA lawsuit against Epic Games over unauthorized use of a deceased actor's voice and likeness. Epic's own leadership has said AI's goal internally is to make staff 'more efficient,' even as the company simultaneously sues its OWN former contractors for leaking confidential game secrets — a reminder that the same company building AI tools trained partly on voice/likeness data is also fighting hard to keep its own internal information locked down.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 186, "_entity_id": 300, "_entity_slug": "fortnite-epic-games", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Apple TV+", "Category": "Streaming Service", "Terms & Conditions URL": "https://www.apple.com/legal/internet-services/itunes/us/terms.html", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.apple.com/legal/privacy/", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "Apple TV+ is governed by Apple's Media Services Terms, which also cover the App Store, Apple Music, Apple Books, Apple Arcade, and Apple Fitness+. Apple does NOT sell user data and does not operate an advertising exchange (unlike Google, Meta, and Amazon). Apple's privacy-as-product positioning means Apple TV+ viewing data is not cross-sold to advertisers — a structural difference from every other streaming service in this tracker.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Apple's Media Services Terms contain no arbitration clause and no class action waiver. Disputes governed by California law, Santa Clara County courts. Apple is the ONLY major streaming service without mandatory arbitration. Netflix, Disney+, Paramount+, Max, and Peacock all require it.", "Fees / Billing Flags": "Apple TV+ is $9.99/month (increased from $6.99 in Oct 2023). No ad-supported tier. Apple One bundle ($19.95-$37.95/month) combines TV+ with Music, Arcade, iCloud+, Fitness+, and News+.", "Notes": "Apple TV+ is the only major streaming service without mandatory arbitration. Apple's privacy positioning extends to its streaming data — no ad-supported tier, no advertising exchange, no cross-platform behavioral tracking. Contrast with Netflix (added arbitration April 2026), Disney+ (arbitration + $2.75M CCPA settlement), and Peacock (Comcast's arbitration clause + $117.5M breach settlement).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cupertino", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Added 2026-08-06 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Apple Inc.", "Years Referenced in Finding (heuristic)": "2023, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Apple Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — No troubling items are substantiated for Apple TV+ itself in this row: the text states Apple does not sell user data, operates no advertising exchange, and has no arbitration clause or class action waiver in its Media Services Terms. The settlement and litigation figures cited (Netflix's arbitration addition, Disney+'s CCPA/COPPA settlements, Peacock's breach settlement) belong to competitor rows and are used here only as comparison to Apple's structurally different, less troubling posture, per the cross-reference rule.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=?; datasale=N; affiliates=N; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Apple's arbitration-free structure and no-data-sale policy are explicitly and clearly stated, with direct competitor contrasts.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "App / Service", "Ownership Path": "Apple TV+  <-  Apple Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your data shared corporate-wide; your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Apple TV+ takes nothing from the list this tracker checks - but 9 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:37:01Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Apple TV+ is the only major streaming service in this tracker without mandatory arbitration — no class action waiver, no jury trial waiver, disputes go to California courts. Every competitor requires it: Netflix added mandatory arbitration in April 2026 (the most recent addition, logged in the POLICY CHANGES tab), Disney+ has it (alongside a $2.75M CCPA settlement and $10M COPPA settlement), Paramount+ has it, Max has it, Peacock has it (alongside a $117.5M breach settlement). Apple's no-arbitration posture extends across ALL its consumer services — Apple Music, the App Store, iCloud, Apple Arcade, and Fitness+ are all governed by the same Media Services Terms that lack an arbitration clause. The streaming-service comparison is the clearest illustration of how arbitration is an opt-in CHOICE companies make, not a legal requirement: Apple proves a $3-trillion company can operate consumer services at scale without it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 187, "_entity_id": 301, "_entity_slug": "apple-tv", "_issuer": "Apple Inc.", "_issuer_slug": "apple-inc", "_ticker": "AAPL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Washington Post", "Category": "News/Media Subscription", "Terms & Conditions URL": "https://www.washingtonpost.com/terms-of-sale/", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.washingtonpost.com/privacy-policy/", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "The Washington Post collects subscriber data (name, payment, address), reading behavior (articles read, time spent, scroll depth), and advertising data (cross-site tracking through the Arc XP publishing platform). The Post's Arc XP platform is also licensed to other publishers — creating a data network that extends beyond washingtonpost.com. Jeff Bezos acquired the Post in 2013 for $250M; the degree to which Post subscriber data is siloed from Amazon's infrastructure is governed by the Post's own privacy policy, not by any regulatory firewall.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Washington Post Terms of Sale, AAA rules, DC law. 30-day opt-out via written notice to Washington Post Legal, 1301 K Street NW, Washington DC 20071. The Post is headquartered in DC — this is a DMV-based arbitration clause governed by DC law, not California or New York.", "Fees / Billing Flags": "Digital subscription $4/month (intro), $10/month (standard). Premium tier $12/month. Print+digital varies.", "Notes": "Jeff Bezos-owned since 2013. Arc XP publishing platform licensed to 2,000+ publishers globally. The Post's subscriber-data relationship with Amazon's advertising infrastructure is the key open question — the privacy policy addresses this but the degree of practical separation is not independently verifiable from the policy text alone. DC headquarters means DC consumer-protection law (DCPA) applies.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Washington", "HQ State": "District of Columbia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Added 2026-08-06 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Washington, District of Columbia (DC/MD/VA)", "Parent / Ultimate Owner": "Nash Holdings LLC (Jeff Bezos, sole owner)", "Years Referenced in Finding (heuristic)": "2013", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): DC DLCP CorpOnline — corponline.dcra.dc.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Nash Holdings LLC (Jeff Bezos, sole owner)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] The Post's Arc XP platform, licensed to 2,000+ publishers, creates a reader-tracking network extending beyond washingtonpost.com\nWHAT THE TERMS SAY: The Washington Post collects subscriber data, reading behavior (articles read, time spent, scroll depth), and advertising data through cross-site tracking on the Arc XP publishing platform, which is also licensed to 2,000+ other publishers, creating a data network that extends beyond washingtonpost.com.\nWHY IT MATTERS: Reader behavior data can flow through Arc-powered infrastructure the Post controls even on sites that aren't the Washington Post itself.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-2] Whether Post subscriber data is actually siloed from Jeff Bezos's Amazon advertising infrastructure isn't independently verifiable\nWHAT THE TERMS SAY: Jeff Bezos acquired the Post in 2013 for $250 million; the degree to which Post subscriber data is siloed from Amazon's infrastructure is governed by the Post's own privacy policy rather than any regulatory firewall, and the tracker notes the policy addresses the topic but its practical implementation is not independently verifiable from the policy text alone.\nWHY IT MATTERS: A DMV subscriber who also uses a Kindle, shops on Amazon, and owns an Alexa device is generating data across multiple Bezos-connected platforms with no independently confirmed answer on how separated that data actually stays.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] The Post requires arbitration under DC law, while Bezos-connected Amazon, Whole Foods and Alexa do not\nWHAT THE TERMS SAY: The Post's Terms of Sale impose mandatory binding arbitration with a class action waiver under AAA rules and DC law, with a 30-day opt-out via written notice to Washington Post Legal in DC.\nWHY IT MATTERS: The tracker notes three of the four Bezos-connected platforms a DMV subscriber might use (Amazon, Whole Foods, Alexa) share Amazon's no-arbitration terms, while the Post requires arbitration.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The key question of how siloed Post subscriber data actually is from Amazon's advertising infrastructure is explicitly stated as not independently verifiable from the privacy policy alone.", "Exposure Score (0-100)": 36, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Washington Post  <-  Nash Holdings LLC (Jeff Bezos, sole owner)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Washington Post you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The Washington Post — headquartered at 1301 K Street NW, Washington DC, owned by Jeff Bezos since 2013 — has a mandatory arbitration clause governed by DC law with a 30-day opt-out. For a DMV consumer, this is one of the few arbitration clauses in the tracker governed by DC law rather than California or New York. The Post's Arc XP publishing platform, licensed to 2,000+ publishers globally, creates a data network that extends far beyond washingtonpost.com — reader behavior data from Arc-powered sites flows through infrastructure the Post controls. The Bezos ownership creates the tracker's most direct Amazon-adjacent data question: the degree to which Post subscriber data is technically siloed from Amazon's advertising infrastructure is governed by the Post's own privacy policy, which addresses the topic but whose practical implementation is not independently verifiable. A DMV subscriber who reads the Post on their Kindle, orders from Amazon, shops at Whole Foods, and has an Alexa device is generating data across four Bezos-connected platforms — three of which (Amazon, Whole Foods, Alexa) share Amazon's no-arbitration terms, while the Post requires arbitration.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 188, "_entity_id": 303, "_entity_slug": "washington-post", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Coursera", "Category": "Education Platform", "Terms & Conditions URL": "https://www.coursera.org/about/terms", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.coursera.org/about/privacy", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "Coursera processes learner data including course completion, quiz scores, peer-review submissions, video-watching patterns, and professional certificates. Coursera's university partners (Stanford, Yale, Google, IBM) receive aggregate learner data. Coursera for Business and Coursera for Campus create employer- and university-intermediated data relationships where the individual learner may not have directly agreed to data sharing with their employer/institution.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Coursera ToS, AAA rules, California law. 30-day opt-out. The arbitration clause covers disputes over certificate authenticity, course-credit transferability, and data sharing with university/employer partners.", "Fees / Billing Flags": "Individual courses free to audit; Coursera Plus $59/month or $399/year for unlimited certificates. Professional certificates $39-79/month. Degrees $9,000-$45,000+.", "Notes": "Coursera partners with 300+ universities and companies. Learner completion data shared with certificate-issuing institutions. Coursera for Business provides employer dashboards showing individual employee learning progress — the arbitration clause governs whether employees can dispute this workplace-surveillance use of their learning data.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Added 2026-08-06 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Coursera, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Coursera, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Coursera for Business lets employers see individual employees' learning progress through dashboard analytics\nWHAT THE TERMS SAY: Coursera for Business and Coursera for Campus create employer- and university-intermediated data relationships where the individual learner may not have directly agreed to data sharing with their employer or institution; employers can see individual employee learning progress through dashboard analytics.\nWHY IT MATTERS: The arbitration clause governs whether an employee can dispute this workplace-surveillance-style use of their learning data, rather than that use requiring the learner's direct, separate consent.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-2] Coursera isn't a FERPA-covered institution, so student-like learning data lacks the student-privacy protections FERPA would normally provide\nWHAT THE TERMS SAY: Coursera's 300+ university partnerships mean learner data flows to institutions with their own separate FERPA obligations, but Coursera itself is not a FERPA-covered 'educational institution,' creating a regulatory gap where student-like data lacks student-privacy protections.\nWHY IT MATTERS: Career-consequential learner data (completions, quiz scores, certificates) can fall outside the specific legal protections that would apply if a traditional school held it.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Coursera's mandatory arbitration covers disputes over certificate authenticity and course-credit transferability\nWHAT THE TERMS SAY: Coursera's terms impose mandatory binding arbitration with a class action waiver, 30-day opt-out, under AAA rules and California law, covering disputes over certificate authenticity, course-credit transferability, and data sharing with university/employer partners.\nWHY IT MATTERS: If a university refuses to accept a Coursera credit or an employer questions a certificate's validity, the learner's recourse is individual arbitration, not a class action, even though the certificate can appear on job applications.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Practices such as the employer-dashboard data flow and the FERPA gap are described structurally, without any confirmed lawsuit, breach, or regulatory action tied to Coursera specifically.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Coursera  <-  Coursera, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Coursera you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:37:33Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Coursera processes some of the most career-consequential consumer data in this tracker: course completions, quiz scores, peer reviews, and professional certificates that appear on LinkedIn profiles and job applications. The arbitration clause covers disputes over certificate authenticity and course-credit transferability — meaning if a university refuses to accept a Coursera credit, or an employer questions a certificate's validity, the learner's recourse is individual arbitration, not a class action. Coursera for Business creates an additional layer: employers can see individual employee learning progress through dashboard analytics, and the arbitration clause governs whether employees can dispute this workplace-surveillance application of their learning data. Coursera's 300+ university partnerships (Stanford, Yale, Johns Hopkins, University of Michigan) mean that learner data flows to institutions that have their own, separate FERPA obligations — but Coursera itself is not a FERPA-covered 'educational institution,' creating a regulatory gap where student-like data lacks student-privacy protections.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 189, "_entity_id": 305, "_entity_slug": "coursera", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Airbnb", "Category": "Vacation Rental / Home Sharing", "Terms & Conditions URL": "https://www.airbnb.com/terms", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.airbnb.com/terms/privacy_policy", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "Airbnb processes guest identity data (government ID for verification), host property details (photos, location, pricing), payment data, messaging between guests and hosts, review content, and search/booking patterns. Airbnb's identity-verification system collects facial-recognition data (selfie + ID comparison) — the first consumer platform in this tracker to require biometric identity verification for ALL users, not just optional features. Guest search patterns reveal travel intent, budget, and companion information (number of guests, pet-friendly searches).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Airbnb ToS, AAA rules, California law. 30-day opt-out via email to arbitration-opt-out@airbnb.com. Airbnb's three-party structure (guest, host, platform) means the arbitration clause governs guest-Airbnb and host-Airbnb disputes but NOT direct guest-host disputes, which Airbnb mediates through its Resolution Center.", "Fees / Billing Flags": "Airbnb takes 3% from hosts and 14-16% from guests (service fee). Airbnb Plus, Luxe, and Categories carry additional host requirements. Cancellation policies vary by listing.", "Notes": "Airbnb's mandatory biometric identity verification (facial recognition) for all users is a BIPA/CUBI risk in Illinois and Texas. Airbnb's Host Guarantee and AirCover for Hosts create insurance-like obligations governed by the same arbitration clause. The three-party marketplace structure makes Airbnb's arbitration clause more complex than any single-party service.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Added 2026-08-06 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Airbnb, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Airbnb, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] Airbnb is the first platform in this tracker to require facial-recognition ID verification for all users, not as an optional feature\nWHAT THE TERMS SAY: Airbnb's identity-verification system collects facial-recognition data (a selfie compared against an ID) and is the first consumer platform in this tracker to require biometric identity verification for all users, not just as an optional feature; in Illinois (BIPA) and Texas (CUBI) this creates potential biometric-data liability.\nWHY IT MATTERS: Every Airbnb user must upload a government ID and take a selfie for facial-recognition comparison as a mandatory condition of using the service, not a choice.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] A host must arbitrate an AirCover payout dispute; a guest can't class-action a fraudulent listing\nWHAT THE TERMS SAY: Airbnb's mandatory arbitration with a 30-day opt-out covers disputes between a guest and Airbnb and between a host and Airbnb, but not direct guest-host disputes, which go through Airbnb's Resolution Center instead; a host whose property is damaged can't sue Airbnb in court over an AirCover payout, and a guest who finds a listing fraudulent can't join a class action, both must arbitrate individually.\nWHY IT MATTERS: The three-party marketplace structure creates an arbitration complexity where a guest suing a host directly might still reach open court, since the host isn't bound by the guest's arbitration agreement with Airbnb, even as claims against Airbnb itself are pushed into individual arbitration.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Wrong corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only the mandatory biometric ID verification and the three-party arbitration structure are flagged as distinctly troubling in this row; the remaining data collection (payment, messaging, reviews, search patterns) is described as standard marketplace functionality without an associated harm, breach, or lawsuit specific to Airbnb.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The mandatory biometric verification is clearly and specifically described, but its legal risk is framed via comparison to other companies' settlements and lawsuits (Snap, Google Nest) rather than a confirmed Airbnb-specific case.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 6/30 (biometric_collection+6) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Airbnb  <-  Airbnb, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Airbnb you gave up your biometric identifiers, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:37:36Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Airbnb is the first major consumer platform in this tracker to require BIOMETRIC IDENTITY VERIFICATION for all users — not as an optional security feature, but as a mandatory condition of using the service. Every Airbnb user must upload a government-issued ID and take a selfie for facial-recognition comparison. In Illinois (BIPA) and Texas (CUBI), this creates potential biometric-data liability similar to the Snap/Bitmoji $35M settlement and the Google Nest lawsuits documented elsewhere in this tracker. Airbnb's three-party marketplace structure also creates an arbitration complexity unique in this dataset: the mandatory arbitration clause with 30-day opt-out governs disputes between guests and Airbnb, and between hosts and Airbnb, but does NOT govern direct guest-host disputes (those go through Airbnb's Resolution Center, which is itself governed by the arbitration clause). A host whose property is damaged by a guest can't sue Airbnb in court over the AirCover payout — they must arbitrate. A guest who finds a listing fraudulent can't join a class action — they must arbitrate individually. But a guest suing a host for unsafe conditions might go to court, since the host isn't bound by the guest's arbitration agreement with Airbnb.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 190, "_entity_id": 307, "_entity_slug": "airbnb", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Tesla", "Category": "Electric Vehicles / Software", "Terms & Conditions URL": "https://www.tesla.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.tesla.com/legal/privacy", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "Tesla collects more data from its vehicles than any automaker in this tracker: cabin camera footage, external camera footage (8 cameras, 360°), GPS location history, driving behavior (speed, braking, acceleration, steering), battery charge patterns, Supercharger usage, Autopilot/FSD engagement data, and voice commands. Tesla's fleet learning model means YOUR driving data trains the AI that drives EVERY other Tesla. Elon Musk has stated Tesla vehicles will be 'the most productive asset on earth' as robotaxis — meaning the data collected today is being used to build tomorrow's autonomous fleet. No opt-out for camera data collection while the vehicle is operating.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Tesla Order Agreement, AAA Consumer Arbitration Rules. 30-day opt-out via written notice. Judge Haywood S. Gilliam Jr. (N.D. Cal., Oct 2023) ruled that Tesla owners who signed the Order Agreement and did NOT opt out within 30 days must arbitrate Autopilot/FSD claims individually — including claims involving DEATHS and serious injuries. The court found the arbitration clause was NOT unconscionable and was in the 'same size font as the rest of the agreement.' A California class was later certified (July 2026, Judge Lin) for owners who DID opt out or purchased pre-arbitration — creating two parallel tracks: individual arbitration for non-opt-outs, class action for opt-outs. Separately, in July 2025, an arbitrator ordered Tesla to refund $10,000+ for FSD that failed to deliver self-driving capability, plus ~$8,000 in arbitration fees. A new Kentucky class action (Waller v. Tesla, filed June 29, 2026) covers owners across 27 states who opted out of arbitration.", "Fees / Billing Flags": "Vehicle purchase $35K-$130K+. FSD (Full Self-Driving) subscription $99/month or $8,000 one-time. Supercharger per-kWh pricing varies by location. Tesla Insurance (available in 12 states) uses real-time driving data to set premiums.", "Notes": "Tesla is the only company in this tracker where the arbitration clause covers both a physical product (the vehicle) and a software service (Autopilot/FSD) that controls a 2-ton machine at highway speed. Tesla Insurance uses the SAME driving data collected by the car to set insurance premiums — the vehicle is simultaneously the product, the data collector, and the insurance-risk assessor. Compare with GM's FTC consent order (OnStar Smart Driver data sold to LexisNexis without consent) — Tesla does the same thing but ALSO controls the insurance product.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Palo Alto", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Added 2026-08-06 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://techcrunch.com/2023/10/02/tesla-autopilot-arbitration-win-could-set-legal-benchmark-in-auto-industry", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Tesla, Inc. (Elon Musk, CEO/largest shareholder)", "Years Referenced in Finding (heuristic)": "2024, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "CT Corporation System (California) / Corporation Trust Company (Delaware) — CONFIRM on live registry before serving", "Registered Agent Address / Service Notes": "Tesla, Inc. is a Delaware-incorporated corporation. Delaware registered agents for Delaware-domestic corporations are commonly Corporation Trust Company, Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801. NOT INDEPENDENTLY VERIFIED for Tesla specifically this pass — confirm via the Delaware Division of Corporations entity search before relying on it. Corporate/legal correspondence address: Tesla, Inc., Legal Department, 1 Tesla Road, Austin, TX 78725. Arbitration opt-out notices historically directed to Tesla Legal, 3500 Deer Creek Road, Palo Alto, CA 94304.", "Company Brief": "Tesla, Inc. designs and manufactures electric vehicles, battery energy storage, and solar products, and develops the Autopilot and Full Self-Driving (FSD) driver-assistance software. It is unusual among automakers in selling direct to consumers with no franchised dealer network, meaning the purchase agreement and the software terms of service form a single contractual relationship with one company. Tesla also underwrites its own insurance product in a number of states, priced in part from telemetry the vehicle itself reports.", "Investor Overview": "Nasdaq: TSLA. Vertically integrated across vehicle manufacture, charging (Supercharger network), insurance, and autonomous-driving software. INVESTOR-RELEVANT LEGAL STRUCTURE: Tesla has successfully compelled individual arbitration for Autopilot/FSD claims including death and serious-injury cases (N.D. Cal., Judge Haywood S. Gilliam Jr., Oct 2023), which materially limits aggregate litigation exposure from owners who did not opt out. Countervailing exposure: a California class was certified in July 2026 for owners who DID opt out or who purchased before the arbitration provision, and a Kentucky class action (Waller v. Tesla, filed 2026-06-29) covers opt-out owners across 27 states — creating two parallel litigation tracks.", "Major Issues Record": "2023-10: Judge Gilliam (N.D. Cal.) compels individual arbitration for Autopilot/FSD claims where owners signed the Order Agreement and did not opt out within 30 days; court found the clause not unconscionable and printed in the same size font as the surrounding agreement. | 2025-07: An arbitrator orders Tesla to refund a customer $10,000+ for FSD that did not deliver promised self-driving capability, plus approximately $8,000 in arbitration fees — evidence that individual arbitration can succeed, at a cost per claimant most owners will not incur. | 2026-06-29: Waller v. Tesla filed in Kentucky covering arbitration opt-out owners across 27 states. | 2026-07: California Arbitration Opt-Out class certified (In re Tesla ADAS Litigation), narrowed to a class period ending 2024-07-31. | Ongoing: Tesla Insurance uses vehicle-reported driving telemetry to price premiums, an internal-use analogue to the third-party data sales that produced GM's FTC consent order (Jan 2026).", "T&C Key Provisions (paraphrased)": "PARAPHRASED, not quoted. Tesla's Order Agreement provides for binding individual arbitration under AAA consumer rules with a class-action waiver, and gives the buyer 30 days from signing to opt out in writing. Courts have read the clause to reach Autopilot and FSD claims, including personal-injury and wrongful-death claims. Vehicle data collection is addressed in Tesla's separate Customer Privacy Notice; camera and telemetry collection is not separately opt-outable while the vehicle is operating. CONSUMER ACTION: the 30-day arbitration opt-out is the single highest-value action available to a Tesla buyer, and it must be exercised in writing at purchase — it is not available later.", "Re-verify By": "2026-11-13 (Waller v. Tesla and the CA class action are both active — status will move)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Tesla buyers who miss the 30-day opt-out must arbitrate Autopilot/FSD death and injury claims individually.\nWHAT THE TERMS SAY: Tesla's Order Agreement mandates binding individual arbitration under AAA rules with a class action waiver. A federal judge (Gilliam, N.D. Cal., Oct 2023) ruled that owners who signed and did not opt out within 30 days must arbitrate Autopilot/FSD claims individually, including claims involving deaths and serious injuries, finding the clause not unconscionable and printed in the same font size as the rest of the agreement.\nWHY IT MATTERS: A consumer harmed by an Autopilot/FSD defect causing death or serious injury has no path to a class action or jury trial unless they opted out in writing within 30 days of signing.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SURVEILLANCE_PRICING · FL-2] Tesla uses the driving and camera data it collects to set your Tesla Insurance premium in real time.\nWHAT THE TERMS SAY: Tesla collects continuous camera, GPS, and driving-behavior data with no opt-out for camera data while the vehicle is operating; Tesla Insurance (available in 12 states) uses this real-time driving data to set premiums.\nWHY IT MATTERS: The vehicle is simultaneously the data collector and the insurance-risk assessor, so a driver's behavior directly affects their insurance cost, with no way to opt out of camera collection while driving.\n(evidence: Data Sharing/Selling Flags | SCARY | Fees / Billing Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[AI_TRAINING · FL-2] No opt-out for Tesla camera data while the vehicle is operating; driving data trains the AI in every Tesla.\nWHAT THE TERMS SAY: Tesla collects cabin and external camera footage from 8 cameras, GPS location history, driving behavior, and voice commands; its fleet learning model means one owner's driving data trains the AI used across every other Tesla, and there is no opt-out for camera data collection while the vehicle is operating.\nWHY IT MATTERS: Consumers cannot decline in-cabin/exterior camera recording during normal use, and their driving data contributes to training Tesla's broader autonomous-driving system with no way to opt out of that specific collection.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=N; affiliates=N; biometric=?; aitrain=Y; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Arbitration terms, court rulings, and data practices are documented with specific case names, dates, and judges.", "Exposure Score (0-100)": 49, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 9/30 (ai_training_on_user_data+5, precise_location_tracking+4) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nAI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Tesla  <-  Tesla, Inc. (Elon Musk, CEO/largest shareholder)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A continuous record of everywhere you physically go.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your data shared corporate-wide.\n\nNOT YET DETERMINED (7 of 13): your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Tesla you gave up your content used as AI training data, your physical movements, your right to sue, and your right to join a class action. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 66.7, "URL Last Validated": "2026-09-08T19:37:39Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Tesla's Terms of Use create the most vertically integrated consumer-data regime in this tracker. The same company that BUILDS your car, DRIVES it (Autopilot/FSD), CHARGES it (Supercharger network), INSURES it (Tesla Insurance in 12 states), and ARBITRATES disputes about it also collects continuous data from 8 cameras, GPS, cabin microphones, and driving-behavior sensors. Tesla Insurance uses this SAME data to set premiums in real time — your car is simultaneously reporting your driving behavior to your insurer and to the AI training pipeline for Tesla's autonomous fleet. The arbitration clause covers Autopilot and FSD failures — meaning a crash caused by a software defect in a 2-ton vehicle traveling at highway speed is subject to individual arbitration, not a class action. GM's FTC consent order (Jan 2026) established that selling driving data to insurance-scoring companies without consent violates consumer-protection law — but GM was selling to THIRD parties (LexisNexis, Verisk), while Tesla uses the data INTERNALLY for its own insurance product, a structural difference that may place it outside the FTC precedent. Compare with Uber's AV arbitration clause (cross-cutting finding #25): Uber pre-emptively extended arbitration to autonomous vehicles that barely exist on its platform; Tesla's clause covers an autonomous-driving system that is ALREADY deployed on millions of vehicles.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 191, "_entity_id": 309, "_entity_slug": "tesla", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "PayPal", "Category": "Payment Platform", "Terms & Conditions URL": "https://www.paypal.com/us/legalhub/useragreement-full", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.paypal.com/us/legalhub/privacy-full", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "PayPal processes payment data for 430M+ active accounts across 200+ markets. PayPal's data network includes: transaction amounts, merchant categories, sender/recipient identities, linked bank accounts, credit card numbers, shipping addresses, and increasingly, BNPL (Pay in 4) credit data. PayPal Honey (acquired 2020 for $4B) collects browsing and shopping behavior across e-commerce sites through its browser extension — this is the most surveillance-intensive PayPal product because it sees your shopping activity BEFORE you decide to purchase.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. PayPal User Agreement, AAA rules, Delaware law. 30-day opt-out via written notice to PayPal Inc., Attn: Litigation Department, 2211 North First Street, San Jose CA 95131. The arbitration clause governs PayPal, Venmo, Xoom, Braintree consumer products, and PayPal Honey. A dispute over Honey's browser tracking is arbitrated under the same clause as a Venmo payment dispute.", "Fees / Billing Flags": "No fee for personal payments funded by PayPal balance or bank. 2.99% for credit/debit-funded payments. Merchant fees 2.29-3.49% + $0.49. Pay in 4 (BNPL) no interest if paid on time. Currency conversion 3-4% spread.", "Notes": "PayPal is the parent of Venmo (already documented in this tracker). The PayPal Honey browser extension is the key finding: it collects shopping behavior ACROSS the web, not just on PayPal-powered sites. This makes Honey structurally similar to a surveillance tool that happens to offer coupons. PayPal's BNPL product (Pay in 4) creates credit-like obligations governed by the same arbitration clause as payment disputes.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Jose", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Added 2026-08-06 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "PayPal Holdings, Inc.", "Years Referenced in Finding (heuristic)": "2020", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: PayPal Holdings, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] One arbitration clause covers PayPal, Venmo, Xoom, Braintree, and Honey's web-tracking disputes alike.\nWHAT THE TERMS SAY: PayPal's User Agreement imposes mandatory binding arbitration under AAA rules with a class action waiver, governed by Delaware law, with a 30-day opt-out to a San Jose litigation-department address; the same clause governs disputes over Venmo, Xoom, Braintree, and PayPal Honey.\nWHY IT MATTERS: A dispute over Honey's browsing-behavior tracking is forced into the same individual-arbitration process as a Venmo payment dispute, with no class action unless the consumer opts out in writing within 30 days.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-2] PayPal Honey tracks shopping behavior across the entire web, not just PayPal-powered sites.\nWHAT THE TERMS SAY: PayPal Honey (acquired 2020 for $4B, installed by 17M+ users) collects browsing and shopping behavior across e-commerce sites via its browser extension, including which products are viewed, added to cart, abandoned, or bought, on any e-commerce site.\nWHY IT MATTERS: This lets PayPal observe a consumer's shopping intent before a purchase decision is made, extending data collection well beyond payment processing itself.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — T&C Key Provisions and Major Issues Record fields are empty for this row; only two distinct, company-specific harms (arbitration scope and Honey's cross-web tracking) are substantiated in the available text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Data-sharing and arbitration practices are described specifically, but Key Provisions and Major Issues fields are empty, leaving parts of the picture unconfirmed.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "PayPal  <-  PayPal Holdings, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using PayPal you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:37:41Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "PayPal processes payments for 430 million active accounts — and its most data-intensive product isn't payments at all. PayPal Honey (acquired 2020, $4B), a browser extension installed by 17M+ users, tracks shopping behavior ACROSS the entire web: which products you view, which you add to cart, which you abandon, and which you buy — on ANY e-commerce site, not just PayPal-powered ones. This browsing-surveillance data is governed by the same mandatory arbitration clause as a Venmo person-to-person payment dispute. PayPal's Pay in 4 (BNPL) product creates an additional data layer: purchase-financing decisions that reveal budget constraints and spending priorities, governed by the same terms. A consumer who uses PayPal for payments, Venmo for social payments, and Honey for coupons has given one company (PayPal Holdings) visibility into their payment network, their social-payment graph, AND their shopping-intent data — all under one arbitration clause with a 30-day opt-out to a San Jose PO box.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 192, "_entity_id": 310, "_entity_slug": "paypal", "_issuer": "PayPal Holdings, Inc.", "_issuer_slug": "paypal-holdings-inc", "_ticker": "PYPL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Costco", "Category": "Warehouse Club / Retail", "Terms & Conditions URL": "https://www.costco.com/terms-and-conditions.html", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.costco.com/privacy-policy.html", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "Costco's membership model means the company has a DIRECT relationship with every shopper — unlike Walmart or Target, where anyone can walk in. Costco collects purchase history linked to a specific membership number across all categories: groceries, pharmacy (HIPAA-covered), optical, hearing aids, travel, auto buying, and Costco Services (home/auto insurance). The Costco Anywhere Visa (issued by Citi) creates a combined retail + financial data profile. Costco's pharmacy is one of the largest in the US — prescription data is HIPAA-covered but the rest of the membership purchase data is not.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Costco.com Terms & Conditions, AAA rules, Washington state law (Costco HQ: Issaquah, WA). 30-day opt-out. The in-store membership agreement may contain separate terms — check the physical membership application.", "Fees / Billing Flags": "Membership: Gold Star $65/year, Executive $130/year (2% annual reward). No markup above 14% on branded goods, 15% on Kirkland Signature.", "Notes": "Costco's membership model creates a data completeness that open-access retailers can't match: every purchase is tied to a specific person/household. The Costco Citi Visa creates a payment-plus-rewards data stream. Costco Travel, Costco Auto, and Costco Services extend the relationship into travel, vehicles, and home services — all under one membership number. The Executive membership's 2% reward requires Costco to track annual spending precisely.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Issaquah", "HQ State": "Washington", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Added 2026-08-06 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Costco Wholesale Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Costco Wholesale Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Costco's 30-day arbitration clause covers disputes across groceries, pharmacy, travel, and insurance.\nWHAT THE TERMS SAY: MANDATORY binding arbitration with class action waiver under Costco.com Terms & Conditions, AAA rules, Washington state law, with a 30-day opt-out; the tracker notes the separate in-store membership agreement may contain its own terms.\nWHY IT MATTERS: A member's dispute over any category under the membership - pharmacy, optical, travel, insurance - is pushed into individual arbitration unless they opt out within 30 days.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Costco's membership number links HIPAA-covered pharmacy data to unprotected retail and travel data.\nWHAT THE TERMS SAY: Costco links purchase history to a specific membership number across groceries, pharmacy (HIPAA-covered), optical, hearing aids, travel, auto buying, and Costco Services; the pharmacy data is HIPAA-covered but the rest of the membership purchase data is not.\nWHY IT MATTERS: A member's health-adjacent purchases (pharmacy, hearing aids, optical) sit alongside a broader retail profile that lacks HIPAA-level protection, creating a more complete profile than open-access retailers can build.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] The Costco Citi Visa merges retail purchase data with financial data across Costco and non-Costco spending.\nWHAT THE TERMS SAY: The Costco Anywhere Visa, issued by Citi, creates a combined retail + financial data profile; Citi sees every Costco and non-Costco purchase made with the card, while Costco separately tracks precise annual spend for the Executive membership's 2% reward.\nWHY IT MATTERS: Two companies (Costco and Citi) each build a detailed profile of a member's spending, extending visibility beyond what either would see alone.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "No breach or litigation is documented, and Key Provisions/Major Issues fields are empty, so findings rely on descriptive SCARY/Notes text only.", "Exposure Score (0-100)": 33, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Costco  <-  Costco Wholesale Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Costco you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Costco's membership model makes it structurally different from every other retailer in this tracker. At Walmart, Target, or Best Buy, a shopper can pay cash and leave no data trail. At Costco, every transaction is tied to a membership number — creating a comprehensive purchase profile that spans groceries, electronics, pharmacy (HIPAA-covered), optical, hearing aids, travel, auto buying, and home services. The Costco Anywhere Visa (issued by Citi) adds a financial-data layer: Citi sees every Costco purchase AND every non-Costco purchase made with the card, while Costco sees the 2% Executive reward calculation that requires precise annual-spend tracking. A Costco member who uses the pharmacy, buys glasses at the optical center, books travel through Costco Travel, and pays with the Costco Visa has given the company visibility across health, vision, travel, and spending — a data profile more comprehensive than any single-category retailer can build. The mandatory arbitration clause with 30-day opt-out governs disputes across all of these categories under one membership agreement.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 193, "_entity_id": 312, "_entity_slug": "costco", "_issuer": "Costco Wholesale Corporation", "_issuer_slug": "costco-wholesale-corporation", "_ticker": "COST", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Chewy", "Category": "Pet Supplies / Veterinary Telehealth", "Terms & Conditions URL": "https://www.chewy.com/app/content/terms", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.chewy.com/app/content/privacy", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "Chewy processes pet-owner purchase data (food, medication, supplements), veterinary telehealth consultations (Connect with a Vet), prescription pet medications (Chewy Pharmacy, DEA-licensed), pet insurance claims, and Autoship subscription data. Chewy's data profile reveals not just what you buy but your pet's health conditions, medications, dietary restrictions, and veterinary history. Pet prescription data is NOT covered by HIPAA (which applies to human health data only). Chewy Pharmacy's controlled-substance dispensing (e.g., gabapentin for pets) is DEA-regulated but the purchase data itself has no health-privacy protection.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Chewy ToS, AAA rules, Florida law (Chewy HQ: Plantation, FL). 30-day opt-out via written notice to Chewy Inc., Legal Department, 7700 W Sunrise Blvd, Plantation FL 33322. The arbitration clause covers veterinary telehealth consultations — health-adjacent data with no HIPAA protection.", "Fees / Billing Flags": "Free shipping over $49. Autoship 5-10% discount. Chewy Pharmacy pricing competitive with retail. Connect with a Vet (telehealth) included for Chewy customers.", "Notes": "Chewy was founded by Ryan Cohen (later GameStop chairman), sold to PetSmart in 2017 for $3.35B, and IPO'd in 2019. PetSmart's parent (BC Partners) retains a ~77% stake. Chewy's Autoship program creates a recurring-purchase data stream that reveals pet health changes (switching from regular food to prescription diet = health event). The veterinary telehealth service creates the tracker's only example of health-consultation data with ZERO health-privacy-law protection.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Plantation", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Added 2026-08-06 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "Chewy, Inc. (BC Partners/PetSmart retain ~77% stake via class B shares)", "Years Referenced in Finding (heuristic)": "2017, 2019", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Chewy, Inc. (BC Partners/PetSmart retain ~77% stake via class B shares)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Chewy's arbitration clause covers vet telehealth consultations that carry no HIPAA protection.\nWHAT THE TERMS SAY: MANDATORY binding arbitration with class action waiver, AAA rules, Florida law, 30-day opt-out; the clause covers veterinary telehealth consultations (Connect with a Vet) - health-adjacent data with no HIPAA protection.\nWHY IT MATTERS: A dispute over a mishandled telehealth consultation about a pet's health is pushed into individual arbitration, with no class action unless the consumer opts out within 30 days.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Chewy's pet-health data - prescriptions, vet consults, dietary changes - has no HIPAA-equivalent protection.\nWHAT THE TERMS SAY: Chewy's data profile reveals pet health conditions, medications, dietary restrictions, and veterinary history through purchases, DEA-licensed Chewy Pharmacy prescriptions, and Connect with a Vet telehealth; pet prescription data is not covered by HIPAA, which applies only to human health data.\nWHY IT MATTERS: Chewy's own privacy policy is the only protection for this health-adjacent data, since no health-privacy law covers pet medical information the way HIPAA covers human data.\n(evidence: Data Sharing/Selling Flags | SCARY | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct harms are substantiated - arbitration scope over telehealth, and the absence of health-privacy protection for pet data. The Autoship longitudinal-signal point in Notes restates the same underlying data-protection gap rather than describing a separate practice, and Key Provisions/Major Issues fields are empty.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "No breach or litigation is documented for Chewy; findings rely on the SCARY/Notes description rather than confirmed incidents.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Chewy  <-  Chewy, Inc. (BC Partners/PetSmart retain ~77% stake via class B shares)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Chewy you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:38:54Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Chewy's data profile is unlike anything else in this tracker: it reveals your pet's health conditions, medications, dietary restrictions, and veterinary history — and NONE of it is protected by HIPAA, which applies only to human health data. Chewy Pharmacy is DEA-licensed and dispenses controlled substances (gabapentin, tramadol for pets), but the purchase data has no health-privacy protection beyond Chewy's own privacy policy. Chewy's Connect with a Vet telehealth service creates health-consultation records — a veterinarian discussing your pet's symptoms — governed by the same arbitration clause as a chew-toy purchase. The Autoship program (recurring scheduled deliveries) creates a longitudinal health signal: switching from regular food to a prescription diet, adding a joint supplement, or stopping a flea medication all correlate with pet health events that Chewy can observe through purchase-pattern changes. A Chewy customer who uses Autoship, the pharmacy, and the telehealth service has given one company a comprehensive pet-health record with no regulatory floor — making Chewy's privacy policy the ONLY protection, and the mandatory arbitration clause the ONLY dispute path.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 194, "_entity_id": 314, "_entity_slug": "chewy", "_issuer": "Chewy", "_issuer_slug": "chewy", "_ticker": "CHWY", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Capital One", "Category": "Banking / Credit Cards", "Terms & Conditions URL": "https://www.capitalone.com/digital/terms-and-conditions/", "T&C Direct PDF?": null, "Privacy Policy URL": "https://www.capitalone.com/privacy/", "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Capital One processes credit card transaction data (350M+ accounts), banking data (checking, savings, CDs), auto loan data, and increasingly, shopping-reward data through Capital One Shopping (browser extension, fmr. Wikibuy, acquired 2018). Like PayPal Honey, Capital One Shopping tracks browsing and shopping behavior ACROSS the web — not just on Capital One-affiliated sites. Capital One's 2019 breach (106M credit card applicants, one of the largest bank breaches in US history) was caused by a misconfigured AWS WAF — Capital One was an early AWS adopter, and the breach was traced to a former AWS employee.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Capital One Customer Agreement, AAA rules, Virginia law (Capital One HQ: McLean, VA — DMV). 30-day opt-out via written notice to Capital One, Attn: Legal Operations, 15000 Capital One Drive, Richmond VA 23238. The arbitration clause covers credit card, banking, and auto loan disputes. The 2019 breach ($190M class settlement, 2022) was a CLASS action that survived the arbitration clause because it was filed as a negligence/data-security claim, not a contract dispute.", "Fees / Billing Flags": "No annual fee on most consumer cards. Venture X $395/year. Auto loan rates competitive. No foreign transaction fees on travel cards. Capital One Cafés (free banking + coffee shops) operate in DMV at Tysons, Georgetown, Bethesda, and Clarendon.", "Notes": "Capital One is headquartered in McLean, Virginia — one of the largest private employers in the DMV corridor (50,000+ employees in the region). Capital One Cafés operate in Georgetown, Tysons Corner, Bethesda, and Clarendon — physical locations where the Capital One brand intersects daily DMV life. The 2019 breach ($190M settlement) was caused by a misconfigured cloud infrastructure component, not a traditional hack — a finding about cloud-vendor dependency, not just Capital One's security.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "McLean", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-13", "Provenance (who determined this)": "Added 2026-08-13 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": "https://www.security.org/identity-theft/breach/capital-one/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ: McLean, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "Capital One Financial Corporation (McLean, VA)", "Years Referenced in Finding (heuristic)": "2018, 2019, 2022", "Audit Depth": "Full audit", "Registered Agent (Name)": "Corporation Service Company (CSC) — Virginia registered agent", "Registered Agent Address / Service Notes": "Registered Office: 100 Shockoe Slip, Fl 2, Richmond, VA 23219-4100. Principal Office: 1680 Capital One Dr, McLean, VA 22102-3407. VERIFIED against the Virginia SCC Clerk's Information System entity record for CAPITAL ONE FINANCIAL CORPORATION. CRITICAL SERVICE CAVEAT: Capital One Financial Corporation (the Delaware holding company) and Capital One, National Association (the OCC-chartered bank, FDIC Cert. 4297, Fed RSSD 112837) are SEPARATE legal entities. Service on the holding company's registered agent does NOT bind the bank. Each entity requires its own service event against its own agent. Legacy Discover claims may involve yet another entity — some Discover entities were dissolved post-merger, and service on a dissolved entity neither starts the clock nor tolls the statute of limitations.", "Company Brief": "Capital One Financial Corporation is a Delaware-incorporated bank holding company headquartered in the Capital One Tower, Tysons/McLean, Virginia. Founded 1994 in Richmond by Richard Fairbank and Nigel Morris. It is the largest credit-card issuer in the United States and one of the largest auto lenders, operating across the US, Canada, and the UK through three segments: credit cards, consumer banking, and commercial banking. Following the Discover acquisition it also owns the Discover, Diners Club, and Pulse payment networks — making it one of very few US institutions that both issues cards and operates a card network.", "Investor Overview": "NYSE: COF. S&P 100 and S&P 500 component. Revenue $53.4B (2025). Total assets $669.0B (2025). Total equity $94.6B (2025). Operating income $5.91B (2024). Net income before tax $4.747B (2024). Employees 76,300 (2025). Capital ratio 12.9% (2023). Chairman/President/CEO: Richard Fairbank (founder). CFO: Andrew Young. Brands: Capital One, CreditWise, Discover, Diners Club, Pulse. INVESTOR-RELEVANT RISK: the Discover integration adds network economics but also consolidates two consumer-complaint and regulatory surfaces; the 2019 breach cost ~$270M+ in combined penalties and settlement.", "Major Issues Record": "2019-07: Breach disclosed — ~106M US and Canadian credit-card applicants. Root cause was a misconfigured web application firewall in Capital One's AWS environment exploited via SSRF by Paige Thompson, a former AWS employee. Data included names, addresses, credit scores, and ~140K SSNs / ~80K linked bank account numbers. | 2020-08: OCC assessed an $80M civil money penalty for risk-management deficiencies tied to the cloud migration. | 2022: $190M class settlement receives final approval (Edmonson v. Capital One, E.D. Va., 1:21-cv-00332). The class action SURVIVED Capital One's arbitration clause because the claims sounded in negligence and data security rather than in contract. | 2024-02: Discover acquisition announced; subsequently completed, bringing the Discover/Diners Club/Pulse networks in-house. | Ongoing: Capital One Shopping (fmr. Wikibuy, acquired 2018) operates a browser extension that observes shopping behavior across third-party e-commerce sites, not only Capital One properties.", "T&C Key Provisions (paraphrased)": "PARAPHRASED, not quoted. Capital One's Customer Agreement provides for mandatory individual arbitration and waives class actions, with a 30-day window to reject the arbitration provision by written notice. Governing law is Virginia. The agreement covers credit card, deposit, and auto-loan relationships. Separate agreements govern Capital One Shopping and the mobile app. CONSUMER ACTION: rejection notice goes to Capital One, Attn: Legal Operations, 15000 Capital One Drive, Richmond VA 23238 — send within 30 days of account opening and keep proof of mailing.", "Re-verify By": "2027-02-13 (re-check Discover integration status and any new CFPB/OCC actions)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Capital One's 2019 breach exposed 106 million applicants' data, including about 140,000 SSNs.\nWHAT THE TERMS SAY: Breach disclosed July 2019: ~106M US and Canadian credit-card applicants affected; root cause was a misconfigured web application firewall in Capital One's AWS environment, exploited via SSRF by a former AWS employee (Paige Thompson); data included names, addresses, credit scores, ~140K SSNs, and ~80K linked bank account numbers.\nWHY IT MATTERS: Applicants and customers had highly sensitive financial identifiers exposed - names, addresses, credit scores, ~140K SSNs and ~80K linked bank account numbers - and a $190M class settlement received final approval in 2022.\n(evidence: Major Issues Record | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-1] The OCC fined Capital One $80 million for risk-management failures tied to its cloud migration.\nWHAT THE TERMS SAY: In August 2020, the OCC assessed an $80M civil money penalty against Capital One for risk-management deficiencies tied to the cloud migration.\nWHY IT MATTERS: This is a confirmed regulatory finding that Capital One's own risk controls, not just an external attacker, contributed to the exposure of customer data.\n(evidence: Major Issues Record; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Capital One's arbitration clause covers card, banking, and auto-loan disputes, with a 30-day opt-out.\nWHAT THE TERMS SAY: MANDATORY binding arbitration with class action waiver under AAA rules and Virginia law; 30-day opt-out via written notice to a specific Richmond, VA address; the clause covers credit card, banking, and auto loan disputes. The 2019 breach's $190M class settlement (2022) survived this clause only because it was filed as a negligence/data-security claim rather than a contract dispute.\nWHY IT MATTERS: Most account disputes are pushed into individual arbitration with no class action; only claims framed outside the contract, like the breach negligence suit, escaped this restriction.\n(evidence: Arbitration / Class Action Waiver | Major Issues Record; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The breach, regulatory penalty, and settlement are documented with specific dates, dollar figures, and a docket citation.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Capital One  <-  Capital One Financial Corporation (McLean, VA)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Capital One you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "2026-09-08T19:38:57Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Capital One is headquartered in McLean, Virginia — one of the largest private employers in the DMV corridor, with 50,000+ employees, Capital One Cafés in Georgetown, Tysons, Bethesda, and Clarendon, and its name on the arena where the Washington Capitals and Wizards play. The 2019 breach exposed 106 million credit card applicants' data — one of the largest bank breaches in US history — and it was caused not by a traditional hack but by a misconfigured WAF (Web Application Firewall) in Capital One's AWS infrastructure, exploited by a former AWS employee (Paige Thompson). The $190M class settlement (2022) survived Capital One's arbitration clause because the claims sounded in negligence and data security, not contract. Capital One Shopping (fmr. Wikibuy, acquired 2018) is a browser extension that, like PayPal Honey, tracks shopping behavior across the entire web — creating a surveillance layer that extends far beyond Capital One's own card transactions. A DMV resident who banks at Capital One, carries a Venture card, uses Capital One Shopping, and has an auto loan through Capital One has given one Virginia-headquartered company visibility across banking, credit, shopping-intent, and vehicle-financing data — all under a Virginia-law arbitration clause with a 30-day opt-out.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 195, "_entity_id": 61, "_entity_slug": "capital-one", "_issuer": "Capital One", "_issuer_slug": "capital-one", "_ticker": "COF", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "TaskRabbit", "Category": "Gig Economy / Home Services", "Terms & Conditions URL": "https://www.taskrabbit.com/terms", "T&C Direct PDF?": null, "Privacy Policy URL": "https://www.taskrabbit.com/privacy", "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "TaskRabbit processes home-address data (where tasks are performed), task descriptions (which reveal home conditions, security vulnerabilities, and personal schedules), payment data, and Tasker identity verification. TaskRabbit's data is uniquely intimate: a client requesting furniture assembly is sharing their home address, their availability schedule, and effectively letting a stranger into their home — all governed by TaskRabbit's T&C, not by any in-person service contract.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. TaskRabbit ToS, AAA rules, California law. 30-day opt-out. TaskRabbit is an IKEA subsidiary (acquired 2017) — the arbitration clause is from a Swedish parent company's US subsidiary, governed by California law.", "Fees / Billing Flags": "TaskRabbit takes a 15% service fee from clients on top of the Tasker's hourly rate. Taskers set their own rates. No subscription fee.", "Notes": "TaskRabbit was acquired by IKEA's parent (Ingka Group) in 2017, making it the only gig-economy platform in this tracker owned by a furniture retailer. The IKEA connection creates a data bridge between furniture purchase behavior and home-service needs. TaskRabbit operates in the DMV (DC, Arlington, Alexandria, Bethesda, Silver Spring).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-13", "Provenance (who determined this)": "Added 2026-08-13 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Ingka Group (IKEA parent, Sweden)", "Years Referenced in Finding (heuristic)": "2017", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Ingka Group (IKEA parent, Sweden)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] TaskRabbit's arbitration clause covers property damage and safety disputes with Taskers who enter your home.\nWHAT THE TERMS SAY: MANDATORY binding arbitration with class action waiver, AAA rules, California law, 30-day opt-out; TaskRabbit is an IKEA subsidiary and the clause covers disputes over task quality, property damage, and personal safety.\nWHY IT MATTERS: If a Tasker damages property or a background check was inadequate, recourse is individual arbitration, not a class action or jury trial.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Booking a TaskRabbit shares your home address, your at-home schedule, and your home's condition.\nWHAT THE TERMS SAY: TaskRabbit processes home-address data, task descriptions (revealing home conditions and security vulnerabilities), and client availability schedules, all governed by TaskRabbit's terms rather than an in-person service contract.\nWHY IT MATTERS: This is unusually intimate data - where a customer lives, when they will be home, and a task description that reveals home conditions and security vulnerabilities - handled under TaskRabbit's T&C rather than an in-person service contract.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct, company-specific harms are substantiated (arbitration scope, and address/schedule/home-condition data exposure); the IKEA cross-company 'data bridge' point in Notes is speculative rather than a stated practice, and Key Provisions/Major Issues are empty.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "No breach, litigation, or Key Provisions/Major Issues detail is documented; findings come only from the SCARY/Notes narrative.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "TaskRabbit  <-  Ingka Group (IKEA parent, Sweden)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using TaskRabbit you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:38:59Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "TaskRabbit collects the most physically intimate consumer data in this tracker: your home address, your schedule of when you'll be home, a description of what needs fixing (which reveals household conditions), and the identity of the stranger you're letting inside — all governed by a mandatory arbitration clause from a California-headquartered, Swedish-owned company (IKEA acquired TaskRabbit in 2017). A DMV resident who books a TaskRabbit for IKEA furniture assembly in their apartment has shared their home address, apartment layout (implicit in the task), and availability with a platform owned by the company that sold them the furniture — a vertically integrated service-and-data relationship. TaskRabbit's arbitration clause covers disputes over task quality, property damage, and personal safety — meaning if a Tasker damages your property or if TaskRabbit's background-check process was inadequate, your recourse is individual arbitration, not a class action.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 196, "_entity_id": 317, "_entity_slug": "taskrabbit", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Bluesky", "Category": "Social Network", "Terms & Conditions URL": "https://bsky.social/about/support/tos", "T&C Direct PDF?": null, "Privacy Policy URL": "https://bsky.social/about/support/privacy-policy", "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Bluesky processes social-media posts, follower graphs, direct messages, and profile data. Bluesky's AT Protocol (decentralized architecture) means that user data can be hosted on independent servers (Personal Data Servers, PDS) rather than exclusively on Bluesky's infrastructure — a structural difference from every other social network in this tracker. A user who runs their own PDS controls where their data physically resides. Bluesky does NOT sell advertising as of this entry — the business model is not yet fully established.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Bluesky PBLLC (Public Benefit LLC) ToS do not contain an arbitration clause or class action waiver. Disputes governed by Delaware law, Delaware courts. Bluesky's no-arbitration posture is consistent with its decentralization ethos — the company is positioning itself as the anti-X/anti-Meta alternative. Compare directly with X (Twitter), which has a class action waiver, $100 liability cap, and split statute-of-limitations.", "Fees / Billing Flags": "Free. No subscription tier as of this entry (Bluesky+ or equivalent may launch in the future). No advertising revenue model yet.", "Notes": "Bluesky was incubated by Jack Dorsey (Twitter co-founder) as an internal Twitter project, then spun out as an independent company. The AT Protocol allows federation — meaning Bluesky's data architecture is designed so that competing services can interoperate, unlike X/Meta/Snapchat's walled gardens. The absence of arbitration, combined with the decentralized data model, makes Bluesky the most structurally consumer-protective social network in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-13", "Provenance (who determined this)": "Added 2026-08-13 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Bluesky PBLLC (Public Benefit LLC, Jay Graber CEO)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Bluesky PBLLC (Public Benefit LLC, Jay Graber CEO)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Bluesky has no ad model yet, so whether its favorable posture survives monetizing is untested.\nWHAT THE TERMS SAY: Bluesky does not sell advertising as of this entry; the business model is not yet fully established. The tracker notes that when Bluesky eventually monetizes, whether the no-arbitration posture survives will test whether the decentralization promise was real or aspirational.\nWHY IT MATTERS: Consumers relying on Bluesky's currently favorable terms have no guarantee those terms persist once the company adopts a revenue model.\n(evidence: Data Sharing/Selling Flags | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — This row documents Bluesky's terms as unusually consumer-protective (no arbitration, no class waiver, decentralized data architecture); the only forward-looking risk noted is that Bluesky's business model isn't yet established, so whether its favorable terms survive monetization is untested rather than a stated troubling practice.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Bluesky's terms are stated plainly and directly, with no arbitration clause and a clear jurisdiction (Delaware).", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "App / Service", "Ownership Path": "Bluesky  <-  Bluesky PBLLC (Public Benefit LLC, Jay Graber CEO)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action; your right to stop paying by inaction.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Bluesky takes nothing from the list this tracker checks - but 9 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:39:01Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Bluesky is the anti-X in every structural way this tracker measures. X (Twitter) has a class action waiver, $100 liability cap, split statute-of-limitations (1 year federal, 2 years state), and an expanded 'Content' definition covering AI prompts. Bluesky has NO arbitration clause, NO class action waiver, and a decentralized data architecture (AT Protocol) that lets users host their own data on independent servers — meaning a user who runs their own Personal Data Server controls where their data physically resides, a capability no other social network in this tracker offers. Bluesky is a Public Benefit LLC, not a standard corporation — its charter requires considering public benefit alongside shareholder returns. Jack Dorsey incubated the AT Protocol project while still CEO of Twitter; the irony that his alternative to Twitter offers structurally better consumer protections than the platform he built and Elon Musk subsequently acquired is itself a finding about how ownership and incentive structure shape T&C. Bluesky has no advertising model yet — when it eventually monetizes, whether the no-arbitration posture survives will be a test of whether the decentralization promise was real or aspirational.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 197, "_entity_id": 320, "_entity_slug": "bluesky", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Tubi", "Category": "Streaming Service (ad-supported, free)", "Terms & Conditions URL": "https://tubitv.com/static/terms", "T&C Direct PDF?": null, "Privacy Policy URL": "https://tubitv.com/static/privacy", "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Tubi is a FREE, ad-supported streaming service — no subscription fee, no paywall. This means Tubi's entire business model is built on advertising data: viewing history, device information, IP-based location, and ad-interaction data (which ads you watched, skipped, or clicked). Tubi processes more advertising-behavior data per user than subscription streamers (Netflix, Disney+) because ads are the ONLY revenue source. Fox Corporation acquired Tubi in 2020 for $440M.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Tubi ToS, AAA rules, California law. 30-day opt-out. The arbitration clause covers disputes over ad-targeting practices — the exact mechanism through which Tubi generates all of its revenue. A consumer who watches Tubi for free has 'paid' with their viewing data, and disputes over how that data is monetized are arbitrated, not litigated.", "Fees / Billing Flags": "Free. No subscription option. Revenue is 100% advertising-supported. Tubi does not offer an ad-free tier.", "Notes": "Tubi is owned by Fox Corporation (Fox News, Fox Sports, Fox Broadcasting). The Fox ownership means Tubi's viewing data sits alongside Fox News's political-content viewing data within the same corporate family — creating a combined entertainment + news + political viewing profile under one parent. Tubi had 80M+ MAU as of 2024.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-13", "Provenance (who determined this)": "Added 2026-08-13 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Fox Corporation (Rupert Murdoch family)", "Years Referenced in Finding (heuristic)": "2020, 2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Fox Corporation (Rupert Murdoch family)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Tubi's arbitration clause covers disputes over ad-targeting, its sole source of revenue.\nWHAT THE TERMS SAY: MANDATORY binding arbitration with class action waiver, AAA rules, California law, 30-day opt-out; the clause covers disputes over ad-targeting practices.\nWHY IT MATTERS: Since Tubi's revenue is 100% advertising, a dispute over how viewing data is monetized goes to individual arbitration, not a court or class action.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-2] Tubi collects granular ad-response data - which ads you watched, skipped, or clicked.\nWHAT THE TERMS SAY: As a free, ad-supported service, Tubi collects viewing history, device information, IP-based location, and ad-interaction data (which ads were watched, skipped, or clicked); the tracker states Tubi processes more advertising-behavior data per user than subscription streamers because ads are its only revenue source.\nWHY IT MATTERS: Users get no ad-free option and effectively pay with a more detailed behavioral profile than subscription competitors build.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Tubi's viewing data sits in the same corporate family as Fox News's audience data.\nWHAT THE TERMS SAY: Tubi is owned by Fox Corporation (Fox News, Fox Sports, Fox Broadcasting); the tracker states this means Tubi's viewing data sits alongside Fox News's political-content viewing data within the same corporate family.\nWHY IT MATTERS: A user's entertainment-viewing profile could sit within one corporate family alongside political-content engagement data, though the tracker does not state that such combination is actually occurring.\n(evidence: Notes | SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Corporate-affiliation and ad-data claims are asserted but not tied to a specific incident, litigation, or Key Provisions text (both fields are empty).", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Tubi  <-  Fox Corporation (Rupert Murdoch family)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your right to stop paying by inaction.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Tubi you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:39:04Z (HTTP 200, CHANGED)", "SCARY (most astonishing T&C item)": "Tubi is the largest FREE streaming service in the US (80M+ monthly active users) — and because it's free, YOU are the product, not the customer. Every other streaming service in this tracker (Netflix, Disney+, Paramount+, Max, Peacock, Apple TV+) generates most of its revenue from subscriptions; Tubi generates 100% from advertising. This means Tubi collects and monetizes more viewing-behavior data per user than any subscription streamer: not just what you watched, but which ads you saw, how long you watched each ad, which you skipped, and which you clicked — a granular advertising-response profile that subscription streamers don't need to build. Tubi is owned by Fox Corporation, which also owns Fox News, Fox Sports, and Fox Broadcasting — meaning a user's Tubi viewing data (entertainment choices) sits in the same corporate family as Fox News's audience data (political-content engagement). The mandatory arbitration clause with 30-day opt-out covers disputes over ad-targeting practices. Compare with Apple TV+ (no arbitration, no ads, no viewing-data monetization) — Apple TV+ charges money and leaves you alone; Tubi is free and watches you back.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 198, "_entity_id": 322, "_entity_slug": "tubi", "_issuer": "Fox Corporation", "_issuer_slug": "fox-corporation", "_ticker": "FOXA", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Rivian", "Category": "Electric Vehicles", "Terms & Conditions URL": "https://rivian.com/legal/terms-of-service", "T&C Direct PDF?": null, "Privacy Policy URL": "https://rivian.com/legal/privacy-policy", "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Rivian vehicles collect continuous sensor data: 11 cameras, 5 radar units, 12 ultrasonic sensors, GPS, cabin microphone, driver-attention monitoring, battery/charging data, and over-the-air update logs. Rivian's fleet data trains its autonomous-driving development program. Unlike Tesla, Rivian is also Amazon's exclusive delivery-van manufacturer (100,000-vehicle order) — meaning Rivian simultaneously builds consumer EVs AND commercial surveillance vehicles (Amazon delivery vans with 4 exterior cameras operating in residential neighborhoods). Rivian's data practices for the consumer vehicle and the Amazon van may share infrastructure.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Rivian Terms of Service, AAA rules, California law. 30-day opt-out via written notice to Rivian Automotive, LLC, Legal Department, 14600 Myford Road, Irvine CA 92606. Like Tesla, the arbitration clause covers vehicle defects AND software/autonomous-driving failures. Rivian's vehicles are sold directly (no dealerships), so the purchase agreement and the T&C are the same contractual relationship.", "Fees / Billing Flags": "R1T pickup $73K+, R1S SUV $76K+, R2 (upcoming) ~$45K. Rivian Adventure Network charging. No dealer markup (direct sales model).", "Notes": "Rivian is the only company in this tracker that simultaneously builds consumer vehicles AND Amazon's delivery fleet. Amazon owns ~17% of Rivian and has an exclusive 100,000-van order. The question of whether consumer-vehicle data infrastructure is shared with Amazon-van data infrastructure is not addressed in Rivian's consumer privacy policy.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Irvine", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-13", "Provenance (who determined this)": "Added 2026-08-13 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Rivian Automotive, Inc. (Amazon ~17% stake, IPO Nov 2021)", "Years Referenced in Finding (heuristic)": "2021", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Rivian Automotive, Inc. (Amazon ~17% stake, IPO Nov 2021)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Rivian's arbitration clause covers vehicle defects and autonomous-driving failures, 30-day opt-out.\nWHAT THE TERMS SAY: MANDATORY binding arbitration, AAA rules, California law, 30-day opt-out to an Irvine, CA address; covers vehicle defects and software/autonomous-driving failures; the purchase agreement and T&C are the same contractual relationship since Rivian sells direct.\nWHY IT MATTERS: A consumer harmed by a Rivian software or autonomous-driving defect is pushed to individual arbitration unless they opt out within 30 days of purchase.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-2] Rivian's privacy policy doesn't say if your SUV's data infrastructure is shared with Amazon's delivery vans.\nWHAT THE TERMS SAY: Rivian builds both consumer EVs and Amazon's delivery vans (a 100,000-vehicle order; Amazon owns ~17% of Rivian); the vans carry 4 exterior cameras operating in residential neighborhoods. The tracker states whether consumer-vehicle data infrastructure is shared with the Amazon-van data infrastructure is not addressed in Rivian's consumer privacy policy.\nWHY IT MATTERS: Consumers can't tell from Rivian's own privacy policy whether their vehicle's data systems are technically connected to a commercial surveillance fleet driving through neighborhoods.\n(evidence: Notes | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[AI_TRAINING · FL-2] Rivian collects camera, cabin-mic, driver-monitoring data; fleet data trains its autonomous-driving program.\nWHAT THE TERMS SAY: Rivian vehicles collect continuous sensor data - 11 cameras, 5 radar units, 12 ultrasonic sensors, GPS, cabin microphone, driver-attention monitoring, battery/charging data, and over-the-air update logs; fleet data trains Rivian's autonomous-driving development program.\nWHY IT MATTERS: Continuous sensor collection - including a cabin microphone and driver-attention monitoring - accompanies normal vehicle use, and Rivian's fleet data trains its autonomous-driving development program.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Rivian's own privacy policy does not address the Amazon-van data-infrastructure question, and Key Provisions/Major Issues fields are empty.", "Exposure Score (0-100)": 41, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 9/30 (ai_training_on_user_data+5, precise_location_tracking+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nAI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Rivian  <-  Rivian Automotive, Inc. (Amazon ~17% stake, IPO Nov 2021)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A continuous record of everywhere you physically go.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Rivian you gave up your content used as AI training data, your physical movements, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:39:06Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Rivian occupies a unique position in this tracker: it simultaneously builds consumer electric vehicles (R1T, R1S) AND Amazon's commercial delivery vans — 100,000 electric delivery vehicles equipped with 4 exterior cameras that operate in residential neighborhoods across the US, recording continuously while delivering packages. Amazon owns ~17% of Rivian's stock. The consumer privacy question this creates is unprecedented: does the sensor-data infrastructure Rivian developed for your personal SUV share code, servers, or data pipelines with the delivery-van surveillance system that drives past your house? Rivian's consumer privacy policy doesn't address the Amazon-van relationship. The mandatory arbitration clause with 30-day opt-out covers vehicle defects, software failures, and data disputes — the same structure as Tesla, but with the added Amazon-fleet dimension. Rivian's direct-sales model (no dealerships) means the purchase agreement and the digital T&C are one contractual relationship, unlike GM or Ford where the dealer is an intermediary. Compare with Tesla (vertically integrated data-to-insurance) and GM (FTC consent order for selling driving data).", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Consumer Apps", "_row_id": 199, "_entity_id": 324, "_entity_slug": "rivian", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "New York Times", "Category": "News/Media Subscription", "Terms & Conditions URL": "https://help.nytimes.com/hc/en-us/articles/115014893428-Terms-of-Service", "T&C Direct PDF?": null, "Privacy Policy URL": "https://help.nytimes.com/hc/en-us/articles/115014892108-Privacy-Policy", "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "The NYT collects subscriber data, reading behavior (articles, time-on-page, scroll depth), podcast listening (The Daily, Serial), Wirecutter product-review click-throughs (affiliate revenue), NYT Games data (Wordle, Connections, Spelling Bee — daily play patterns), NYT Cooking recipe saves, and The Athletic sports-reading data (acquired 2022, $550M). The NYT's advertising and data practices are governed by its own privacy policy, which permits sharing with advertising partners. NYT's lawsuit against OpenAI (filed Dec 2023, SDNY) is the highest-profile AI-training copyright case — the T&C explicitly prohibit using NYT content to train AI models.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. NYT Terms of Service, AAA rules, New York law. 30-day opt-out. The arbitration clause covers disputes over content access, subscription billing, and data practices. The OpenAI lawsuit was filed by the NYT as a corporate plaintiff, not as a consumer — the arbitration clause doesn't bind corporate litigation.", "Fees / Billing Flags": "Digital subscription $4/month (intro), $17/month (standard). NYT All Access (News + Games + Cooking + Wirecutter + The Athletic) $25/month. Print+digital varies.", "Notes": "The NYT is the largest US newspaper by digital subscription (10M+ paid subscribers). The acquisition of Wordle (2022), The Athletic ($550M, 2022), and Serial Productions (2020) expanded the NYT's data footprint from news reading into gaming patterns, sports engagement, and podcast listening — all under one subscription and one arbitration clause.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-13", "Provenance (who determined this)": "Added 2026-08-13 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "The New York Times Company (Sulzberger family, controlling shareholders)", "Years Referenced in Finding (heuristic)": "2020, 2022, 2023", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: The New York Times Company (Sulzberger family, controlling shareholders)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] NYT's arbitration clause covers billing and data disputes across News, Games, Cooking, and The Athletic.\nWHAT THE TERMS SAY: MANDATORY binding arbitration with class action waiver, AAA rules, New York law, 30-day opt-out; the clause covers disputes over content access, subscription billing, and data practices.\nWHY IT MATTERS: A subscriber's dispute over billing or how their reading/game/podcast data is used goes to individual arbitration, not a class action.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-2] NYT All Access combines news reading, Wordle streaks, Cooking saves, and sports data in one profile.\nWHAT THE TERMS SAY: The NYT collects reading behavior, podcast listening, Wirecutter click-throughs, NYT Games daily play patterns, NYT Cooking recipe saves, and The Athletic sports-reading data, all governed by one privacy policy that permits sharing with advertising partners.\nWHY IT MATTERS: A single subscription can reveal a user's news interests, daily game habits, food preferences, sports loyalties, and even commute timing (via podcast patterns) to one company whose privacy policy permits sharing with advertising partners.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Key Provisions and Major Issues Record are empty for this row; the OpenAI lawsuit is NYT acting as a corporate plaintiff protecting its own content, not a term affecting NYT's own consumers, so it isn't counted as a third troubling item.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration and data-sharing details are described specifically, but Key Provisions/Major Issues fields are empty and no consumer-facing incident is documented.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "New York Times  <-  The New York Times Company (Sulzberger family, controlling shareholders)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using New York Times you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:39:09Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The New York Times has transformed from a newspaper into a data platform — and every data stream is governed by one mandatory arbitration clause. A subscriber who reads the news, plays Wordle and Connections daily, saves recipes on NYT Cooking, reads The Athletic for sports, and listens to The Daily podcast has given the NYT visibility across news interests, cognitive-game habits (Wordle streaks reveal daily engagement patterns), food preferences, sports-team loyalties, and commute timing (podcast listening patterns) — a behavioral profile more comprehensive than any single social-media platform builds. The NYT's lawsuit against OpenAI (filed Dec 2023, SDNY) is the most consequential AI-training copyright case in progress — the NYT alleges ChatGPT can reproduce its articles nearly verbatim and that OpenAI used millions of NYT articles as training data without authorization. The T&C explicitly prohibit AI training. Compare with the Washington Post (Bezos-owned, DC-law arbitration, Arc XP platform): the NYT and Post represent two different models of news-platform data governance — the NYT under New York law, the Post under DC law, with different advertising partnerships and different AI-training stances.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Consumer Apps", "_row_id": 200, "_entity_id": 326, "_entity_slug": "new-york-times", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "OpenAI (ChatGPT / Sora)", "Category": "LLM Provider / AI Assistant", "Terms & Conditions URL": "https://openai.com/policies/terms-of-use/", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://openai.com/policies/privacy-policy/", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Consumer default is training-on-your-content unless you opt out (Settings > Data Controls). Users retain ownership of Input and are assigned rights to Output, but OpenAI takes a broad license to use both to operate and improve services. Standard consumer deletion is 30 days for deleted/temporary chats; API 30 days. Business/Enterprise and Zero Data Retention API customers are carved out of training by default.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. OpenAI ToS, AAA rules. 30-day opt-out via written notice to OpenAI LLC, Legal Department, 3180 18th Street, San Francisco CA 94110. The clause covers disputes over AI-generated content accuracy, data training practices, and the copyright implications of ChatGPT outputs. Given the NYT v. OpenAI litigation (preservation order May 2025, 20M logs ordered into discovery Nov 2025), the arbitration clause applies to individual users but does NOT bind corporate/media plaintiffs who never accepted the consumer ToS.", "Fees / Billing Flags": "Liability cap is the greater of 12 months of fees paid or $100. Outputs disclaimed AS IS with an explicit accuracy disclaimer - reliance risk sits with the user, including for professional advice.", "Notes": "PRIVATE LITIGATION (copyright/discovery): NYT-led publisher coalition (incl. NY Daily News, Center for Investigative Reporting, The Intercept, Ziff Davis) v. OpenAI & Microsoft, SDNY, Judge Sidney Stein / Magistrate Judge Ona Wang. Also author class actions and a ~400-newspaper suit. NOT a consumer-privacy suit, but the discovery fight is the consumer-privacy story. Timeline: May 13 2025 preservation order; June 26 2025 Stein affirmed on appeal; Oct 9 2025 order lifted, normal 30-day deletion resumed; Jan 2026 Stein upheld production of a 20M-conversation sample; July 9 2026 publishers moved for sanctions. Advertising Terms and Ad Tools Terms now exist as separate published policies - worth re-checking as ad products roll out. Cross-ref: Microsoft rows in Consumer Apps and Productivity & Comms Apps tabs (co-defendant). URLs are the canonical policy landing pages; re-verify effective dates, terms were current as of Jan 1 2026 version.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "OpenAI OpCo, LLC, 1455 Third Street, San Francisco, CA 94158, USA", "Legal / Privacy Contact Email": "privacy@openai.com (data-subject requests: dsar@openai.com; portal: privacy.openai.com)", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R7) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.thurrott.com/a-i/openai-a-i/330404/openai-must-turn-over-chatgpt-logs-in-new-york-times-case", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "OpenAI, Inc. (transitioning from nonprofit to PBC)", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: OpenAI, Inc. (transitioning from nonprofit to PBC)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[RETENTION_PERIOD · FL-2] A court order forced OpenAI to preserve chat logs indefinitely, overriding its 30-day deletion policy.\nWHAT THE TERMS SAY: In May 2025 a federal magistrate ordered OpenAI to preserve all ChatGPT output logs indefinitely, overriding its own 30-day deletion policy and users' explicit delete requests; Judge Stein affirmed this on appeal in June 2025; normal deletion only resumed in October 2025, and in January 2026 the court upheld an order pushing 20 million conversations into discovery.\nWHY IT MATTERS: Users who deleted chats, or used temporary chat, had no guarantee their conversations were actually erased during the preservation window, and were not notified or given a chance to object before their conversations entered litigation discovery.\n(evidence: SCARY | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] OpenAI's arbitration clause doesn't reach the discovery fight putting 20 million chats at risk.\nWHAT THE TERMS SAY: MANDATORY binding arbitration with class action waiver, AAA rules, 30-day opt-out to a San Francisco address; the clause applies to individual users but does not bind corporate/media plaintiffs like the NYT-led coalition suing in the copyright case that produced the preservation order.\nWHY IT MATTERS: A consumer's own arbitration agreement offers no protection against having their private conversations swept into a lawsuit they aren't a party to.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[LIABILITY_CAP_INDEMNITY · FL-1] OpenAI caps liability at 12 months of fees or $100, while disclaiming ChatGPT's accuracy entirely.\nWHAT THE TERMS SAY: Liability cap is the greater of 12 months of fees paid or $100; outputs are disclaimed AS IS with an explicit accuracy disclaimer, putting reliance risk on the user, including for professional advice.\nWHY IT MATTERS: A free user's maximum recovery is $100 regardless of harm, and users bear the risk of relying on inaccurate outputs even for professional-advice-type questions.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=?; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Court dates, judges, and rulings are documented in detail across Notes and SCARY.", "Exposure Score (0-100)": 57, "Exposure Band": "High", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 8, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 5/30 (ai_training_on_user_data+5) | Contract 8/20 (liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 20/20 (severity5+20, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "OpenAI (ChatGPT / Sora)  <-  OpenAI, Inc. (transitioning from nonprofit to PBC)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using OpenAI (ChatGPT / Sora) you gave up your content used as AI training data, a broad licence to your own content, your right to sue, your right to join a class action, and your right to meaningful compensation. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "2026-09-08T19:39:11Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "In May 2025 a federal magistrate ordered OpenAI to preserve every ChatGPT output log indefinitely - overriding both its own 30-day deletion policy and users' explicit delete requests - and Judge Stein affirmed it on appeal in June, rejecting the argument that user privacy should outweigh discovery. Normal deletion only resumed in October 2025, but everything captured inside the window stayed in storage, and in January 2026 the court upheld an order pushing 20 million conversations into discovery. None of those users were notified or given any chance to object; individual users who tried to intervene were denied as non-parties. In July 2026 the publishers moved for sanctions, alleging OpenAI deleted or compressed billions of conversations despite the preservation order. Sam Altman has publicly acknowledged people treat ChatGPT like a therapist, lawyer, or priest - and that those conversations can be subpoenaed, because no privilege attaches to any of it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "LLM Providers", "_row_id": 201, "_entity_id": 329, "_entity_slug": "openai-chatgpt-sora", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Anthropic (Claude)", "Category": "LLM Provider / AI Assistant", "Terms & Conditions URL": "https://www.anthropic.com/legal/consumer-terms", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.anthropic.com/legal/privacy", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Consumer (Free/Pro/Max) training is opt-OUT as of the Aug 2025 change - it applies unless you turn it off in Settings > Privacy. Opting in extends retention from 30 days to 5 years. Commercial tiers (Claude for Work, Enterprise, Education, Gov, API) are contractually excluded from training. Policy-violation conversations are retained 2 years; trust-and-safety classification scores 7 years. Company states it does not sell user data. Consumer accounts are not HIPAA-compliant; BAA available on enterprise.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Anthropic's Terms of Service, AAA Consumer Arbitration Rules. 30-day opt-out via written notice to Anthropic PBC, Legal Department, 548 Market Street, PMB 90375, San Francisco CA 94104-5401. The $1.5B copyright settlement (Bartz v. Anthropic, finalized July 2026, Judge Martinez-Olguin) was a CLASS action — it was not blocked by the arbitration clause because the plaintiffs (authors/publishers) were not consumer-ToS users. Anthropic's June 2026 privacy policy update created a two-tier system: consumer accounts (Free/Pro/Max) have different data-handling terms than Team/Enterprise accounts using the same AI system.", "Fees / Billing Flags": "Standard consumer subscription tiers (Free/Pro/Max). No unusual fee or billing findings surfaced this pass - not independently confirmed either way, recommend a direct follow-up if billing practices matter to the use case.", "Notes": "PRIVATE LITIGATION (copyright, resolved): Bartz v. Anthropic PBC, No. 3:24-cv-05417-AMO (N.D. Cal.), filed Aug 2024 by authors Andrea Bartz, Charles Graeber, Kirk Wallace Johnson. Judge Alsup's 2025 ruling held that training on legally purchased, scanned books was fair use - the piracy of the source files was the exposure. Alsup retired; Judge Araceli Martinez-Olguin granted final approval July 20 2026, overruling all 53 objections. 91.3% claims rate; 350 opt-outs covering 1,802 works (0.03%). Service awards trimmed from $50,000 to $15,000 each. Release is past-only through Aug 25 2025 and expressly does NOT release claims about AI outputs or future conduct. Also: Reddit sued Anthropic in June 2025 over scraping (see Perplexity row - same enforcement wave). July 8 2026 consumer Privacy Policy added agentic-task data flows to connected third-party services, a Verification Data category, and research-study data. Anthropic named a South Korea domestic representative under PIPA. NOTE FOR FUTURE SESSIONS: this row was researched by a Claude instance; findings were sourced from Authors Guild, TechCrunch, Pearl Cohen, and independent policy trackers rather than company self-reporting, and the unflattering findings are recorded here at the same standard as every other row.\n\nAUG 2026 RE-VERIFICATION (triple-check pass): figures confirmed against the Authors Guild, Pearl Cohen and JURIST reporting on the final approval order, Bartz v. Anthropic PBC, No. 3:24-cv-05417-AMO (N.D. Cal.). Corrections applied to the SCARY cell: Works List is 482,460 titles (previously written as 'about 500,000'); per-work figure ~$3,100 (previously 'roughly $3,000'); claims were filed for 440,490 works. Added: fee award detail - 12.5% request ($187.5M, a 6.92 lodestar multiplier) rejected; $101,561,111 awarded on a 3.75 multiplier of a $27,082,963 lodestar, plus $2,635,197.46 expenses and an $18.22M administration cost reserve. Service awards $15,000 each (reduced from $50,000). 350 valid opt-outs covering 1,802 works (0.03%). Class defined as copyright owners of books in the LibGen/PiLiMi versions Anthropic downloaded, each with an ISBN or ASIN and US Copyright Office registration within five years of first publication.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Anthropic PBC, 548 Market St, PMB 90375, San Francisco, CA 94104, USA (EU: Anthropic Ireland Ltd, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29)", "Legal / Privacy Contact Email": "privacy@anthropic.com (DPO: dpo@anthropic.com)", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.courthousenews.com/anthropic-to-pay-1-5-billion-copyright-settlement-to-authors-publishers/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Anthropic PBC", "Years Referenced in Finding (heuristic)": "2026, 2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Anthropic PBC). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Anthropic paid $1.5B, the largest copyright recovery in US history, for training Claude on pirated books.\nWHAT THE TERMS SAY: On July 20, 2026 a federal judge granted final approval to a $1.5B settlement over books Anthropic downloaded from shadow libraries LibGen and PiLiMi to train Claude; the certified Works List covers 482,460 titles at roughly $3,100 each; Anthropic must destroy the original pirated files.\nWHY IT MATTERS: This is a confirmed, adjudicated finding, not an allegation, that Claude's training data included pirated copyrighted works at a scale of nearly half a million titles.\n(evidence: Notes | SCARY; Stated in tracker (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "[RETENTION_PERIOD · FL-2] Anthropic switched to opt-out chat training in 2025, extending retention from 30 days to 5 years.\nWHAT THE TERMS SAY: As of the August 2025 change, consumer (Free/Pro/Max) training is opt-OUT - it applies unless turned off in Settings; opting in extends retention from 30 days to 5 years; conversations flagged for policy review are retained 2 years and trust-and-safety classification scores 7 years, and can still be used for training regardless of the opt-out toggle.\nWHY IT MATTERS: A user who doesn't actively find and disable the new default has their conversations retained for years instead of 30 days, and safety-flagged conversations can be used for training even if the user opted out.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Anthropic's arbitration clause didn't block the $1.5B suit only because authors weren't ToS users.\nWHAT THE TERMS SAY: MANDATORY binding arbitration with class action waiver, AAA Consumer Arbitration Rules, 30-day opt-out to a San Francisco address; the Bartz settlement was a class action not blocked by the clause because the plaintiffs (authors/publishers) were not consumer-ToS users.\nWHY IT MATTERS: An ordinary Claude user with an account-level dispute is still bound to individual arbitration; only non-users, like the authors in Bartz, were able to bring a class action.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=N; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The settlement, opt-out change, and retention periods are documented with specific dates, dollar figures, and docket citations, including a triple-check re-verification pass.", "Exposure Score (0-100)": 49, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 5/30 (ai_training_on_user_data+5) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Anthropic (Claude)  <-  Anthropic PBC", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (9 of 13): your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Anthropic (Claude) you gave up your content used as AI training data, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "2026-09-08T19:39:14Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "On July 20, 2026 Judge Araceli Martinez-Olguin granted final approval to a $1.5 billion settlement - the largest copyright recovery in US history - over books Anthropic downloaded from the shadow libraries LibGen and PiLiMi to train Claude. The certified Works List runs to 482,460 titles at roughly $3,100 each, about four times the $750 statutory minimum for infringement, and Anthropic must destroy the original pirated files. The court overruled all 53 objections, recorded a 91.3% claims rate, and cut class counsel's requested 12.5% fee ($187.5M) to $101.6M as far outside the reasonable range for mega-fund cases - every dollar not paid in fees stays in a non-reversionary fund for authors. Separately, the company reversed its own founding privacy position: consumer chats were explicitly not used for training until August 2025, when Free, Pro and Max users were given until October 8 to opt out or be opted in, with retention jumping from 30 days to five years. And the privacy policy makes the ceiling explicit: conversations flagged for safety review can still be used for training regardless of what your opt-out toggle says.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "LLM Providers", "_row_id": 202, "_entity_id": 331, "_entity_slug": "anthropic-claude", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google (Gemini)", "Category": "LLM Provider / AI Assistant", "Terms & Conditions URL": "https://policies.google.com/terms/generative-ai", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://support.google.com/gemini/answer/13594961 (Gemini Apps Privacy Hub); https://policies.google.com/privacy", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Human reviewers - Google employees AND third-party contractors - read and annotate a portion of Gemini conversations. Reviewed conversations are disconnected from the Google Account but retained up to THREE YEARS and are not deleted when the user deletes their activity. Turning off Gemini Apps Activity still leaves conversations stored up to 72 hours. Web & App Activity and Location History continue collecting separately. Legal basis for the processing is stated as legitimate interests.", "Arbitration / Class Action Waiver": "Google's US consumer terms have historically NOT imposed blanket mandatory arbitration for core Google services (unlike most peers here) - but Gemini use is layered over Google Terms of Service plus service-specific terms, and arbitration provisions vary by product and by whether a paid Google One / AI subscription is attached. Not independently confirmed for the Gemini-specific stack this pass - recommend a direct follow-up before relying on it.", "Fees / Billing Flags": "Free tier plus paid subscription tiers bundled through Google One / AI plans. No distinct fee findings this pass.", "Notes": "The headline finding here is a disclosure, not a lawsuit: Google's own support documentation instructs users not to enter confidential information. Human review + 3-year retention is documented company policy, not an allegation. ConductAtlas flags the human-review clause against GDPR Arts. 13 and 28 and CCPA 1798.100/.140, with EU DPAs and the CPPA as enforcement authorities - engagement noted, no confirmed enforcement action as of this pass. Google I/O 2026 announced 'Spark,' an agentic Gemini that acts without waiting for a prompt - materially expands the surface area; flag for re-verification next pass. Cross-ref: Google / Alphabet row in Consumer Apps tab, plus Google Drive / Docs / Chrome / Assistant / NotebookLM rows in Productivity & Comms Apps.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R7) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alphabet Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[RETENTION_PERIOD · FL-2] Gemini chats pulled into human review are kept up to 3 years, even after you delete your activity.\nWHAT THE TERMS SAY: Human reviewers - Google employees and third-party contractors - read and annotate a portion of Gemini conversations; reviewed conversations are disconnected from the Google Account but retained up to three years and are not deleted when the user deletes their activity; turning off Gemini Apps Activity still leaves conversations stored up to 72 hours.\nWHY IT MATTERS: The delete function only empties visible history, not the separate review queue, so a user's confidential input can remain accessible to reviewers for years after they think it's gone.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DARK_PATTERN_CONSENT · FL-2] Google processes Gemini conversations for human review under 'legitimate interests,' not user consent.\nWHAT THE TERMS SAY: The stated legal basis for the review/annotation processing is legitimate interests, not consent.\nWHY IT MATTERS: This means Google determined its interest in improving the model outweighs a user's objection, rather than seeking affirmative consent for human review of private conversations.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms for the Gemini-specific stack are explicitly not confirmed this pass, and Key Provisions/Major Issues fields are empty, so only the two data-handling findings in Data Sharing/SCARY are substantiated.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=Y; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The human-review/retention policy is documented company policy, but the arbitration terms for Gemini specifically are explicitly unconfirmed this pass.", "Exposure Score (0-100)": 15, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 13/30 (shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5, precise_location_tracking+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nAI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use", "Entity Type": "Company", "Ownership Path": "Google (Gemini)  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your biometric identifiers; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Google (Gemini) you gave up your content used as AI training data, your physical movements, and your data shared corporate-wide. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:39:14Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Google's own privacy documentation tells you not to type anything confidential into Gemini - because human reviewers, including outside contractors, read and annotate real conversations. Chats pulled into that review pipeline are kept for up to three years and are NOT deleted when you delete your activity: the delete button empties your visible history, not the review queue. Even with Gemini Apps Activity switched off, conversations are still retained for up to 72 hours. And the legal basis Google asserts for all of it is legitimate interests - meaning the company decided its need to train the model outweighs your objection, rather than asking for consent.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "LLM Providers", "_row_id": 203, "_entity_id": 332, "_entity_slug": "google-gemini", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "xAI (Grok)", "Category": "LLM Provider / AI Assistant", "Terms & Conditions URL": "https://x.ai/legal/terms-of-service", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://x.ai/legal/privacy-policy", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "ALLEGED (class action, not adjudicated): embedded third-party tracking code on Grok.com transmits full conversation content, unique per-conversation URLs, page titles and metadata to Google, Meta and TikTok for ad targeting - reportedly including for users who declined cookies. CONFIRMED: the share feature published conversations to publicly crawlable URLs with no disclaimer, unlike OpenAI's equivalent which carried a warning.", "Arbitration / Class Action Waiver": "Y - xAI consumer terms include arbitration and class waiver provisions (verify opt-out mechanics against the live terms). PRIVATE LITIGATION: Skaggs v. X.AI Corp., filed May 14 2026, N.D. Cal. - proposed class action alleging violations of the Electronic Communications Privacy Act, California Invasion of Privacy Act, and the California Constitution. Seeks $5,000 per state-law violation plus federal damages. Proposed class: all US residents who entered queries on Grok.com. Allegations only; not adjudicated as of this pass.", "Fees / Billing Flags": "Free tier plus paid tiers, historically bundled with X Premium subscriptions. No distinct fee findings this pass.", "Notes": "CONFIRMED BREACH-BY-DESIGN (Aug 2025): Forbes first reported, Fortune independently reviewed transcripts. 370,000+ conversations indexed by Google and other crawlers. Exposed content included medical and psychological questions, business details, uploaded attachments, and at least one password. Some indexed transcripts contained material violating xAI's own terms of service. Users had reported the indexing issue as early as January 2025; xAI did not respond to Forbes' request for comment. Musk's public response was to post 'Grok FTW' promoting Grok over ChatGPT after OpenAI pulled its own share feature. Separate reputational incidents (the 'MechaHitler' output, unprompted conspiracy content) are documented but are model-behavior findings rather than T&C findings - noted for context, not counted as contract terms. Cross-ref: Meta AI row in this tab (parallel share-feature failure) and the OpenAI row (pulled its version after ~4,500 chats were indexed).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Palo Alto", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "X.AI LLC — mailing address not published in the consumer privacy policy reviewed this pass; note xAI states it is a separate company from X Corp.", "Legal / Privacy Contact Email": "Not verified this pass — recommend a direct follow-up", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R7) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "xAI Corp. (Elon Musk)", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: xAI Corp. (Elon Musk)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 370,000+ Grok chats, including medical questions and a password, were indexed by Google via the share button.\nWHAT THE TERMS SAY: Confirmed by independent reporting (Forbes, Fortune): the share feature published conversations to publicly crawlable URLs with no disclaimer; 370,000+ conversations were indexed, including medical/psychological questions, business details, uploaded attachments, and at least one password; users had reported the issue since January 2025 and xAI did not respond to press inquiries.\nWHY IT MATTERS: Users who shared a Grok conversation, believing it was private or limited, had highly sensitive content (health questions, a password) become publicly searchable with no warning that this would happen.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] A pending suit alleges Grok.com routed entire chats to Google, Meta, and TikTok for ad targeting.\nWHAT THE TERMS SAY: ALLEGED, not adjudicated: embedded third-party tracking code on Grok.com transmits full conversation content, per-conversation URLs, page titles, and metadata to Google, Meta, and TikTok for ad targeting, reportedly including for users who declined cookies; Skaggs v. X.AI Corp. was filed May 14, 2026 in N.D. Cal. seeking $5,000 per state-law violation.\nWHY IT MATTERS: If true, private conversation content covering health, finance, or legal topics was shared with major ad platforms regardless of a user's cookie choice; this remains an allegation, not a confirmed finding.\n(evidence: Data Sharing/Selling Flags | Arbitration / Class Action Waiver | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] xAI's arbitration and class-waiver terms apply, though the opt-out window isn't verified this pass.\nWHAT THE TERMS SAY: xAI consumer terms include arbitration and class waiver provisions; the tracker notes the opt-out mechanics should be verified against the live terms.\nWHY IT MATTERS: Consumers face individual arbitration and a class-action waiver by default, though the tracker cannot confirm exactly how or whether they can opt out.\n(evidence: Arbitration / Class Action Waiver; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The share-feature exposure is confirmed by independent reporting, but the tracking-code lawsuit is allegation-only and arbitration opt-out mechanics are unverified.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 23, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 23/30 (forced_arbitration+12, class_action_waiver+9, optout_window_unverified+2) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "xAI (Grok)  <-  xAI Corp. (Elon Musk)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using xAI (Grok) you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:39:17Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "In August 2025, Forbes found more than 370,000 private Grok conversations sitting in Google's search index - medical and psychological questions, business details, uploaded files, and at least one password. The cause was the share button: on Grok it published the conversation to a public URL with no warning and no disclaimer, where OpenAI's version at least carried one. Users had been flagging the problem since January; xAI did not respond to press inquiries, and Musk's public reaction was to post 'Grok FTW' promoting Grok as the alternative to ChatGPT, whose similar feature had already been pulled. Then in May 2026 a proposed class action alleged that Grok.com's embedded tracking code was routing entire conversations - finance, health, legal - to Google, Meta and TikTok for ad targeting, allegedly even for users who had opted out of cookies, seeking $5,000 per violation.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "LLM Providers", "_row_id": 204, "_entity_id": 334, "_entity_slug": "xai-grok", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "DeepSeek (Hangzhou DeepSeek AI Co., Ltd.)", "Category": "LLM Provider / AI Assistant", "Terms & Conditions URL": "https://chat.deepseek.com/downloads/DeepSeek%20Terms%20of%20Use.html", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://chat.deepseek.com/downloads/DeepSeek%20Privacy%20Policy.html", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Privacy policy (last updated Feb 10 2026) acknowledges storing personal data on servers in the People's Republic of China: account details, everything typed into chat, uploaded files and audio, IP address, device data, location, cookies, and KEYSTROKE PATTERNS - typing rhythm and cadence, which functions as a behavioral biometric identifier. China's 2017 National Intelligence Law obliges organizations to support, assist and cooperate with state intelligence work; no user agreement can contract around that.", "Arbitration / Class Action Waiver": "Chinese-law-governed terms; US-style arbitration/class-waiver analysis largely inapplicable, and practical recourse for a US consumer is limited by jurisdiction rather than by a waiver clause. REGULATORY ACTION (confirmed, distinct from private suits): Italy's Garante ordered a block within 72 hours of investigating; investigations followed in 13 European jurisdictions; the EDPB created a dedicated AI Enforcement Task Force. Government-device bans in Italy, Australia, Taiwan, South Korea, Czech Republic, Netherlands, plus multiple US federal agencies and states. 'No DeepSeek on Government Devices Act' advanced in Congress with bipartisan support.", "Fees / Billing Flags": "Free consumer chatbot; low-cost API. The product is free at the point of use - the exchange is the data collection described above.", "Notes": "CONFIRMED SECURITY FINDINGS (independent researchers, not allegations): Wiz discovered a publicly accessible DeepSeek database holding 1M+ records - user chat histories, API keys, backend system logs, internal operational detail - with no authentication or access control whatsoever. NowSecure found hardcoded encryption keys and some user/device data transmitted unencrypted. Feroot Security reported hidden code in the web platform linking to China Mobile's authentication registry (CMPassport.com); China Mobile is a state-controlled carrier previously barred from US operations - Feroot's finding is a researcher claim, treat as strong lead rather than adjudicated fact. CyberCX assessed with high confidence that outputs align with CCP strategic narratives. IMPORTANT DISTINCTION for the tracker: the open-weights model run locally on your own hardware carries none of this - the findings attach to the hosted web app and API, not the weights.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Hangzhou", "HQ State": "China", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R7) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Hangzhou, China (non-US)", "Parent / Ultimate Owner": "Hangzhou DeepSeek Artificial Intelligence Co., Ltd. (High-Flyer quant fund affiliate)", "Years Referenced in Finding (heuristic)": "2017", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (China) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in China. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] DeepSeek's policy admits it collects keystroke patterns - a behavioral biometric - with your chats.\nWHAT THE TERMS SAY: DeepSeek's privacy policy (last updated Feb 10, 2026) acknowledges storing account details, everything typed into chat, uploaded files and audio, IP address, device data, location, cookies, and keystroke patterns (typing rhythm and cadence) on servers in the People's Republic of China.\nWHY IT MATTERS: Keystroke cadence functions as a behavioral biometric identifier that can potentially identify a user across accounts, and China's National Intelligence Law obliges cooperation with state intelligence, which no privacy policy can contract around.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] Researchers found a DeepSeek database with million+ chat histories and API keys, no authentication.\nWHAT THE TERMS SAY: Confirmed by independent researchers (Wiz): a publicly accessible DeepSeek database held 1M+ records - user chat histories, API keys, backend system logs, internal operational detail - with no authentication or access control; NowSecure separately found hardcoded encryption keys and some unencrypted data transmission.\nWHY IT MATTERS: Anyone who found the exposed database could read or modify user chat histories and API keys, a direct confirmed security failure rather than a policy risk.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[REGULATORY_PENALTY · FL-3] Italy blocked DeepSeek within 72 hours; 13 EU jurisdictions and other governments banned or probed it.\nWHAT THE TERMS SAY: Italy's Garante ordered a block within 72 hours of investigating; investigations followed in 13 European jurisdictions; the EDPB created a dedicated AI Enforcement Task Force; government-device bans followed in Italy, Australia, Taiwan, South Korea, Czech Republic, Netherlands, and multiple US federal agencies and states.\nWHY IT MATTERS: Multiple regulators have taken concrete enforcement action rather than merely raising concerns, reflecting an unusually broad, confirmed regulatory response.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Security findings are attributed to named independent researchers (Wiz, NowSecure) and regulatory actions are specifically dated and enumerated.", "Exposure Score (0-100)": 18, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (biometric_collection+6, precise_location_tracking+4) | Contract 0/20 (none) | Record 8/20 (severity2+2, breach+3, penalty+3) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "DeepSeek (Hangzhou DeepSeek AI Co., Ltd.)  <-  Hangzhou DeepSeek Artificial Intelligence Co., Ltd. (High-Flyer quant fund affiliate)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using DeepSeek (Hangzhou DeepSeek AI Co., Ltd.) you gave up your biometric identifiers and your physical movements. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "DeepSeek's own privacy policy states that it collects your keystroke patterns - not just what you type but the rhythm and cadence of how you type it, which functions as a behavioral biometric capable of identifying you across accounts - and stores it, along with your chats and uploaded files, on servers inside the People's Republic of China, where the 2017 National Intelligence Law obliges companies to cooperate with state intelligence work and no privacy policy can override it. Then the execution matched the policy: security firm Wiz found a DeepSeek database sitting publicly on the internet with over a million records - chat histories, API keys, backend logs - and no authentication at all, meaning anyone who found it could read or modify the contents. Italy's regulator ordered a block within 72 hours; thirteen European jurisdictions opened investigations, and government-device bans followed from Canberra to Washington.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "LLM Providers", "_row_id": 205, "_entity_id": 336, "_entity_slug": "deepseek-hangzhou-deepseek-ai-co-ltd", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Perplexity AI", "Category": "LLM Provider / AI Search", "Terms & Conditions URL": "https://www.perplexity.ai/hub/legal/terms-of-service", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.perplexity.ai/hub/legal/privacy-policy", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Consumer chat/search data handling follows the sector norm (training-by-default with opt-out controls); the distinctive exposure here is not what Perplexity does with YOUR data but how it acquires everyone else's - the Comet agentic browser acts on the user's behalf on third-party sites, which is what triggered the Amazon suit. Anyone deploying Comet for business tasks should assume the target site's ToS applies to them.", "Arbitration / Class Action Waiver": "Consumer terms include arbitration/class-waiver provisions - verify opt-out window against the live terms. PRIVATE LITIGATION (all copyright/contract, none consumer-privacy): Dow Jones & NYP Holdings (News Corp) v. Perplexity, SDNY Oct 2024 - two counts copyright infringement plus false designation of origin/trademark dilution, seeking $150,000 per proven infringement. NYT cease-and-desist. Reddit v. Perplexity, SerpApi, Oxylabs UAB and AWM Proxy (Oct 2025) - a federal judge allowed Reddit's DMCA anti-circumvention claims to proceed on approximately July 31 2026. Amazon v. Perplexity over the Comet agent shopping in violation of Amazon's ToS. Chicago Tribune / NYT actions also reported. NO confirmed regulatory action found this pass.", "Fees / Billing Flags": "Free tier plus Pro subscription. No distinct fee findings this pass.", "Notes": "August 2025: Cloudflare publicly accused Perplexity of 'stealth crawling' - retrieving content from sites that had explicitly blocked its declared crawler. Perplexity denied intentional wrongdoing, called the report a publicity stunt, and argued Cloudflare conflated user-initiated requests with automated bot traffic. Contested, both sides on record - do not write this up as settled. Perplexity has publicly counted roughly three dozen media lawsuits against generative AI makers overall, and has signed revenue-share deals with Time, Fortune and Der Spiegel, so its posture is genuinely mixed rather than uniformly adversarial. AWM Proxy, named as a co-defendant in the Reddit suit, is described in reporting as a former Russian botnet - the alleged supply chain here runs from scraping middlemen to AI companies. Cross-ref: Anthropic row (Reddit sued Anthropic June 2025 in the same enforcement wave) and the OpenAI row (NYT/publisher coalition).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Perplexity AI, Inc. — street address not published in the privacy notice; EU/UK Art. 27 representative and DPO is VeraSafe (VeraSafe Ireland Ltd / VeraSafe United Kingdom Ltd)", "Legal / Privacy Contact Email": "support@perplexity.ai (EU/UK: via VeraSafe contact form)", "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R7) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Perplexity AI, Inc.", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Perplexity AI, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] Perplexity's Comet agent shops on your behalf in ways Amazon says breach its own terms.\nWHAT THE TERMS SAY: The Comet agentic browser acts on the user's behalf on third-party sites; Amazon has sued Perplexity alleging Comet's shopping violates Amazon's ToS. The tracker states anyone deploying Comet for business tasks should assume the target site's ToS applies to them.\nWHY IT MATTERS: A user who lets Comet act on their behalf could end up in breach of a website's terms of service without directly taking the action themselves.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] Perplexity faces suits from Dow Jones, NY Post, Reddit, and Chicago Tribune over how it acquires content.\nWHAT THE TERMS SAY: Dow Jones & NYP Holdings (News Corp) v. Perplexity (SDNY, Oct 2024) alleges copyright infringement and trademark dilution seeking $150,000 per proven infringement; in Reddit v. Perplexity/SerpApi/Oxylabs/AWM Proxy a federal judge allowed DMCA anti-circumvention claims to proceed around July 31, 2026; NYT sent a cease-and-desist; a Chicago Tribune action is also reported.\nWHY IT MATTERS: This is company-facing legal risk rather than a direct consumer harm, but multiple ongoing suits over content acquisition signal legal exposure that could affect the service.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The Cloudflare 'stealth crawling' accusation is contested (Perplexity denies it and calls it a publicity stunt, per Notes/SCARY), so it isn't counted as a third confirmed item; only the Comet/Amazon consumer-facing risk and the active content-acquisition litigation are substantiated.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Multiple lawsuits are confirmed as filed, but core allegations like stealth crawling are contested and denied by Perplexity, and consumer arbitration opt-out terms are unverified.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 23, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 23/30 (forced_arbitration+12, class_action_waiver+9, optout_window_unverified+2) | Data 5/30 (ai_training_on_user_data+5) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Perplexity AI  <-  Perplexity AI, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Perplexity AI you gave up your content used as AI training data, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Perplexity is the rare case where the customer isn't the one whose data is at issue - the company is, as of this pass, facing suits from Dow Jones and the New York Post (seeking $150,000 per proven infringement), Reddit, Amazon, and the Chicago Tribune, all over how it acquires content rather than how it handles yours. Cloudflare publicly accused it in August 2025 of stealth crawling - fetching pages from sites that had explicitly blocked its declared crawler - which Perplexity denies and calls a publicity stunt. On July 31, 2026 a federal judge let Reddit's DMCA anti-circumvention claims proceed, and the co-defendants in that case include scraping middlemen and AWM Proxy, described in reporting as a former Russian botnet. The practical consumer lesson is the Amazon suit: Perplexity's Comet agent shops on your behalf, and Amazon's position is that doing so violates its terms - meaning the agent can put YOU in breach of a third party's contract.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "LLM Providers", "_row_id": 206, "_entity_id": 338, "_entity_slug": "perplexity-ai", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Microsoft (Copilot)", "Category": "LLM Provider / AI Assistant", "Terms & Conditions URL": "https://www.microsoft.com/en-us/servicesagreement", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://privacy.microsoft.com/en-us/privacystatement", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "TWO DIFFERENT PRODUCTS, TWO DIFFERENT DEALS. Microsoft 365 Copilot (commercial, ~$30/user/mo) is contractually excluded from foundation-model training under the Products and Services Data Protection Addendum - prompts, responses, and Microsoft Graph data are not used to train, retention is tenant-controlled via Purview, and it carries GDPR, ISO 27001, HIPAA and ISO 42001 commitments. Consumer Copilot is a separate product under different terms - and employees routinely sign into it with personal accounts, which is exactly how the enterprise protection gets bypassed in practice. On Copilot+ PCs, Recall and Click to Do run on-device with local snapshots; most Copilot chat still runs in the cloud.", "Arbitration / Class Action Waiver": "Y - the Microsoft Services Agreement contains a binding arbitration clause and class action waiver for US consumers, with a documented opt-out procedure. Verify the current opt-out mechanics and window against the live MSA. Co-defendant with OpenAI in the NYT publisher litigation (see OpenAI row) - that is a copyright case, not a consumer-privacy case.", "Fees / Billing Flags": "Consumer Copilot free tier plus paid tiers bundled into Microsoft 365 subscriptions; M365 Copilot commercial add-on is a per-seat charge. Standard Microsoft auto-renewal terms apply - see the Microsoft rows in Consumer Apps for prior billing findings.", "Notes": "Jan 7 2026: Microsoft enabled Anthropic as a default subprocessor for M365 Copilot (Researcher, Copilot Studio, Office agents). EU and UK tenants have it disabled by default, and Anthropic-model processing sits OUTSIDE the EU Data Boundary and outside in-country LLM processing commitments - a material data-residency detail for any EU-facing org. OpenAI also remains a subprocessor. Copilot Chat routes LLM calls to the nearest regional datacenter but can spill into other regions under high utilization; EU traffic stays in the EU Data Boundary, worldwide traffic can be sent to the EU or elsewhere. Cross-ref: Microsoft (Outlook/365), LinkedIn (Microsoft), Xbox (Microsoft), Candy Crush/King rows in Consumer Apps; Microsoft Teams, Edge, Word, OneDrive, Skype rows in Productivity & Comms Apps.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Redmond", "HQ State": "Washington", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA", "Legal / Privacy Contact Email": "No published privacy email; Microsoft routes requests via microsoft.com/concern/privacy (30-day response commitment)", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R7) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Microsoft Corporation", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Microsoft Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] Copilot inherits file permissions, turning sloppy permission hygiene into a searchable disclosure engine.\nWHAT THE TERMS SAY: Microsoft 365 Copilot's contractual protection excludes tenant prompts from foundation-model training, but Copilot inherits existing permissions and will surface anything an employee technically has access to - an unlocked HR folder, an open finance spreadsheet, an old anyone-with-the-link file - and the contract has nothing to say about it.\nWHY IT MATTERS: Even with strong contractual data protections, poor internal permission hygiene becomes instantly and broadly searchable through Copilot, a risk the contract doesn't address.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[AI_TRAINING · FL-2] Employees who sign into consumer Copilot with personal accounts bypass M365's training protections.\nWHAT THE TERMS SAY: Consumer Copilot is a separate product under different terms than the contractually training-excluded M365 Copilot; employees routinely sign into consumer Copilot with personal accounts, which is exactly how the enterprise protection gets bypassed in practice.\nWHY IT MATTERS: An employee who thinks they're using the protected enterprise tool may actually be using consumer Copilot, whose prompts and data aren't excluded from training the way tenant data is.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Microsoft made Anthropic a default M365 Copilot subprocessor, processing data outside the EU Data Boundary.\nWHAT THE TERMS SAY: As of Jan 7, 2026, Microsoft enabled Anthropic as a default subprocessor for M365 Copilot (Researcher, Copilot Studio, Office agents); Anthropic-model processing sits outside the EU Data Boundary and outside in-country LLM processing commitments; EU and UK tenants have it disabled by default, on by default for everyone else; OpenAI also remains a subprocessor.\nWHY IT MATTERS: Non-EU/UK organizations get this data-residency-affecting subprocessor turned on automatically without an affirmative choice, unlike EU/UK tenants, who are protected by default.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The permission-inheritance risk, consumer/enterprise split, and subprocessor change are each described with specific dates and mechanisms.", "Exposure Score (0-100)": 31, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 23, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 23/30 (forced_arbitration+12, class_action_waiver+9, optout_window_unverified+2) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Microsoft (Copilot)  <-  Microsoft Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Microsoft (Copilot) you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:39:22Z (HTTP 200, CHANGED)", "SCARY (most astonishing T&C item)": "Microsoft 365 Copilot's contractual protection is genuinely one of the strongest in this tab - your tenant's prompts are excluded from foundation-model training and retention is tenant-controlled - but it doesn't protect against the failure mode that actually happens, because Copilot inherits existing permissions and will cheerfully surface anything an employee technically has access to: the HR folder nobody locked down, the finance spreadsheet on an open SharePoint site, the old anyone-with-the-link file. In other words the tool converts sloppy file permissions into an instant, searchable disclosure engine, and the contract has nothing to say about it. Two other splits matter: consumer Copilot runs under entirely different terms than the enterprise product employees think they're using, and as of January 7, 2026 Microsoft enabled Anthropic as a default subprocessor whose processing sits outside the EU Data Boundary - disabled by default for EU and UK tenants, on by default for everyone else.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "LLM Providers", "_row_id": 207, "_entity_id": 339, "_entity_slug": "microsoft-copilot", "_issuer": "Microsoft Corporation", "_issuer_slug": "microsoft-corporation", "_ticker": "MSFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Meta AI (Llama)", "Category": "LLM Provider / AI Assistant", "Terms & Conditions URL": "https://www.meta.ai/terms/", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.facebook.com/privacy/policy/", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "As of the Oct 2025 policy update, AI chat content feeds ad and content personalization across Facebook, Instagram and WhatsApp - the first time active AI conversations, not just browsing and behavioral signals, became an ad-targeting input at scale. Linking accounts means an AI chat in one app can shape ads in another. Meta states chats about religion, health, politics or sexual orientation are excluded from ad targeting, though they may still be stored and used internally for product improvement. There is NO opt-out for this in the US; the EU, UK and South Korea are carved out by local law. Meta AI conversations on WhatsApp are NOT end-to-end encrypted and may be used for training.", "Arbitration / Class Action Waiver": "Meta's US consumer terms have historically routed disputes to courts in California rather than imposing blanket consumer arbitration - materially different from most peers in this tab. Not independently re-confirmed for the Meta AI product terms this pass; recommend a direct follow-up before relying on it. See the Meta rows in Consumer Apps for prior findings.", "Fees / Billing Flags": "Free; monetized through advertising - which, per the Oct 2025 change, now includes signals drawn from AI conversations.", "Notes": "CONFIRMED DESIGN FAILURE (2025): the Meta AI app's Discover feed published shared conversations publicly, often with username and profile photo attached. Reporting (Business Insider, TechCrunch, WIRED, Fortune, Malwarebytes) documented publicly visible chats covering tax evasion questions, medical topics, child custody, grief, financial distress and job arbitration strategy. Meta's position is that sharing required a deliberate multistep action - the counter-finding is that the UX did not make the consequence legible, which is the same category of failure as the Grok share button. March 2026: a Meta AI agent reportedly caused an internal data exposure by giving faulty instructions to an engineer, briefly making sensitive user and company data accessible to employees - single-source report, treat as a lead pending confirmation. May 2026 counter-development, worth recording fairly: Meta launched Incognito Chat on WhatsApp and the Meta AI app, built on WhatsApp Private Processing, with conversations processed in an environment Meta states it cannot read and messages that disappear by default. Cross-ref: Meta (Facebook/Instagram/WhatsApp), WhatsApp (Meta), Threads (Meta) rows in Consumer Apps; Meta Messenger in Productivity & Comms Apps; GIPHY and Meta Horizon in Media, News & Creative Apps.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Menlo Park", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Meta Platforms, Inc., ATTN: Privacy Operations, 1 Meta Way, Menlo Park, CA 94025, USA (corporate/SEC address: 1601 Willow Road, Menlo Park, CA 94025)", "Legal / Privacy Contact Email": "No published privacy email; Meta routes all requests through in-product privacy forms", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R7) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Meta Platforms, Inc.", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Meta Platforms, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] Meta AI's Discover feed published shared chats publicly, often with username and photo attached.\nWHAT THE TERMS SAY: Confirmed design failure (2025): the Meta AI app's Discover feed published shared conversations publicly, often with username and profile photo attached; reporting documented publicly visible chats covering tax evasion, medical topics, child custody, grief, financial distress, and job arbitration strategy. Meta says sharing required a deliberate multistep action, but the UX did not make the consequence legible.\nWHY IT MATTERS: Users who thought they were sharing privately or narrowly had highly sensitive personal information made publicly visible and attributable to them.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[AI_TRAINING · FL-2] Since Oct 2025, Meta AI chat content feeds ad targeting across FB, Instagram, and WhatsApp, no US opt-out.\nWHAT THE TERMS SAY: As of the Oct 2025 policy update, AI chat content feeds ad and content personalization across Facebook, Instagram and WhatsApp; linked accounts mean an AI chat in one app can shape ads in another; chats about religion, health, politics, or sexual orientation are excluded from ad targeting but may still be stored and used internally; there is no opt-out for this in the US (EU, UK, South Korea are carved out by local law).\nWHY IT MATTERS: US users cannot opt out of having active AI conversation content used to target ads across Meta's apps, unlike users in jurisdictions with stronger privacy law.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] Meta AI conversations inside WhatsApp are not covered by end-to-end encryption and may train models.\nWHAT THE TERMS SAY: Meta AI conversations on WhatsApp are NOT end-to-end encrypted and may be used for training.\nWHY IT MATTERS: Users who assume WhatsApp's standard encryption protects all their conversations there are wrong when they're talking to Meta AI within the app.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The Discover-feed failure and the October 2025 ad-targeting policy are both documented with specific dates and named press outlets.", "Exposure Score (0-100)": 10, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (ai_training_on_user_data+5, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Meta AI (Llama)  <-  Meta Platforms, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Meta AI (Llama) you gave up your content used as AI training data. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Meta AI's Discover feed turned a share button into a publishing button: users' conversations about tax evasion, medical conditions, child custody, grief and financial distress appeared in a public feed, in many cases with their username and profile photo still attached. Meta's defense is that publishing required a deliberate multistep action - which is precisely the point, because thousands of people plainly did not understand what the button did. Then in October 2025 the policy changed so that AI chat content feeds ad targeting across Facebook, Instagram and WhatsApp, the first time active AI conversations became an advertising signal at scale, with no opt-out available in the US while the EU, UK and South Korea were carved out because their laws wouldn't permit it. Meta AI conversations inside WhatsApp are not covered by end-to-end encryption.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "LLM Providers", "_row_id": 208, "_entity_id": 340, "_entity_slug": "meta-ai-llama", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Moonshot AI (Kimi)", "Category": "LLM Provider / AI Assistant", "Terms & Conditions URL": "https://www.kimi.com/user/agreement/userAgreement", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.kimi.com/user/agreement/userPrivacy?version=v2", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Privacy policy permits user prompts and uploaded content to be used to train and improve models, with NO documented in-product opt-out for consumers as of mid-2026 - rights are exercised by emailing the company, not by a toggle. The policy never names a storage jurisdiction; it says only that data may be transferred to servers outside your country of residence. Policy also lists CLIPBOARD DATA among collected categories - the buffer that temporarily holds copied passwords, account numbers and verification codes. No explicit prohibition on sharing user prompts for third-party model training. Unilateral modification clause with no minimum notice period.", "Arbitration / Class Action Waiver": "Chinese-law exposure regardless of corporate structure: the consumer service lists Singapore entity MOONSHOT AI PTE. LTD. as controller of record, but the parent (Beijing Moonshot Technology Co., Ltd.), engineering team and infrastructure are Chinese, and China's National Intelligence Law (2017), Cybersecurity Law (2017) and Data Security Law (2021) reach the parent regardless of server location or offshore holding structure. INDEMNITY RUNS ONE WAY: user agrees to defend and hold Moonshot harmless for claims arising from inputs, outputs and use. No confirmed regulatory enforcement or litigation against Moonshot found this pass.", "Fees / Billing Flags": "Free consumer product. Liability cap on the consumer site is reported as the LESSER of fees paid or $50 - so for a free user, effectively fifty dollars or nothing. Compare OpenAI's greater-of-12-months-or-$100. No copyright/output indemnity of the kind OpenAI, Anthropic, Google and Microsoft offer.", "Notes": "CONFIRMED INCIDENT: In April 2026 Kimi disclosed one user's complete resume - full name, phone number, detailed work history - to an unrelated user during a routine PowerPoint translation task. The OECD AI Incidents Monitor catalogued it as a confirmed cross-user data isolation failure; reviewers described it as a cross-talk architecture flaw in data isolation and access privilege design rather than a simple model hallucination. Company closed a $3.5B round at a $35B valuation (July 2026); independent testing reportedly found a 51% hallucination rate omitted from its published benchmarks - single-source, treat as a lead. Contested enforcement question: a leaked internal model identifier in March 2026 suggested a downstream product was built on Kimi weights without attribution - unresolved. IMPORTANT: as with DeepSeek, running the open weights locally carries none of the hosted-service data exposure. Storage jurisdiction being UNSTATED is the finding - unstated does not mean China, it means unstated, which is itself disqualifying for a data-sovereignty decision.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Beijing", "HQ State": "China", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R7) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Beijing, China (non-US)", "Parent / Ultimate Owner": "Moonshot AI (Beijing Yuezhi Technology)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (China) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in China. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Kimi's privacy policy lists clipboard data among what it collects - often your copied passwords.\nWHAT THE TERMS SAY: Kimi's privacy policy lists clipboard data among collected categories - the buffer that temporarily holds copied passwords, account numbers, and verification codes; there is no in-product opt-out for training, only an email request; the policy never names a storage jurisdiction, saying only that data may be transferred outside the user's country of residence.\nWHY IT MATTERS: Ordinary clipboard use, like copying a password or 2FA code, could be captured by the app, and users have no toggle to stop their prompts from being used for training.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] Kimi disclosed one user's full resume to a completely unrelated user during a routine translation.\nWHAT THE TERMS SAY: In April 2026, Kimi disclosed one user's complete resume to an unrelated user during a routine PowerPoint translation task; the OECD AI Incidents Monitor catalogued it as a confirmed cross-user data isolation failure, described as a cross-talk architecture flaw rather than a hallucination.\nWHY IT MATTERS: This is a confirmed, catalogued incident of one user's personal data leaking directly to another user, not a theoretical risk.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[LIABILITY_CAP_INDEMNITY · FL-1] Kimi users must indemnify the company, while its own liability caps at $50 or nothing for free users.\nWHAT THE TERMS SAY: The user agrees to defend and hold Moonshot harmless for claims arising from inputs, outputs, and use (indemnity runs one way); the consumer liability cap is the lesser of fees paid or $50, so for a free user it is effectively fifty dollars or nothing; there is a unilateral modification clause with no minimum notice period.\nWHY IT MATTERS: A free user who is harmed can recover essentially nothing, while bearing legal exposure for their own use of the service.\n(evidence: Fees / Billing Flags | Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The policy never names a storage jurisdiction, and no regulatory enforcement or litigation was found this pass, though the resume-leak incident is independently catalogued.", "Exposure Score (0-100)": 23, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (ai_training_on_user_data+5, sensitive_exposure_tag+3) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 5/20 (severity2+2, breach+3) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Moonshot AI (Kimi)  <-  Moonshot AI (Beijing Yuezhi Technology)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Moonshot AI (Kimi) you gave up your content used as AI training data, your right to meaningful compensation, and your right to be consulted before terms change. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:39:25Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Kimi's privacy policy lists clipboard data among the categories it collects - the buffer that briefly holds whatever you last copied, which for most people routinely includes passwords, account numbers and two-factor codes. There is no in-product toggle to opt out of model training; you have to email the company and ask. The policy never names the country where your data is stored, saying only that it may be transferred outside your country of residence - and an unnamed jurisdiction is itself the finding, because you cannot assess a data-sovereignty risk you are not told the shape of. Then April 2026 supplied the concrete case: Kimi handed one user's complete resume, including full name, phone number and work history, to a completely unrelated user during a routine PowerPoint translation, an incident the OECD AI Incidents Monitor catalogued as a confirmed cross-user data isolation failure. The consumer liability cap is the lesser of fees paid or fifty dollars.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "LLM Providers", "_row_id": 209, "_entity_id": 343, "_entity_slug": "moonshot-ai-kimi", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Mistral AI (Le Chat)", "Category": "LLM Provider / AI Assistant", "Terms & Conditions URL": "https://mistral.ai/terms", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://legal.mistral.ai/terms/privacy-policy", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Tier split is the whole story. FREE Le Chat: prompts and responses used for model training BY DEFAULT under a legitimate-interest basis, opt out via account privacy settings. Free/Pro/Student plans all carry an opt-out right. PAID API and Le Chat Enterprise: contractually excluded from training. Standard stateless API retains input/output 30 rolling days for abuse monitoring, then deletes; Agents API retains until account termination; Fine-Tuning API until you delete it. Zero Data Retention available on the Scale API plan - but NOT available on Le Chat at all, because the consumer product depends on stored conversation history to work. Memory feature stores user-provided information including health data, gated behind explicit consent.", "Arbitration / Class Action Waiver": "French entity (Mistral AI SAS), EU-governed terms - no US-style mandatory consumer arbitration or class action waiver of the kind that dominates the rest of this tab. GDPR data-subject rights and EU supervisory authorities are the live recourse mechanism instead. No confirmed regulatory action or major litigation against Mistral found this pass.", "Fees / Billing Flags": "Free tier, Pro/Student consumer tiers, paid API tiers, Enterprise. The meaningful fee finding is structural rather than punitive: the free tier is the tier that trains on you, and paid tiers are opted out by default - the price difference IS the privacy difference, stated plainly.", "Notes": "This is the tab's cleanest comparative record and should be written up that way rather than forced into drama. Mistral is the only provider in this set headquartered in the EU: a French data controller, natively subject to GDPR, EU data residency by default, no US-subprocessor dependency for La Plateforme. That is a genuinely different structural posture from every other row here, and for a Mid-Atlantic nonprofit or small business with EU-facing obligations it is the material differentiator. Honest caveats: the free consumer tier still trains by default like everyone else's, ZDR does not exist on the consumer product, and the privacy policy acknowledges models are trained on third-party and publicly-available internet data that may contain personal information despite filtering. Policy versions moved fast - Jan 1 2026 and Apr 8 2026 effective dates both observed this pass; re-verify before relying on specifics.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Paris", "HQ State": "France", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Mistral AI, Attn: Privacy Team, 15 rue des Halles, 75001 Paris, France (French company no. 952 418 325; DPO reachable at the same address, Attn: DPO)", "Legal / Privacy Contact Email": "No published address-free email; written requests to the Paris address above", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R7) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Paris, France (non-US)", "Parent / Ultimate Owner": "Mistral AI SAS (Paris, France)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (France) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in France. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[AI_TRAINING · FL-2] Mistral's free Le Chat tier trains on your chats by default; paid tiers are excluded automatically.\nWHAT THE TERMS SAY: FREE Le Chat: prompts and responses are used for model training by default under a legitimate-interest basis, opt out via account privacy settings; PAID API and Le Chat Enterprise are contractually excluded from training; the tracker states the price difference is the privacy difference.\nWHY IT MATTERS: Free-tier users bear a privacy cost, training by default, that is removed simply by paying, meaning privacy becomes a purchasable feature rather than a baseline default.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[RETENTION_PERIOD · FL-2] Zero Data Retention isn't available on Le Chat, and its Memory feature can store health data.\nWHAT THE TERMS SAY: Zero Data Retention is available on the Scale API plan but not on Le Chat, because the consumer product depends on stored conversation history to work; the Memory feature stores user-provided information including health data, gated behind explicit consent.\nWHY IT MATTERS: A consumer wanting the strongest data-minimization option has no path to it on the product they'd actually use, and health data can be retained in Memory once consented.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Mistral's row is framed as the comparatively favorable case in this tab (EU jurisdiction, no US-style arbitration, no confirmed litigation); only two distinct company-specific harms are substantiated - free-tier training-by-default and the absence of Zero Data Retention on the consumer product.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The tier-by-tier training and retention rules are stated plainly and specifically; the tracker describes this as the tab's cleanest comparative record.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 5/30 (ai_training_on_user_data+5) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use", "Entity Type": "Company", "Ownership Path": "Mistral AI (Le Chat)  <-  Mistral AI SAS (Paris, France)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Mistral AI (Le Chat) you gave up your content used as AI training data. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:39:26Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The most striking thing about Mistral is how ordinary its terms look next to the rest of this tab - and that is the finding. It is the only provider here headquartered in the EU, a French data controller natively subject to GDPR with EU data residency by default and no US-style mandatory arbitration or class action waiver, which means an actual regulator with actual enforcement power stands behind your rights rather than a private arbitrator you waived your way into. The catch is the tier split, stated more plainly than most competitors manage: the free Le Chat tier trains on your conversations by default and you must go turn it off, while paid API and Enterprise tiers are contractually excluded - the price difference is the privacy difference. And Zero Data Retention, which Mistral does offer on the API, is simply not available on the consumer chat product at all, because Le Chat needs your stored history to function.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "LLM Providers", "_row_id": 210, "_entity_id": 345, "_entity_slug": "mistral-ai-le-chat", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Alibaba Cloud (Qwen / Tongyi)", "Category": "LLM Provider (China)", "Terms & Conditions URL": "https://www.alibabacloud.com/help/en/legal/latest/alibaba-cloud-international-website-product-terms-of-service", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.alibabacloud.com/help/en/legal/latest/alibaba-cloud-international-website-privacy-policy", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "Alibaba Cloud hosts the Qwen/Tongyi model family. Data processed through Alibaba's hosted API routes through Chinese infrastructure and is subject to China's Personal Information Protection Law (PIPL, effective Nov 1 2021), Cybersecurity Law (2017), and the 2017 National Intelligence Law. PIPL requires consent for sensitive personal information and imposes cross-border transfer restrictions — but it also operates alongside state-access provisions that have no US or EU equivalent. Qwen open weights (Apache 2.0 for several releases) can be self-hosted, which removes the hosted-API data-residency question entirely. Alibaba Cloud publishes a China compliance trust center documenting PIPL/CSL obligations.", "Arbitration / Class Action Waiver": "Alibaba Cloud's International Website Product Terms of Service govern non-China users; the China-mainland terms are separate. Dispute resolution for international customers is specified in the applicable regional terms (Singapore entity for much of APAC). No US-style AAA/JAMS consumer arbitration clause with a 30-day opt-out of the kind used by OpenAI, Anthropic, and Google — the structure is a commercial cloud agreement, not a US consumer contract. NOT INDEPENDENTLY FETCHED this pass; the governing-entity and forum details should be confirmed against the specific regional terms before citation.", "Fees / Billing Flags": "Pay-as-you-go API pricing. Qwen open-weight models are free to self-host. Alibaba Cloud free-tier credits available for new accounts.", "Notes": "Alibaba Group's AI arm. Qwen is among the most-downloaded open-weight model families globally. The self-host-vs-hosted-API distinction is the central consumer/enterprise decision: self-hosted open weights carry no data-residency exposure; the hosted API routes through Chinese infrastructure. Alibaba was also an investor in Zhipu AI (per Reuters reporting on the Entity List designation).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Hangzhou", "HQ State": "China", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-17", "Provenance (who determined this)": "Added 2026-08-17 from user-supplied LLM benchmark comparison files (rankerai.html, rankerai2.html). NOTE: those files' benchmark scores and model version names were NOT independently verified and are NOT recorded as fact in this tracker — only the company identities were imported. T&C/privacy/jurisdiction findings below are from independent web_search verification this session.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Hangzhou, China (non-US)", "Parent / Ultimate Owner": "Alibaba Group Holding Limited (NYSE: BABA, Hangzhou)", "Years Referenced in Finding (heuristic)": "2017, 2021", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (China) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in China. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Alibaba's hosted Qwen API routes prompts through China's infrastructure, under a law with no US/EU peer.\nWHAT THE TERMS SAY: Data processed through Alibaba's hosted API is subject to China's PIPL, Cybersecurity Law, and the 2017 National Intelligence Law; PIPL requires consent for sensitive data and restricts cross-border transfers, but operates alongside state-access provisions with no US or EU equivalent.\nWHY IT MATTERS: A consumer or business using the hosted API, rather than self-hosting the open weights, has their prompts and outputs subject to Chinese state-access law that doesn't apply to Western-hosted alternatives.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — The tracker frames Alibaba Cloud's dispute-resolution structure as a commercial cloud agreement, not a US consumer contract, and states governing-entity and forum details were not independently fetched this pass, so only the hosted-API jurisdiction-exposure finding is well-supported.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The tracker explicitly states governing-entity and dispute-forum details were not independently fetched this pass and should be confirmed before citation.", "Exposure Score (0-100)": 8, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Alibaba Cloud (Qwen / Tongyi)  <-  Alibaba Group Holding Limited (NYSE: BABA, Hangzhou)", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "2026-09-08T19:39:30Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Alibaba Cloud hosts the Qwen/Tongyi model family — one of the most widely downloaded open-weight model families in the world — and the consumer/enterprise question it raises is the cleanest jurisdiction choice in this tracker's LLM Providers tab. Using Qwen through Alibaba's HOSTED API routes prompts, outputs, and account data through Chinese infrastructure subject to PIPL (China's 2021 privacy law, which mirrors GDPR in consent and cross-border-transfer structure), the 2017 Cybersecurity Law, and the 2017 National Intelligence Law — the last of which has no US or EU analogue and is the reason Western enterprises treat Chinese hosted APIs differently from Chinese open weights. SELF-HOSTING the same Qwen weights (Apache 2.0 on several releases) removes the data-residency question entirely: the model runs on your hardware and no prompt leaves your infrastructure. This is a distinction that does not exist for OpenAI, Anthropic, or Google, whose frontier models are hosted-API-only. For a DMV small business evaluating AI vendors, 'is this model Chinese?' is the wrong question; 'am I sending my data to a Chinese server, or running the weights locally?' is the right one.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "LLM Providers", "_row_id": 211, "_entity_id": 347, "_entity_slug": "alibaba-cloud-qwen-tongyi", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Zhipu AI / Z.ai (GLM)", "Category": "LLM Provider (China)", "Terms & Conditions URL": "https://open.bigmodel.cn/usercenter/agreement", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://open.bigmodel.cn/usercenter/privacy", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "Zhipu AI (Beijing Zhipu Huazhang Technology Co., Ltd.) hosts the GLM model family via its bigmodel.cn / Z.ai platforms. Hosted-API data routes through Chinese infrastructure subject to PIPL, the Cybersecurity Law, and the 2017 National Intelligence Law. GLM open weights have been released under MIT license for several versions, which permits self-hosting outside Chinese jurisdiction. Zhipu was spun out of Tsinghua University and has released GLM-130B (2022, open source), ChatGLM (2023), and GLM-4/GLM-4-Plus (2024).", "Arbitration / Class Action Waiver": "Chinese platform terms (bigmodel.cn) govern the hosted API. No US-style consumer arbitration clause with AAA/JAMS and a 30-day opt-out. Disputes for the mainland platform are governed by Chinese law. NOT INDEPENDENTLY FETCHED this pass — the specific dispute-resolution forum should be confirmed before citation.", "Fees / Billing Flags": "Pay-as-you-go API pricing on bigmodel.cn. GLM open weights (MIT on several releases) free to self-host.", "Notes": "Zhipu is the FIRST Chinese large-model company added to the US Commerce Department's Entity List (effective Jan 16, 2025, per Federal Register). Investors reportedly included Alibaba and Tencent. Zhipu publicly disputed the designation, stating it 'lacks a factual basis' and that it does not rely on US large-model technology. Vendor-reported benchmark claims for GLM have been noted by third-party trackers as diverging from independent indices — vendor and independent figures should be read separately.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Beijing", "HQ State": "China", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-17", "Provenance (who determined this)": "Added 2026-08-17 from user-supplied LLM benchmark comparison files (rankerai.html, rankerai2.html). NOTE: those files' benchmark scores and model version names were NOT independently verified and are NOT recorded as fact in this tracker — only the company identities were imported. T&C/privacy/jurisdiction findings below are from independent web_search verification this session.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Pending - severity 4/5, no source yet", "Region Basis": "HQ: Beijing, China (non-US)", "Parent / Ultimate Owner": "Beijing Zhipu Huazhang Technology Co., Ltd. (Tsinghua University spinout)", "Years Referenced in Finding (heuristic)": "2020, 2022, 2023, 2024, 2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (China) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in China. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-3] Zhipu AI is the first Chinese AI firm on the US Commerce Department's Entity List.\nWHAT THE TERMS SAY: Effective January 16, 2025, per the Federal Register final rule, Zhipu became the first Chinese large-model company added to the Entity List (25 China-based and 2 Singapore-based entities added); BIS cited advancing China's military modernization through advanced AI research; Zhipu disputed the designation as lacking a factual basis.\nWHY IT MATTERS: This doesn't prohibit US consumers from using Zhipu's models, but restricts Zhipu's ability to buy US technology without a license, signaling the company's regulatory posture.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-2] Zhipu's hosted API routes data through China's infrastructure; its dispute forum is unverified.\nWHAT THE TERMS SAY: Hosted-API data on bigmodel.cn/Z.ai routes through Chinese infrastructure subject to PIPL, the Cybersecurity Law, and the 2017 National Intelligence Law; there is no US-style consumer arbitration clause with AAA/JAMS and a 30-day opt-out; the specific dispute-resolution forum was not independently fetched this pass.\nWHY IT MATTERS: A user of the hosted API is subject to Chinese state-access law, and the tracker cannot yet confirm the exact dispute-resolution terms that would apply.\n(evidence: Arbitration / Class Action Waiver | Data Sharing/Selling Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct company-specific findings are substantiated - the Entity List designation and the unverified hosted-API dispute-resolution forum; benchmark-inflation claims are attributed to third-party trackers without independent confirmation.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Entity List action is confirmed via Federal Register citation, but dispute-resolution forum details were not independently fetched this pass.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Zhipu AI / Z.ai (GLM)  <-  Beijing Zhipu Huazhang Technology Co., Ltd. (Tsinghua University spinout)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Zhipu AI / Z.ai (GLM) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "2026-09-08T19:39:33Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Zhipu AI is the FIRST Chinese large-model company placed on the US Commerce Department's Entity List — effective January 16, 2025, per the Federal Register final rule that added 25 China-based and 2 Singapore-based entities. BIS cited advancing China's military modernization through advanced AI research. Zhipu publicly responded that the decision 'lacks a factual basis,' noted its origins in Tsinghua University research, and said the listing would not have a substantial impact on operations. For a US consumer or business, the Entity List designation is not a prohibition on USING Zhipu's models — it restricts Zhipu's ability to BUY US technology without a license. But it is a signal about the company's regulatory posture, and it compounds the underlying jurisdiction question: Zhipu's hosted API (bigmodel.cn, Z.ai) routes data through Chinese infrastructure subject to the 2017 National Intelligence Law, while Zhipu's GLM open weights are MIT-licensed and can be self-hosted anywhere. The same self-host-vs-hosted-API split documented in the Alibaba/Qwen row applies here, with an added export-control overlay that Alibaba does not carry.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "LLM Providers", "_row_id": 212, "_entity_id": 349, "_entity_slug": "zhipu-ai-z-ai-glm", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "MiniMax", "Category": "LLM Provider (China)", "Terms & Conditions URL": "https://www.minimax.io/platform/protocol/service-agreement", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.minimax.io/platform/protocol/privacy-policy", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "MiniMax operates under Chinese law and is subject to PIPL, the Cybersecurity Law, and the 2017 National Intelligence Law. Independent analysis notes that for EU users, data transfers to China require GDPR safeguards (Standard Contractual Clauses or an adequacy decision — China has no EU adequacy decision). Enterprise customers are advised to request a Data Processing Agreement. Publicly available analysis is explicit that the specific details of MiniMax's data handling beyond its published privacy policy are NOT independently known.", "Arbitration / Class Action Waiver": "Chinese platform terms govern the hosted API. No US-style consumer arbitration clause with a 30-day opt-out identified. NOT INDEPENDENTLY FETCHED this pass.", "Fees / Billing Flags": "Pay-as-you-go API pricing. Some MiniMax models released as open weights.", "Notes": "MiniMax is one of China's 'AI tiger' companies. Consumer-facing products include the Hailuo video-generation tool. The company's data-handling specifics beyond its published privacy policy are not independently verifiable — a limitation that applies to most Chinese AI providers and is worth stating explicitly rather than assuming either good or bad practice.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Shanghai", "HQ State": "China", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-17", "Provenance (who determined this)": "Added 2026-08-17 from user-supplied LLM benchmark comparison files (rankerai.html, rankerai2.html). NOTE: those files' benchmark scores and model version names were NOT independently verified and are NOT recorded as fact in this tracker — only the company identities were imported. T&C/privacy/jurisdiction findings below are from independent web_search verification this session.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Shanghai, China (non-US)", "Parent / Ultimate Owner": "Shanghai MiniMax Technology Co., Ltd.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (China) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in China. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] MiniMax's actual data-handling practices beyond its published privacy policy are not known.\nWHAT THE TERMS SAY: Independent analysis concludes MiniMax is a legitimate AI company operating under Chinese law, but the specific details of its data handling practices beyond what is published in its privacy policy are not known with certainty; EU users transferring data to China require GDPR safeguards (Standard Contractual Clauses) since China has no EU adequacy decision.\nWHY IT MATTERS: Consumers and EU businesses cannot verify MiniMax's actual data practices beyond its stated policy, and EU users face extra contractual burden due to the lack of an adequacy decision.\n(evidence: Data Sharing/Selling Flags | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — The tracker explicitly rates this row low and states there is no confirmed adverse finding against MiniMax; the only substantiated point is the general opacity of its data practices beyond its published policy, which the tracker deliberately treats as an epistemic limit rather than a proven harm.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The tracker states directly that MiniMax's data-handling practices beyond its published privacy policy are not independently known.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "MiniMax  <-  Shanghai MiniMax Technology Co., Ltd.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, MiniMax takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "2026-09-08T19:39:35Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "MiniMax illustrates the epistemic limit this tracker runs into with Chinese AI providers: independent analysis of MiniMax's data safety concludes that it is 'a legitimate AI company with significant funding and a growing user base' operating 'under Chinese law and subject to its requirements' — but that 'the specific details of their data handling practices beyond what is published in their privacy policy' are NOT known with certainty. That is the honest finding. For EU users, transfers to China require GDPR safeguards (SCCs), and China has no EU adequacy decision — meaning a European business using MiniMax's hosted API needs contractual machinery that a European business using Mistral does not. For enterprise use, a Data Processing Agreement should be requested directly. This row is deliberately rated severity 2 rather than higher: there is no confirmed adverse finding against MiniMax, and rating it higher on jurisdiction alone would conflate 'Chinese' with 'proven bad,' which the evidence does not support.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "LLM Providers", "_row_id": 213, "_entity_id": 351, "_entity_slug": "minimax", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cohere", "Category": "LLM Provider (Canada)", "Terms & Conditions URL": "https://cohere.com/terms-of-use", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://cohere.com/privacy", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "Cohere is headquartered in Toronto, Canada, and is subject to PIPEDA (Personal Information Protection and Electronic Documents Act) rather than to US federal law. Like 1Password (also Toronto-headquartered, documented in this tracker's Productivity tab), Cohere's Canadian jurisdiction means it is not directly subject to US National Security Letters, which can compel US companies to disclose data without notifying the affected user. Cohere positions itself toward enterprise and sovereign-AI deployments, including private/on-premise options that keep data inside a customer's own infrastructure.", "Arbitration / Class Action Waiver": "Cohere's Terms of Use govern API and platform access. Enterprise agreements are separately negotiated. NOT INDEPENDENTLY FETCHED this pass — whether a US-style arbitration clause with an opt-out window applies to self-serve API users should be confirmed before citation.", "Fees / Billing Flags": "Pay-as-you-go API pricing; enterprise and private-deployment pricing negotiated. Open weights released for several models under non-commercial licenses.", "Notes": "Cohere is the most prominent Canadian frontier-model company and the only non-US, non-Chinese, non-EU provider in this tracker's LLM Providers tab. Its sovereign-AI and private-deployment positioning is the commercial expression of the same jurisdiction logic that makes 1Password's Canadian HQ a structural feature rather than a detail.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Toronto", "HQ State": "Canada", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-17", "Provenance (who determined this)": "Added 2026-08-17 from user-supplied LLM benchmark comparison files (rankerai.html, rankerai2.html). NOTE: those files' benchmark scores and model version names were NOT independently verified and are NOT recorded as fact in this tracker — only the company identities were imported. T&C/privacy/jurisdiction findings below are from independent web_search verification this session.", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Toronto, Canada (non-US)", "Parent / Ultimate Owner": "Cohere Inc. (Toronto, Canada)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Canada) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Canada. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] Whether self-serve Cohere API users face US-style mandatory arbitration is not confirmed.\nWHAT THE TERMS SAY: Cohere's Terms of Use govern API and platform access, with enterprise agreements separately negotiated; the tracker states this was not independently fetched this pass and whether a US-style arbitration clause with an opt-out window applies to self-serve API users should be confirmed before citation.\nWHY IT MATTERS: A self-serve API user can't yet know from this tracker whether they're bound by mandatory arbitration or retain access to courts.\n(evidence: Arbitration / Class Action Waiver; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Cohere's row is framed around its favorable Canadian jurisdiction (PIPEDA, no direct exposure to US National Security Letters) rather than a documented harm; the only open question is the unverified arbitration status for self-serve API users.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The tracker explicitly states arbitration terms for self-serve API users were not independently fetched this pass.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Cohere  <-  Cohere Inc. (Toronto, Canada)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Cohere takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "2026-09-08T19:39:38Z (HTTP 200, CHANGED)", "SCARY (most astonishing T&C item)": "Cohere is the only Canadian frontier-model provider in this tracker — and its Toronto headquarters is a structural feature, not a trivia item. Canadian companies are subject to PIPEDA rather than to US federal surveillance law, which means Cohere is not directly subject to US National Security Letters: the mechanism that can compel a US provider to hand over data without notifying the customer. This is the same jurisdiction advantage documented for 1Password (also Toronto) in the Productivity & Comms Apps tab, and it is the mirror image of the Flo/Clue reproductive-data finding (cross-cutting #28) and the Aldi/Lidl data-choice finding (cross-cutting #30): in each case, the deciding factor between two functionally similar products is which country's courts and which country's compulsion process would process a government demand for the data. Cohere's enterprise and sovereign-deployment options extend this further by allowing models to run inside a customer's own infrastructure, removing the vendor from the data path entirely.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "LLM Providers", "_row_id": 214, "_entity_id": 353, "_entity_slug": "cohere", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "TII (Falcon)", "Category": "LLM Provider (UAE, government research institute)", "Terms & Conditions URL": "https://falconllm.tii.ae/falcon-terms-and-conditions.html", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.tii.ae/privacy-policy", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "The Technology Innovation Institute (TII) is a government research institute in Abu Dhabi, part of the UAE's Advanced Technology Research Council. Falcon models have been released as open weights under permissive licenses (Apache 2.0 for several releases), which means the primary consumption mode is SELF-HOSTING — the weights run on the user's own infrastructure and no prompt data reaches TII at all. This is structurally different from every hosted-API provider in this tab: there is no ongoing data relationship to govern.", "Arbitration / Class Action Waiver": "Falcon open-weight licenses govern model use, not a consumer service agreement. Because the dominant use mode is self-hosting, there is typically no consumer arbitration relationship at all — the license is a copyright/use grant, not a service contract with a dispute-resolution clause. Any TII-hosted service would be governed separately. NOT INDEPENDENTLY FETCHED this pass.", "Fees / Billing Flags": "Falcon open weights are free to download and self-host under their applicable license terms. No consumer subscription.", "Notes": "TII is a state research institute, not a commercial company — making it the only government-run model provider in this tracker. The Falcon-H1 Arabic release referenced in the user-supplied benchmark files reflects TII's focus on Arabic-language capability, a sovereign-capability motivation distinct from the commercial motivations of every other provider in this tab.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Abu Dhabi", "HQ State": "United Arab Emirates", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-17", "Provenance (who determined this)": "Added 2026-08-17 from user-supplied LLM benchmark comparison files (rankerai.html, rankerai2.html). NOTE: those files' benchmark scores and model version names were NOT independently verified and are NOT recorded as fact in this tracker — only the company identities were imported. T&C/privacy/jurisdiction findings below are from independent web_search verification this session.", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Abu Dhabi, United Arab Emirates (non-US)", "Parent / Ultimate Owner": "Technology Innovation Institute (Advanced Technology Research Council, Government of Abu Dhabi)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (United Arab Emirates) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in United Arab Emirates. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] Any directly TII-hosted service, unlike self-hosted Falcon weights, has separate unverified terms.\nWHAT THE TERMS SAY: Falcon open-weight licenses govern model use, not a consumer service agreement; because the dominant use mode is self-hosting, there is typically no consumer arbitration relationship; any TII-hosted service would be governed separately, and this was not independently fetched this pass.\nWHY IT MATTERS: A user relying on a TII-hosted, rather than self-hosted, version of Falcon would be subject to terms this tracker hasn't yet reviewed.\n(evidence: Arbitration / Class Action Waiver; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — TII is a government research institute distributing open weights for self-hosting, with no consumer data relationship of the kind other rows document; the only open item is that any directly TII-hosted service would carry separate, not-yet-fetched terms.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The self-hosted mode is clearly described as having no data relationship, but terms for any directly TII-hosted service were not independently fetched this pass.", "Exposure Score (0-100)": 0, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "TII (Falcon)  <-  Technology Innovation Institute (Advanced Technology Research Council, Government of Abu Dhabi)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, TII (Falcon) takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "2026-09-08T19:39:40Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "TII (Technology Innovation Institute, Abu Dhabi) is the only GOVERNMENT RESEARCH INSTITUTE in this tracker's LLM Providers tab — and it demonstrates the model-distribution mode that makes the whole arbitration and data-residency analysis moot. Falcon models are released as open weights under permissive licenses; the dominant use mode is self-hosting, where the model runs on the user's own hardware and no prompt, output, or account data ever reaches TII. There is no hosted API relationship to govern, no privacy policy that meaningfully applies to inference, and typically no arbitration clause — because a weights license is a copyright grant, not a service contract. This is the same structural point the Alibaba/Qwen and Zhipu/GLM rows make from the opposite direction: the consequential question for AI privacy is not the provider's nationality but whether the deployment is hosted (vendor sees everything, vendor's jurisdiction governs) or self-hosted (vendor sees nothing, no jurisdiction question arises). TII's state ownership and Arabic-language focus reflect a sovereign-capability motivation rather than a commercial one.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "LLM Providers", "_row_id": 215, "_entity_id": 356, "_entity_slug": "tii-falcon", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "EuroLLM (EU consortium)", "Category": "LLM Project (EU, community/academic consortium)", "Terms & Conditions URL": "https://huggingface.co/utter-project", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://huggingface.co/utter-project", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "EuroLLM is a community/academic consortium project (associated with EU-funded multilingual NLP research, including the UTTER project), not a commercial company. Models are released as open weights on Hugging Face. Because there is no hosted commercial API operated by a single vendor, there is no consumer data-collection relationship of the kind every other row in this tab describes. Data governance for any given deployment is determined by whoever hosts the weights.", "Arbitration / Class Action Waiver": "Open-weight model release under the applicable model license. No consumer service agreement, no arbitration clause, no class action waiver — because there is no commercial service contract. NOT INDEPENDENTLY FETCHED this pass; the specific license terms for a given EuroLLM release should be confirmed before citation.", "Fees / Billing Flags": "Free open weights. No commercial subscription. Compute costs borne by whoever self-hosts.", "Notes": "IMPORTANT CLASSIFICATION NOTE: the user-supplied benchmark file lists this entry's organization as 'Community' rather than a company. EuroLLM is included here for completeness of the model-provider landscape, but it is NOT a company with terms of service in the sense the rest of this tracker audits. It is the clearest example in the dataset of a model with no vendor relationship at all.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-17", "Provenance (who determined this)": "Added 2026-08-17 from user-supplied LLM benchmark comparison files (rankerai.html, rankerai2.html). NOTE: those files' benchmark scores and model version names were NOT independently verified and are NOT recorded as fact in this tracker — only the company identities were imported. T&C/privacy/jurisdiction findings below are from independent web_search verification this session.", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ on file - consortium project, no single corporate location", "Parent / Ultimate Owner": "EU academic/community consortium (no single corporate parent)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — EuroLLM is an academic/community consortium releasing open weights with no commercial vendor, no hosted API, no terms of service, and no data-sharing exposure - the tracker frames this explicitly as the floor case with no contract and thus no troubling term to report.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "There is no commercial vendor, terms of service, or privacy policy governing EuroLLM at all - the tracker documents this as the absence of any disclosure regime by design, not concealment.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 17/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "EuroLLM (EU consortium)  <-  EU academic/community consortium (no single corporate parent)", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 83.3, "URL Last Validated": "2026-09-08T19:39:43Z (HTTP 200, CHANGED)", "SCARY (most astonishing T&C item)": "EuroLLM is the limit case for this entire tracker: a multilingual model developed by an EU academic/community consortium and released as open weights, with NO commercial vendor, NO hosted API, NO terms of service, NO privacy policy governing inference, NO arbitration clause, and NO class action waiver — because there is no company on the other side of the transaction. Every other row in this tracker documents what a company's contract does to a consumer's rights. This row documents what happens when there is no contract: the user who downloads EuroLLM weights and runs them locally has no counterparty, no dispute-resolution forum, and no data-sharing exposure, because no data leaves their machine. That is worth recording precisely because it establishes the floor: the arbitration clauses, data-sharing provisions, and jurisdiction choices documented across the other 1,000+ rows are all consequences of choosing a HOSTED commercial relationship, not inherent properties of using AI. Note: the source file classifies this entry's organization as 'Community,' not as a company — it is included for landscape completeness.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "LLM Providers", "_row_id": 216, "_entity_id": 358, "_entity_slug": "eurollm-eu-consortium", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "GM (myChevrolet / myGMC / myBuick / myCadillac)", "Category": "Auto App", "Terms & Conditions URL": "gm.com/legal/vehicle-terms (Vehicle Mobile App Terms — not individually confirmed as direct PDF this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "gm.com/privacy-statement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MAJOR REGULATORY ACTION: GM (via OnStar Smart Driver) sold driving-behavior data to LexisNexis Risk Solutions and Verisk Analytics, which fed into insurer risk scores/rate increases WITHOUT customers realizing they'd been enrolled. FTC filed a complaint (Jan 2025) calling GM's enrollment process misleading; consent order finalized Jan 14, 2026, now requiring affirmative express consent before collecting/using driving behavior data. California AG separately announced a $12.75M CCPA settlement (May 8, 2026) — reportedly the largest CCPA fine in history, though critics note it's ~0.007% of GM's annual revenue. GM has since publicly announced ending its LexisNexis/Verisk partnerships.", "Arbitration / Class Action Waiver": "Same Vehicle Mobile App Terms as covered by GM's overall Consumer Privacy Statement; arbitration terms not independently confirmed this pass — verify the specific myChevrolet/myGMC app Terms of Service.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "THE single most concrete, high-value flag in this entire auto-app batch: an actual FTC consent order + state AG settlement over deceptive data practices, not just theoretical contract risk. Directly relevant to any customer-facing consumer-protection messaging.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Detroit", "HQ State": "Michigan", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.ftc.gov/news-events/news/press-releases/2026/01/ftc-finalizes-order-settling-allegations-gm-onstar-collected-sold-geolocation-data-without-consumers", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Michigan' is a non-DMV US state", "Parent / Ultimate Owner": "General Motors Company", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Michigan LARA Business Entity Search — cofs.lara.state.mi.us/SearchApi/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: General Motors Company). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] GM sold driving data to LexisNexis and Verisk without clear consent; FTC order and $12.75M CCPA settlement.\nWHAT THE TERMS SAY: GM (via OnStar Smart Driver) sold driving-behavior data to LexisNexis Risk Solutions and Verisk Analytics, which fed into insurer risk scores/rate increases without customers realizing they'd been enrolled; the FTC filed a complaint (Jan 2025) calling GM's enrollment process misleading; a consent order finalized Jan 14, 2026 now requires affirmative express consent; the California AG separately announced a $12.75M CCPA settlement (May 8, 2026), reportedly the largest CCPA fine in history though only about 0.007% of GM's annual revenue; GM has since ended the LexisNexis/Verisk partnerships.\nWHY IT MATTERS: Customers' driving behavior directly affected their insurance rates without their clear knowledge or consent, a confirmed regulatory finding, not an allegation.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Fees/Billing is explicitly 'not itemized this pass' and the arbitration clause is not independently confirmed for the myChevrolet/myGMC app terms; the FTC consent order and CCPA settlement is the only fully substantiated, company-specific item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The FTC consent order and CCPA settlement are documented with specific dates and dollar figures, though arbitration terms and fees are explicitly unconfirmed.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "GM (myChevrolet / myGMC / myBuick / myCadillac)  <-  General Motors Company", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using GM (myChevrolet / myGMC / myBuick / myCadillac) you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:39:46Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "GM sold ordinary customers' driving behavior — hard braking, speeding, late-night driving — to LexisNexis and Verisk, who fed it straight into INSURANCE RISK SCORES that raised people's rates, and the FTC found customers were never clearly told they'd been enrolled. GM paid the largest CCPA fine in history over it ($12.75 million) — which sounds huge until you realize it works out to roughly 0.007% of GM's annual revenue.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Auto Apps", "_row_id": 217, "_entity_id": 360, "_entity_slug": "gm-mychevrolet-mygmc-mybuick-mycadillac", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ford (FordPass)", "Category": "Auto App", "Terms & Conditions URL": "fordpass.com/content/ford_com/fp_app/en_us/termsprivacy.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "Same page (Privacy Policy, Terms and Conditions combined) — about.att... (correction: Ford's own privacy portal, not individually split from Terms in this pass)", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Collects driving data, location, and vehicle health/usage info continuously once modem is activated; anyone the account owner invites to the app gets FULL access to vehicle location/health/usage history, not just driving privileges — a real privacy exposure for shared/family vehicles. California's privacy regulator (CPPA) specifically cited Ford's opt-out-of-sale process as unnecessarily 'friction-heavy,' resulting in a $375,703 California fine for making consumers hand over excessive data just to opt out.", "Arbitration / Class Action Waiver": "Binding individual arbitration; explicitly bars combining claims, notifying others of potential claims, or any representative/class/collective/private-attorney-general proceeding without Ford's consent.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The 'anyone you invite gets full vehicle history access' design is worth flagging separately from the arbitration/data-sale issues — it's a data-sharing-by-design problem, not just fine print.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$187.3B", "Market Cap": "$54.4B", "Employees": "171,000", "HQ City": "Dearborn", "HQ State": "Michigan", "CEO": "James Farley Jr.", "Ticker": "F", "Website (Corporate)": "ford.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (F). Service route: c/o General Counsel / Corporate Secretary, Dearborn, Michigan — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Michigan' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Michigan LARA Business Entity Search — cofs.lara.state.mi.us/SearchApi/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Anyone invited to a FordPass account gets full access to the vehicle's location and health history.\nWHAT THE TERMS SAY: FordPass collects driving data, location, and vehicle health/usage info continuously once the modem is activated; anyone the account owner invites to the app gets FULL access to vehicle location/health/usage history, not just driving privileges.\nWHY IT MATTERS: This is a real privacy exposure for shared or family vehicles - inviting a house-sitter or teen driver silently grants them the owner's entire location and usage history, not just permission to drive.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-3] California fined Ford $375,703 for making its data-sale opt-out process needlessly hard to use.\nWHAT THE TERMS SAY: California's privacy regulator (CPPA) specifically cited Ford's opt-out-of-sale process as unnecessarily 'friction-heavy,' resulting in a $375,703 California fine for making consumers hand over excessive data just to opt out.\nWHY IT MATTERS: This is a confirmed regulatory finding that Ford's own opt-out mechanism was designed in a way that discouraged consumers from exercising their rights.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Ford's arbitration clause bars even notifying other customers of a potential shared claim.\nWHAT THE TERMS SAY: Binding individual arbitration that explicitly bars combining claims, notifying others of potential claims, or any representative/class/collective/private-attorney-general proceeding without Ford's consent.\nWHY IT MATTERS: This goes beyond a standard class waiver by also barring a customer from even notifying others about a potential shared claim.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The account-sharing design, CPPA fine, and arbitration scope are each stated specifically, including a precise fine amount.", "Exposure Score (0-100)": 54, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 0/20 (none) | Record 11/20 (severity3+8, penalty+3) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Ford (FordPass)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ford (FordPass) you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, and your right to join a class action. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:40:13Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "If you invite ANYONE to your FordPass account — a spouse, a teenager, a house-sitter borrowing the car for a week — they don't just get permission to drive. They get FULL ACCESS to the vehicle's entire location history, health data, and usage records. Sharing driving privileges silently shares your whole location history too, and California specifically fined Ford $375,703 for making the opt-out process needlessly hard to use.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Auto Apps", "_row_id": 218, "_entity_id": 361, "_entity_slug": "ford-fordpass", "_issuer": "Ford (FordPass)", "_issuer_slug": "ford-fordpass", "_ticker": "F", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Toyota App / Toyota Connected Services", "Category": "Auto App", "Terms & Conditions URL": "toyota.com (Connected Services Terms of Use; 'NOTICE OF MANDATORY ARBITRATION PROVISION' banner confirmed via litigation record, direct URL not individually captured this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "toyota.com/support/privacy-notice", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Toyota affiliate 'Connected Analytic Services' (CAS) is registered as a consumer reporting agency and is legally permitted to sell driving data to insurers (incl. Progressive) with the customer's consent given through the Toyota app; Toyota disclosed a 2023 breach exposing location data of 2.15 million customers (Nov 2013–Apr 2023, Japan-based cloud misconfiguration). Consumer Reports flagged that the initial consent to data sharing is often given unknowingly during first infotainment setup.", "Arbitration / Class Action Waiver": "ACTIVE 2026 LITIGATION: Philip Siefke v. Toyota Motor North America (E.D. Texas) alleges Toyota illegally sold/shared driving behavior data since MY2018 to Progressive Insurance and CAS without proper consent. Feb 2026: judge granted Toyota's (and Progressive's and CAS's) motion to COMPEL ARBITRATION, citing the boldface 'NOTICE OF MANDATORY ARBITRATION PROVISION' banner atop the Connected Services Terms — a textbook example of an arbitration clause blocking a data-privacy class claim in real time.", "Fees / Billing Flags": "Declining Connected Services means losing remote features entirely (no partial opt-out).", "Notes": "This is a live, ongoing court case (as of Feb 2026) directly on point for a customer-issues audit — not hypothetical.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] A judge ordered a Toyota driving-data lawsuit into arbitration, citing a bold notice atop the terms.\nWHAT THE TERMS SAY: In Siefke v. Toyota Motor North America (E.D. Texas), alleging Toyota illegally sold/shared driving behavior data since MY2018 to Progressive Insurance and CAS without proper consent, a judge in Feb 2026 granted Toyota's, Progressive's, and CAS's motion to compel arbitration, citing the boldface 'NOTICE OF MANDATORY ARBITRATION PROVISION' banner atop the Connected Services Terms.\nWHY IT MATTERS: This is a live example of an arbitration clause blocking a data-privacy class claim in real time, meaning affected customers must pursue individual arbitration instead of a class action.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SALE · FL-2] A Toyota affiliate is registered as a consumer reporting agency so it can legally sell data to insurers.\nWHAT THE TERMS SAY: Toyota affiliate 'Connected Analytic Services' (CAS) is registered as a consumer reporting agency and is legally permitted to sell driving data to insurers, including Progressive, with customer consent given through the Toyota app; Consumer Reports flagged that initial consent is often given unknowingly during first infotainment setup.\nWHY IT MATTERS: The consent enabling this data sale is often given without the customer realizing it, during a routine setup step.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CONFIRMED_BREACH · FL-2] A 2023 Toyota breach exposed a decade of location data for 2.15 million customers.\nWHAT THE TERMS SAY: Toyota disclosed a breach exposing location data of 2.15 million customers (Nov 2013-Apr 2023), caused by a Japan-based cloud misconfiguration.\nWHY IT MATTERS: A decade of location data for over two million customers was exposed due to a cloud configuration error.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The lawsuit, arbitration ruling, and CAS registration are documented with a specific case name, court, and date.", "Exposure Score (0-100)": 56, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Toyota App / Toyota Connected Services  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Toyota App / Toyota Connected Services you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, and your right to join a class action. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:40:14Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "A Toyota affiliate is literally REGISTERED AS A CONSUMER REPORTING AGENCY specifically so it can legally sell your driving data to insurers like Progressive. When a customer sued over this, a federal judge ORDERED THE CASE INTO ARBITRATION — citing a bold, all-caps 'NOTICE OF MANDATORY ARBITRATION PROVISION' banner sitting right at the top of the Connected Services terms. And declining Connected Services isn't a partial opt-out — you lose remote features ENTIRELY, an all-or-nothing choice.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Auto Apps", "_row_id": 219, "_entity_id": 362, "_entity_slug": "toyota-app-toyota-connected-services", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Honda / HondaLink", "Category": "Auto App", "Terms & Conditions URL": "honda.com (HondaLink Terms of Use — direct URL not individually captured this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "honda.com (privacy notice not individually captured this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "'Driver Feedback' program data-sharing toggle is reported to be buried two menus past the safety-feature toggle in the infotainment settings — a UX-level dark-pattern concern distinct from the legal text itself; Honda previously shared driver data with insurance brokers via LexisNexis/Verisk but DROPPED the Verisk partnership following public/regulatory pressure (per multiple 2025–2026 sources), unlike GM which required an FTC order to change course.", "Arbitration / Class Action Waiver": "Not confirmed this pass — verify current HondaLink Terms of Use arbitration clause directly.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Worth noting as a partial 'positive contrast': Honda voluntarily dropped a data broker relationship without waiting for an enforcement action, unlike GM.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] Honda buries its 'Driver Feedback' data-sharing opt-out two menus past the safety-feature toggle.\nWHAT THE TERMS SAY: The 'Driver Feedback' program data-sharing toggle is reported to be buried two menus past the safety-feature toggle in the infotainment settings - a UX-level dark-pattern concern distinct from the legal text itself.\nWHY IT MATTERS: Even though the opt-out technically exists, its placement makes it unlikely most drivers will find and use it.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Honda shared driver data with insurance brokers via LexisNexis/Verisk, then dropped the Verisk partnership.\nWHAT THE TERMS SAY: Honda previously shared driver data with insurance brokers via LexisNexis/Verisk but dropped the Verisk partnership following public/regulatory pressure, per multiple 2025-2026 sources.\nWHY IT MATTERS: Honda did share driving data with insurance brokers via LexisNexis/Verisk in the past; it dropped the Verisk partnership following public/regulatory pressure, per multiple 2025-2026 sources, without the FTC order GM required.\n(evidence: Data Sharing/Selling Flags | Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms are not confirmed this pass, and Honda's row is framed largely as a positive contrast (voluntarily dropping the Verisk data-broker relationship); only two distinct issues are substantiated - the buried opt-out toggle and the past broker-sharing practice.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are explicitly not confirmed this pass, and the toggle-placement claim is 'reported' rather than independently verified by the tracker.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Honda / HondaLink  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Honda / HondaLink you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The toggle to opt out of Honda's 'Driver Feedback' data-sharing program is buried TWO MENUS deep, past the safety-feature settings, inside the infotainment system — exactly the kind of layout choice that keeps a setting technically available while making sure most drivers never actually find it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Auto Apps", "_row_id": 220, "_entity_id": 363, "_entity_slug": "honda-hondalink", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Hyundai (Bluelink)", "Category": "Auto App", "Terms & Conditions URL": "hyundaiusa.com (Bluelink Terms — direct URL not individually captured this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "hyundaiusa.com (privacy notice not individually captured this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Named in active 2024–2026 mass-arbitration/class-action activity (with Kia, Mitsubishi, GM) over alleged undisclosed sharing of driving-behavior data with LexisNexis/Verisk feeding insurer risk scores; Hyundai also dropped its Verisk partnership following scrutiny, similar to Honda. Opt-out requires resetting Bluelink to factory settings in the infotainment system AND separately terminating the account in the Bluelink mobile app — a two-step, easy-to-miss process.", "Arbitration / Class Action Waiver": "Not confirmed this pass — verify current Bluelink Terms of Use.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Currently part of an active mass-arbitration recruitment effort (see attorney intake sites) alongside Kia, Mitsubishi, and GM specifically over driving-data-to-insurer sharing — a live, ongoing issue.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Hyundai is named with Kia, Mitsubishi and GM in mass-arbitration activity over alleged undisclosed sharing.\nWHAT THE TERMS SAY: Named in active 2024-2026 mass-arbitration/class-action activity (with Kia, Mitsubishi, GM) over alleged undisclosed sharing of driving-behavior data with LexisNexis/Verisk feeding insurer risk scores; Hyundai dropped its Verisk partnership following scrutiny, similar to Honda.\nWHY IT MATTERS: Customers are actively pursuing claims that Hyundai shared driving data with insurance-scoring brokers without adequate disclosure.\n(evidence: Arbitration / Class Action Waiver | Data Sharing/Selling Flags; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[OTHER · FL-1] Opting out of Hyundai's data collection requires two separate steps - miss either, and you haven't.\nWHAT THE TERMS SAY: Opt-out requires resetting Bluelink to factory settings in the infotainment system AND separately terminating the account in the Bluelink mobile app - a two-step, easy-to-miss process.\nWHY IT MATTERS: A customer who completes only one step may believe they've opted out while data collection continues.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration clause terms for Bluelink specifically are not confirmed this pass; only two distinct points are substantiated - the mass-arbitration activity over broker data-sharing, and the two-step opt-out design.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Bluelink's own Terms of Use arbitration clause is not confirmed this pass, though the mass-arbitration activity and opt-out mechanics are described specifically.", "Exposure Score (0-100)": 8, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Hyundai (Bluelink)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Hyundai (Bluelink) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Opting out of Hyundai's data collection isn't one step — it's TWO, done in two completely different places: reset Bluelink to factory settings IN THE CAR, and separately terminate the account IN THE PHONE APP. Miss either half, and you haven't actually opted out at all, even if you think you have.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Auto Apps", "_row_id": 221, "_entity_id": 364, "_entity_slug": "hyundai-bluelink", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Kia (Kia Connect / UVO)", "Category": "Auto App", "Terms & Conditions URL": "kia.com (Kia Connect Terms — direct URL not individually captured this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "kia.com (privacy notice not individually captured this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Kia's privacy policy has been publicly criticized (Mozilla Foundation 2023/2025 'Privacy Nightmare on Wheels' research) for reserving the right to collect information about a driver's sex life, religious beliefs, and political opinions — categories with no clear connection to vehicle operation; Kia's 'Driving Score' program is specifically flagged by consumer researchers as the feature to watch for opt-out purposes.", "Arbitration / Class Action Waiver": "Named alongside Hyundai/Mitsubishi/GM in active mass-arbitration recruitment over driving-data-to-insurer sharing (LexisNexis/Verisk); not independently confirmed whether Kia's own Terms include a class-action waiver — verify directly, though industry pattern strongly suggests yes.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The sex-life/religion/political-opinion data category (per Mozilla's research, not confirmed independently by us this pass) is the single most alarming specific claim found anywhere in this auto-app batch — flag for direct verification against Kia's actual current privacy policy text before repeating it in any customer-facing material.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Kia's policy allegedly reserves the right to collect data on a driver's sex life and political views.\nWHAT THE TERMS SAY: Mozilla Foundation research ('Privacy Nightmare on Wheels,' 2023/2025) alleges Kia's privacy policy reserves the right to collect information about a driver's sex life, religious beliefs, and political opinions - categories with no clear connection to vehicle operation; this has not been independently re-verified against Kia's current policy text.\nWHY IT MATTERS: If accurate, this would mean Kia's policy authorizes collecting some of the most sensitive personal data categories imaginable with no stated connection to operating the car; the tracker flags this as unconfirmed and to be verified directly.\n(evidence: Data Sharing/Selling Flags | Notes | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] Kia is named with Hyundai, Mitsubishi, and GM in mass-arbitration recruitment over data sharing.\nWHAT THE TERMS SAY: Named alongside Hyundai/Mitsubishi/GM in active mass-arbitration recruitment over driving-data-to-insurer sharing (LexisNexis/Verisk); whether Kia's own Terms include a class-action waiver is not independently confirmed, though the tracker notes the industry pattern strongly suggests yes.\nWHY IT MATTERS: Kia is named in active mass-arbitration recruitment over driving-data-to-insurer sharing (LexisNexis/Verisk), and whether Kia's own Terms include a class-action waiver is not independently confirmed.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Whether Kia's own Terms include a class-action waiver is not independently confirmed this pass, and Fees/Billing is not itemized; only two distinct points are substantiated, and the most serious one (the sensitive-data-category allegation) is explicitly flagged by the tracker as needing direct re-verification.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The most serious claim, sensitive-category data collection, is explicitly flagged as not independently re-verified, and arbitration/fee details are largely unconfirmed or not itemized.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "App / Service", "Ownership Path": "Kia (Kia Connect / UVO)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Kia (Kia Connect / UVO) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Mozilla Foundation research ('Privacy Nightmare on Wheels') alleges Kia's privacy policy reserves the right to collect information about a driver's SEX LIFE, RELIGIOUS BELIEFS, and POLITICAL OPINIONS — categories with no obvious connection to actually operating a car. This is the single most alarming specific claim found anywhere across every auto app in this tracker — it has not been independently re-verified against Kia's current policy text by us directly, so confirm before repeating it, but it's serious enough to flag prominently regardless.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Auto Apps", "_row_id": 222, "_entity_id": 365, "_entity_slug": "kia-kia-connect-uvo", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Stellantis (Jeep / Ram / Chrysler / Dodge — Uconnect)", "Category": "Auto App", "Terms & Conditions URL": "stellantis.com / mopar.com (Uconnect Terms — direct URL not individually captured this pass; opt-out requires calling 800-800-2813 and requesting 'Cancel for Privacy Reasons')", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "stellantis.com (privacy notice not individually captured this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "UNUSUALLY HARSH OPT-OUT DESIGN: the only way to fully opt out of data collection is a phone call requesting 'Cancel for Privacy Reasons' (not a menu toggle or app setting) — and doing so also disables ALL future over-the-air software updates and Wi-Fi services permanently, not just the data-sharing feature. A 2024 InvestigateTV test of a 2019 Jeep Compass found it actively gathering personal information (potentially including SSN-adjacent identifiers) that Stellantis's own public response to a U.S. Senator's inquiry did not fully disclose.", "Arbitration / Class Action Waiver": "Not confirmed this pass — verify current Uconnect/SiriusXM Guardian Terms of Service.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The 'opt out of privacy = lose all future software updates forever' bundling is a genuinely aggressive practice worth flagging prominently — it turns a privacy choice into a permanent functionality penalty.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024, 2019", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] Opting out of Stellantis's data collection permanently disables all future software updates and Wi-Fi.\nWHAT THE TERMS SAY: The only way to fully opt out of data collection is a phone call requesting 'Cancel for Privacy Reasons' - not a menu toggle; doing so also disables ALL future over-the-air software updates and Wi-Fi services permanently, not just the data-sharing feature.\nWHY IT MATTERS: Stellantis bundles the privacy choice with a permanent functionality penalty, discouraging customers from ever opting out.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] A 2024 test of a Jeep found it gathering data Stellantis's own Senate-inquiry response didn't disclose.\nWHAT THE TERMS SAY: A 2024 InvestigateTV test of a 2019 Jeep Compass found it actively gathering personal information (potentially including SSN-adjacent identifiers) that Stellantis's own public response to a U.S. Senator's inquiry did not fully disclose.\nWHY IT MATTERS: This suggests Stellantis's own public disclosures understated what data the vehicle actually collects, based on independent testing.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms are not confirmed this pass and fees are not itemized; only the opt-out design and the InvestigateTV testing finding are substantiated as distinct, company-specific items.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The opt-out mechanism and 2024 test finding are described specifically, but the arbitration clause is not confirmed this pass.", "Exposure Score (0-100)": 9, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 4/20 (termination_or_confiscation+4) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "App / Service", "Ownership Path": "Stellantis (Jeep / Ram / Chrysler / Dodge — Uconnect)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Stellantis (Jeep / Ram / Chrysler / Dodge — Uconnect) you gave up your right to keep what you paid for. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "There's no toggle to opt out of Stellantis's data collection — you have to CALL and specifically request 'Cancel for Privacy Reasons.' And choosing privacy comes at a permanent price: doing so disables ALL future over-the-air software updates and Wi-Fi services in your vehicle, FOREVER, not just the data-sharing feature. Stellantis turned a privacy choice into a permanent functionality punishment — and a 2024 test of a 2019 Jeep found it collecting information Stellantis's own response to a US Senator's inquiry didn't fully disclose.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Auto Apps", "_row_id": 223, "_entity_id": 366, "_entity_slug": "stellantis-jeep-ram-chrysler-dodge-uconnect", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Nissan (NissanConnect)", "Category": "Auto App", "Terms & Conditions URL": "nissanusa.com (NissanConnect Terms — direct URL not individually captured this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "nissanusa.com (privacy notice not individually captured this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Named by Mozilla's 2023/2025 research as one of several automakers whose stated data collection extends into sensitive categories without clear driver consent; not independently confirmed by us this pass beyond that general industry callout.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Thin independent verification this pass — flagged for direct follow-up against Nissan's actual current Terms/Privacy Notice rather than relying on secondary source characterizations.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Research names Nissan among automakers whose data collection allegedly reaches sensitive categories.\nWHAT THE TERMS SAY: Named by Mozilla's 2023/2025 research as one of several automakers whose stated data collection extends into sensitive categories without clear driver consent; not independently confirmed by the tracker beyond that general industry callout.\nWHY IT MATTERS: If accurate, this would mean Nissan collects sensitive personal categories without clear consent, but the tracker explicitly treats this as unverified secondary-source characterization rather than a confirmed finding.\n(evidence: Data Sharing/Selling Flags | Notes | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — The tracker explicitly states verification is thin this pass and flags the Mozilla-sourced claim for direct follow-up against Nissan's actual current terms rather than treating it as confirmed; no other fields (Arbitration, Fees, Key Provisions, Major Issues) contain content.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The tracker states this row has thin independent verification and that the only claim present is an unconfirmed secondary-source characterization.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "App / Service", "Ownership Path": "Nissan (NissanConnect)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Nissan (NissanConnect) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Independent research (Mozilla Foundation) names Nissan among automakers whose data collection extends into sensitive categories without clear driver consent — though this hasn't been independently re-verified against Nissan's own current terms, so treat as a flag for direct follow-up rather than a confirmed finding.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Auto Apps", "_row_id": 224, "_entity_id": 367, "_entity_slug": "nissan-nissanconnect", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Subaru (Starlink connected services)", "Category": "Auto App", "Terms & Conditions URL": "subaru.com (Starlink Terms — not individually captured this pass; note this is unrelated to SpaceX's Starlink internet service, a naming collision worth flagging to avoid confusing customers)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "subaru.com (privacy notice not individually captured this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Data-sharing default is reported to be ON out of the box for Subaru's Starlink connected-services bundle (remote services, automatic collision notification, stolen vehicle recovery); LexisNexis Risk Solutions has had a data partnership with Subaru per Consumer Reports' 15-automaker review.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Name-collision alert: 'Subaru Starlink' (car connectivity brand) vs. 'Starlink' (SpaceX satellite internet, already covered in the Internet Providers tab) are completely unrelated companies/services — worth a footnote if this tracker is ever read by someone skimming both tabs.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Subaru's connected-services data sharing is on by default, feeding a LexisNexis data partnership.\nWHAT THE TERMS SAY: Data-sharing default is reported to be ON out of the box for Subaru's Starlink connected-services bundle (remote services, automatic collision notification, stolen vehicle recovery); LexisNexis Risk Solutions has had a data partnership with Subaru per Consumer Reports' 15-automaker review.\nWHY IT MATTERS: No action is required from the customer before Subaru and its data partner LexisNexis Risk Solutions begin collecting.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration terms are not confirmed this pass and fees are not itemized; the Notes field only contains an unrelated name-collision footnote (Subaru Starlink vs. SpaceX Starlink), so only the default-on data-sharing finding is substantiated.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The default-on sharing and LexisNexis partnership are stated specifically, but arbitration terms are not confirmed this pass.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Subaru (Starlink connected services)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Subaru (Starlink connected services) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Subaru's connected-services data sharing comes turned ON BY DEFAULT right out of the box — no action required from you for Subaru (and its data partner LexisNexis Risk Solutions) to start collecting. And yes, 'Subaru Starlink' has nothing to do with SpaceX's Starlink internet service — an unrelated company borrowed the same name, which is worth knowing before assuming any connection between the two.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Auto Apps", "_row_id": 225, "_entity_id": 368, "_entity_slug": "subaru-starlink-connected-services", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Mazda (Mazda Connected Services)", "Category": "Auto App", "Terms & Conditions URL": "mazdausa.com/site/terms-of-use-connectedservices", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "mazdausa.com (Connectivity Privacy Policy referenced/incorporated by the Terms, not individually located as a direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass beyond what the Terms of Use themselves disclose.", "Arbitration / Class Action Waiver": "Binding individual arbitration via AAA Consumer Rules; NOTABLY CUSTOMER-FRIENDLY relative to peers: Mazda pays the customer's arbitrator fees regardless of who initiates, reimburses the customer's reasonable attorney fees if Mazda loses, and will NOT seek its own fees back even if it wins (unless the claim was frivolous/bad-faith) — a real, concrete contrast to the more one-sided arbitration terms seen elsewhere in this audit (carriers, most banks). One-year statute of limitations to begin arbitration after a claim arises.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Genuinely worth highlighting as a positive-contrast example when discussing what fairer arbitration terms look like in practice — useful if part of your customer education materials will contrast good vs. bad clauses.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Mazda still requires individual arbitration with a one-year filing deadline, despite fair fee terms.\nWHAT THE TERMS SAY: Binding individual arbitration via AAA Consumer Rules; Mazda pays the customer's arbitrator fees regardless of who initiates, reimburses the customer's reasonable attorney fees if Mazda loses, and won't seek its own fees back even if it wins unless the claim was frivolous/bad-faith; there is a one-year statute of limitations to begin arbitration after a claim arises.\nWHY IT MATTERS: Even with unusually fair fee-shifting terms, a customer still loses access to court and must act within one year or lose the claim entirely; the tracker notes this as a genuinely positive contrast to most other rows in this tab.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — This row is explicitly framed as a positive-contrast example of fairer arbitration terms; Data Sharing is not independently confirmed and Fees are not itemized, so the one-year filing deadline within an otherwise fee-fair arbitration clause is the only substantive item.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration fee terms are described specifically and favorably, but Data Sharing practices are not independently confirmed and fees are not itemized.", "Exposure Score (0-100)": 20, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Mazda (Mazda Connected Services)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Mazda (Mazda Connected Services) you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "2026-09-08T19:40:14Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Mazda's arbitration terms are unusually FAIR — it pays your arbitrator fees, reimburses your attorney fees if you win, and won't come after your fees even if IT wins. The 'scary' part is what that says about everyone else in this tab: a company voluntarily agreeing to a level playing field is rare enough to be worth specifically pointing out, which tells you something about how the default in this industry usually looks.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Auto Apps", "_row_id": 226, "_entity_id": 369, "_entity_slug": "mazda-mazda-connected-services", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "BMW (My BMW App / ConnectedDrive)", "Category": "Auto App", "Terms & Conditions URL": "bmwusa.com (My BMW App Terms — manufacturer-level document not individually captured this pass; only a single BMW DEALERSHIP's website privacy policy was reviewed, which is not the same document)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "bmwusa.com (manufacturer-level privacy notice not individually captured this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed at the manufacturer level this pass — the dealership-level policy reviewed is illustrative only (shows dealerships often layer their OWN arbitration clause on top of BMW corporate's, governed by different state law, e.g. Texas for that specific dealer) but should not be cited as BMW corporate's actual terms.", "Arbitration / Class Action Waiver": "Not confirmed at the manufacturer level.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "IMPORTANT METHODOLOGY NOTE FOR THIS ENTIRE CATEGORY: individual BMW (and likely other brand) DEALERSHIPS often have their own separate privacy policy and arbitration clause layered on top of the manufacturer's app/connected-services terms. A customer's actual rights may depend on both documents, not just the manufacturer's app terms researched here — worth a general caveat across all 15 automaker rows.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-3] BMW dealerships often layer their own arbitration clause atop the manufacturer's app terms.\nWHAT THE TERMS SAY: The dealership-level policy reviewed is illustrative only - it shows dealerships often layer their OWN arbitration clause on top of BMW corporate's, governed by different state law (e.g., Texas for that specific dealer); this should not be cited as BMW corporate's actual terms, which are not independently confirmed at the manufacturer level this pass.\nWHY IT MATTERS: A customer's actual legal rights may depend on both the manufacturer's app terms and a separate dealership contract they may never have carefully read, potentially governed by a state law unrelated to where they live.\n(evidence: Notes | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — BMW's own manufacturer-level arbitration and data-sharing terms were not independently confirmed this pass; the only substantiated point is the general dealership-layered-arbitration methodology caveat, illustrated by one example dealership that should not be read as BMW corporate's own terms.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The tracker explicitly states manufacturer-level data-sharing and arbitration terms were not independently confirmed this pass, relying only on one illustrative dealership example.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "App / Service", "Ownership Path": "BMW (My BMW App / ConnectedDrive)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, BMW (My BMW App / ConnectedDrive) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Reading BMW's own app/connected-services terms may not tell you your full legal exposure at all. Individual BMW DEALERSHIPS frequently layer their OWN separate arbitration clause on top of BMW corporate's — governed by whatever state law that specific dealership picks, which may have nothing to do with where you actually live. You could read one contract carefully and still be bound by a second one you never saw.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Auto Apps", "_row_id": 227, "_entity_id": 370, "_entity_slug": "bmw-my-bmw-app-connecteddrive", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Mercedes-Benz (Mercedes me connect)", "Category": "Auto App", "Terms & Conditions URL": "mbusa.com/content/dam/mb-nafta/us/mercedes-me-connect/Terms-of-Use-MMC-Services.pdf", "T&C Direct PDF?": "YES", "Privacy Policy URL": "mbusa.com/content/dam/mb-nafta/us/legal/Jan%202024%20Privacy%20Notice%20for%20Mercedes%20me%20connect%20Connected%20Vehicle%20Services.pdf", "Privacy Direct PDF?": "YES", "Data Sharing/Selling Flags": "Mozilla's research (cited in secondary sources) describes Mercedes vehicles monitoring facial expressions, voice commands, and mood via in-cabin sensors, with some models reportedly shipping with TikTok pre-installed — a potential data flow to a third-party platform separate from Mercedes's own systems; Mercedes reportedly still failed Mozilla's privacy benchmark despite public statements about privacy commitments.", "Arbitration / Class Action Waiver": "Binding arbitration under AAA commercial/consumer rules with an explicit class-action waiver; arbitration hearings held in the STATE OF GEORGIA regardless of where the customer lives (a fixed, non-negotiable venue); Mercedes caps its own attorney-fee exposure at $5,000 and the customer's fee reimbursement at $2,500 if Mercedes loses — concrete dollar caps worth noting since most other companies in this audit don't specify a number.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The Georgia-only arbitration venue is a real practical burden for out-of-state customers (including all of DC/MD/VA and the other states on your list) — worth flagging as a distinct 'issue pertaining to customers' beyond the arbitration clause's mere existence.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Mercedes requires arbitration hearings to be held in Georgia regardless of where the customer lives.\nWHAT THE TERMS SAY: Binding arbitration under AAA commercial/consumer rules with an explicit class-action waiver; arbitration hearings are held in the STATE OF GEORGIA regardless of where the customer lives, a fixed non-negotiable venue; Mercedes caps its own attorney-fee exposure at $5,000 and the customer's fee reimbursement at $2,500 if Mercedes loses.\nWHY IT MATTERS: An out-of-state customer, including anyone in DC, Maryland, or Virginia, would have to travel to Georgia to be heard, and the customer's own fee recovery is capped at $2,500 even if they win.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Mercedes's in-cabin sensors reportedly monitor facial expressions and mood; some models ship with TikTok.\nWHAT THE TERMS SAY: Mozilla's research, cited in secondary sources, describes Mercedes vehicles monitoring facial expressions, voice commands, and mood via in-cabin sensors, with some models reportedly shipping with TikTok pre-installed - a potential data flow to a third-party platform separate from Mercedes's own systems; Mercedes reportedly still failed Mozilla's privacy benchmark despite public statements about privacy commitments.\nWHY IT MATTERS: In-cabin mood and facial monitoring, plus a reportedly pre-installed third-party app, is a potential data flow to a platform separate from Mercedes's own systems, and Mercedes reportedly still failed Mozilla's privacy benchmark despite public statements about privacy commitments.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees/Billing is not itemized this pass; only two distinct, company-specific items are substantiated - the Georgia-only arbitration venue with specific fee caps, and the in-cabin sensor/TikTok data-flow finding, which is itself sourced to secondary reporting on Mozilla's research.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration venue and fee caps are stated as concrete contract terms, but the in-cabin monitoring claim is attributed to secondary reporting on Mozilla's research rather than confirmed directly.", "Exposure Score (0-100)": 43, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 9/30 (biometric_collection+6, sensitive_exposure_tag+3) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Mercedes-Benz (Mercedes me connect)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Mercedes-Benz (Mercedes me connect) you gave up your biometric identifiers, your right to sue, your right to join a class action, and your right to meaningful compensation. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:40:17Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Mercedes's in-cabin sensors reportedly monitor facial expressions, voice, and even MOOD — and some models have shipped with TikTok pre-installed, a direct data pathway to a third-party platform sitting inside your car. If something ever goes wrong and you need arbitration, Mercedes requires the hearing to happen IN THE STATE OF GEORGIA, no matter where you actually live — meaning every DC, Maryland, and Virginia customer in this tracker would have to travel there just to be heard.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Auto Apps", "_row_id": 228, "_entity_id": 371, "_entity_slug": "mercedes-benz-mercedes-me-connect", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Volkswagen (Car-Net)", "Category": "Auto App", "Terms & Conditions URL": "vw.com (Car-Net Terms — direct URL not individually captured this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "vw.com (privacy notice not individually captured this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "VW settled a CLASS ACTION in 2022 specifically over its Car-Net data collection practices (per secondary-source research, not independently verified by us this pass — confirm case name/terms directly); separately, VW/Audi disclosed a breach exposing 3.3 million customer records (primarily US/Canada, Aug 2019–May 2021) including names, addresses, emails, and vehicle purchase/inquiry details, used for sales and marketing purposes.", "Arbitration / Class Action Waiver": "Not confirmed this pass — verify current Car-Net Terms of Service arbitration clause directly.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The 2022 class-action settlement (if confirmed) would be a genuinely useful precedent to cite, since it shows a case that reportedly was NOT blocked by arbitration — worth verifying directly since that would be a useful contrast to Toyota's/GM's arbitration-blocked outcomes above.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Herndon", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": "https://techcrunch.com/2021/06/11/volkswagen-says-a-vendors-security-lapse-exposed-3-3-million-drivers-details/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ: Herndon, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "Volkswagen AG (Wolfsburg, Germany)", "Years Referenced in Finding (heuristic)": "2019, 2021", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Volkswagen AG (Wolfsburg, Germany)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] VW/Audi exposed 3.3 million customers' names, addresses, and purchase details in a breach.\nWHAT THE TERMS SAY: VW/Audi disclosed a breach exposing 3.3 million customer records (primarily US/Canada, Aug 2019-May 2021) including names, addresses, emails, and vehicle purchase/inquiry details, used for sales and marketing purposes.\nWHY IT MATTERS: Data gathered to sell customers more cars ended up exposed in a breach instead, affecting millions of people.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-3] VW reportedly settled a 2022 class action over Car-Net data practices, not independently verified.\nWHAT THE TERMS SAY: VW settled a class action in 2022 specifically over its Car-Net data collection practices, per secondary-source research not independently verified by the tracker this pass; confirming the case name and terms directly is recommended.\nWHY IT MATTERS: If confirmed, this would be a rare example of a class action that was not blocked by arbitration, unlike the Toyota/GM outcomes documented elsewhere in this tab, but it remains unverified.\n(evidence: Data Sharing/Selling Flags | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The Car-Net Terms of Service arbitration clause is not confirmed this pass, and the 2022 class-action settlement is explicitly flagged as secondary-source and not independently verified; only the confirmed 2019-2021 breach and the unverified settlement are documented.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach is confirmed with specific dates and record counts, but the 2022 settlement and the current Car-Net arbitration clause are both explicitly unverified this pass.", "Exposure Score (0-100)": 14, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "App / Service", "Ownership Path": "Volkswagen (Car-Net)  <-  Volkswagen AG (Wolfsburg, Germany)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Volkswagen (Car-Net) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "2026-09-08T19:40:17Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "VW/Audi exposed 3.3 MILLION customers' names, addresses, emails, and vehicle purchase details (2019-2021) — data that had been collected specifically to fuel SALES AND MARKETING, meaning the very information gathered to sell you more cars ended up in a breach instead.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Auto Apps", "_row_id": 229, "_entity_id": 373, "_entity_slug": "volkswagen-car-net", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Tesla (Tesla App)", "Category": "Auto App", "Terms & Conditions URL": "tesla.com/legal", "T&C Direct PDF?": "NOT CONFIRMED (legal hub page; specific App Terms of Use PDF not individually captured this pass)", "Privacy Policy URL": "tesla.com/legal/privacy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Tesla's cabin camera is reported to be active at all times during Autopilot use, capturing images used for analysis, training, and storage; a 2026 software update (2026.8.6, per secondary source) reportedly added facial age estimation. Tesla provides a data-request portal (tesla.com) allowing owners to download a copy of their own held data — a genuinely useful transparency feature relative to most peers.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — verify current Tesla Motors Vehicle Agreement/App Terms arbitration clause directly.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "OPT-OUT TRADE-OFF: disabling 'Data Sharing' in the vehicle's Privacy settings stops driving-data transmission to Tesla but also disables remote diagnostics; going further and opting out of data sharing entirely can reduce Autopilot functionality — a real feature-for-privacy trade-off that should be disclosed plainly to customers rather than buried in settings menus.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$94.8B", "Market Cap": "$1.4T", "Employees": "125,665", "HQ City": "Austin", "HQ State": "Texas", "CEO": "Elon Musk", "Ticker": "TSLA", "Website (Corporate)": "tesla.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (TSLA). Service route: c/o General Counsel / Corporate Secretary, Austin, Texas — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[BIOMETRICS · FL-2] Tesla cabin camera reportedly active during Autopilot; 2026 update reportedly added facial age estimation.\nWHAT THE TERMS SAY: Tesla's cabin camera is reported to be active at all times during Autopilot use, capturing images used for analysis, training, and storage; a 2026 software update (2026.8.6, per secondary source) reportedly added facial age estimation.\nWHY IT MATTERS: Continuous in-cabin recording during Autopilot, now reportedly including facial age estimation, is a biometric-adjacent data practice tied to normal vehicle use, not a separate opt-in feature.\n(evidence: Data Sharing/Selling Flags | SCARY; Tracker says unconfirmed (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[OTHER · FL-1] Opting out of Tesla's data sharing costs you remote diagnostics, and can reduce Autopilot function.\nWHAT THE TERMS SAY: Disabling 'Data Sharing' in the vehicle's Privacy settings stops driving-data transmission to Tesla but also disables remote diagnostics; going further and opting out of data sharing entirely can reduce Autopilot functionality.\nWHY IT MATTERS: Privacy and vehicle features are directly traded against each other rather than offered independently, so declining data collection has a real functional cost.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Tesla's Motor Vehicle Agreement/App Terms arbitration clause is not independently confirmed this pass, and Fees are not itemized; the cabin-camera/facial-age-estimation claims are also sourced to a secondary report rather than confirmed directly, alongside the confirmed privacy-for-features trade-off.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=Y; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The privacy-for-features trade-off is described as a stated design choice, but the camera/facial-age-estimation claims are attributed to a secondary source and the arbitration clause is not confirmed this pass.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 11, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 11/30 (biometric_collection+6, ai_training_on_user_data+5) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nAI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use", "Entity Type": "App / Service", "Ownership Path": "Tesla (Tesla App)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Tesla (Tesla App) you gave up your content used as AI training data and your biometric identifiers. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Tesla's in-cabin camera reportedly stays ACTIVE THE ENTIRE TIME you use Autopilot, capturing images used for training and storage — and a 2026 software update reportedly added FACIAL AGE ESTIMATION on top of that. And the privacy trade-off isn't subtle: opt out of data sharing and you lose remote diagnostics; opt out further and you can lose actual Autopilot functionality. Privacy and features are directly traded against each other, not offered separately.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Auto Apps", "_row_id": 230, "_entity_id": 374, "_entity_slug": "tesla-tesla-app", "_issuer": "Tesla (Tesla App)", "_issuer_slug": "tesla-tesla-app", "_ticker": "TSLA", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Rivian (Rivian App)", "Category": "Auto App", "Terms & Conditions URL": "rivian.com/legal/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "rivian.com/legal (privacy notice not individually located as a direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass beyond what the Terms themselves disclose.", "Arbitration / Class Action Waiver": "Binding individual arbitration; the definition of 'Dispute' subject to arbitration is EXPLICITLY drafted to include claims for 'violations of consumer protection, privacy or data security laws' — i.e., Rivian's clause is drafted, like Toyota's and T-Mobile's, to specifically sweep privacy/data-security complaints into mandatory arbitration rather than leaving that ambiguous; arbitration proceedings are explicitly required to be kept STRICTLY CONFIDENTIAL, including the mere fact that an arbitration exists — an unusually broad gag provision compared to peers.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The confidentiality requirement extending to concealing the EXISTENCE of an arbitration (not just its content) is one of the more aggressive individual clauses found across this entire audit so far — worth flagging specifically.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Rivian's arbitration is secret to the point you can't say it's happening, and covers privacy claims\nWHAT THE TERMS SAY: Rivian's terms define 'Dispute' to explicitly include claims for violations of consumer protection, privacy, or data-security law, sweeping those into binding individual arbitration. Arbitration proceedings must be kept strictly confidential, including the mere fact that an arbitration is taking place.\nWHY IT MATTERS: A user cannot pursue a privacy or data-security complaint in court, and the confidentiality clause bars even mentioning to anyone that a dispute with Rivian is underway.\n(evidence: Arbitration | SCARY | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data Sharing/Selling Flags is 'not independently confirmed' and Fees/Billing Flags is 'not itemized this pass'; only the arbitration/confidentiality clause is substantive enough to support a distinct finding.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause is clearly documented, but data sharing and fees are both unconfirmed this pass.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Rivian (Rivian App)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Rivian (Rivian App) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "2026-09-08T19:40:19Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Rivian's arbitration clause requires that arbitration proceedings be kept STRICTLY CONFIDENTIAL — including the mere FACT that an arbitration is happening at all. You couldn't even tell a friend 'I'm in arbitration with Rivian right now' without potentially violating your own agreement with the company. That's one of the most aggressive gag provisions found anywhere in this entire tracker.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Auto Apps", "_row_id": 231, "_entity_id": 375, "_entity_slug": "rivian-rivian-app", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Comcast Xfinity", "Category": "ISP", "Terms & Conditions URL": "xfinity.com/Corporate/Customers/Policies/SubscriberAgreement (Residential Services Agreement)", "T&C Direct PDF?": "YES (assets.xfinity.com/.../RSA_01012024.pdf)", "Privacy Policy URL": "xfinity.com/privacy/policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same Comcast-wide privacy policy as Xfinity Mobile (see Carriers tab) covers Internet/TV/Voice too; note the Residential Services Agreement (Internet/TV/Voice) is a SEPARATE legal document from the Xfinity Mobile Customer Agreement, even though both defer to the same overall privacy policy.", "Arbitration / Class Action Waiver": "Binding arbitration (Section 13) + jury trial waiver (14) + class/collective/representative action waiver (15), all explicitly broken into separate numbered sections; 30-day opt-out from first service activation via xfinity.com/arbitrationoptout or mail; opting out for one Comcast account (e.g., Mobile) does NOT cover other accounts (e.g., Internet) — must opt out separately per account.", "Fees / Billing Flags": "Largest cable ISP in the country; serves DC, MD, VA, and FL directly from this consolidated list.", "Notes": "Covers DC/MD/VA/FL for this list. Same corporate parent as Xfinity Mobile already documented in Carriers tab, but this is a legally distinct agreement — don't assume one opt-out covers both.\n\nFTC 6(b) STAFF REPORT CROSS-REFERENCE (verified this pass): 'A Look at What ISPs Know About You: Examining the Privacy Practices of Six Major Internet Service Providers,' released Oct 21 2021, approved 4-0. Orders issued in 2019 under FTC Act sec. 6(b) to AT&T, Comcast/Xfinity, Charter, T-Mobile, Verizon and Google Fiber - together ~98% of the mobile internet market - plus three affiliated ad entities (AT&T's Appnexus/Xandr, Verizon Online LLC, Oath Americas/Verizon Media). FINDINGS: ISPs combine data across product lines; combine personal, app-usage and web-browsing data to target ads; place consumers into SENSITIVE CATEGORIES including by race and sexual orientation; share real-time location data with third parties; and while several promise not to 'sell' personal data, they permit it to be used, transferred and monetised by others while burying the disclosures. The report also found many ISPs make the choices they advertise difficult to actually exercise. Data-access requests received ran between ZERO and 380 per month across the six. This is a STAFF REPORT, not an enforcement action - no penalties attach. Treat as one connected finding across every ISP row rather than six separate ones.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$123.7B", "Market Cap": "$84.0B", "Employees": "182,000", "HQ City": "Philadelphia", "HQ State": "Pennsylvania", "CEO": "Brian Roberts", "Ticker": "CMCSA", "Website (Corporate)": "comcast.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (CMCSA). Service route: c/o General Counsel / Corporate Secretary, Philadelphia, Pennsylvania — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Comcast was one of six ISPs the FTC found sorting customers into categories including race and orientation\nWHAT THE TERMS SAY: The tracker frames the FTC's 6(b) staff report findings as the substance of Comcast's row: the studied ISPs combine personal, app-usage and browsing data for ad targeting and place consumers into sensitive categories including by race and sexual orientation, while several simultaneously promised not to 'sell' data.\nWHY IT MATTERS: Even where a company says it doesn't 'sell' data, the FTC found the underlying data is still used, transferred, and monetized by others, and disclosures and opt-outs are made hard to exercise.\n(evidence: SCARY | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Comcast requires opting out of arbitration separately for every account you have, including Mobile\nWHAT THE TERMS SAY: Binding arbitration, jury-trial waiver, and class/collective/representative-action waiver are each broken into separate sections with a 30-day opt-out window, but opting out on one Comcast account (e.g. Mobile) does not cover another (e.g. Internet) — each must be opted out separately.\nWHY IT MATTERS: A customer who successfully opts out of arbitration for one Comcast service can still be bound to mandatory arbitration on another, unless they repeat the process per account.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] One Comcast privacy policy governs Internet, TV, Voice, and Mobile data together, not separately\nWHAT THE TERMS SAY: The same Comcast-wide privacy policy that covers Xfinity Mobile also governs Internet, TV, and Voice service, even though the Residential Services Agreement is a legally separate document from the Mobile Customer Agreement.\nWHY IT MATTERS: Data collected through a customer's home internet use can sit under the same governing privacy terms as their mobile and TV usage, with no separate consent layer between services.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration mechanics are clearly documented, but data-sharing specifics rest on an aggregate industry report rather than Comcast-specific disclosure.", "Exposure Score (0-100)": 42, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_30d+3) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Comcast Xfinity  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to a jury.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Comcast Xfinity you gave up your data shared corporate-wide, your right to sue, your right to join a class action, and your right to a jury. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Comcast was one of six ISPs the FTC studied under compulsory 6(b) orders, and the report's findings are the row's substance: the studied ISPs combine data across product lines, merge personal, app-usage and web-browsing data for ad targeting, sort customers into sensitive categories including by RACE and SEXUAL ORIENTATION, and share real-time location data with third parties - while several simultaneously promise not to 'sell' your data, a promise the FTC found technically true and practically meaningless because the data is still used, transferred and monetised by others. The single most damning number in the report is about consumer engagement: across all six ISPs, data-access requests ran between zero and 380 per MONTH. Comcast's privacy policy also spans Xfinity internet, mobile and TV as one document, so the cross-product combining the FTC described is structural, not incidental.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Internet Providers", "_row_id": 232, "_entity_id": 376, "_entity_slug": "comcast-xfinity", "_issuer": "Comcast Xfinity", "_issuer_slug": "comcast-xfinity", "_ticker": "CMCSA", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Verizon Fios", "Category": "ISP", "Terms & Conditions URL": "verizon.com/support/fios-customer-agreement/", "T&C Direct PDF?": "verizon.com/about/sites/default/files/documents/terms/version_15-1_internet_tos.pdf (Verizon Online Internet ToS — companion doc)", "Privacy Policy URL": "verizon.com/about/privacy/full-privacy-policy (shared Verizon privacy policy)", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same shared Verizon privacy policy as Verizon Wireless (see Carriers tab).", "Arbitration / Class Action Waiver": "Binding arbitration clause + class action waiver explicitly flagged in a dedicated 'NOTICE OF ARBITRATION AGREEMENT' banner at the top of the Fios Customer Agreement; arbitrator cannot preside over class/collective arbitration under any circumstance per the companion Internet ToS.", "Fees / Billing Flags": "Not itemized this pass — pull the current Fios-specific fee schedule directly.", "Notes": "IMPORTANT: Fios (fiber) is only in DC/MD/VA/NY for this 7-state list — Verizon does NOT operate Fios in CA, TX, or FL; those markets were SOLD TO FRONTIER years ago (see Frontier row below). Don't list 'Verizon' as a CA/TX/FL internet provider without this caveat.\n\nFTC 6(b) STAFF REPORT CROSS-REFERENCE (verified this pass): 'A Look at What ISPs Know About You: Examining the Privacy Practices of Six Major Internet Service Providers,' released Oct 21 2021, approved 4-0. Orders issued in 2019 under FTC Act sec. 6(b) to AT&T, Comcast/Xfinity, Charter, T-Mobile, Verizon and Google Fiber - together ~98% of the mobile internet market - plus three affiliated ad entities (AT&T's Appnexus/Xandr, Verizon Online LLC, Oath Americas/Verizon Media). FINDINGS: ISPs combine data across product lines; combine personal, app-usage and web-browsing data to target ads; place consumers into SENSITIVE CATEGORIES including by race and sexual orientation; share real-time location data with third parties; and while several promise not to 'sell' personal data, they permit it to be used, transferred and monetised by others while burying the disclosures. The report also found many ISPs make the choices they advertise difficult to actually exercise. Data-access requests received ran between ZERO and 380 per month across the six. This is a STAFF REPORT, not an enforcement action - no penalties attach. Treat as one connected finding across every ISP row rather than six separate ones.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$138.2B", "Market Cap": "$184.9B", "Employees": "99,600", "HQ City": "New York", "HQ State": "New York", "CEO": "Hans Vestberg", "Ticker": "VZ", "Website (Corporate)": "verizon.com", "Main Mailing Address (legal/privacy notices)": "Verizon Privacy Office, 1300 I Street NW, Suite 500 East, Washington, DC 20005, USA (International: Verizon Legal Dept, Reading International Business Park, Basingstoke Road, Reading, Berkshire RG2 6DA, UK)", "Legal / Privacy Contact Email": "No published privacy email; Verizon routes requests through its online privacy form", "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (VZ). Service route: c/o General Counsel / Corporate Secretary, New York, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Verizon's 'third-party' ad sharing is really in-house: Fios data can reach its own ad subsidiaries\nWHAT THE TERMS SAY: Verizon was the only ISP in the FTC's study where the agency also had to issue orders to two affiliated ad entities, Verizon Online LLC and Oath Americas (rebranded Verizon Media). Fios runs on the same shared Verizon privacy policy as Verizon Wireless, with no separate consent layer.\nWHY IT MATTERS: Describing this as 'sharing with third parties' understates it, since the ISP and the ad business are the same corporate family, combining fixed-line browsing, mobile location, and advertising profile under one document.\n(evidence: SCARY | Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Fios flags its arbitration clause up front and bars the arbitrator from ever hearing a class claim\nWHAT THE TERMS SAY: A dedicated 'NOTICE OF ARBITRATION AGREEMENT' banner appears at the top of the Fios Customer Agreement, and a companion Internet ToS states the arbitrator cannot preside over class or collective arbitration under any circumstance.\nWHY IT MATTERS: Consumers are blocked from both individual class litigation and any form of collective arbitration, leaving only one-by-one individual claims.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] The same FTC study covering Fios found ISPs sorting customers by race and sexual orientation\nWHAT THE TERMS SAY: The row's own FTC 6(b) cross-reference states the studied ISPs (Verizon among them) combined data across product lines and placed consumers into sensitive categories including by race and sexual orientation, and shared real-time location data with third parties.\nWHY IT MATTERS: This is an industry-wide staff-report finding rather than a Verizon-specific enforcement action, but it applies to Verizon as one of the six studied companies.\n(evidence: Notes; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and the shared-affiliate structure are clearly stated, but the sensitive-category finding rests on an aggregate FTC report, not a Verizon-specific disclosure.", "Exposure Score (0-100)": 42, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Verizon Fios  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Verizon Fios you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:40:24Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Verizon was one of the six ISPs in the FTC's 6(b) study, and it was the only one where the FTC also had to issue orders to TWO affiliated advertising entities - Verizon Online LLC and Oath Americas, rebranded Verizon Media. That is the finding: the ISP and the ad business are the same company, so 'sharing with third parties' understates it. Fios runs on the same shared Verizon privacy policy as Verizon Wireless and 5G Home Internet, meaning your fixed-line browsing, your mobile location and your advertising profile sit under one governing document with no separate consent layer between them. Verizon also owned Yahoo and AOL during this period - see the Email Providers tab for what that ownership chain did to those users.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Internet Providers", "_row_id": 233, "_entity_id": 377, "_entity_slug": "verizon-fios", "_issuer": "Verizon Fios", "_issuer_slug": "verizon-fios", "_ticker": "VZ", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cox Communications", "Category": "ISP", "Terms & Conditions URL": "cox.com/aboutus/policies/customer-service-agreement.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "cox.com/aboutus/policies/annual-privacy-notice.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Standard opt-out of 'sale'/'sharing' of personal info and targeted-advertising cookies via a Manage Privacy Preferences tool (CCPA-style controls, offered nationwide not just to CA residents).", "Arbitration / Class Action Waiver": "Mandatory binding arbitration + class/'Mass Action' waiver (defined broadly to include any coordinated action of 25+ similar arbitration demands, not just formal class actions — a notably aggressive anti-coordination clause); 30-day opt-out via ArbitrationOptOut@cox.com or mail.", "Fees / Billing Flags": "Early termination liability on term contracts equals remaining months' recurring charges (business/fiber tiers); residential ETF terms vary by minimum-term agreement.", "Notes": "MAJOR PENDING CHANGE: Charter Communications (Spectrum) is in the process of ACQUIRING Cox Communications. A Connecticut consumer-protection settlement was already filed (Jan 2026) covering that state's Cox customers transitioning to Charter, including honoring 'price for life' agreements and expanded customer-service commitments. Cox's own terms/entity may not survive this list's shelf life — re-verify before finalizing customer materials, and expect Cox customers nationwide (incl. VA/CA) to eventually transition to Charter/Spectrum terms.\n\nFTC 6(b) STAFF REPORT CROSS-REFERENCE (verified this pass): 'A Look at What ISPs Know About You: Examining the Privacy Practices of Six Major Internet Service Providers,' released Oct 21 2021, approved 4-0. Orders issued in 2019 under FTC Act sec. 6(b) to AT&T, Comcast/Xfinity, Charter, T-Mobile, Verizon and Google Fiber - together ~98% of the mobile internet market - plus three affiliated ad entities (AT&T's Appnexus/Xandr, Verizon Online LLC, Oath Americas/Verizon Media). FINDINGS: ISPs combine data across product lines; combine personal, app-usage and web-browsing data to target ads; place consumers into SENSITIVE CATEGORIES including by race and sexual orientation; share real-time location data with third parties; and while several promise not to 'sell' personal data, they permit it to be used, transferred and monetised by others while burying the disclosures. The report also found many ISPs make the choices they advertise difficult to actually exercise. Data-access requests received ran between ZERO and 380 per month across the six. This is a STAFF REPORT, not an enforcement action - no penalties attach. Treat as one connected finding across every ISP row rather than six separate ones.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Cox's arbitration waiver blocks any coordinated action of 25+ similar claims, not just formal class suits\nWHAT THE TERMS SAY: Cox requires mandatory binding arbitration plus a 'Mass Action' waiver defined broadly to include any coordinated action of 25 or more similar arbitration demands, not just formal class actions — described as a notably aggressive anti-coordination clause, with a 30-day opt-out.\nWHY IT MATTERS: Customers who try to band together through mass arbitration filings, a common workaround to class waivers, can still be blocked by this broader definition.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[AUTO_RENEWAL_FEES · FL-1] Cox's lump-sum ETF equals remaining months' charges only on business/fiber tiers; residential ETF terms vary\nWHAT THE TERMS SAY: Early termination liability on business/fiber term contracts equals the remaining months' recurring charges; residential early-termination-fee terms vary by the specific minimum-term agreement signed.\nWHY IT MATTERS: Ending service early can mean paying for months of a service you're no longer using, in a lump sum.\n(evidence: Fees; Stated in tracker (fidelity pass 1: Overstated corrected))", "Top Troubling #3": "[UNILATERAL_CHANGES · FL-4] Cox customers may be shifted onto Charter/Spectrum's terms via the pending acquisition, not their own\nWHAT THE TERMS SAY: Charter Communications is in the process of acquiring Cox Communications; a Connecticut consumer-protection settlement was already filed covering that state's transitioning customers, and the tracker expects Cox customers nationwide to eventually move to Charter/Spectrum terms.\nWHY IT MATTERS: Customers who agreed to Cox's terms may end up governed by a different company's terms and privacy practices without separately agreeing to them.\n(evidence: Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration and ETF terms are clearly stated, but data-sharing controls are described as standard/table-stakes and Cox's own practices were not among the FTC-studied ISPs.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Cox Communications  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Cox Communications you gave up your right to sue, your right to join a class action, and your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:40:28Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Cox offers the standard opt-out of 'sale' and 'sharing' plus a targeted-advertising control, and the honest assessment is that this is table stakes rather than a distinguishing protection. The FTC's ISP study found the industry-wide problem is not the absence of controls but their design: the disclosures are buried, the mechanics of exercising a choice are difficult enough that almost nobody completes them, and the 'we don't sell your data' framing survives while the data still flows. Cox was not among the six ISPs compelled to produce records in that study, so its practices are undocumented at that level of detail - unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Internet Providers", "_row_id": 234, "_entity_id": 378, "_entity_slug": "cox-communications", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Charter Spectrum", "Category": "ISP", "Terms & Conditions URL": "spectrum.com (Residential Terms of Service; Enterprise version reviewed this pass: enterprise.spectrum.com/.../230120-Enterprise-Service-Agreement-for-the-Web.pdf)", "T&C Direct PDF?": "NOT CONFIRMED for residential (enterprise version is a direct PDF; residential version not individually located this pass)", "Privacy Policy URL": "spectrum.com privacy policy (not individually located this pass — verify directly)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed for residential this pass; enterprise version references CPNI/personally identifiable information handling per Cable Communications Act + Electronic Communications Privacy Act. MAJOR NEW BREACH (April 2026, disclosed May 27, 2026): the ShinyHunters group used a VOICE PHISHING (vishing) attack to obtain a Charter employee's Microsoft Entra (Azure Active Directory) credentials, then pivoted into Charter's SALESFORCE CRM environment — the same underlying attack pattern documented across dozens of other companies throughout this entire tracker. ShinyHunters claimed to have exfiltrated 40-42 MILLION RECORDS; independent analysis confirmed information tied to at least 13 million individuals plus ~27,000 employee records. When Charter refused to pay the ransom, ShinyHunters published portions of the stolen data on its dark-web leak site. AT LEAST FOUR separate class actions were filed in Connecticut federal court within weeks (Kent v. Charter Communications and others), alleging Charter failed to maintain reasonable cybersecurity, including inadequate employee training against exactly this kind of social-engineering attack — exposed data reportedly included names, emails, physical addresses, phone numbers, account/plan information, and customer-support ticket details.", "Arbitration / Class Action Waiver": "Mandatory arbitration under FAA; excludes disputes over unauthorized use/receipt of service and IP validity disputes from arbitration (those go to court); notably, injunctive relief cannot be awarded by the arbitrator at all (must be sought in court separately) per the enterprise agreement — verify if the residential agreement mirrors this.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Currently ACQUIRING Cox Communications (see above) — Spectrum's own footprint and terms are about to expand significantly across multiple states in this list. Serves CA, TX, NY, FL directly today.\n\nFTC 6(b) STAFF REPORT CROSS-REFERENCE (verified this pass): 'A Look at What ISPs Know About You: Examining the Privacy Practices of Six Major Internet Service Providers,' released Oct 21 2021, approved 4-0. Orders issued in 2019 under FTC Act sec. 6(b) to AT&T, Comcast/Xfinity, Charter, T-Mobile, Verizon and Google Fiber - together ~98% of the mobile internet market - plus three affiliated ad entities (AT&T's Appnexus/Xandr, Verizon Online LLC, Oath Americas/Verizon Media). FINDINGS: ISPs combine data across product lines; combine personal, app-usage and web-browsing data to target ads; place consumers into SENSITIVE CATEGORIES including by race and sexual orientation; share real-time location data with third parties; and while several promise not to 'sell' personal data, they permit it to be used, transferred and monetised by others while burying the disclosures. The report also found many ISPs make the choices they advertise difficult to actually exercise. Data-access requests received ran between ZERO and 380 per month across the six. This is a STAFF REPORT, not an enforcement action - no penalties attach. Treat as one connected finding across every ISP row rather than six separate ones.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] A vishing attack on one Charter employee's login led to a Salesforce breach affecting millions\nWHAT THE TERMS SAY: ShinyHunters used a voice-phishing (vishing) attack to obtain a Charter employee's Microsoft Entra (Azure Active Directory) credentials, then pivoted into Charter's Salesforce CRM environment. The group claimed to have exfiltrated 40-42 million records; independent analysis confirmed information tied to at least 13 million individuals plus ~27,000 employee records. The class actions allege exposed data reportedly included names, emails, physical addresses, phone numbers, account/plan information, and customer-support ticket details.\nWHY IT MATTERS: When Charter refused to pay the ransom, ShinyHunters published portions of the stolen data on its dark-web leak site.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] At least four class actions accuse Charter of inadequate training against the exact attack used on it\nWHAT THE TERMS SAY: At least four separate class actions were filed in Connecticut federal court within weeks of the breach disclosure (including Kent v. Charter Communications), alleging Charter failed to maintain reasonable cybersecurity, including inadequate employee training against social-engineering attacks like the one used.\nWHY IT MATTERS: These are allegations in pending litigation, not adjudicated findings, but they directly target Charter's security practices around the breach.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Charter's arbitrator reportedly cannot order an injunction — you'd need to go to court separately for that\nWHAT THE TERMS SAY: Mandatory arbitration applies under the FAA, with disputes over unauthorized use/receipt of service and IP validity carved out to court; per the enterprise agreement, the arbitrator cannot award injunctive relief at all, and it is unverified whether the residential agreement mirrors this.\nWHY IT MATTERS: If confirmed for residential customers too, this would mean arbitration can't force Charter to stop a practice — only a separate court filing could.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach and resulting lawsuits are documented in concrete detail, but whether residential arbitration mirrors the enterprise agreement's injunctive-relief limit is unverified.", "Exposure Score (0-100)": 31, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Charter Spectrum  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Charter Spectrum you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Charter was one of the six ISPs compelled to produce records under the FTC's 6(b) orders, so its residential practices were examined at a level of detail the company never disclosed voluntarily - and the report's findings on placing customers into sensitive categories, including by race and sexual orientation, and sharing real-time location data with third parties, apply to the studied group. The report did not name which ISP did what, which is itself worth noting: the FTC obfuscated attribution to preserve participant anonymity, so consumers got the aggregate finding without the ability to act on it by switching providers.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Internet Providers", "_row_id": 235, "_entity_id": 379, "_entity_slug": "charter-spectrum", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "AT&T Internet / AT&T Fiber", "Category": "ISP", "Terms & Conditions URL": "att.com/legal/terms.internetAttTermsOfService", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "about.att.com/privacy/privacy-notice.html (shared AT&T privacy notice)", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same shared AT&T Privacy Notice as AT&T wireless (see Carriers tab); this Internet ToS separately governs how AT&T handles Account and location information for internet service specifically.", "Arbitration / Class Action Waiver": "Binding arbitration + class action/jury trial waiver, same structure as AT&T wireless; liability is capped at a refund of what you paid AT&T for the affected service during the issue period, up to a 24-month maximum — a fairly low liability ceiling worth flagging.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Serves CA, TX, FL directly from this list; AT&T Fiber has been expanding aggressively (ACSI's top-rated fiber ISP per 2026 rankings cited in research).\n\nFTC 6(b) STAFF REPORT CROSS-REFERENCE (verified this pass): 'A Look at What ISPs Know About You: Examining the Privacy Practices of Six Major Internet Service Providers,' released Oct 21 2021, approved 4-0. Orders issued in 2019 under FTC Act sec. 6(b) to AT&T, Comcast/Xfinity, Charter, T-Mobile, Verizon and Google Fiber - together ~98% of the mobile internet market - plus three affiliated ad entities (AT&T's Appnexus/Xandr, Verizon Online LLC, Oath Americas/Verizon Media). FINDINGS: ISPs combine data across product lines; combine personal, app-usage and web-browsing data to target ads; place consumers into SENSITIVE CATEGORIES including by race and sexual orientation; share real-time location data with third parties; and while several promise not to 'sell' personal data, they permit it to be used, transferred and monetised by others while burying the disclosures. The report also found many ISPs make the choices they advertise difficult to actually exercise. Data-access requests received ran between ZERO and 380 per month across the six. This is a STAFF REPORT, not an enforcement action - no penalties attach. Treat as one connected finding across every ISP row rather than six separate ones.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "AT&T Chief Privacy Office, 208 S. Akard St., Room 2901, Dallas, TX 75202, USA (AT&T also operates a Data Request Center and a Global Legal Demand Center for law-enforcement demands)", "Legal / Privacy Contact Email": "privacypolicy@att.com", "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[LIABILITY_CAP_INDEMNITY · FL-1] AT&T caps its own liability at a refund of up to 24 months of what you paid, no matter the harm\nWHAT THE TERMS SAY: AT&T Internet/Fiber's liability is capped at a refund of what the customer paid for the affected service during the issue period, up to a 24-month maximum — described in the tracker as a fairly low liability ceiling.\nWHY IT MATTERS: Whatever the scale of a service failure or resulting harm, a customer's maximum recovery from AT&T is limited to a portion of their own past payments.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] AT&T Internet uses the same binding arbitration, class waiver, and jury waiver as AT&T wireless\nWHAT THE TERMS SAY: Binding arbitration plus a class-action/jury-trial waiver applies to AT&T Internet/Fiber, using the same structure documented for AT&T wireless service.\nWHY IT MATTERS: Consumers lose access to both a jury trial and collective legal action over internet-service disputes, mirroring restrictions already in place for AT&T's phone customers.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] AT&T's ad-tech partner built partly on subscriber data was sold to Microsoft, with no subscriber notice\nWHAT THE TERMS SAY: AT&T Internet and Fiber run under the same AT&T Privacy Notice as wireless, with no separate fixed-line consent regime; AT&T's affiliated ad-tech arm Appnexus (rebranded Xandr) received its own FTC compulsory order and was later sold to Microsoft.\nWHY IT MATTERS: Advertising infrastructure built partly around AT&T subscriber data changed corporate hands entirely, in a transfer no subscriber consented to or was notified of at the time.\n(evidence: SCARY | Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration and the liability cap are clearly stated, but fees are not itemized this pass.", "Exposure Score (0-100)": 47, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 30, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 30/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "AT&T Internet / AT&T Fiber  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to a jury.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using AT&T Internet / AT&T Fiber you gave up your data shared corporate-wide, your right to sue, your right to join a class action, your right to a jury, and your right to meaningful compensation. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:41:02Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "AT&T was one of six ISPs studied by the FTC, and the only one whose affiliated ad-tech arm - Appnexus, rebranded Xandr - was significant enough to receive its own compulsory order. Xandr was subsequently sold to Microsoft, which means the advertising infrastructure built partly around AT&T subscriber data changed corporate hands entirely, a transfer no subscriber consented to or was notified of at the time. AT&T Internet and Fiber run under the same AT&T Privacy Notice as wireless, so there is no separate fixed-line consent regime. AT&T's much larger 2024 breach exposures are recorded in the Carriers tab - cross-reference rather than duplicate.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Internet Providers", "_row_id": 236, "_entity_id": 380, "_entity_slug": "at-t-internet-at-t-fiber", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Frontier Communications", "Category": "ISP", "Terms & Conditions URL": "frontier.com/documents/corporate/terms/residential-internet-service-may-2025.pdf", "T&C Direct PDF?": "YES", "Privacy Policy URL": "frontier.com/corporate/policies (privacy policy linked from Policies page)", "Privacy Direct PDF?": "NOT CONFIRMED (HTML index page; direct privacy PDF not located this pass)", "Data Sharing/Selling Flags": "Not independently confirmed this pass.", "Arbitration / Class Action Waiver": "Mandatory arbitration explicitly bars consolidating multiple customers' claims 'absent Frontier's written agreement' even in mass-arbitration scenarios; Frontier proactively updated arbitration terms in July 2022 specifically to change 'pre-arbitration notices and the process for commencing arbitration claims' — i.e., made the path to arbitration itself more procedurally complex, with a 30-day opt-out window tied to that specific update.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "CRITICAL FOR THIS LIST: Frontier acquired VERIZON'S LANDLINE/FIOS INTERNET OPERATIONS in California, Florida, and Texas years ago. Anyone in those 3 states with 'Fios-branded' service from that legacy footprint is actually a Frontier customer under Frontier's terms, not Verizon's — a common point of customer confusion worth calling out explicitly in any customer-facing material.\n\nFTC 6(b) STAFF REPORT CROSS-REFERENCE (verified this pass): 'A Look at What ISPs Know About You: Examining the Privacy Practices of Six Major Internet Service Providers,' released Oct 21 2021, approved 4-0. Orders issued in 2019 under FTC Act sec. 6(b) to AT&T, Comcast/Xfinity, Charter, T-Mobile, Verizon and Google Fiber - together ~98% of the mobile internet market - plus three affiliated ad entities (AT&T's Appnexus/Xandr, Verizon Online LLC, Oath Americas/Verizon Media). FINDINGS: ISPs combine data across product lines; combine personal, app-usage and web-browsing data to target ads; place consumers into SENSITIVE CATEGORIES including by race and sexual orientation; share real-time location data with third parties; and while several promise not to 'sell' personal data, they permit it to be used, transferred and monetised by others while burying the disclosures. The report also found many ISPs make the choices they advertise difficult to actually exercise. Data-access requests received ran between ZERO and 380 per month across the six. This is a STAFF REPORT, not an enforcement action - no penalties attach. Treat as one connected finding across every ISP row rather than six separate ones.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Frontier bars combining multiple customers' arbitration claims unless Frontier itself agrees\nWHAT THE TERMS SAY: Frontier's mandatory arbitration explicitly bars consolidating multiple customers' claims 'absent Frontier's written agreement,' even in mass-arbitration scenarios; Frontier proactively updated its arbitration terms in July 2022 to change the pre-arbitration notice and filing process, making the path to arbitration itself more procedurally complex, with a 30-day opt-out tied to that update.\nWHY IT MATTERS: This blocks a common workaround consumers use against class waivers — filing many individual arbitrations together — unless Frontier itself consents.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] In many Frontier territories there's no other wireline option, so its terms are effectively compulsory\nWHAT THE TERMS SAY: The tracker notes Frontier frequently serves large rural footprints where it is the only wireline provider available, meaning consumer protections premised on the ability to switch providers — opt-outs, competitive pressure, reputational cost — don't function.\nWHY IT MATTERS: A customer who dislikes Frontier's terms may have no alternative provider to switch to, leaving state regulation as the only remaining leverage.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data Sharing/Selling Flags is 'not independently confirmed' and Fees/Billing Flags is 'not itemized this pass'; only the mass-arbitration bar and the no-alternative-provider structure are substantive enough for distinct findings.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration procedure is clearly described, but data sharing and fees are both unconfirmed this pass.", "Exposure Score (0-100)": 23, "Exposure Band": "Low", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Frontier Communications  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Frontier Communications you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "2026-09-08T19:41:04Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Frontier's row was thin on prior passes, and the finding worth recording is jurisdictional rather than sensational: Frontier serves large rural footprints where it is frequently the ONLY wireline provider available, which makes its privacy terms non-negotiable in a way urban customers' are not. Every meaningful consumer protection in this space assumes a functioning ability to switch providers - opt-outs, competitive pressure, reputational cost. Where a household has one option, the terms are effectively compulsory and the only remaining leverage is state regulation. Recommend a follow-up on Frontier's 2024-26 breach notifications filed with state attorneys general.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Internet Providers", "_row_id": 237, "_entity_id": 381, "_entity_slug": "frontier-communications", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Optimum (Altice USA)", "Category": "ISP", "Terms & Conditions URL": "optimum.com/terms-of-service/residential/internet", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "optimum.net (Customer Privacy Notice referenced/incorporated by the Terms of Service, not independently located as a direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass.", "Arbitration / Class Action Waiver": "Binding arbitration + class action waiver, 30-day opt-out. ACTIVE, CONCRETE CUSTOMER ISSUE: a law firm (Milberg) is currently pursuing MASS ARBITRATION claims on behalf of over a million tristate-area Optimum subscribers who kept being billed for premium sports programming (MSG Networks) after Altice and MSG's carriage agreement expired and the channels went dark — a live, ongoing example of exactly the kind of billing/arbitration issue this audit is meant to catch.", "Fees / Billing Flags": "Same MSG Networks blackout above is a direct billing-fairness issue: customers allegedly charged for content they could no longer access, with no automatic rebate offered.", "Notes": "Optimum is the primary Altice-owned ISP brand in the NY market for this list; the live MSG Networks arbitration situation is worth flagging prominently to any NY-based customers.\n\nFTC 6(b) STAFF REPORT CROSS-REFERENCE (verified this pass): 'A Look at What ISPs Know About You: Examining the Privacy Practices of Six Major Internet Service Providers,' released Oct 21 2021, approved 4-0. Orders issued in 2019 under FTC Act sec. 6(b) to AT&T, Comcast/Xfinity, Charter, T-Mobile, Verizon and Google Fiber - together ~98% of the mobile internet market - plus three affiliated ad entities (AT&T's Appnexus/Xandr, Verizon Online LLC, Oath Americas/Verizon Media). FINDINGS: ISPs combine data across product lines; combine personal, app-usage and web-browsing data to target ads; place consumers into SENSITIVE CATEGORIES including by race and sexual orientation; share real-time location data with third parties; and while several promise not to 'sell' personal data, they permit it to be used, transferred and monetised by others while burying the disclosures. The report also found many ISPs make the choices they advertise difficult to actually exercise. Data-access requests received ran between ZERO and 380 per month across the six. This is a STAFF REPORT, not an enforcement action - no penalties attach. Treat as one connected finding across every ISP row rather than six separate ones.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] Over a million Optimum subscribers were allegedly billed for sports channels that had gone dark\nWHAT THE TERMS SAY: After Altice and MSG Networks' carriage agreement expired and the channels went dark, customers were allegedly charged for premium sports programming they could no longer access, with no automatic rebate offered.\nWHY IT MATTERS: Consumers can be billed for content they lost access to through a carriage dispute they had no part in, without the charge being automatically corrected.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] A law firm is pursuing mass arbitration for over a million Optimum subscribers over the MSG billing\nWHAT THE TERMS SAY: A law firm (Milberg) is currently pursuing mass arbitration claims on behalf of over a million tristate-area Optimum subscribers over being billed for the blacked-out MSG Networks programming, alongside Optimum's standard binding-arbitration-plus-class-waiver structure with a 30-day opt-out.\nWHY IT MATTERS: This is a live, ongoing claim rather than a resolved case, and it shows customers are relying on mass arbitration, not court, to seek relief.\n(evidence: Arbitration | Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-2] Only a VPN or encrypted DNS limits what Optimum, as a cable ISP, sees of your devices and destinations\nWHAT THE TERMS SAY: The tracker notes cable ISPs like Optimum sit at a data-collection vantage point different from a website: they see every destination, every device on the home network, and the timing of all of it, unaffected by private browsing, password managers, or ad blockers — only a VPN or encrypted DNS changes that visibility.\nWHY IT MATTERS: Standard privacy tools consumers rely on for individual sites do nothing to limit what their ISP itself can observe about their household's internet use.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The MSG billing/arbitration situation is concretely documented, but Optimum's own data-sharing practices are unconfirmed this pass.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Optimum (Altice USA)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Optimum (Altice USA) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:41:05Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Nothing independently confirmed for Optimum this pass. The structural note that matters: Altice USA operates Optimum as a regional cable incumbent, and cable ISPs sit at a data-collection vantage point that is qualitatively different from a website's - they see every destination, every device on the home network, and the timing of all of it, regardless of which sites have their own privacy policies. Using a private browsing window, a password manager or an ad blocker changes nothing about what the ISP observes. Only a VPN or encrypted DNS moves that boundary, and neither is a default. Recorded as unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Internet Providers", "_row_id": 238, "_entity_id": 382, "_entity_slug": "optimum-altice-usa", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CenturyLink / Quantum Fiber / Brightspeed", "Category": "ISP", "Terms & Conditions URL": "brightspeed.com/content/dam/brightspeed/images/legal/BSPD_LEGAL_High-speed_internet_subscriber_service-agreement_071322.pdf", "T&C Direct PDF?": "YES", "Privacy Policy URL": "brightspeed.com / centurylink.com (privacy policy not individually located this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass.", "Arbitration / Class Action Waiver": "Subscriber Agreement explicitly reserves the right for the company to unilaterally change 'the Dispute Resolution and Arbitration; Governing Law provision' itself — i.e., the arbitration clause can be amended by the company at will, subject to standard notice; verify current opt-out mechanism directly.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "CRITICAL OWNERSHIP CHAIN: Lumen Technologies (parent of CenturyLink and its fiber brand Quantum Fiber) sold large parts of its network to private equity firm Apollo Global Management in 2022, which used it to create Brightspeed — now the 12th-largest US ISP. If you were a CenturyLink or Quantum Fiber customer in an affected area, you became a Brightspeed customer automatically on Oct 3, 2022, under Brightspeed's terms, not CenturyLink's. Determine which brand actually serves each customer before citing 'CenturyLink' terms.\n\nFTC 6(b) STAFF REPORT CROSS-REFERENCE (verified this pass): 'A Look at What ISPs Know About You: Examining the Privacy Practices of Six Major Internet Service Providers,' released Oct 21 2021, approved 4-0. Orders issued in 2019 under FTC Act sec. 6(b) to AT&T, Comcast/Xfinity, Charter, T-Mobile, Verizon and Google Fiber - together ~98% of the mobile internet market - plus three affiliated ad entities (AT&T's Appnexus/Xandr, Verizon Online LLC, Oath Americas/Verizon Media). FINDINGS: ISPs combine data across product lines; combine personal, app-usage and web-browsing data to target ads; place consumers into SENSITIVE CATEGORIES including by race and sexual orientation; share real-time location data with third parties; and while several promise not to 'sell' personal data, they permit it to be used, transferred and monetised by others while burying the disclosures. The report also found many ISPs make the choices they advertise difficult to actually exercise. Data-access requests received ran between ZERO and 380 per month across the six. This is a STAFF REPORT, not an enforcement action - no penalties attach. Treat as one connected finding across every ISP row rather than six separate ones.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[UNILATERAL_CHANGES · FL-3] The company can amend its own arbitration and governing-law clause at will, with just standard notice\nWHAT THE TERMS SAY: The Subscriber Agreement explicitly reserves the right for the company to unilaterally change 'the Dispute Resolution and Arbitration; Governing Law provision' itself, subject to standard notice.\nWHY IT MATTERS: The rules governing how disputes get resolved are not fixed at signup — the company can rewrite them later, and the current opt-out mechanism needs direct verification.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] Customers were shifted from CenturyLink to a private-equity-owned Brightspeed automatically, with new terms\nWHAT THE TERMS SAY: Lumen Technologies sold large parts of its network to Apollo Global Management in 2022 to create Brightspeed, the 12th-largest US ISP; customers in affected areas became Brightspeed customers automatically on Oct 3, 2022, under Brightspeed's terms rather than CenturyLink's.\nWHY IT MATTERS: A customer's records and governing agreement moved to a new corporate owner, with a new privacy policy and security posture, without the customer being asked again.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data Sharing/Selling Flags is 'not independently confirmed' and Fees/Billing Flags is 'not itemized this pass'; only the self-amendable arbitration clause and the ownership-transfer-without-new-consent pattern are substantive enough for findings.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing and fees are both unconfirmed this pass, and the brand has been split and sold between corporate parents, making current terms hard to pin down.", "Exposure Score (0-100)": 21, "Exposure Band": "Low", "Sub: Dispute Rights /30": 14, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 14/30 (forced_arbitration+12, optout_window_unverified+2) | Data 0/30 (none) | Contract 5/20 (unilateral_modification+5) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "CenturyLink / Quantum Fiber / Brightspeed  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using CenturyLink / Quantum Fiber / Brightspeed you gave up your right to sue and your right to be consulted before terms change. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "2026-09-08T19:41:07Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass, and the brand fragmentation is itself the finding: CenturyLink, Quantum Fiber and Brightspeed represent a copper-and-fiber footprint that has been split, rebranded and sold between corporate parents, with Brightspeed carved out to a private-equity buyer. Each transfer moves subscriber records into a new entity with a new privacy policy and a new security posture, and the customer's consent travels with the asset without ever being asked again. For a consumer trying to determine who currently holds their billing and usage history, the honest answer may require reading three companies' policies.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Internet Providers", "_row_id": 239, "_entity_id": 383, "_entity_slug": "centurylink-quantum-fiber-brightspeed", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Astound Broadband (fmr. RCN)", "Category": "ISP", "Terms & Conditions URL": "astound.com/policies-disclaimers/internet-access-agreement/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "astound.com/policies-disclaimers/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Standard 'business records' retention framing; explicit California Notice at Collection carve-out suggests CCPA-driven disclosures layered onto an otherwise generic privacy policy.", "Arbitration / Class Action Waiver": "Binding arbitration (Section 14 of Internet Access Agreement / Section 27 of general Customer Terms) under FAA; broadly defined 'Dispute' explicitly includes challenges to the arbitration clause's own validity — i.e., even arguing the arbitration clause is unenforceable must itself go through arbitration in the first instance, a fairly aggressive/self-reinforcing structure.", "Fees / Billing Flags": "$14.99 one-time activation fee; 30-day money-back guarantee capped at one month's recurring fee (equipment/usage-based fees excluded from refund).", "Notes": "RCN rebranded to 'Astound Broadband' (parent: Radiate HoldCo, LLC); directly serves the DC metro area and several Texas cities (Austin, Dallas, Houston, San Antonio, etc.) among others on this list — relevant to both the DMV and TX portions of your request.\n\nFTC 6(b) STAFF REPORT CROSS-REFERENCE (verified this pass): 'A Look at What ISPs Know About You: Examining the Privacy Practices of Six Major Internet Service Providers,' released Oct 21 2021, approved 4-0. Orders issued in 2019 under FTC Act sec. 6(b) to AT&T, Comcast/Xfinity, Charter, T-Mobile, Verizon and Google Fiber - together ~98% of the mobile internet market - plus three affiliated ad entities (AT&T's Appnexus/Xandr, Verizon Online LLC, Oath Americas/Verizon Media). FINDINGS: ISPs combine data across product lines; combine personal, app-usage and web-browsing data to target ads; place consumers into SENSITIVE CATEGORIES including by race and sexual orientation; share real-time location data with third parties; and while several promise not to 'sell' personal data, they permit it to be used, transferred and monetised by others while burying the disclosures. The report also found many ISPs make the choices they advertise difficult to actually exercise. Data-access requests received ran between ZERO and 380 per month across the six. This is a STAFF REPORT, not an enforcement action - no penalties attach. Treat as one connected finding across every ISP row rather than six separate ones.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Astound requires arbitration even to argue that its own arbitration clause is unenforceable\nWHAT THE TERMS SAY: Astound's binding arbitration under the FAA uses a broadly defined 'Dispute' that explicitly includes challenges to the arbitration clause's own validity — meaning even arguing the clause is unenforceable must itself first go through arbitration, described in the tracker as a fairly aggressive, self-reinforcing structure.\nWHY IT MATTERS: A customer who believes the arbitration requirement itself is illegal or invalid cannot simply go to court to argue that — they must raise it inside arbitration first.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[AUTO_RENEWAL_FEES · FL-1] Astound's money-back guarantee caps refunds at one month and excludes equipment and usage fees\nWHAT THE TERMS SAY: Astound charges a $14.99 one-time activation fee, and its 30-day money-back guarantee is capped at one month's recurring fee, with equipment and usage-based fees excluded from the refund.\nWHY IT MATTERS: A customer who cancels within the guarantee window may still be out the activation fee and any equipment/usage charges, despite the 'money-back' framing.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-2] Astound's detailed privacy disclosure exists mainly because California requires it, not because of you\nWHAT THE TERMS SAY: Astound provides standard 'business records' retention framing plus an explicit California Notice at Collection, which the tracker frames as illustrating how one state's law becomes a de facto national floor since it's cheaper to publish one notice than two.\nWHY IT MATTERS: A customer's actual privacy disclosures may depend more on which state legislature has acted than on anything specific they agreed to.\n(evidence: SCARY | Data Sharing; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration and fee structures are clearly stated, but broader data-sharing practices rely on generic retention language plus a state-mandated notice.", "Exposure Score (0-100)": 23, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Astound Broadband (fmr. RCN)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Astound Broadband (fmr. RCN) you gave up your right to sue and your right to stop paying by inaction. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "2026-09-08T19:41:10Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Astound uses standard 'business records' retention framing and provides an explicit California Notice at Collection - the latter being the more interesting detail, because it illustrates how a single state's law becomes the de facto national floor. California residents get an enumerated disclosure of what is collected and why; residents of states without comparable statutes see the same notice only because it is cheaper to publish one document than two. Your privacy rights from this provider are largely determined by which state legislature has acted, not by anything you agreed to.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Internet Providers", "_row_id": 240, "_entity_id": 384, "_entity_slug": "astound-broadband-fmr-rcn", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google Fiber (GFiber)", "Category": "ISP", "Terms & Conditions URL": "gfiber.com/legal/terms/residential/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "gfiber.com (privacy policy not individually located this pass — note this is a separate entity from Google/Alphabet's main privacy policy)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass; note Google Fiber Inc. is legally distinct from Google LLC generally, so its privacy practices are not automatically covered by the main Google Privacy Policy a customer may already be familiar with.", "Arbitration / Class Action Waiver": "Binding arbitration via AAA Consumer Arbitration Rules; notably broad scope explicitly includes claims for 'mental or emotional distress' arising from the relationship, and claims that arose before the customer even accepted the terms (e.g., disputes over how the service was marketed) — an unusually wide net compared to peers.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Limited but growing footprint in TX (Austin) and parts of CA on this 7-state list; consistently rated #1 for customer satisfaction among ISPs (J.D. Power 2025) and lowest latency, so it's a rare 'positive contrast' provider worth having in a customer education context alongside the complaint-prone larger ISPs.\n\nFTC 6(b) STAFF REPORT CROSS-REFERENCE (verified this pass): 'A Look at What ISPs Know About You: Examining the Privacy Practices of Six Major Internet Service Providers,' released Oct 21 2021, approved 4-0. Orders issued in 2019 under FTC Act sec. 6(b) to AT&T, Comcast/Xfinity, Charter, T-Mobile, Verizon and Google Fiber - together ~98% of the mobile internet market - plus three affiliated ad entities (AT&T's Appnexus/Xandr, Verizon Online LLC, Oath Americas/Verizon Media). FINDINGS: ISPs combine data across product lines; combine personal, app-usage and web-browsing data to target ads; place consumers into SENSITIVE CATEGORIES including by race and sexual orientation; share real-time location data with third parties; and while several promise not to 'sell' personal data, they permit it to be used, transferred and monetised by others while burying the disclosures. The report also found many ISPs make the choices they advertise difficult to actually exercise. Data-access requests received ran between ZERO and 380 per month across the six. This is a STAFF REPORT, not an enforcement action - no penalties attach. Treat as one connected finding across every ISP row rather than six separate ones.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Google Fiber's arbitration clause reaches 'emotional distress' claims and disputes from before you signed\nWHAT THE TERMS SAY: Binding arbitration via AAA Consumer Arbitration Rules has a notably broad scope that explicitly includes claims for 'mental or emotional distress' arising from the relationship, and claims that arose before the customer even accepted the terms, such as disputes over how the service was marketed — described as an unusually wide net compared to peers.\nWHY IT MATTERS: The arbitration requirement can capture disputes over how the service was advertised to a customer before they ever signed up, not just post-signup issues.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Whether 'Google Fiber Inc.' is really separate from Google LLC's data trove can't be verified from outside\nWHAT THE TERMS SAY: Google Fiber Inc. is legally distinct from Google LLC, so its privacy practices are not automatically covered by the main Google Privacy Policy a customer may already know; the tracker notes this legal separation is exactly what a consumer cannot verify from the outside.\nWHY IT MATTERS: Google already holds search, browsing, location, email, and video history for most users, and Fiber adds the network layer beneath all of it, with the corporate separation's practical effect unclear.\n(evidence: SCARY | Data Sharing; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] Google Fiber was one of six ISPs the FTC found sorting customers into categories like race and orientation\nWHAT THE TERMS SAY: The row's FTC 6(b) cross-reference states the studied ISPs, including Google Fiber, combined data across product lines and placed consumers into sensitive categories including by race and sexual orientation, and shared real-time location data with third parties.\nWHY IT MATTERS: This is an aggregate industry-level finding from a staff report, not a Google Fiber-specific enforcement action, but it applies to Google Fiber as one of the six studied companies.\n(evidence: Notes; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration scope is clearly stated, but data-sharing practices and the effect of the Google LLC/Google Fiber Inc. separation are unconfirmed this pass.", "Exposure Score (0-100)": 29, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Google Fiber (GFiber)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Google Fiber (GFiber) you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "2026-09-08T19:41:11Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Google Fiber was one of the six ISPs subject to the FTC's compulsory 6(b) orders. The specific hazard here is combination: Google already holds search, browsing, location, email and video history for most of its users, and Google Fiber adds the network layer underneath all of it. Google Fiber Inc. is legally a distinct entity from Google LLC, and that distinction is exactly the thing a consumer cannot verify from the outside - whether the corporate separation constrains data flow in practice, or only on the organisational chart. CROSS-REF: the Google/Alphabet and Google Gemini rows elsewhere in this tracker.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Internet Providers", "_row_id": 241, "_entity_id": 385, "_entity_slug": "google-fiber-gfiber", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "T-Mobile Home Internet", "Category": "ISP (fixed wireless)", "Terms & Conditions URL": "Same governing document as T-Mobile wireless — see Carriers tab (t-mobile.com/responsibility/legal/terms-and-conditions)", "T&C Direct PDF?": "NO (HTML only, per Carriers tab)", "Privacy Policy URL": "Same as T-Mobile wireless — t-mobile.com/privacy-center/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "No separate privacy framework identified from wireless service — same policy applies.", "Arbitration / Class Action Waiver": "Same binding arbitration + broad privacy/data-security dispute scope documented in the Carriers tab for T-Mobile wireless applies here as well, since Home Internet is billed under the same customer agreement.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Nationwide fixed-wireless offering; increasingly common alternative to wired ISPs in all 7 states, especially suburban/rural pockets of TX, CA, and FL. Governed by the SAME T&Cs already documented for T-Mobile wireless — no separate research needed, just confirm the customer is aware it's one contract.\n\nFTC 6(b) STAFF REPORT CROSS-REFERENCE (verified this pass): 'A Look at What ISPs Know About You: Examining the Privacy Practices of Six Major Internet Service Providers,' released Oct 21 2021, approved 4-0. Orders issued in 2019 under FTC Act sec. 6(b) to AT&T, Comcast/Xfinity, Charter, T-Mobile, Verizon and Google Fiber - together ~98% of the mobile internet market - plus three affiliated ad entities (AT&T's Appnexus/Xandr, Verizon Online LLC, Oath Americas/Verizon Media). FINDINGS: ISPs combine data across product lines; combine personal, app-usage and web-browsing data to target ads; place consumers into SENSITIVE CATEGORIES including by race and sexual orientation; share real-time location data with third parties; and while several promise not to 'sell' personal data, they permit it to be used, transferred and monetised by others while burying the disclosures. The report also found many ISPs make the choices they advertise difficult to actually exercise. Data-access requests received ran between ZERO and 380 per month across the six. This is a STAFF REPORT, not an enforcement action - no penalties attach. Treat as one connected finding across every ISP row rather than six separate ones.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "T-Mobile USA, Inc., Attn: Chief Privacy Officer, 12920 SE 38th Street, Bellevue, WA 98006, USA", "Legal / Privacy Contact Email": "privacy@t-mobile.com (privacy line 1-877-937-8997)", "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] T-Mobile Home Internet inherits the same broad privacy/data-security arbitration scope as wireless\nWHAT THE TERMS SAY: T-Mobile Home Internet is billed under the same customer agreement as T-Mobile wireless, so the same binding arbitration and broad privacy/data-security dispute scope documented for wireless applies here too.\nWHY IT MATTERS: A dispute over how T-Mobile handles home-internet account data can be swept into the same mandatory arbitration terms as a wireless dispute.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[LOCATION_TRACKING · FL-2] A 'home internet' product is contractually a mobile product, with mobile-style location data collection\nWHAT THE TERMS SAY: Home Internet has no separate privacy framework — the wireless policy governs it entirely — which the tracker notes means a service marketed as a home broadband replacement is contractually a mobile product, and mobile carriers collect and monetize real-time location data in ways fixed-line providers historically did not.\nWHY IT MATTERS: A household that signs up expecting a wired-style internet product may not realize it is contractually subject to mobile-style location data practices.\n(evidence: SCARY | Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] There's no separate privacy policy or product boundary between T-Mobile's home internet and wireless data\nWHAT THE TERMS SAY: No separate privacy framework was identified for Home Internet from wireless service — the same policy applies, with the tracker noting no separate research was needed since it is one contract.\nWHY IT MATTERS: Data from a household's fixed home-internet usage sits under the exact same governing document as their mobile usage, with no boundary between the two.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The row is clear that Home Internet has no separate privacy or arbitration framework, but fees are not itemized this pass.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "T-Mobile Home Internet  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using T-Mobile Home Internet you gave up your physical movements and your right to sue. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "T-Mobile was one of the six ISPs compelled to produce records in the FTC's study, and Home Internet has no separate privacy framework - the wireless policy governs it entirely. That means a service marketed as a home broadband replacement is contractually a mobile product, which matters because mobile carriers collect and monetise real-time location data in ways fixed-line providers historically did not. T-Mobile's extensive breach history is recorded in the Carriers tab; the relevant point here is that signing up for home internet placed the household inside that same policy and that same incident history.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Internet Providers", "_row_id": 242, "_entity_id": 386, "_entity_slug": "t-mobile-home-internet", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Verizon 5G Home Internet / LTE Home Internet", "Category": "ISP (fixed wireless)", "Terms & Conditions URL": "Same governing document as Verizon wireless/Fios — see Carriers tab and Fios row above", "T&C Direct PDF?": "See Fios row (companion Internet ToS is a direct PDF)", "Privacy Policy URL": "Same as Verizon wireless — verizon.com/about/privacy/full-privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same shared Verizon privacy policy as wireless and Fios — no separate framework.", "Arbitration / Class Action Waiver": "Same binding arbitration + class action waiver documented for Verizon wireless/Fios applies.", "Fees / Billing Flags": "$15/mo mobile+home bundle discount when paired with a Verizon postpaid mobile plan; multi-year price guarantees advertised (3–5 years depending on plan) contingent on autopay + paperless billing enrollment.", "Notes": "Available nationwide including areas without Fios fiber; same underlying customer agreement as Verizon wireless — no separate research needed.\n\nFTC 6(b) STAFF REPORT CROSS-REFERENCE (verified this pass): 'A Look at What ISPs Know About You: Examining the Privacy Practices of Six Major Internet Service Providers,' released Oct 21 2021, approved 4-0. Orders issued in 2019 under FTC Act sec. 6(b) to AT&T, Comcast/Xfinity, Charter, T-Mobile, Verizon and Google Fiber - together ~98% of the mobile internet market - plus three affiliated ad entities (AT&T's Appnexus/Xandr, Verizon Online LLC, Oath Americas/Verizon Media). FINDINGS: ISPs combine data across product lines; combine personal, app-usage and web-browsing data to target ads; place consumers into SENSITIVE CATEGORIES including by race and sexual orientation; share real-time location data with third parties; and while several promise not to 'sell' personal data, they permit it to be used, transferred and monetised by others while burying the disclosures. The report also found many ISPs make the choices they advertise difficult to actually exercise. Data-access requests received ran between ZERO and 380 per month across the six. This is a STAFF REPORT, not an enforcement action - no penalties attach. Treat as one connected finding across every ISP row rather than six separate ones.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$138.2B", "Market Cap": "$184.9B", "Employees": "99,600", "HQ City": "New York", "HQ State": "New York", "CEO": "Hans Vestberg", "Ticker": "VZ", "Website (Corporate)": "verizon.com", "Main Mailing Address (legal/privacy notices)": "Verizon Privacy Office, 1300 I Street NW, Suite 500 East, Washington, DC 20005, USA (International: Verizon Legal Dept, Reading International Business Park, Basingstoke Road, Reading, Berkshire RG2 6DA, UK)", "Legal / Privacy Contact Email": "No published privacy email; Verizon routes requests through its online privacy form", "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (VZ). Service route: c/o General Counsel / Corporate Secretary, New York, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Verizon Wireless, Fios, and 5G Home Internet all sit under one privacy policy with no product boundary\nWHAT THE TERMS SAY: 5G/LTE Home Internet uses the same shared Verizon privacy policy as Verizon Wireless and Fios, with no separate framework — three services a customer would consider different purchases governed by one document, producing a single combined customer profile.\nWHY IT MATTERS: The FTC's ISP study identified combining data across product lines as a central concern, and the tracker calls this row that concern in its cleanest form, since no product boundary was ever drawn.\n(evidence: SCARY | Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] 5G Home Internet carries the same binding arbitration and class-action waiver as Verizon wireless/Fios\nWHAT THE TERMS SAY: The same binding arbitration plus class-action waiver documented for Verizon wireless and Fios applies to 5G/LTE Home Internet.\nWHY IT MATTERS: Customers lose access to class litigation over disputes about this home-internet service, under terms they may not have separately reviewed.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[AUTO_RENEWAL_FEES · FL-1] Verizon's multi-year price guarantee on home internet is contingent on staying enrolled in autopay/paperless\nWHAT THE TERMS SAY: Multi-year price guarantees (3-5 years depending on plan) are advertised as contingent on autopay and paperless billing enrollment.\nWHY IT MATTERS: A customer who later disables autopay or paperless billing for any reason may put their advertised long-term price guarantee at risk, though the row does not spell out the exact consequence.\n(evidence: Fees; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The shared-policy and arbitration terms are clearly stated, but the exact consequence of losing the autopay/paperless-billing price guarantee is not spelled out.", "Exposure Score (0-100)": 39, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Verizon 5G Home Internet / LTE Home Internet  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Verizon 5G Home Internet / LTE Home Internet you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same shared Verizon privacy policy as Fios and Verizon Wireless - no separate framework for the home product at all. Three services a customer would describe as different purchases, one governing document, and a single combined profile underneath. The FTC's ISP study identified combining data across product lines as one of its central concerns, and this row is that concern in its cleanest form: there is no product boundary to cross because the policy never drew one.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Internet Providers", "_row_id": 243, "_entity_id": 387, "_entity_slug": "verizon-5g-home-internet-lte-home-internet", "_issuer": "Verizon 5G Home Internet / LTE Home Internet", "_issuer_slug": "verizon-5g-home-internet-lte-home-internet", "_ticker": "VZ", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Starlink (SpaceX)", "Category": "ISP (satellite)", "Terms & Conditions URL": "starlink.com/legal/documents/DOC-1195-14735-72", "T&C Direct PDF?": "NOT CONFIRMED (URL structure suggests a stable direct link, but not confirmed as a static PDF vs. dynamically rendered page this pass)", "Privacy Policy URL": "starlink.com/legal/privacy-policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "NOTABLE FLAG: Starlink's privacy policy states normal (non-Enterprise, non-Government) customer data MAY be used for AI training by default — Enterprise and Government accounts are automatically opted out, but residential customers are not mentioned as auto-opted-out, implying residential data may be used for AI training unless the customer opts out themselves. Also explicitly describes its data sharing with 'trusted third-party partners' as potentially qualifying as a 'sale' or 'sharing' under California law even though Starlink says it isn't 'in the conventional sense' — a semantic hedge worth flagging rather than taking at face value.", "Arbitration / Class Action Waiver": "Binding arbitration administered by the International Chamber of Commerce (ICC) rather than the more common AAA — unusual among US ISPs and potentially less familiar/accessible for US consumers; class arbitration and class actions are both explicitly prohibited; Starlink pays ICC fees upfront but can seek reimbursement if a claim is found frivolous.", "Fees / Billing Flags": "30-day full refund on the Starlink Kit hardware if returned undamaged.", "Notes": "Relevant across all 7 states, especially rural CA, TX, and FL where wired options are limited; the AI-training data-use question and the unusual ICC arbitration venue are the two standout issues here relative to traditional ISPs.\n\nFTC 6(b) STAFF REPORT CROSS-REFERENCE (verified this pass): 'A Look at What ISPs Know About You: Examining the Privacy Practices of Six Major Internet Service Providers,' released Oct 21 2021, approved 4-0. Orders issued in 2019 under FTC Act sec. 6(b) to AT&T, Comcast/Xfinity, Charter, T-Mobile, Verizon and Google Fiber - together ~98% of the mobile internet market - plus three affiliated ad entities (AT&T's Appnexus/Xandr, Verizon Online LLC, Oath Americas/Verizon Media). FINDINGS: ISPs combine data across product lines; combine personal, app-usage and web-browsing data to target ads; place consumers into SENSITIVE CATEGORIES including by race and sexual orientation; share real-time location data with third parties; and while several promise not to 'sell' personal data, they permit it to be used, transferred and monetised by others while burying the disclosures. The report also found many ISPs make the choices they advertise difficult to actually exercise. Data-access requests received ran between ZERO and 380 per month across the six. This is a STAFF REPORT, not an enforcement action - no penalties attach. Treat as one connected finding across every ISP row rather than six separate ones.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AI_TRAINING · FL-2] Starlink auto-opts Enterprise and Government customers out of AI training, but not regular households\nWHAT THE TERMS SAY: Starlink's privacy policy states normal (non-Enterprise, non-Government) customer data may be used for AI training by default; Enterprise and Government accounts are automatically opted out, but residential customers are not mentioned as auto-opted-out, implying residential data may be used for AI training unless the customer opts out themselves.\nWHY IT MATTERS: A residential customer's data can be used to train AI models by default, while the tiers with more purchasing power get the stronger, automatic protection.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SALE · FL-2] Starlink shares data with 'trusted partners' in a way that may legally be a data sale, despite its denial\nWHAT THE TERMS SAY: Starlink explicitly describes its data sharing with 'trusted third-party partners' as potentially qualifying as a 'sale' or 'sharing' under California law, even though Starlink says it isn't a sale 'in the conventional sense' — a semantic hedge the tracker flags rather than takes at face value.\nWHY IT MATTERS: Consumers relying on a plain-English 'we don't sell your data' assurance may not realize the practice can still legally count as a sale or sharing under state privacy law.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Starlink arbitrates through an international commercial body, not the AAA venue US consumers usually see\nWHAT THE TERMS SAY: Binding arbitration is administered by the International Chamber of Commerce (ICC) rather than the more common AAA, unusual among US ISPs and potentially less familiar or accessible for US consumers; class arbitration and class actions are both explicitly prohibited, and Starlink can seek reimbursement of its upfront ICC fees if a claim is found frivolous.\nWHY IT MATTERS: A less-familiar international arbitration venue, combined with the risk of owing Starlink's fees back if a claim is deemed frivolous, can discourage consumers from pursuing legitimate disputes.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=Y; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The AI-training and data-sharing practices are directly stated, but the 'not a sale in the conventional sense' language is a hedge on how the practice should be classified.", "Exposure Score (0-100)": 46, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 17, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 17/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nAI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Starlink (SpaceX)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your content and your conversations, as raw material to train AI models.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (8 of 13): your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Starlink (SpaceX) you gave up your personal data sold onward, your content used as AI training data, your data shared corporate-wide, your right to sue, and your right to join a class action. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:41:13Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The notable flag on Starlink is that its privacy policy distinguishes normal residential service from Enterprise and Government tiers, with the stronger commitments attached to the tiers that are not sold to households. That tiering is worth naming plainly because it recurs across this entire tracker - in the LLM Providers tab, in Microsoft Copilot, in Mistral, in Anthropic and OpenAI's commercial carve-outs. The pattern is consistent enough to be a structural finding rather than a coincidence: the meaningful data protections are a purchasable enterprise feature, and the consumer tier is the one that funds the difference. Starlink also serves many customers with no terrestrial alternative, which removes the ability to walk away.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Internet Providers", "_row_id": 244, "_entity_id": 388, "_entity_slug": "starlink-spacex", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Pepco", "Category": "Electric Utility (DC/MD)", "Terms & Conditions URL": "pepco.com/en/legal/pages/terms-and-conditions.aspx (approximate; direct URL not independently confirmed this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "pepco.com/en/legal/pages/privacy-policy.aspx (approximate; direct URL not independently confirmed this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "DC PSC-regulated utility. Smart-meter data collected from ~900,000 customers in DC and suburban MD. DC PSC Order 20645 (2020) established specific rules for utility customer data access and privacy. Pepco's smart-meter data reveals household occupancy patterns, appliance usage, and daily routines.", "Arbitration / Class Action Waiver": "Regulated utility — customer disputes governed by the DC Public Service Commission and MD Public Service Commission. Pepco (Potomac Electric Power Company) is an Exelon subsidiary serving DC and southern Maryland. No private arbitration clause. DC PSC has specific customer privacy and data-sharing rules.", "Fees / Billing Flags": "HISTORICAL SHUTOFF-PROTECTION EPISODE: during a documented billing-spike controversy, the Maryland Public Service Commission ordered Pepco (and BGE) to DELAY service shutoffs for a week after nearly 43,000 Pepco customers and ~84,000 BGE customers faced potential termination — the PSC specifically created a work group to investigate what caused the unusual bill spike and to develop mandatory alternative payment plans, indicating regulators found the utilities' own billing/shutoff practices warranted intervention rather than treating the spike as solely a customer-usage issue.", "Notes": "DC AND MARYLAND CUSTOMERS CAN 'SHOP' for a competitive electricity SUPPLIER even though Pepco remains the mandatory DELIVERY utility — unlike Virginia, where Dominion Energy customers cannot choose an alternate supplier at all (see Dominion Energy Virginia row). Recommend a direct follow-up on Pepco's actual current Terms/Privacy Policy given the approximate URLs above.\n\nSMART METER CROSS-REFERENCE (verified this pass): Naperville Smart Meter Awareness v. City of Naperville, 900 F.3d 521 (7th Cir. 2018) - the first case addressing whether the Fourth Amendment protects smart meter data. The court held 3-0 that collecting energy-consumption readings at 15-minute intervals IS a search under the Fourth Amendment, because appliances have distinct consumption signatures and the data reveals when a home is occupied or vacant, sleeping and eating routines, which appliances are present and when used, and EV charging patterns that expose travel history. It then held the search REASONABLE because the utility collected for non-prosecutorial purposes. The court expressly flagged that its analysis would change if collection were done with prosecutorial intent, by law enforcement rather than the utility, if the data were more accessible to officials outside the utility, or if intervals were shorter than 15 minutes - and it relied on Naperville's policy of requiring a warrant or court order before releasing customer data to third parties including police. Naperville residents could not opt out; the 'non-wireless' alternative was still a smart meter collecting equally rich data, just manually retrieved. Naperville retained readings up to three years. NOT binding in the 4th Circuit (MD/VA) or D.C. Circuit - persuasive only. The operative consumer question for every utility in this tab is therefore: what is the collection interval, what is the retention period, and what is the written policy on law enforcement requests?", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Exelon Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Pepco's ~900,000 smart meters expose occupancy data; its own read interval vs. Naperville's 15-min is unstated\nWHAT THE TERMS SAY: Pepco's smart meters collect data from roughly 900,000 DC/MD customers; per the Naperville v. City of Naperville ruling applied in the row, 15-minute interval readings reveal when a home is occupied or vacant, sleep and meal routines, which appliances are present, and EV charging patterns exposing travel history — detailed enough that the Seventh Circuit held collecting it is a Fourth Amendment search.\nWHY IT MATTERS: Naperville is Seventh Circuit law and does not bind Maryland, Virginia, or DC, and Pepco's own current retention period and law-enforcement-request policy are not stated in the row.\n(evidence: Data Sharing | Notes | SCARY; Inferred from tracker text (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "[OTHER · FL-1] Regulators had to order Pepco to delay shutting off ~43,000 customers after an unexplained bill spike\nWHAT THE TERMS SAY: During a documented billing-spike controversy, the Maryland Public Service Commission ordered Pepco (and BGE) to delay service shutoffs for a week after nearly 43,000 Pepco customers faced potential termination, and created a work group to investigate the spike's cause and develop mandatory alternative payment plans.\nWHY IT MATTERS: Regulators intervening to delay mass shutoffs and investigate the utility's own billing indicates the PSC found Pepco's billing/shutoff practices themselves warranted scrutiny, not just customer usage.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No private arbitration clause exists for this regulated utility (disputes go through the DC/MD Public Service Commissions), so no arbitration-related finding applies; only the smart-meter surveillance exposure and the billing/shutoff episode are substantive enough for findings.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The shutoff episode and smart-meter collection interval are documented, but Pepco's own retention period and law-enforcement disclosure policy are not stated.", "Exposure Score (0-100)": 23, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 11, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 11/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 4/20 (termination_or_confiscation+4) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Pepco  <-  Exelon Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to join a class action; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Pepco you gave up your physical movements, your data shared corporate-wide, and your right to keep what you paid for. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Smart meters read a home every 15 minutes and, per the Seventh Circuit, that data reveals when the house is empty, when people sleep and eat, which appliances are present, and EV charging patterns that expose travel history - enough that the court held collecting it IS a Fourth Amendment search. It allowed the practice only because the utility collected for non-prosecutorial purposes, and expressly warned the analysis would change with shorter intervals, law-enforcement involvement, or easier access by officials outside the utility. Pepco is an Exelon subsidiary alongside BGE and Delmarva, so one parent's decisions about collection frequency, retention and law enforcement response govern electricity customers across DC, Maryland and Delaware at once. Naperville is Seventh Circuit law and does not bind Maryland, Virginia or DC.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Power Utilities (MD-VA-DC)", "_row_id": 245, "_entity_id": 390, "_entity_slug": "pepco", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "BGE (Baltimore Gas & Electric)", "Category": "Electric/Gas Utility (MD)", "Terms & Conditions URL": "bge.com/AboutUs/Pages/TermsofUse.aspx (approximate; not independently confirmed this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "bge.com/AboutUs/Pages/PrivacyPolicy.aspx (approximate; not independently confirmed this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "MD PSC-regulated utility serving 1.3M gas and electric customers in central Maryland. Smart-meter deployment covers nearly all customers. BGE's Peak Rewards and Smart Energy Rewards programs collect additional behavioral data (thermostat settings, demand-response participation).", "Arbitration / Class Action Waiver": "Regulated utility — customer disputes governed by the MD Public Service Commission. BGE is an Exelon subsidiary serving central Maryland. No private arbitration clause. MD PSC has established specific smart-meter data privacy rules.", "Fees / Billing Flags": "SAME shutoff-protection episode as Pepco (see Pepco row): ~84,000 BGE customers faced potential termination during a documented billing-spike controversy, prompting a Maryland PSC-ordered delay and an investigation into the cause of the unusual bill increases. BGE is the OLDEST gas utility in the nation and the LARGEST utility in Maryland (1.25 million residential/small-business electric customers across 2,300+ square miles), a subsidiary of Exelon (same parent as Pepco and Delmarva Power).", "Notes": "BGE, Pepco, and Delmarva Power are ALL Exelon subsidiaries — worth treating as a connected corporate family for purposes of any cross-utility pattern (shared parent company, likely shared data/billing infrastructure) rather than three fully independent companies.\n\nSMART METER CROSS-REFERENCE (verified this pass): Naperville Smart Meter Awareness v. City of Naperville, 900 F.3d 521 (7th Cir. 2018) - the first case addressing whether the Fourth Amendment protects smart meter data. The court held 3-0 that collecting energy-consumption readings at 15-minute intervals IS a search under the Fourth Amendment, because appliances have distinct consumption signatures and the data reveals when a home is occupied or vacant, sleeping and eating routines, which appliances are present and when used, and EV charging patterns that expose travel history. It then held the search REASONABLE because the utility collected for non-prosecutorial purposes. The court expressly flagged that its analysis would change if collection were done with prosecutorial intent, by law enforcement rather than the utility, if the data were more accessible to officials outside the utility, or if intervals were shorter than 15 minutes - and it relied on Naperville's policy of requiring a warrant or court order before releasing customer data to third parties including police. Naperville residents could not opt out; the 'non-wireless' alternative was still a smart meter collecting equally rich data, just manually retrieved. Naperville retained readings up to three years. NOT binding in the 4th Circuit (MD/VA) or D.C. Circuit - persuasive only. The operative consumer question for every utility in this tab is therefore: what is the collection interval, what is the retention period, and what is the written policy on law enforcement requests?", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Exelon Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] BGE's Peak Rewards program adds thermostat and demand-response data on top of smart-meter readings\nWHAT THE TERMS SAY: Nearly all of BGE's 1.3M gas and electric customers have smart meters, and BGE's Peak Rewards and Smart Energy Rewards programs collect additional behavioral data (thermostat settings, demand-response participation) beyond standard interval readings, which the Naperville ruling's reasoning treats as revealing occupancy and routine detail.\nWHY IT MATTERS: Beyond the baseline smart-meter exposure, enrolling in BGE's rewards programs adds another layer of behavioral data collection tied to in-home devices.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-1] Regulators had to order BGE to delay shutting off ~84,000 customers after the same unexplained bill spike\nWHAT THE TERMS SAY: The same billing-spike controversy documented for Pepco led to a Maryland PSC-ordered delay after nearly 84,000 BGE customers faced potential termination, prompting an investigation into the cause of the unusual bill increases.\nWHY IT MATTERS: Tens of thousands of BGE customers nearly lost service over a billing spike regulators found serious enough to investigate and force a delay on.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[RETENTION_PERIOD · FL-2] BGE's smart-meter data retention period and police-request policy aren't prominent in customer materials\nWHAT THE TERMS SAY: The tracker states the practical question for a BGE customer is not whether the meter is collecting data — it is — but what BGE's retention period is and what its written policy requires before releasing usage data to police, and that 'neither is prominent in customer-facing materials.'\nWHY IT MATTERS: Customers cannot easily find out how long their detailed usage data is kept or under what conditions BGE turns it over to law enforcement.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Peak Rewards data collection and shutoff episode are documented, but BGE's retention period and law-enforcement policy are explicitly noted as not prominent/unstated.", "Exposure Score (0-100)": 17, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 11, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 11/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 4/20 (termination_or_confiscation+4) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "BGE (Baltimore Gas & Electric)  <-  Exelon Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to join a class action; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using BGE (Baltimore Gas & Electric) you gave up your physical movements, your data shared corporate-wide, and your right to keep what you paid for. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "BGE is an Exelon company, sharing a corporate parent with Pepco and Delmarva Power, which means the smart-meter data-handling policies that matter to a Baltimore household are set at the same level as those for a DC or Delaware one. The Seventh Circuit's Naperville ruling established that 15-minute interval consumption data is constitutionally protected enough to count as a search, because it exposes occupancy, sleep and meal routines and appliance-level detail. The practical question for a BGE customer is not whether the meter is collecting - it is - but what the retention period is and what BGE's written policy requires before releasing usage data to police. Neither is prominent in customer-facing materials.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Power Utilities (MD-VA-DC)", "_row_id": 246, "_entity_id": 391, "_entity_slug": "bge-baltimore-gas-electric", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Delmarva Power", "Category": "Electric/Gas Utility (MD)", "Terms & Conditions URL": "delmarva.com (Terms of Use not individually located as direct URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "delmarva.com (Privacy Policy not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass.", "Fees / Billing Flags": "CONFIRMED BILLING ERROR (Delaware, historical but instructive precedent): a SINGLE customer complaint to the state's Division of the Public Advocate about questionable late-payment charges led Delmarva to review its files and discover THOUSANDS of customers were owed refunds dating back years — illustrating how a systemic billing error can persist for years until one customer happens to escalate it through a state regulator rather than the company's own internal review catching it first. SEPARATE, ONGOING COMPLAINT PATTERN (BBB, current): customers report Delmarva repeatedly LOSING/MISAPPLYING PAYMENTS already confirmed by the customer's bank as sent, then issuing disconnect notices and demanding the same proof of payment be resubmitted multiple times despite the utility's own staff confirming receipt of the documentation.", "Notes": "The 'company only found the billing error because one customer escalated to a state regulator' pattern is a useful illustration of why regulatory escalation (not just calling the company) can matter for systemic billing issues.\n\nSMART METER CROSS-REFERENCE (verified this pass): Naperville Smart Meter Awareness v. City of Naperville, 900 F.3d 521 (7th Cir. 2018) - the first case addressing whether the Fourth Amendment protects smart meter data. The court held 3-0 that collecting energy-consumption readings at 15-minute intervals IS a search under the Fourth Amendment, because appliances have distinct consumption signatures and the data reveals when a home is occupied or vacant, sleeping and eating routines, which appliances are present and when used, and EV charging patterns that expose travel history. It then held the search REASONABLE because the utility collected for non-prosecutorial purposes. The court expressly flagged that its analysis would change if collection were done with prosecutorial intent, by law enforcement rather than the utility, if the data were more accessible to officials outside the utility, or if intervals were shorter than 15 minutes - and it relied on Naperville's policy of requiring a warrant or court order before releasing customer data to third parties including police. Naperville residents could not opt out; the 'non-wireless' alternative was still a smart meter collecting equally rich data, just manually retrieved. Naperville retained readings up to three years. NOT binding in the 4th Circuit (MD/VA) or D.C. Circuit - persuasive only. The operative consumer question for every utility in this tab is therefore: what is the collection interval, what is the retention period, and what is the written policy on law enforcement requests?", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] One customer's complaint uncovered thousands of Delmarva customers owed refunds for years-old overcharges\nWHAT THE TERMS SAY: A single customer complaint to Delaware's Division of the Public Advocate about questionable late-payment charges led Delmarva to review its files and discover thousands of customers were owed refunds dating back years — a systemic billing error that persisted until one customer happened to escalate it to a state regulator.\nWHY IT MATTERS: A billing error affecting thousands of customers went uncorrected for years until an individual, not Delmarva's own internal review, forced the discovery.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[TERMINATION_CONFISCATION · FL-1] Customers report Delmarva losing bank-confirmed payments, then sending disconnect notices anyway\nWHAT THE TERMS SAY: An ongoing BBB complaint pattern reports Delmarva repeatedly losing or misapplying payments already confirmed by the customer's bank as sent, then issuing disconnect notices and demanding the same proof of payment be resubmitted multiple times, despite the utility's own staff confirming receipt of the documentation.\nWHY IT MATTERS: Customers who already paid can still face disconnection threats over Delmarva's own record-keeping errors, and have to repeatedly re-prove payment already acknowledged as received.\n(evidence: Fees; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] Delmarva's smart meters reveal the same occupancy and appliance-level detail as neighboring utilities\nWHAT THE TERMS SAY: Delmarva's smart-meter data reveals household occupancy and appliance-usage patterns; per the Naperville ruling applied in the row, 15-minute interval data reveals occupancy, appliance inventory, and EV charging behavior, and a federal appellate court has already held that collecting it constitutes a search.\nWHY IT MATTERS: Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules, but the underlying granularity of what the meter collects is unaffected by that safeguard.\n(evidence: Data Sharing | Notes | SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The confirmed billing-error episode is well documented, but the ongoing lost-payment complaint pattern is BBB-sourced and not independently confirmed, and arbitration terms are unconfirmed.", "Exposure Score (0-100)": 19, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 4/20 (termination_or_confiscation+4) | Record 8/20 (severity3+8) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Delmarva Power  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Delmarva Power you gave up your physical movements and your right to keep what you paid for. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Third of Exelon's three Mid-Atlantic utilities alongside Pepco and BGE, and the row exists mainly to prevent the impression that three separate assessments were made - they were not. One parent, one set of data-governance decisions, three brands. The Naperville finding applies identically: interval consumption data reveals occupancy patterns, appliance inventory and EV charging behaviour, and a federal appellate court has already held that collecting it constitutes a search. Delmarva serves rural Delaware and Maryland Eastern Shore customers who generally have no alternative provider, so opting out of the relationship is not available.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Power Utilities (MD-VA-DC)", "_row_id": 247, "_entity_id": 392, "_entity_slug": "delmarva-power", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Dominion Energy Virginia", "Category": "Electric Utility (VA)", "Terms & Conditions URL": "dominionenergy.com/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "dominionenergy.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "VA SCC-regulated utility serving 2.7M customers in Virginia. The tracker's existing SCARY text documents $3.95B in accumulated parent penalties (environmental, coal ash). Smart-meter rollout covers most Virginia customers. Dominion's data center power supply contracts (Northern Virginia hosts ~70% of global internet traffic through data centers) create an unusual dual relationship — Dominion is simultaneously a regulated consumer utility AND a commercial power supplier to the world's largest cloud infrastructure.", "Arbitration / Class Action Waiver": "Regulated utility — customer disputes governed by the Virginia State Corporation Commission (SCC). Dominion is one of the largest US utilities by market cap. No private arbitration clause — the SCC handles rate cases, service complaints, and data-access disputes.", "Fees / Billing Flags": "MULTIPLE DOCUMENTED CUSTOMER COMPLAINTS (BBB/ConsumerAffairs, 2026): customers report UNAUTHORIZED SERVICE SHUTOFFS (one case: power turned off despite no outstanding balance, autopay enabled, and a shutoff scheduled weeks later — based on a third party incorrectly telling Dominion the unit had been vacated); other customers report BILLING ACCURACY DISPUTES where bills nearly doubled year-over-year with no usage change, and customer service allegedly could not explain day-to-day usage swings (e.g., $5 one day, $36 the next) beyond citing the meter reading itself as authoritative. Virginia residents also cannot 'shop' for a different electricity supplier the way DC/Maryland customers can (see Pepco/BGE row) — Virginia's electric market remains regulated/non-competitive.", "Notes": "The 'unauthorized shutoff based on a third party's incorrect report that the unit was vacated' complaint is a concrete, serious operational-error example worth flagging — a utility shutoff in winter with no verification directly with the actual account holder is a real safety/harm issue distinct from a typical billing dispute.\n\nSMART METER CROSS-REFERENCE (verified this pass): Naperville Smart Meter Awareness v. City of Naperville, 900 F.3d 521 (7th Cir. 2018) - the first case addressing whether the Fourth Amendment protects smart meter data. The court held 3-0 that collecting energy-consumption readings at 15-minute intervals IS a search under the Fourth Amendment, because appliances have distinct consumption signatures and the data reveals when a home is occupied or vacant, sleeping and eating routines, which appliances are present and when used, and EV charging patterns that expose travel history. It then held the search REASONABLE because the utility collected for non-prosecutorial purposes. The court expressly flagged that its analysis would change if collection were done with prosecutorial intent, by law enforcement rather than the utility, if the data were more accessible to officials outside the utility, or if intervals were shorter than 15 minutes - and it relied on Naperville's policy of requiring a warrant or court order before releasing customer data to third parties including police. Naperville residents could not opt out; the 'non-wireless' alternative was still a smart meter collecting equally rich data, just manually retrieved. Naperville retained readings up to three years. NOT binding in the 4th Circuit (MD/VA) or D.C. Circuit - persuasive only. The operative consumer question for every utility in this tab is therefore: what is the collection interval, what is the retention period, and what is the written policy on law enforcement requests?", "Industry (Fortune 500)": "Utilities: Gas and Electric", "Revenue (Fortune 500)": "$16.5B", "Market Cap": "$62.5B", "Employees": "14,700", "HQ City": "Richmond", "HQ State": "Virginia", "CEO": "Robert Blue", "Ticker": "D", "Website (Corporate)": "dominionenergy.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (D). Service route: c/o General Counsel / Corporate Secretary, Richmond, Virginia — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Pending - severity 4/5, no source yet", "Region Basis": "HQ state 'Virginia' is DC/MD/VA", "Parent / Ultimate Owner": "Dominion Energy, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Dominion Energy, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[TERMINATION_CONFISCATION · FL-4] Customers report Dominion cutting power despite no balance owed, on a third party's incorrect vacancy report\nWHAT THE TERMS SAY: Multiple documented customer complaints (BBB/ConsumerAffairs, 2026) include a case where power was turned off despite no outstanding balance and autopay enabled, based on a third party incorrectly telling Dominion the unit had been vacated, with a shutoff scheduled weeks later.\nWHY IT MATTERS: The tracker flags this as a real safety/harm issue distinct from a typical billing dispute — a winter-capable shutoff triggered without verifying directly with the actual account holder.\n(evidence: Fees; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[OTHER · FL-1] Customers report bills nearly doubling with no usage change, and Dominion citing only the meter as proof\nWHAT THE TERMS SAY: Other documented complaints describe billing-accuracy disputes where bills nearly doubled year-over-year with no usage change, with customer service allegedly unable to explain day-to-day swings (e.g., $5 one day, $36 the next) beyond citing the meter reading itself as authoritative; Virginia customers also cannot 'shop' for an alternate electricity supplier.\nWHY IT MATTERS: Customers facing unexplained bill spikes have no competitive alternative to switch to and reportedly get no explanation beyond the meter reading itself.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[REGULATORY_PENALTY · FL-1] Dominion's parent has ~$3.95B in penalties, dwarfing any privacy-specific fine that would ever apply here\nWHAT THE TERMS SAY: The tracker notes Dominion's parent has accumulated roughly $3.95 billion in penalties (environmental, coal ash — not privacy-related), a sum large enough that it reframes the row: for a regulated monopoly utility, data-handling failures are simply not where the financial risk lives.\nWHY IT MATTERS: The tracker's own reasoning is that this financial reality means data-privacy compliance is unlikely to get proportionate attention, since the real regulatory and financial exposure lies elsewhere.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The shutoff and billing complaints are documented with specific detail, though sourced from BBB/ConsumerAffairs complaint records rather than Dominion's own disclosures.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 4/20 (termination_or_confiscation+4) | Record 20/20 (severity5+20) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent", "Entity Type": "Company", "Ownership Path": "Dominion Energy Virginia  <-  Dominion Energy, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Dominion Energy Virginia you gave up your physical movements and your right to keep what you paid for. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:41:21Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Dominion's parent has accumulated roughly $3.95 billion in penalties - a figure large enough that it reframes how to read every other row in this tab, because the sums involved dwarf what a privacy penalty would ever produce. That is the uncomfortable finding: for a regulated monopoly utility, data-handling failures are simply not where the financial risk lives, which means they are not where the compliance attention goes either. Layered on top is the Naperville problem - smart meter interval data is detailed enough that a federal appeals court called collecting it a Fourth Amendment search - and a Virginia customer has no competitive alternative to switch to if they dislike the answer.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Power Utilities (MD-VA-DC)", "_row_id": 248, "_entity_id": 394, "_entity_slug": "dominion-energy-virginia", "_issuer": "Dominion Energy, Inc.", "_issuer_slug": "dominion-energy-inc", "_ticker": "D", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Appalachian Power (American Electric Power)", "Category": "Electric Utility (VA)", "Terms & Conditions URL": "appalachianpower.com (Terms not individually located as direct URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "appalachianpower.com (Privacy Policy not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass.", "Fees / Billing Flags": "Appalachian Power's rates are GENERALLY HIGHER than Dominion Energy Virginia's due to the mountainous Shenandoah Valley/Roanoke/Blacksburg terrain increasing distribution costs — a structural, geography-driven rate difference rather than a billing-practice issue. SEPARATE, RECENT REGULATORY CHANGE: Virginia's HB 921 (signed April 13, 2026, effective July 1, 2026) expanded retail electricity choice for LARGE nonresidential Appalachian Power/Dominion customers (annual peak demand over 5 MW, previously capped at 1% of the utility's total peak load — that cap was eliminated) and shortened the notice period to RETURN to utility service from 5 years to 18 months. Residential customers remain ineligible for retail choice, so this change does not affect typical individual customers.", "Notes": "Not itemized this pass.\n\nSMART METER CROSS-REFERENCE (verified this pass): Naperville Smart Meter Awareness v. City of Naperville, 900 F.3d 521 (7th Cir. 2018) - the first case addressing whether the Fourth Amendment protects smart meter data. The court held 3-0 that collecting energy-consumption readings at 15-minute intervals IS a search under the Fourth Amendment, because appliances have distinct consumption signatures and the data reveals when a home is occupied or vacant, sleeping and eating routines, which appliances are present and when used, and EV charging patterns that expose travel history. It then held the search REASONABLE because the utility collected for non-prosecutorial purposes. The court expressly flagged that its analysis would change if collection were done with prosecutorial intent, by law enforcement rather than the utility, if the data were more accessible to officials outside the utility, or if intervals were shorter than 15 minutes - and it relied on Naperville's policy of requiring a warrant or court order before releasing customer data to third parties including police. Naperville residents could not opt out; the 'non-wireless' alternative was still a smart meter collecting equally rich data, just manually retrieved. Naperville retained readings up to three years. NOT binding in the 4th Circuit (MD/VA) or D.C. Circuit - persuasive only. The operative consumer question for every utility in this tab is therefore: what is the collection interval, what is the retention period, and what is the written policy on law enforcement requests?\n\n[RECOVERED from an unheaded column during the Aug 2026 structural fix; this text was present in the file but sat outside any labelled column] The HB 921 change is relevant primarily to large commercial/industrial Appalachian Power and Dominion customers, not typical residential ratepayers — worth noting this distinction if referencing the law change.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] In Appalachian Power's mountain territory there's no alternative provider at any price to switch to\nWHAT THE TERMS SAY: The tracker notes AEP's Appalachian footprint covers Virginia/West Virginia territory with no alternative electricity provider at any price, meaning every consumer-protection mechanism premised on switching providers is inoperative, leaving the state corporation commission as the only meaningful lever.\nWHY IT MATTERS: A customer dissatisfied with rates or practices has no competing provider to switch to, unlike some neighboring markets.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Appalachian Power's smart meters capture the same occupancy-revealing detail described for other utilities\nWHAT THE TERMS SAY: Smart-meter data reveals household occupancy and appliance-usage patterns; per the Naperville ruling applied throughout this tab, 15-minute interval data reveals the detail a federal appeals court held constitutes a Fourth Amendment search.\nWHY IT MATTERS: The row recommends a follow-up on AEP's actual retention schedule and law-enforcement request policy, which are not stated here.\n(evidence: Data Sharing | SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration is 'not independently confirmed' and no billing/fee practice specific to Appalachian Power is documented this pass (the rate difference from Dominion is geography-driven, and Virginia's HB 921 explicitly does not affect residential customers); only the no-alternative-provider structure and the smart-meter surveillance pattern are substantive enough for findings.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The tracker states nothing is confirmed specific to Appalachian Power this pass; findings rest on structural/monopoly reasoning and a shared smart-meter cross-reference.", "Exposure Score (0-100)": 9, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Appalachian Power (American Electric Power)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Appalachian Power (American Electric Power) you gave up your physical movements. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed specific to Appalachian Power this pass. The finding worth carrying is the rural monopoly structure: AEP's Appalachian footprint covers Virginia and West Virginia territory where there is no alternative electricity provider at any price, so every consumer-protection mechanism premised on switching is inoperative. Smart meter data at 15-minute intervals reveals household occupancy and routine in the detail the Seventh Circuit described, and the only meaningful lever a customer has is the state corporation commission. Recommend a follow-up on AEP's retention schedule and law-enforcement request policy.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Power Utilities (MD-VA-DC)", "_row_id": 249, "_entity_id": 395, "_entity_slug": "appalachian-power-american-electric-power", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "NOVEC (Northern Virginia Electric Cooperative)", "Category": "Electric Cooperative (VA)", "Terms & Conditions URL": "novec.com (Terms of Use not individually located as direct URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "novec.com (Privacy Policy not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "As a CUSTOMER-OWNED COOPERATIVE (not an investor-owned utility like Pepco/Dominion/BGE), NOVEC is structurally accountable directly to the customers it serves rather than to outside shareholders — a genuinely different governance/incentive structure worth noting. NOVEC has historically scored at or near the top of J.D. Power's utility customer-satisfaction rankings among electric cooperatives nationally, consistent with this cooperative accountability structure. Recommend a direct follow-up on NOVEC's actual Terms/Privacy Policy given the thin verification this pass.\n\nSMART METER CROSS-REFERENCE (verified this pass): Naperville Smart Meter Awareness v. City of Naperville, 900 F.3d 521 (7th Cir. 2018) - the first case addressing whether the Fourth Amendment protects smart meter data. The court held 3-0 that collecting energy-consumption readings at 15-minute intervals IS a search under the Fourth Amendment, because appliances have distinct consumption signatures and the data reveals when a home is occupied or vacant, sleeping and eating routines, which appliances are present and when used, and EV charging patterns that expose travel history. It then held the search REASONABLE because the utility collected for non-prosecutorial purposes. The court expressly flagged that its analysis would change if collection were done with prosecutorial intent, by law enforcement rather than the utility, if the data were more accessible to officials outside the utility, or if intervals were shorter than 15 minutes - and it relied on Naperville's policy of requiring a warrant or court order before releasing customer data to third parties including police. Naperville residents could not opt out; the 'non-wireless' alternative was still a smart meter collecting equally rich data, just manually retrieved. Naperville retained readings up to three years. NOT binding in the 4th Circuit (MD/VA) or D.C. Circuit - persuasive only. The operative consumer question for every utility in this tab is therefore: what is the collection interval, what is the retention period, and what is the written policy on law enforcement requests?", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-3] NOVEC sits partly outside the state oversight that governs investor-owned utilities like Dominion\nWHAT THE TERMS SAY: As a member-owned cooperative rather than an investor-owned utility, NOVEC has no shareholders monetizing customer data, but the tracker notes Virginia cooperatives sit partly outside the State Corporation Commission rate regulation that governs Dominion, so the oversight constraining an investor-owned utility applies differently here.\nWHY IT MATTERS: The governance structure that removes a shareholder profit motive also means less of the external regulatory oversight that applies to Dominion, BGE, and Pepco.\n(evidence: SCARY | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] NOVEC's smart meters expose the same occupancy detail regardless of its cooperative ownership structure\nWHAT THE TERMS SAY: NOVEC's smart-meter data reveals household occupancy and appliance-usage patterns; the tracker notes the Naperville smart-meter analysis is unaffected by ownership structure — interval consumption data reveals the same household detail regardless of who owns the wires.\nWHY IT MATTERS: Being a customer-owned cooperative doesn't change what the meter itself collects or how detailed that data is.\n(evidence: Data Sharing | SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and Fees/Billing Flags are both unconfirmed or not itemized this pass, and the row is explicitly marked 'unverified rather than clean'; only the reduced-oversight structure and the ownership-neutral smart-meter exposure are substantive enough for findings.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The tracker explicitly marks NOVEC's practices as unverified rather than clean, recommending a direct follow-up on its actual Terms/Privacy Policy.", "Exposure Score (0-100)": 9, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "NOVEC (Northern Virginia Electric Cooperative)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using NOVEC (Northern Virginia Electric Cooperative) you gave up your physical movements. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "NOVEC is a member-owned cooperative rather than an investor-owned utility, and that is a genuine structural difference worth stating fairly: customers are members with governance rights, and there are no shareholders whose returns depend on monetising anything. The catch is that Virginia cooperatives sit partly outside the State Corporation Commission rate regulation that governs Dominion, so the oversight that constrains an investor-owned utility applies differently here. The Naperville smart-meter analysis is unaffected by ownership structure - interval consumption data reveals the same household detail regardless of who owns the wires. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Power Utilities (MD-VA-DC)", "_row_id": 250, "_entity_id": 396, "_entity_slug": "novec-northern-virginia-electric-cooperative", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Rappahannock Electric Cooperative", "Category": "Electric Cooperative (VA)", "Terms & Conditions URL": "myrec.coop (Terms of Use not individually located as direct URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "myrec.coop (Privacy Policy not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Same customer-owned cooperative structure as NOVEC (see that row) — has also historically scored well in J.D. Power utility customer-satisfaction rankings. Recommend a direct follow-up on actual Terms/Privacy Policy given thin verification this pass.\n\nSMART METER CROSS-REFERENCE (verified this pass): Naperville Smart Meter Awareness v. City of Naperville, 900 F.3d 521 (7th Cir. 2018) - the first case addressing whether the Fourth Amendment protects smart meter data. The court held 3-0 that collecting energy-consumption readings at 15-minute intervals IS a search under the Fourth Amendment, because appliances have distinct consumption signatures and the data reveals when a home is occupied or vacant, sleeping and eating routines, which appliances are present and when used, and EV charging patterns that expose travel history. It then held the search REASONABLE because the utility collected for non-prosecutorial purposes. The court expressly flagged that its analysis would change if collection were done with prosecutorial intent, by law enforcement rather than the utility, if the data were more accessible to officials outside the utility, or if intervals were shorter than 15 minutes - and it relied on Naperville's policy of requiring a warrant or court order before releasing customer data to third parties including police. Naperville residents could not opt out; the 'non-wireless' alternative was still a smart meter collecting equally rich data, just manually retrieved. Naperville retained readings up to three years. NOT binding in the 4th Circuit (MD/VA) or D.C. Circuit - persuasive only. The operative consumer question for every utility in this tab is therefore: what is the collection interval, what is the retention period, and what is the written policy on law enforcement requests?", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Smart-meter reads can reveal when the home is occupied, per the tracker's own data-sharing note\nWHAT THE TERMS SAY: The row states smart-meter data reveals household occupancy and appliance-usage patterns, and that sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.\nWHY IT MATTERS: Even with a warrant requirement, the underlying meter data is granular enough to expose when someone is home, asleep, or away, and no company-specific privacy policy was independently confirmed this pass.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-3] No independently confirmed arbitration or fee terms exist for this member-owned utility\nWHAT THE TERMS SAY: Arbitration/class-action terms and fee practices are both marked 'not independently confirmed this pass,' and the SCARY field states nothing was confirmed for this cooperative.\nWHY IT MATTERS: The tracker's own read is that the absence of findings for small member-owned utilities reflects an absence of public scrutiny, not confirmed good practice, so consumers have no real visibility into this company's actual dispute-resolution or data terms.\n(evidence: Arbitration | Fees | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two items rise above generic industry boilerplate: the shared smart-meter/data-sharing paragraph applies verbatim to every utility in this tab, and the Naperville smart-meter court case is about a different city in a non-binding jurisdiction, not a finding about Rappahannock itself.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration, fees, and SCARY are all marked not independently confirmed, leaving only generic industry-wide smart-meter context in this company's own fields.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Rappahannock Electric Cooperative  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Rappahannock Electric Cooperative takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Same cooperative structure as NOVEC and SMECO - member-owned, no shareholder monetisation pressure, and correspondingly different oversight than an investor-owned utility. The honest reading of three consecutive blank cooperative rows is that small member-owned utilities generate very little public record of any kind: no SEC filings, limited regulatory proceedings, no national press attention. Absence of findings here reflects absence of scrutiny, not demonstrated good practice, and that distinction should survive into anything published from this tracker.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Power Utilities (MD-VA-DC)", "_row_id": 251, "_entity_id": 397, "_entity_slug": "rappahannock-electric-cooperative", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Potomac Edison (FirstEnergy)", "Category": "Electric Utility (MD)", "Terms & Conditions URL": "firstenergycorp.com (Potomac Edison Terms of Use not individually located as direct URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "firstenergycorp.com (Privacy Policy not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Potomac Edison is a subsidiary of FirstEnergy (formerly Allegheny Power), an investor-owned utility distinct from the Exelon family (Pepco/BGE/Delmarva) — recommend a direct follow-up on FirstEnergy's broader corporate privacy/legal record given thin verification of Potomac Edison specifically this pass.\n\nSMART METER CROSS-REFERENCE (verified this pass): Naperville Smart Meter Awareness v. City of Naperville, 900 F.3d 521 (7th Cir. 2018) - the first case addressing whether the Fourth Amendment protects smart meter data. The court held 3-0 that collecting energy-consumption readings at 15-minute intervals IS a search under the Fourth Amendment, because appliances have distinct consumption signatures and the data reveals when a home is occupied or vacant, sleeping and eating routines, which appliances are present and when used, and EV charging patterns that expose travel history. It then held the search REASONABLE because the utility collected for non-prosecutorial purposes. The court expressly flagged that its analysis would change if collection were done with prosecutorial intent, by law enforcement rather than the utility, if the data were more accessible to officials outside the utility, or if intervals were shorter than 15 minutes - and it relied on Naperville's policy of requiring a warrant or court order before releasing customer data to third parties including police. Naperville residents could not opt out; the 'non-wireless' alternative was still a smart meter collecting equally rich data, just manually retrieved. Naperville retained readings up to three years. NOT binding in the 4th Circuit (MD/VA) or D.C. Circuit - persuasive only. The operative consumer question for every utility in this tab is therefore: what is the collection interval, what is the retention period, and what is the written policy on law enforcement requests?", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] Potomac Edison's parent FirstEnergy was the subject of a major Ohio legislative-bribery corruption matter\nWHAT THE TERMS SAY: The tracker states FirstEnergy, Potomac Edison's parent, was the subject of one of the largest utility corruption matters in recent US history, involving legislative bribery in Ohio, with penalties and governance consequences attaching to the corporate parent that sets policy for Potomac Edison's Maryland and West Virginia customers; this pass did not verify settlement figures or current posture, so none are asserted.\nWHY IT MATTERS: The corporate parent that sets policy for Potomac Edison's Maryland and West Virginia customers has been the subject of one of the largest utility corruption matters in recent US history; this pass did not independently verify the settlement figures or current posture, and nothing was confirmed against Potomac Edison itself this pass.\n(evidence: SCARY; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Smart-meter reads can reveal when the home is occupied, per the tracker's own data-sharing note\nWHAT THE TERMS SAY: The row states smart-meter data reveals household occupancy and appliance-usage patterns, and that sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.\nWHY IT MATTERS: Even with a warrant requirement, the underlying meter data is granular enough to expose occupancy patterns, and no Potomac-Edison-specific privacy policy was independently confirmed this pass.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Two items found; arbitration and fees are both marked not independently confirmed for Potomac Edison specifically, and the FirstEnergy corruption matter is explicitly flagged as needing a direct follow-up before any settlement figures are published.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed about Potomac Edison specifically this pass; the FirstEnergy corruption matter is flagged as needing a direct follow-up before any numbers are published.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Potomac Edison (FirstEnergy)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Potomac Edison (FirstEnergy) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed against Potomac Edison itself this pass. The material fact is the parent: FirstEnergy has been the subject of one of the largest utility corruption matters in recent US history, involving legislative bribery in Ohio, and the resulting penalties and governance consequences attach to the corporate parent that sets policy for Potomac Edison's Maryland and West Virginia customers. This pass did not independently verify the settlement figures or current posture, so no numbers are asserted here - recommend a direct follow-up before publishing anything about the FirstEnergy matter. The Naperville smart-meter analysis applies to Potomac Edison as to every other utility in this tab.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Power Utilities (MD-VA-DC)", "_row_id": 252, "_entity_id": 398, "_entity_slug": "potomac-edison-firstenergy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "SMECO (Southern Maryland Electric Cooperative)", "Category": "Electric Cooperative (MD)", "Terms & Conditions URL": "smeco.coop (Terms of Use not individually located as direct URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "smeco.coop (Privacy Policy not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "SMECO scored highest of ALL Mid-Atlantic utilities surveyed in a J.D. Power customer-satisfaction study (783, ahead of Dominion Energy Virginia, Rappahannock, BGE, Pepco, Delmarva Power, and Potomac Edison) — the same customer-owned-cooperative structure as NOVEC/Rappahannock likely contributes to this. Recommend a direct follow-up on actual Terms/Privacy Policy given thin verification this pass.\n\nSMART METER CROSS-REFERENCE (verified this pass): Naperville Smart Meter Awareness v. City of Naperville, 900 F.3d 521 (7th Cir. 2018) - the first case addressing whether the Fourth Amendment protects smart meter data. The court held 3-0 that collecting energy-consumption readings at 15-minute intervals IS a search under the Fourth Amendment, because appliances have distinct consumption signatures and the data reveals when a home is occupied or vacant, sleeping and eating routines, which appliances are present and when used, and EV charging patterns that expose travel history. It then held the search REASONABLE because the utility collected for non-prosecutorial purposes. The court expressly flagged that its analysis would change if collection were done with prosecutorial intent, by law enforcement rather than the utility, if the data were more accessible to officials outside the utility, or if intervals were shorter than 15 minutes - and it relied on Naperville's policy of requiring a warrant or court order before releasing customer data to third parties including police. Naperville residents could not opt out; the 'non-wireless' alternative was still a smart meter collecting equally rich data, just manually retrieved. Naperville retained readings up to three years. NOT binding in the 4th Circuit (MD/VA) or D.C. Circuit - persuasive only. The operative consumer question for every utility in this tab is therefore: what is the collection interval, what is the retention period, and what is the written policy on law enforcement requests?", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Smart-meter reads can reveal when the home is occupied, per the tracker's own data-sharing note\nWHAT THE TERMS SAY: The row states smart-meter data reveals household occupancy and appliance-usage patterns, and that sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.\nWHY IT MATTERS: Even with a warrant requirement, the underlying meter data is granular enough to expose occupancy patterns, and no SMECO-specific privacy policy was independently confirmed this pass.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-3] No independently confirmed arbitration or fee terms exist for this member-owned utility\nWHAT THE TERMS SAY: Arbitration/class-action terms and fee practices are both marked 'not independently confirmed this pass,' and the SCARY field states nothing was confirmed for this cooperative.\nWHY IT MATTERS: As with the other two cooperatives in this tab, the tracker's own read is that the absence of findings reflects an absence of public scrutiny rather than confirmed good practice.\n(evidence: Arbitration | Fees | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two items rise above generic industry boilerplate; the J.D. Power satisfaction ranking and the Naperville smart-meter case (a different jurisdiction, non-binding) are context, not company-specific troubling findings.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration, fees, and SCARY are all marked not independently confirmed, leaving only generic industry-wide smart-meter context in this company's own fields.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "SMECO (Southern Maryland Electric Cooperative)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, SMECO (Southern Maryland Electric Cooperative) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. SMECO is the third member-owned cooperative in this tab, serving Southern Maryland, and the assessment mirrors NOVEC and Rappahannock: member governance, no shareholder monetisation incentive, and very little public record either way. The one thing a cooperative member can actually do that an investor-owned utility customer cannot is attend and vote at annual meetings, where smart-meter retention periods and law-enforcement data policies are legitimate agenda items. That is a real lever and it is almost never used.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Power Utilities (MD-VA-DC)", "_row_id": 253, "_entity_id": 399, "_entity_slug": "smeco-southern-maryland-electric-cooperative", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Washington Gas", "Category": "Natural Gas Utility (DC/MD/VA)", "Terms & Conditions URL": "washingtongas.com (Terms of Use not individually located as direct URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "washingtongas.com (Privacy Policy not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Multi-jurisdictional regulated utility serving 1.2M customers across DC, MD, and VA. The only utility in this tracker regulated by THREE different state/district commissions simultaneously. Customer data governance varies by jurisdiction — DC PSC, MD PSC, and VA SCC each have different rules.", "Arbitration / Class Action Waiver": "Regulated utility — customer disputes governed by DC PSC, MD PSC, and VA SCC. Washington Gas Light Company is a subsidiary of AltaGas Ltd. (Calgary, Canada). No private arbitration clause.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Washington Gas is the primary natural gas (not electric) utility across DC, Maryland, and Virginia — the only gas-specific (rather than electric) utility in this tab, meaning it's the right company to flag for gas-specific safety/billing issues (e.g., gas-leak reporting) distinct from the electric utilities documented elsewhere. Recommend a direct follow-up given thin verification this pass.\n\nSMART METER CROSS-REFERENCE (verified this pass): Naperville Smart Meter Awareness v. City of Naperville, 900 F.3d 521 (7th Cir. 2018) - the first case addressing whether the Fourth Amendment protects smart meter data. The court held 3-0 that collecting energy-consumption readings at 15-minute intervals IS a search under the Fourth Amendment, because appliances have distinct consumption signatures and the data reveals when a home is occupied or vacant, sleeping and eating routines, which appliances are present and when used, and EV charging patterns that expose travel history. It then held the search REASONABLE because the utility collected for non-prosecutorial purposes. The court expressly flagged that its analysis would change if collection were done with prosecutorial intent, by law enforcement rather than the utility, if the data were more accessible to officials outside the utility, or if intervals were shorter than 15 minutes - and it relied on Naperville's policy of requiring a warrant or court order before releasing customer data to third parties including police. Naperville residents could not opt out; the 'non-wireless' alternative was still a smart meter collecting equally rich data, just manually retrieved. Naperville retained readings up to three years. NOT binding in the 4th Circuit (MD/VA) or D.C. Circuit - persuasive only. The operative consumer question for every utility in this tab is therefore: what is the collection interval, what is the retention period, and what is the written policy on law enforcement requests?", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "AltaGas Ltd. (Calgary, Canada)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Combined gas-plus-electric smart-meter data could reconstruct occupancy, with no single policy covering it\nWHAT THE TERMS SAY: Washington Gas's own meter data is described as coarser than electric interval data today, but the tracker notes that combined with an Exelon electric utility's smart-meter data, the two together could reconstruct home occupancy patterns, with no privacy policy covering that cross-company combination.\nWHY IT MATTERS: A DMV household's gas and electric providers are separate companies, so no single privacy policy addresses what their combined data reveals about when someone is home.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is company-specific and substantive: arbitration is affirmatively stated as absent (a positive fact, not a troubling term), fees are not itemized, and the generic smart-meter paragraph shared with every other utility in this tab is already covered by the cross-company data-reconstruction point above.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration is affirmatively confirmed as absent, but fees were not itemized and the SCARY item is analytical reasoning rather than a confirmed company policy.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Washington Gas  <-  AltaGas Ltd. (Calgary, Canada)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Washington Gas takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed specific to Washington Gas this pass. The distinguishing feature is that gas utilities have historically collected far coarser data than electric ones - a gas meter does not produce appliance-level signatures the way 15-minute electrical interval data does, which is what made the Naperville analysis possible. That gap is closing as gas smart metering deploys. For a DMV household, the practical reality is that Washington Gas and an Exelon electric utility together see enough to reconstruct occupancy patterns with confidence, and no single privacy policy covers the combination because they are separate companies.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Power Utilities (MD-VA-DC)", "_row_id": 254, "_entity_id": 401, "_entity_slug": "washington-gas", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Yahoo Mail", "Category": "Email Provider", "Terms & Conditions URL": "yahoo.com/legal/terms/utos/utos-173.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "yahoo.com/legal/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "THE LARGEST DATA BREACH IN INTERNET HISTORY BY RECORD COUNT: Yahoo disclosed a series of breaches (2013-2016) that ultimately affected ALL 3 BILLION Yahoo accounts worldwide — exposing usernames, passwords, email addresses, phone numbers, dates of birth, and security questions/answers. Yahoo reportedly either failed to detect the 2013 breach for TWO YEARS or knew of it and intentionally delayed disclosure; it did not notify users of the 2013 breach until December 2016. An initial $50 million settlement was REJECTED by a federal judge as inadequate, leading to a revised $117.5 MILLION settlement covering account holders (including Yahoo Sports, Finance, Tumblr, and Flickr users) between Jan 2012 and Dec 2016 — offering 2 years of credit monitoring OR a cash payment (estimated $100–$358 with documentation, roughly $8 for undocumented 'alternative compensation' claimants in a 2026 residual distribution). SEPARATE, NEW 2025 CLASS ACTION (Caplan v. Yahoo, S.D.N.Y.): alleges Yahoo's 'ConnectID' technology secretly tracks users across the internet by using their email addresses as a persistent identifier, functioning as a workaround specifically designed to defeat privacy protections meant to PREVENT this kind of cross-site tracking — a technically sophisticated, ongoing tracking allegation distinct from the historical breach.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Yahoo (now part of Apollo Global Management after Verizon sold in 2021) ToS. 30-day opt-out. The 2013 (3B accounts) and 2014 (500M accounts) breaches are the largest consumer data breaches in history — the arbitration clause was in effect at the time and applied to breach-related disputes. The $117.5M class settlement was possible because the court found the arbitration clause did not cover the specific claims raised.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The 3-billion-account figure makes this the single largest breach BY RECORD COUNT found anywhere in this entire audit (Meta's RTB case was described as potentially 'the biggest breach ever' by scale of ongoing harm, but Yahoo's 3 billion affected ACCOUNTS is a larger raw number) — worth flagging as a genuine historical superlative, distinct from the newer ConnectID tracking allegation which is an entirely separate, still-unresolved matter.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://en.wikipedia.org/wiki/Yahoo_data_breaches", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Apollo Global Management (acquired from Verizon Media Group, 2021)", "Years Referenced in Finding (heuristic)": "2013, 2014", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Apollo Global Management (acquired from Verizon Media Group, 2021)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 3 billion accounts breached 2013-2016; disclosure was delayed roughly two years\nWHAT THE TERMS SAY: Yahoo disclosed breaches from 2013-2016 that ultimately affected all 3 billion Yahoo accounts, exposing usernames, passwords, emails, phone numbers, birthdates and security Q&As; Yahoo reportedly either failed to detect the 2013 breach for two years or knew of it and intentionally delayed disclosure until December 2016.\nWHY IT MATTERS: This remains the largest breach by record count in internet history per the tracker, and passwords were hashed with MD5, already considered broken at the time, leaving highly reusable credentials exposed for years before users were told.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-2] SEC fined Yahoo $35M for the two-year disclosure delay; users' share worked out to about 4 cents each\nWHAT THE TERMS SAY: The SEC found Yahoo senior managers and attorneys were told about the 2014 breach and the company failed to fully investigate or disclose it to investors for more than two years, surfacing only as Verizon's acquisition was closing; Yahoo paid $35 million to the SEC, $117.5 million to users, $80 million to shareholders and $29 million from former executives, roughly $226.5 million total.\nWHY IT MATTERS: Per the tracker's own math, users' collective share of that total works out to about four cents per compromised account, showing how little of the penalty reached the people whose data was actually exposed.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with a class-action waiver covers Yahoo accounts, with a 30-day opt-out\nWHAT THE TERMS SAY: Yahoo's ToS, now under Apollo Global Management after Verizon's 2021 sale, requires binding arbitration with a class-action waiver and a 30-day opt-out window; the tracker notes the 2013 and 2014 breaches occurred while this clause was in effect and applied to breach-related disputes, though the $117.5M class settlement went forward because the court found the clause did not cover the specific claims raised.\nWHY IT MATTERS: Users who don't opt out within 30 days give up the right to sue individually or join a class action over most future disputes with Yahoo, even though this particular settlement escaped the clause on a technicality.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Breach scope, SEC penalty figures, and arbitration terms are all documented with specific dates and dollar amounts.", "Exposure Score (0-100)": 44, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Yahoo Mail  <-  Apollo Global Management (acquired from Verizon Media Group, 2021)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Yahoo Mail you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:41:23Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Three billion accounts - every Yahoo account in existence - taken across breaches in 2013 and 2014, still the largest breach by record count in internet history. The part that should land harder than the number is the concealment: the SEC found that Yahoo senior managers and attorneys were told about the 2014 breach and the company failed to fully investigate, and it was not disclosed to the investing public for more than two years, surfacing only as Verizon's acquisition was closing. Yahoo paid $35 million to the SEC for that disclosure failure, $117.5 million to users, $80 million to shareholders and $29 million from former executives - roughly $226.5 million total, of which the users' share works out to about four cents per compromised account. Passwords had been hashed with MD5, which was already considered broken.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Email Providers", "_row_id": 255, "_entity_id": 403, "_entity_slug": "yahoo-mail", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Apple iCloud Mail", "Category": "Email Provider", "Terms & Conditions URL": "apple.com/legal/internet-services/icloud/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "apple.com/legal/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "STRUCTURAL DIFFERENCE FROM PRIVACY-FOCUSED PROVIDERS: Apple encrypts iCloud Mail IN TRANSIT between devices, but Apple itself HOLDS THE DECRYPTION KEYS and can scan content for safety purposes — unlike ProtonMail/Tuta, which use client-side (zero-knowledge) encryption Apple cannot access even if legally compelled. This matters legally: iCloud Mail falls under US privacy law plus federal surveillance authority including FISA orders and the CLOUD Act, which specifically allows US agencies to compel data from global subsidiaries of American companies REGARDLESS of where the physical servers are located or which country's privacy law would otherwise apply — a structural legal-access point that does not exist for Switzerland-based providers like ProtonMail.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — governed by Apple's iCloud Terms and Conditions, which contain no arbitration clause and no class action waiver (confirmed from apple.com/legal/internet-services/icloud/ this session). Disputes governed by California law, Santa Clara County courts. Consistent with Apple's company-wide no-arbitration posture across all consumer products.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The CLOUD Act's cross-border reach is a genuinely important structural fact for anyone choosing an email provider based on where they think their data is physically stored — an American company's FOREIGN subsidiary/server location does not shield data from US legal demands the way choosing a genuinely FOREIGN company (like Switzerland-based ProtonMail) can.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$416.2B", "Market Cap": "$4.8T", "Employees": "164,000", "HQ City": "Cupertino", "HQ State": "California", "CEO": "Tim Cook", "Ticker": "AAPL", "Website (Corporate)": "apple.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AAPL). Service route: c/o General Counsel / Corporate Secretary, Cupertino, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Apple Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Apple Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Apple holds the keys to iCloud Mail and can be compelled to hand over content under FISA/the CLOUD Act\nWHAT THE TERMS SAY: Unlike Proton or Tuta's client-side encryption, Apple encrypts iCloud Mail in transit but retains the decryption keys itself and can scan content for safety purposes; this exposes the service to US surveillance authority including FISA orders and the CLOUD Act, which can compel data from a US company's global subsidiaries regardless of physical server location.\nWHY IT MATTERS: A government order can obtain the actual content of iCloud Mail messages in a way that isn't possible with a zero-knowledge encrypted provider, and storing mail overseas doesn't change that, since the CLOUD Act reaches American companies' foreign servers too.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one distinct troubling practice is documented (Apple's custodial-key encryption model and CLOUD Act exposure); the row's arbitration and monetization facts are stated as points in Apple's favor, not troubling terms.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Arbitration terms were independently confirmed from Apple's own iCloud ToS this session, and the encryption architecture is clearly described.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Apple iCloud Mail  <-  Apple Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Apple iCloud Mail takes nothing from the list this tracker checks - but 10 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:41:26Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Apple's structural position is worth recording accurately rather than flattering: iCloud Mail is encrypted in transit and at rest, but Apple holds the keys, which is a materially weaker guarantee than the end-to-end model Proton and Tuta use. That means Apple can produce message contents in response to a valid legal order in a way Proton cannot. Apple also does not monetise mail content for advertising, which genuinely distinguishes it from Yahoo, AOL and the free webmail tier generally. Both things are true at once, and the consumer takeaway is that 'Apple is the private one' is correct against ad-funded providers and incorrect against end-to-end ones.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Email Providers", "_row_id": 256, "_entity_id": 404, "_entity_slug": "apple-icloud-mail", "_issuer": "Apple Inc.", "_issuer_slug": "apple-inc", "_ticker": "AAPL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "AOL Mail", "Category": "Email Provider", "Terms & Conditions URL": "aol.com/tos.html (or a similarly named legal page under Yahoo/AOL's shared parent company)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "aol.com/privacy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "AOL Mail shares its PARENT COMPANY with Yahoo (both historically under Verizon, now under a private-equity-linked holding structure) and shares similar underlying privacy concerns, including ADVERTISERS being permitted to scan AOL/Yahoo accounts to 'identify and segment potential customers by picking up on contextual buying signals, and past purchases' per privacy researchers. AOL has its OWN separate breach history distinct from Yahoo's: a 2006 SEARCH LOGS DATA LEAK (AOL published 20 million search queries from 650,000 users, later widely cited as a landmark privacy failure since search histories could often be traced back to identifiable individuals) and a separate 2014 DATA BREACH. AOL.com's website security posture is also flagged by researchers as using a WEAK Content Security Policy and an 'unsafe-url' referrer policy — technical security gaps distinct from the account-level breaches.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. AOL is now part of Yahoo (both owned by Apollo Global Management). Same terms as Yahoo Mail. 30-day opt-out.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "AOL Mail accounts are automatically DEACTIVATED after 90 days of inactivity and DELETED after 180 days — relevant if any customer relies on an old AOL address for account recovery/verification purposes elsewhere, since the address could disappear entirely after 6 months of disuse.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] AOL published 20 million search queries from 650,000 users in 2006, often traceable to individuals\nWHAT THE TERMS SAY: AOL published roughly 20 million search queries from 650,000 users in a widely cited 2006 leak, and search histories could often be traced back to identifiable individuals; AOL also had a separate data breach in 2014.\nWHY IT MATTERS: Search-query histories can reveal deeply personal information, and the tracker treats this as a landmark privacy failure distinct from AOL's later 2014 breach.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] AOL applies the same mandatory arbitration and class-action waiver as Yahoo, 30-day opt-out\nWHAT THE TERMS SAY: AOL, now part of Yahoo under Apollo Global Management, applies the same mandatory binding arbitration and class-action waiver terms as Yahoo Mail, with a 30-day opt-out.\nWHY IT MATTERS: AOL users inherit Yahoo's dispute-resolution terms, requiring an active 30-day opt-out to preserve the right to sue or join a class action.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[TERMINATION_CONFISCATION · FL-4] Inactive AOL accounts are deactivated after 90 days and deleted after 180 days\nWHAT THE TERMS SAY: AOL Mail accounts are automatically deactivated after 90 days of inactivity and deleted after 180 days.\nWHY IT MATTERS: Anyone relying on an old AOL address for account recovery or identity verification elsewhere could lose access to it, and the address itself, after just six months of disuse.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=Y; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Breach history, the account retention/deletion policy, and arbitration terms are all specifically dated and quantified in the tracker.", "Exposure Score (0-100)": 43, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 4/20 (termination_or_confiscation+4) | Record 11/20 (severity3+8, breach+3) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "AOL Mail  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using AOL Mail you gave up your data shared corporate-wide, your right to sue, your right to join a class action, and your right to keep what you paid for. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "AOL and Yahoo share a corporate history and, for a period under Verizon, a parent - which means AOL Mail users inherited the consequences of decisions made about a different product entirely. AOL retains a substantial base of long-tenured users who have held the same address for two decades or more, and that is precisely the population for whom an email account has become an identity anchor: it is the recovery address for banking, medical portals and everything else. The longer an address is held, the higher the switching cost and the more consequential a breach, and neither factor appears anywhere in the terms.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Email Providers", "_row_id": 257, "_entity_id": 405, "_entity_slug": "aol-mail", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Proton Mail", "Category": "Email Provider (privacy-focused)", "Terms & Conditions URL": "proton.me/legal/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "proton.me/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "GENUINELY DIFFERENT STRUCTURAL MODEL from most providers in this tab: Proton Mail uses CLIENT-SIDE (zero-knowledge) encryption with keys the USER controls, meaning even Proton itself — and, per the company's own marketing, even the Swiss government — cannot access email content without the user's password. Proton is based in Switzerland, operating under the Swiss Federal Data Protection Act, which provides stronger restrictions on government data access than most other jurisdictions covered in this tracker. IMPORTANT CAVEAT worth independently verifying before treating Proton as fully independent: one source in this research raised that Proton was partly FUNDED BY THE EU, which the source frames as a legitimate question about the company's independence — this claim was not independently confirmed this pass and should be verified directly before repeating it.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Proton AG (Geneva, Switzerland) ToS governed by Swiss law. No US-style arbitration clause or class action waiver. Disputes go to the courts of Geneva. Proton's privacy-first positioning is reinforced by its legal structure — Swiss law provides stronger privacy protections than US law, and the lack of an arbitration clause means disputes over Proton's privacy commitments can be litigated publicly rather than resolved behind closed doors.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The key trade-off for Proton (per multiple independent comparisons) is that IF a user forgets their password, ProtonMail's zero-knowledge design means even Proton CANNOT recover the account/data — the same architecture that provides strong privacy also removes the typical 'company resets your password' safety net most other providers in this tab offer.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2021", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] A binding order from Swiss authorities compelled Proton to log one account's IP and browser fingerprint\nWHAT THE TERMS SAY: In 2021, acting on a French request routed through Europol, Swiss authorities issued a binding order and Proton was compelled to begin logging and hand over the IP address and browser fingerprint for one account tied to a climate activist collective; Proton could not appeal, and arrests followed in France.\nWHY IT MATTERS: Zero-knowledge encryption protects message content but not metadata: Proton can be legally forced to start logging identifying technical details about a specific targeted user going forward, which is exactly what happened here.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one distinct troubling practice is documented (the 2021 compelled-metadata-logging order); the row's other Proton-specific content is either favorable (no arbitration clause, client-side encryption) or an explicitly unverified claim (possible EU funding) that the tracker itself warns not to repeat without independent confirmation.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The 2021 compelled-logging case and its 2021 Swiss court ruling outcome are both documented with specific dates and legal posture.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Proton Mail  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Proton Mail takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:41:31Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Proton's 2021 case is the most instructive entry in this tab because it shows precisely where a privacy promise ends. Swiss authorities, acting on a French request routed through Europol, issued a legally binding order; Proton was compelled to begin logging and hand over the IP address and browser fingerprint for one account tied to a climate activist collective, and arrests followed in France. Proton could not appeal. What it could not hand over was message content - the end-to-end encryption held, which is the promise that actually matters. Proton then rewrote its privacy policy to state the limitation explicitly, and in October 2021 won a Swiss ruling that email services are not telecommunications providers and are therefore exempt from telecom data-retention requirements. Recorded fairly: the marketing overstated, the technical guarantee held, and the company litigated to narrow the gap.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Email Providers", "_row_id": 258, "_entity_id": 406, "_entity_slug": "proton-mail", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Zoho Mail", "Category": "Email Provider (business-focused)", "Terms & Conditions URL": "zoho.com/mail/tou.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "zoho.com/privacy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Zoho's stated business model is subscription revenue, not advertising — Zoho publicly states it does not run an ad network and does not sell customer data, positioning this as a competitive differentiator against Google Workspace and Microsoft 365. Zoho Mail does not scan message content for ad targeting. Indian jurisdiction (DPDP Act 2023) governs; Zoho maintains data centers in multiple regions including the EU and India, allowing customers to select data residency.", "Arbitration / Class Action Waiver": "NO US-STYLE MANDATORY ARBITRATION identified for consumer accounts. Zoho Corporation is Indian-headquartered (Chennai) with US operations in Austin, Texas. Indian jurisdiction means Zoho is subject to India's Digital Personal Data Protection Act (DPDP Act, 2023) rather than to US federal surveillance law — Zoho is not directly subject to US National Security Letters. Specific ToS dispute-resolution clause NOT independently fetched this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Zoho's self-funded, non-VC-backed ownership structure is a genuine point of difference worth noting against most other companies in this tracker, many of which are owned by, or answerable to, large public parent corporations or private equity.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Chennai", "HQ State": "India", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Chennai, India (non-US)", "Parent / Ultimate Owner": "Zoho Corporation Pvt. Ltd. (Chennai, India)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (India) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in India. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] Zoho's actual dispute-resolution clause was not independently verified this pass\nWHAT THE TERMS SAY: The tracker states no US-style mandatory arbitration was identified for Zoho consumer accounts, but notes the specific ToS dispute-resolution clause was not independently fetched this pass; Zoho is governed by India's 2023 DPDP Act rather than US federal privacy law.\nWHY IT MATTERS: Without the actual clause confirmed, users can't be certain whether disputes go to court, arbitration, or another forum, or which country's consumer protections would apply.\n(evidence: Arbitration / Class Action Waiver | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item rises above 'not confirmed': Zoho's stated business model (no ads, no data sale) and self-funded ownership are documented as points in its favor, not troubling terms, and no breach, penalty, or litigation is recorded for this row.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The SCARY field and arbitration field both flag unconfirmed or not-fetched status, so the row is largely a synthesis of business-model claims rather than confirmed terms.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Zoho Mail  <-  Zoho Corporation Pvt. Ltd. (Chennai, India)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Zoho Mail takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:41:33Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Zoho's distinguishing structural feature is that it is privately held and India-headquartered with substantial US operations, and it explicitly does not run an advertising business - which removes the single largest incentive for content scanning that shapes the free webmail tier. Zoho Mail is also frequently used by small businesses for custom-domain email, which puts it in scope for this tracker's small-business mission in a way most consumer webmail is not. Recommend a follow-up on which jurisdiction governs data for US business customers and on India's DPDP Act as it takes effect.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Email Providers", "_row_id": 259, "_entity_id": 408, "_entity_slug": "zoho-mail", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "GMX Mail", "Category": "Email Provider", "Terms & Conditions URL": "gmx.com/general/gmx-terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "gmx.com/general/gmx-privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "GMX's free tier is ad-supported, meaning advertising is the revenue mechanism for free accounts — but under GDPR, ad personalization requires a lawful basis and GMX must honor GDPR data-subject rights (access, erasure, portability, objection) that have no US federal equivalent. German data-protection supervision is handled by the relevant state DPA. This is the same GDPR-vs-US-privacy-policy structural difference documented for Clue (Berlin) in cross-cutting finding #28.", "Arbitration / Class Action Waiver": "NO US-STYLE MANDATORY ARBITRATION — GMX is operated by 1&1 Mail & Media (United Internet AG, Germany) and governed by German law. German/EU jurisdiction means GDPR applies as the operative privacy framework, and disputes go to German courts rather than to AAA/JAMS arbitration. Specific ToS NOT independently fetched this pass.", "Fees / Billing Flags": "Free-tier ads and attachment-size caps are the main trade-off noted by independent reviewers, not a billing/fee issue in the traditional sense.", "Notes": "Recommend a direct follow-up given thin verification this pass; GDPR coverage is a genuine structural positive worth noting relative to non-EU providers in this tab.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Montabaur", "HQ State": "Germany", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Montabaur, Germany (non-US)", "Parent / Ultimate Owner": "1&1 Mail & Media GmbH (United Internet AG)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Germany) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Germany. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] GMX's free tier is ad-supported, keeping a content-monetization incentive despite GDPR coverage\nWHAT THE TERMS SAY: GMX's free accounts are advertising-supported, meaning ad personalization is the revenue mechanism; GDPR requires a lawful basis for that personalization and gives users access, erasure, portability and objection rights with no direct US equivalent, but the tracker notes GDPR constrains how the data may be processed without removing the underlying business reason to want it.\nWHY IT MATTERS: Free GMX users are still subject to a monetization incentive around their account data; GDPR limits what can be done with it but doesn't eliminate why GMX wants it in the first place.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-3] GMX's specific Terms of Service were not independently fetched this pass\nWHAT THE TERMS SAY: The tracker states GMX is governed by German law, with disputes going to German courts rather than AAA/JAMS arbitration, but notes the specific ToS was not independently fetched this pass.\nWHY IT MATTERS: Without the underlying document confirmed, details like data retention periods or the exact dispute-resolution language remain unverified for users deciding whether to trust the free tier.\n(evidence: Arbitration / Class Action Waiver; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Two items found; the row records no breach, penalty, or litigation, and the German/GDPR jurisdictional facts are stated favorably, not as troubling terms.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Both the arbitration/ToS field and the SCARY field note the underlying documents were not independently fetched this pass.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "GMX Mail  <-  1&1 Mail & Media GmbH (United Internet AG)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, GMX Mail takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. GMX is operated by United Internet, a German company, alongside Mail.com - the same parent behind two brands that appear as separate rows in this tab and would be assessed identically. German and EU data protection law applies, which is a real advantage over US free webmail on paper, but GMX's free tier is advertising-supported, so the monetisation incentive that drives content-adjacent data use is present regardless of jurisdiction. GDPR constrains how that data may be processed; it does not remove the business reason to want it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Email Providers", "_row_id": 260, "_entity_id": 411, "_entity_slug": "gmx-mail", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Tutanota (Tuta)", "Category": "Email Provider (privacy-focused)", "Terms & Conditions URL": "tuta.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "tuta.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Tuta is end-to-end encrypted by default — message bodies, subject lines, attachments, contacts, and calendar entries are encrypted client-side so Tuta cannot read them even under legal compulsion. What Tuta CAN see is metadata: account creation date, login IP addresses (Tuta states it strips and does not log these), and message timestamps. German jurisdiction plus E2E encryption is the most privacy-protective combination in this tab. Tuta has publicly reported receiving and contesting German court orders, and has documented cases where it was compelled to log future incoming mail for specific accounts — meaning E2E protects historical content but a court can compel prospective monitoring.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Tuta is a German company governed by German law and GDPR. Disputes go to German courts. Tuta's model is end-to-end encrypted email: the provider cannot read message contents, subject lines, or contacts because they are encrypted client-side. This is the email equivalent of 1Password's zero-knowledge architecture documented in the Productivity tab.", "Fees / Billing Flags": "Free tier storage is limited (roughly 1GB per some comparisons) relative to Gmail/Yahoo/AOL's much larger free tiers — a real usability trade-off for the added privacy.", "Notes": "Given the open-source, publicly-auditable code and subject-line encryption, Tuta is a genuine standout among the more privacy-protective options in this tab — worth distinguishing from providers that merely market themselves as 'secure' without the same technical transparency.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Hanover", "HQ State": "Germany", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Hanover, Germany (non-US)", "Parent / Ultimate Owner": "Tutao GmbH (Hanover, Germany)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Germany) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Germany. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] German courts have compelled Tuta to log future incoming mail for specific accounts\nWHAT THE TERMS SAY: Tuta has publicly reported receiving and contesting German court orders and has documented cases where it was compelled to log future incoming mail for specific accounts; end-to-end encryption protects historical content, but the tracker notes a court can compel prospective monitoring going forward.\nWHY IT MATTERS: Even with subject-line and body encryption, a German court order can force Tuta to start capturing metadata about a targeted account's future mail, something end-to-end encryption alone doesn't prevent.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one distinct troubling practice is documented, the compelled prospective-logging exposure; everything else in the row (the E2E architecture, no arbitration clause, limited free-tier storage) is framed as a trade-off or a positive, not a troubling term.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The encryption architecture and the compelled-logging pattern are both described with concrete detail, even though exact case counts aren't given.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Tutanota (Tuta)  <-  Tutao GmbH (Hanover, Germany)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Tutanota (Tuta) takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:41:39Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass in the sense of a breach or penalty. The finding that matters for Tuta is the same one that defines Proton: a German provider is subject to German court orders, and the relevant question is not whether the company would resist but what it is technically capable of producing when it cannot. Tuta encrypts subject lines as well as bodies, which is a genuine technical step beyond several competitors, since a subject line often carries the substance. The honest framing for this whole category is that end-to-end encryption protects content and does not protect metadata, and metadata - who, when, how often, from where - is frequently what an investigator actually wants.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Email Providers", "_row_id": 261, "_entity_id": 413, "_entity_slug": "tutanota-tuta", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fastmail", "Category": "Email Provider", "Terms & Conditions URL": "fastmail.com/about/tos/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "fastmail.com/about/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Fastmail's business model is paid subscriptions only — no free ad-supported tier, no advertising, no content scanning for ad targeting. Fastmail states it does not sell user data. JURISDICTION CAVEAT: Australia's Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 ('TOLA' / the 'Assistance and Access Act') can compel Australian providers to assist law enforcement, and Australia is a Five Eyes member. Fastmail has publicly discussed this legislation. So while Fastmail's commercial data practices are more protective than ad-supported providers, its jurisdiction is not equivalent to Germany's or Switzerland's for compulsion-resistance purposes.", "Arbitration / Class Action Waiver": "NO US-STYLE MANDATORY ARBITRATION identified — Fastmail is an Australian company governed by Australian law. Australian Consumer Law provides statutory guarantees that cannot be waived by contract. Specific ToS dispute-resolution clause NOT independently fetched this pass.", "Fees / Billing Flags": "No free tier is available — unlike most other providers in this tab, using Fastmail requires a paid subscription from the start.", "Notes": "The 'we don't need to monetize your data because you're already paying us' business model is a meaningful structural distinction worth flagging — similar in spirit to Apple's general privacy positioning (hardware/subscription revenue rather than ads) but applied specifically to email.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Melbourne", "HQ State": "Australia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Melbourne, Australia (non-US)", "Parent / Ultimate Owner": "Fastmail Pty Ltd (Melbourne, Australia)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Australia) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Australia. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Australia's Assistance and Access Act can compel Fastmail to help law enforcement despite its no-ads model\nWHAT THE TERMS SAY: Fastmail is an Australian company subject to the Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018, which can compel Australian providers to assist law enforcement; Australia is also a Five Eyes intelligence-sharing member. The tracker notes Fastmail has publicly discussed this legislation.\nWHY IT MATTERS: Paying for Fastmail removes the advertising incentive to analyze mail, but it doesn't change the jurisdiction: Australian law gives authorities technical-assistance powers with no direct EU equivalent.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one distinct troubling item exists, the TOLA Act/Five Eyes jurisdictional exposure; the row's other content (paid-only model, no ad monetization, Australian Consumer Law guarantees) is stated favorably, and the specific ToS dispute-resolution clause was not independently fetched.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The TOLA Act exposure is clearly documented, but the specific ToS dispute-resolution clause was not independently fetched this pass.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Fastmail  <-  Fastmail Pty Ltd (Melbourne, Australia)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Fastmail takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:41:42Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Fastmail's structural position is distinctive and worth recording plainly: it is Australian, paid-only with no free advertising-supported tier, and therefore has no business model that benefits from analysing customer mail. The countervailing fact is jurisdictional - Australia's Telecommunications and Other Legislation Amendment (Assistance and Access) Act gives authorities powers to compel technical assistance that have no direct equivalent in the EU, and Australia is a Five Eyes member. Paying for a service removes the advertising incentive; it does not remove the jurisdiction. Both belong in an honest assessment.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Email Providers", "_row_id": 262, "_entity_id": 415, "_entity_slug": "fastmail", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Mail.com", "Category": "Email Provider", "Terms & Conditions URL": "mail.com/int/company/terms/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "mail.com/int/company/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Ad-supported free tier under GDPR. Mail.com and GMX share the same operator (1&1 Mail & Media GmbH), meaning a consumer who switches from GMX to Mail.com for privacy reasons has changed brands but not companies — the same pattern documented for Trulia/Zillow, Aldi/Trader Joe's, and the UnitedHealthcare subsidiary cluster elsewhere in this tracker.", "Arbitration / Class Action Waiver": "NO US-STYLE MANDATORY ARBITRATION — same 1&1 Mail & Media / United Internet operator as GMX, governed by German law and GDPR. Mail.com and GMX are sibling services under one parent, a corporate-family relationship a consumer choosing between them would not see from the branding.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Same corporate family as GMX (1&1/United Internet) — worth treating both as related entities for purposes of any cross-provider pattern rather than fully independent companies.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Montabaur", "HQ State": "Germany", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Montabaur, Germany (non-US)", "Parent / Ultimate Owner": "1&1 Mail & Media GmbH (United Internet AG)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Germany) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Germany. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Mail.com and GMX are the same company under different brands, invisible to users choosing between them\nWHAT THE TERMS SAY: Mail.com and GMX are both operated by 1&1 Mail & Media GmbH (United Internet AG); a consumer switching from GMX to Mail.com for privacy reasons changes brands but not the company or its practices, a relationship not apparent from the branding.\nWHY IT MATTERS: Anyone treating Mail.com as an independent alternative to GMX for diversification or privacy reasons is actually staying with the same operator and the same underlying practices.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one distinct troubling item is found, the undisclosed shared-operator relationship with GMX; the row otherwise describes an ordinary ad-supported, GDPR-governed free tier with no confirmed breach, penalty, or litigation specific to Mail.com.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The shared-operator relationship with GMX is clearly stated, but fees were not itemized and the underlying ToS was not independently fetched this pass.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Mail.com  <-  1&1 Mail & Media GmbH (United Internet AG)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Mail.com you gave up your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:41:43Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Mail.com shares its United Internet parent with GMX, so the two rows describe one company's practices under two brands - noted here to prevent a reader treating them as independent data points. Mail.com's free tier is advertising-supported and it markets a large selection of vanity domains, which historically attracts throwaway and secondary-account use. That matters for risk assessment in an underappreciated way: people apply less scrutiny to the terms of an account they consider disposable, and then use it as a recovery address anyway.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Email Providers", "_row_id": 263, "_entity_id": 416, "_entity_slug": "mail-com", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Yandex Mail", "Category": "Email Provider", "Terms & Conditions URL": "yandex.com/legal/rules/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "yandex.com/legal/confidential/en/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED INSIDER BREACH (2021): Yandex disclosed that an EMPLOYEE had been providing unauthorized access to users' email accounts 'for personal gain' — a malicious-insider incident rather than an external hack, affecting over 4,000 accounts. STRUCTURAL DATA-JURISDICTION FLAG: Yandex's own privacy policy explicitly states that for Russian users, personal data is stored on servers located WITHIN RUSSIA, and confirms Russia is a jurisdiction the European Commission has NOT recognized as providing 'adequate' data protection under EU standards — Yandex relies on Standard Contractual Clauses to justify EU-to-Russia data transfers for non-Russian users. Yandex's OWN privacy materials state email correspondence can only be accessed 'on the basis of an official court order' under Russian law, though independent verification of how consistently this is honored (especially amid Russia's post-2022 legal environment) was not possible this pass. SEPARATE 2023 SOURCE-CODE LEAK: ~45GB of Yandex's internal source code was leaked, revealing (for the first time to outside researchers) the internal workings of Yandex's user-analytics tools (Metrika) and behavioral-analytics engine (Crypta) — confirming, rather than merely speculating about, the scale of behavioral data Yandex collects and processes on its users.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected, though Russian jurisdiction means US-style consumer arbitration frameworks likely don't apply the same way as for US-based providers in this tab.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Given Yandex's Russian ownership/jurisdiction and the 2023 source-code leak occurring during the Russia-Ukraine war, any customer choosing this provider should weigh the data-sovereignty implications distinctly from the more typical US/EU privacy considerations that apply to most other providers in this tab.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2021", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] A Yandex employee gave unauthorized access to over 4,000 user mailboxes in 2021\nWHAT THE TERMS SAY: Yandex disclosed that an employee had been providing unauthorized access to users' email accounts 'for personal gain,' a malicious-insider incident rather than an external hack, affecting over 4,000 accounts.\nWHY IT MATTERS: Insider access bypasses the encryption and perimeter defenses that consumer security marketing usually focuses on, and no privacy policy protects against an employee willing to sell access.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] A 2023 leak of Yandex's source code exposed the scale of its Metrika/Crypta behavioral-tracking tools\nWHAT THE TERMS SAY: Roughly 45GB of Yandex's internal source code was leaked in 2023, revealing for the first time to outside researchers the internal workings of Yandex's user-analytics tool (Metrika) and behavioral-analytics engine (Crypta), confirming rather than merely speculating about the scale of behavioral data Yandex collects and processes on users.\nWHY IT MATTERS: This moved Yandex's behavioral data collection from rumor to documented fact, giving outside researchers concrete visibility into how extensively user behavior is tracked and processed.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[NO_DISCLOSURE_THICK_FOG · FL-3] Whether Yandex still limits email access to court orders is unverifiable in Russia's post-2022 legal climate\nWHAT THE TERMS SAY: Yandex's own privacy materials state email correspondence can only be accessed 'on the basis of an official court order' under Russian law, but the tracker notes independent verification of how consistently this is honored, especially amid Russia's post-2022 legal environment, was not possible this pass; Russian user data is stored within Russia, a jurisdiction the European Commission has not recognized as adequate, and Yandex relies on Standard Contractual Clauses to justify EU-to-Russia transfers for non-Russian users.\nWHY IT MATTERS: A stated legal-access policy is only as reliable as the surrounding legal system's enforcement, and the tracker is explicit that this couldn't be checked given current conditions in Russia.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2021 breach and 2023 source-code leak are specifically confirmed, but arbitration terms and current legal-access practices remain unverified this pass.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Yandex Mail  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Yandex Mail takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Yandex disclosed in 2021 that an EMPLOYEE with privileged access had been providing unauthorised access to user mailboxes - an insider incident rather than an external intrusion, and a category that no amount of encryption-in-transit addresses. Insider access is the failure mode that consumer-facing security marketing almost never discusses, because the controls that would prevent it are internal and invisible. Layered on top is jurisdiction: Yandex operates under Russian law, including data-localisation requirements and state access provisions, which means the governing question for a non-Russian user is not the privacy policy but which state can compel what.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Email Providers", "_row_id": 264, "_entity_id": 417, "_entity_slug": "yandex-mail", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Mail.ru", "Category": "Email Provider", "Terms & Conditions URL": "mail.ru (Terms of Service not individually located as direct URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "mail.ru (Privacy Policy not individually located as direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Same broad category as Yandex above — both were named together in a purported 2022 leak (later assessed by researchers as mostly a recompilation of older, previously-leaked credential lists rather than a fresh breach) affecting nearly 5 million accounts across Yandex, Mail.ru, and other Russian email services combined. Mail.ru operates under the same Russian data-localization/jurisdiction considerations as Yandex (see that row).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend treating Mail.ru similarly to Yandex for data-sovereignty purposes given the shared Russian jurisdiction — recommend a direct follow-up on Mail.ru's specific current corporate ownership and Terms given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Mail.ru operates under Russia's SORM lawful-interception regime, per the tracker's cross-reference to Yandex\nWHAT THE TERMS SAY: Mail.ru is subject to the same Russian legal framework as Yandex: data localization requirements, SORM lawful-interception infrastructure, and state access provisions. The tracker states any privacy rights nominally granted are unenforceable in practice for a US or EU user, making the published policy close to irrelevant as a decision input.\nWHY IT MATTERS: Whatever Mail.ru's written privacy policy promises, the tracker's assessment is that Russian state access provisions override it for practical purposes.\n(evidence: SCARY | Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one distinct item is substantiated, the shared Russian-jurisdiction/SORM exposure identical to the Yandex row's structural finding; the tracker explicitly downgrades the 2022 credential dataset to a recompilation of old leaks rather than a fresh breach, and arbitration terms and current ownership were not independently confirmed this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration terms, current ownership, and the breach claim itself are all unconfirmed or explicitly downgraded this pass.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Mail.ru  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Mail.ru takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Named alongside Yandex in a purported credential dataset, and subject to the same Russian legal framework - data localisation requirements, SORM lawful-interception infrastructure, and state access provisions that no terms of service can contract around. The assessment here is identical to Yandex and is recorded as one structural finding rather than two independent ones. For a US or EU user, any privacy rights nominally granted by these services are unenforceable in practice, which makes the published policy close to irrelevant as a decision input.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Email Providers", "_row_id": 265, "_entity_id": 418, "_entity_slug": "mail-ru", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Hushmail", "Category": "Email Provider (privacy-focused)", "Terms & Conditions URL": "hushmail.com/legal/terms-of-service/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "hushmail.com/legal/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Hushmail markets encrypted email with HIPAA-compliant plans for healthcare providers, meaning it operates as a HIPAA business associate for covered entities — a compliance posture most consumer email providers do not offer. HISTORICAL CAVEAT worth stating: Hushmail's architecture is server-side encryption for webmail sessions, and Hushmail has previously complied with a court order to produce decrypted messages for specific accounts. This is materially different from Tuta's client-side E2E model, where the provider does not hold the key at all.", "Arbitration / Class Action Waiver": "NO US-STYLE MANDATORY ARBITRATION identified — Hushmail is Canadian (Vancouver), subject to PIPEDA rather than US federal surveillance law, and therefore not directly subject to US National Security Letters. Same Canadian jurisdiction advantage documented for 1Password and Cohere. Specific ToS NOT independently fetched this pass.", "Fees / Billing Flags": "HIPAA-compliant plans carry a meaningfully higher price point than general consumer email — a cost consideration for any healthcare-provider customer specifically, distinct from typical consumer email pricing.", "Notes": "Hushmail's HIPAA/healthcare specialization is a genuinely distinct niche among the providers in this tab — most relevant to healthcare-adjacent organizations (like BMHC, if it ever needs HIPAA-compliant email for maternal-health-related communications) rather than general consumer use.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Vancouver", "HQ State": "Canada", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Vancouver, Canada (non-US)", "Parent / Ultimate Owner": "Hush Communications Canada Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Canada) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Canada. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Hushmail's server-side encryption let it comply with a court order to decrypt messages for specific accounts\nWHAT THE TERMS SAY: Hushmail's architecture uses server-side encryption for webmail sessions rather than client-side end-to-end encryption, and the tracker notes Hushmail has previously complied with a court order to produce decrypted messages for specific accounts, materially different from Tuta's model where the provider never holds the key at all.\nWHY IT MATTERS: Because Hushmail holds the decryption keys, a valid court order can obtain actual message content, a guarantee gap that matters most for the healthcare and legal professionals the service specifically markets to.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one distinct troubling item is substantiated, the server-side encryption and historical court-order compliance; the SCARY field explicitly declines to assert Hushmail's broader compulsion reputation since it wasn't independently verified this pass, and no breach, penalty, or arbitration clause is recorded.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The server-side-encryption/court-order fact is stated plainly, but the row explicitly declines to verify Hushmail's broader compulsion reputation, and the ToS was not independently fetched.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Hushmail  <-  Hush Communications Canada Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Hushmail takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing independently confirmed this pass, and this is a row where restraint matters: Hushmail has a long-circulating reputation in privacy circles relating to legal compulsion and its server-side encryption model, but this pass did not verify the underlying facts, so none are asserted. What can be said structurally is that Hushmail's architecture has historically involved server-side key handling for its webmail interface, which is a materially different guarantee from client-side end-to-end encryption - and Hushmail markets substantially to healthcare and legal professionals handling third-party confidential information. Recommend a direct follow-up before publishing anything about this provider.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Email Providers", "_row_id": 266, "_entity_id": 420, "_entity_slug": "hushmail", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Visa", "Category": "Card Network", "Terms & Conditions URL": "usa.visa.com/legal/terms-of-service.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "usa.visa.com/legal/global-privacy-notice.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not itemized separately from the antitrust findings below.", "Arbitration / Class Action Waiver": "MASSIVE, 21-YEAR ANTITRUST CASE (In re Payment Card Interchange Fee and Merchant Discount Antitrust Litigation, MDL 1720, filed 2005): merchants allege Visa/Mastercard/issuing banks conspired to FIX INTERCHANGE (swipe) FEES; a Nov 2025 proposed settlement (still pending final court approval as of mid-2026) would trim credit interchange rates by 10 basis points for 5 years, impose a capped 1.25% rate on standard consumer cards for 8 years, and give merchants new rights to surcharge and to accept different card categories (commercial/premium/standard) selectively — covering roughly 12 MILLION US MERCHANTS and aiming to end litigation dating to 2005. SEPARATELY, the DOJ filed its OWN civil antitrust suit against Visa specifically (Sept 2024, still active) alleging Visa illegally monopolized US DEBIT NETWORK markets in violation of the Sherman Act — a distinct, government-brought case running in parallel to the merchant-driven MDL. A separate $231.7 MILLION settlement (Oct 2025, B & R Supermarket v. Visa) resolved merchant claims over costs from counterfeit/lost/stolen card fraud, with Visa paying $119.7M and Mastercard paying $79.8M of that total. In Europe, a new April 2026 UK High Court claim alleges Visa's European interchange fees are an unlawful competition restriction dating back to 2019.", "Fees / Billing Flags": "The interchange-fee cost ultimately gets passed through to CONSUMERS via merchant pricing — while consumers aren't direct parties to most of this litigation, the settlement's surcharging changes and rate caps directly affect what merchants can charge card-paying customers going forward.", "Notes": "This litigation (spanning 21 years, multiple billion-dollar-scale settlements, and a live DOJ monopolization suit) is one of the longest-running, most consequential antitrust sagas found anywhere in this entire audit — the interchange fees at its center are baked into the price of nearly every card transaction most consumers make.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$40.0B", "Market Cap": "$667.7B", "Employees": "31,600", "HQ City": "San Francisco", "HQ State": "California", "CEO": "Ryan McInerney", "Ticker": "V", "Website (Corporate)": "visa.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (V). Service route: c/o General Counsel / Corporate Secretary, San Francisco, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.alston.com/en/insights/publications/2024/04/merchant-plaintiffs-reach-settlement", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Visa Inc.", "Years Referenced in Finding (heuristic)": "2005, 2026, 2024, 2023, 2009", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Visa Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] 21-year interchange-fee antitrust case set to cut card fees embedded in nearly every purchase\nWHAT THE TERMS SAY: The MDL 1720 case, filed in 2005, alleges Visa, Mastercard and issuing banks conspired to fix interchange (swipe) fees; a November 2025 proposed settlement, still pending final court approval as of mid-2026, would cut the credit interchange rate by 10 basis points for five years, cap standard consumer cards at 1.25% for eight years, and give merchants new rights to surcharge or decline certain card categories, covering roughly 12 million US merchants.\nWHY IT MATTERS: US swipe fees on Visa and Mastercard credit alone reached $111.2 billion in 2024, up from $100.8 billion in 2023, and those costs are built into shelf prices, meaning every consumer pays them, including people who pay cash, whether or not they are a party to the case.\n(evidence: Arbitration / Class Action Waiver | Fees | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-1] DOJ sued Visa in Sept 2024 alleging it illegally monopolized the US debit-network market\nWHAT THE TERMS SAY: The DOJ filed its own civil antitrust suit against Visa in September 2024, still active, alleging Visa illegally monopolized US debit network markets in violation of the Sherman Act, a government-brought case running in parallel to the merchant-driven MDL 1720 litigation.\nWHY IT MATTERS: This is a separate government case from the merchant settlement, meaning Visa's debit-network practices face continuing legal exposure even after the 21-year interchange-fee litigation resolves.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[PENDING_LITIGATION · FL-3] A new April 2026 UK lawsuit alleges Visa's European interchange fees violate competition law back to 2019\nWHAT THE TERMS SAY: A new UK High Court claim filed in April 2026 alleges Visa's European interchange fees are an unlawful competition-law restriction dating back to 2019, separate from the US merchant MDL and DOJ cases.\nWHY IT MATTERS: Visa faces overlapping interchange-fee litigation across multiple jurisdictions simultaneously, US merchants, a separate US government suit, and now a UK claim, indicating its fee practices are being challenged as unlawful in more than one legal system at once.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The interchange-fee litigation, DOJ suit, and related settlements are documented with specific dates, dollar figures, and court findings.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Visa  <-  Visa Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Visa takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:41:50Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The merchant antitrust litigation began in June 2005, grew to cover roughly 12 million merchants, and only reached an approved settlement in June 2026 - twenty-one years. Judge Brodie rejected an earlier $30 billion deal in 2024, finding the roughly $6 billion in annual merchant savings 'paltry' relative to what the networks could still charge. The revised settlement cuts the combined average effective credit interchange rate by 10 basis points for five years, caps standard consumer cards at 1.25% for eight years, and finally lets merchants decline categories of cards rather than obeying the honor-all-cards rule. Context for the scale: US swipe fees on Visa and Mastercard credit alone reached $111.2 billion in 2024, up from $100.8 billion in 2023 and roughly quadruple 2009. Those fees are built into shelf prices, so every consumer pays them, including the ones paying cash.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Credit Card Companies", "_row_id": 267, "_entity_id": 422, "_entity_slug": "visa", "_issuer": "Visa Inc.", "_issuer_slug": "visa-inc", "_ticker": "V", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Mastercard", "Category": "Card Network", "Terms & Conditions URL": "mastercard.us/en-us/vision/corp-responsibility/terms-of-use.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "mastercard.us/en-us/vision/corp-responsibility/privacy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not itemized separately from the antitrust findings below.", "Arbitration / Class Action Waiver": "SAME MDL 1720 interchange-fee litigation as Visa (see Visa row) — Mastercard is a co-defendant throughout, including the pending Nov 2025 settlement and the $79.8M share of the separate $231.7M card-fraud-cost settlement (B & R Supermarket v. Visa). SEPARATE, ONGOING April 2026 case (Potayto-Potahto, LLC v. Visa/Mastercard, S.D.N.Y.): a new class action asserting the same underlying federal antitrust theory as MDL 1720, filed AGAINST BOTH networks jointly — indicating merchants continue filing fresh interchange-related claims even as the original 2005 case nears a possible resolution.", "Fees / Billing Flags": "Same consumer pass-through dynamic as Visa — interchange fees affect the prices merchants charge all customers, cardholders and non-cardholders alike.", "Notes": "Mastercard was NOT named in the DOJ's Sept 2024 debit-network monopolization suit (that case targets Visa specifically) — worth noting this as a point of DIFFERENCE between the two networks, even though they're joint defendants in most of the merchant-driven interchange litigation.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$32.8B", "Market Cap": "$461.6B", "Employees": "35,300", "HQ City": "Purchase", "HQ State": "New York", "CEO": "Michael Miebach", "Ticker": "MA", "Website (Corporate)": "mastercard.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (MA). Service route: c/o General Counsel / Corporate Secretary, Purchase, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026, 2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] Mastercard co-defends the long-running MDL 1720 interchange case (filed 2005); the settlement adds new merchant surcharge rights\nWHAT THE TERMS SAY: Mastercard is a co-defendant with Visa throughout the MDL 1720 interchange-fee case, including the pending November 2025 settlement (a 10-basis-point rate cut for five years, a 1.25% cap on standard cards for eight years, and new merchant surcharge/card-category rights) and a $79.8M share of the separate $231.7M card-fraud-cost settlement in B & R Supermarket v. Visa.\nWHY IT MATTERS: The settlement's new surcharge rights mean the cost of premium rewards cards, historically buried in prices charged to all customers including those carrying no card at all, may start showing up directly at the register.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (firewall-edited: unverifiable figure removed) (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] A new April 2026 case accuses both Visa and Mastercard of the same interchange-fee antitrust conduct\nWHAT THE TERMS SAY: A new April 2026 case, Potayto-Potahto, LLC v. Visa/Mastercard (S.D.N.Y.), asserts the same underlying federal antitrust interchange-fee theory as MDL 1720, filed jointly against both networks, meaning merchants continue filing fresh claims even as the 2005 case nears resolution.\nWHY IT MATTERS: Mastercard's interchange-fee legal exposure isn't ending with the MDL 1720 settlement; new litigation on the same theory is already underway.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Two items found; Mastercard's exclusion from the DOJ's Visa-specific debit-monopolization suit is a stated point of difference but is a mitigating fact, not a troubling term, so a third item was not manufactured from it.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Case names, dollar figures, and settlement terms are specifically documented for Mastercard's role in the interchange litigation.", "Exposure Score (0-100)": 4, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Mastercard  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Mastercard takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Co-defendant with Visa in the same twenty-one-year merchant antitrust case, resolved on the same terms approved in June 2026. The provision worth understanding as a consumer is the surcharge right: merchants now have materially expanded ability to add a surcharge for higher-cost cards or discount lower-cost payment methods, which means the cost of your rewards card is about to become visible at the register rather than buried in everyone's prices. Premium rewards cards carry the highest interchange - Amex raised its Platinum annual fee to $895 and Chase raised Sapphire Reserve to $795 in 2025 - and those rewards were always funded by fees merchants recovered from all customers, including people carrying no card at all.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Credit Card Companies", "_row_id": 268, "_entity_id": 423, "_entity_slug": "mastercard", "_issuer": "Mastercard", "_issuer_slug": "mastercard", "_ticker": "MA", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "American Express", "Category": "Card Network/Issuer", "Terms & Conditions URL": "americanexpress.com/en-us/legal-disclosures/us-cardmember-agreements/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "americanexpress.com/en-us/privacy-center/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not itemized separately from the antitrust finding below.", "Arbitration / Class Action Waiver": "$17.5 MILLION SETTLEMENT (2026) over 'ANTI-STEERING' merchant rules: American Express's merchant agreements allegedly prevented retailers (including Walmart, Target, Home Depot, CVS, Walgreens, Kroger, and Best Buy) from encouraging customers to pay with LOWER-FEE cards (i.e., a basic Visa/Mastercard/Discover instead of Amex) — plaintiffs argued this kept prices artificially high for ALL customers, including non-Amex cardholders, since merchants had to price in Amex's higher fees uniformly rather than passing savings through when a cheaper card was used. Notably, A JURY FOUND DAMAGES ONLY FOR THE ILLINOIS CLASS specifically ($12.5M jury verdict for that state) — the jury did NOT find antitrust violations under federal law or under the laws of the other 8 states with certified classes, illustrating how the same underlying conduct can be found unlawful in one state's law but not another's, or under federal law generally.", "Fees / Billing Flags": "Only Illinois-based holders of NON-REWARDS, NO-ANNUAL-FEE Visa/Mastercard/Discover cards used at qualifying merchants between 2015/2016–2022 qualify for an actual payment; debit-card holders in 8 other states are bound by the settlement but receive NO payment — a notable example of a settlement class receiving a legal release without corresponding compensation.", "Notes": "This is a genuinely unusual case where the DEFENDANT (Amex) is a different company than the CARDS actually held by most of the people affected (Visa/Mastercard/Discover users) — worth being precise about this structure since it could otherwise read as a case against Visa/Mastercard/Discover themselves, when it is not.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$72.2B", "Market Cap": "$238.0B", "Employees": "75,100", "HQ City": "New York", "HQ State": "New York", "CEO": "Stephen Squeri", "Ticker": "AXP", "Website (Corporate)": "americanexpress.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AXP). Service route: c/o General Counsel / Corporate Secretary, New York, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2018", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-3] Amex's anti-steering rules led to a 2026 settlement, but a jury found damages only for the Illinois class\nWHAT THE TERMS SAY: American Express's merchant agreements allegedly prevented major retailers (Walmart, Target, Home Depot, CVS, Walgreens, Kroger, Best Buy) from encouraging customers to pay with lower-fee cards, keeping prices higher for all customers including non-Amex cardholders. A 2026 $17.5 million settlement resulted, but a jury found damages only for the Illinois class specifically ($12.5M jury verdict for that state); it did not find antitrust violations under federal law or the laws of the other eight states with certified classes.\nWHY IT MATTERS: The same alleged conduct was found unlawful under Illinois law but not under federal law or eight other states' laws, and only Illinois holders of non-rewards, no-annual-fee Visa/Mastercard/Discover cards used at qualifying merchants between 2015/2016 and 2022 actually qualify for payment; debit-card holders in the other eight states are bound by the settlement release but receive no payment.\n(evidence: Arbitration / Class Action Waiver | Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DISCRIMINATORY_PRACTICE · FL-1] Amex's anti-steering rules survived Supreme Court review in 2018, so the merchant fight moved elsewhere\nWHAT THE TERMS SAY: The tracker states Amex is both the network and the issuer, charges the highest merchant fees in the market, and has historically enforced anti-steering rules preventing merchants from encouraging customers toward cheaper payment methods, a practice the Supreme Court declined to condemn in the 2018 Ohio v. American Express decision, finding plaintiffs failed to show net harm across the two-sided platform.\nWHY IT MATTERS: The tracker's consumer-facing translation is that the reason you rarely see a cash discount at the counter is a contract you are not party to — Amex's anti-steering rules, which the Supreme Court declined to condemn in 2018, after which the merchant fight moved to Visa and Mastercard and to legislation instead.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Two items found. The debit-card holders in the eight non-Illinois states who are release-bound but receive no payment is a real consequence already captured within the anti-steering settlement item rather than treated as a separate finding, since it stems from the same underlying case.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The settlement amount, jury verdict figures, qualifying dates, and named merchants are all specifically documented.", "Exposure Score (0-100)": 8, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "American Express  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, American Express takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Amex's structural position is different from Visa and Mastercard: it is both the network and the issuer, it charges the highest merchant fees in the market, and it has historically enforced anti-steering rules preventing merchants from encouraging customers toward cheaper payment methods - a practice the Supreme Court declined to condemn in the 2018 Ohio v. American Express decision, which held that the plaintiffs had failed to show net harm across the two-sided platform. That ruling is why the merchant fight moved to Visa and Mastercard and to legislation instead. The consumer-facing translation: the reason you rarely see a cash discount at the counter is a contract you are not party to.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Credit Card Companies", "_row_id": 269, "_entity_id": 424, "_entity_slug": "american-express", "_issuer": "American Express", "_issuer_slug": "american-express", "_ticker": "AXP", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Discover Financial Services", "Category": "Card Network/Issuer", "Terms & Conditions URL": "discover.com/credit-cards/member-agreement/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "discover.com/company/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not itemized separately from the antitrust findings below.", "Arbitration / Class Action Waiver": "Discover is REFERENCED (not a defendant) in the American Express anti-steering settlement above — Discover cardholders in Illinois are part of the compensable class in that case, but Discover itself is not accused of wrongdoing there. HISTORICALLY, Discover was itself a PLAINTIFF in a separate, earlier antitrust suit against Visa (alleging a Visa bylaw and Mastercard's 'CPP' policy improperly blocked banks from also issuing Discover cards, harming Discover's ability to compete) — a notable role-reversal where Discover was the one alleging harm from Visa/Mastercard's market practices, distinct from the merchant-driven interchange cases against Visa/Mastercard elsewhere in this tab.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Discover's MERGER WITH CAPITAL ONE was announced (2024) and remains a major ongoing development in the card-network industry — if completed, this would combine a major card issuer (Capital One, already documented in the Banks/Brokerages tabs of this tracker) with one of only four major US card networks, worth monitoring given the scale of consolidation involved.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$17.5B", "Market Cap": "Non-public", "Employees": "21,000", "HQ City": "Riverwoods", "HQ State": "Illinois", "CEO": "Michael Shepherd", "Ticker": "Non-public", "Website (Corporate)": "discover.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (Non-public). Service route: c/o General Counsel / Corporate Secretary, Riverwoods, Illinois — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://topclassactions.com/lawsuit-settlements/closed-settlements/1-2b-discover-credit-card-merchant-interchange-fee-class-action-settlement/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Discover Financial Services (pending acquisition by Capital One, announced Feb 2024)", "Years Referenced in Finding (heuristic)": "2007, 2023, 2026, 2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Discover Financial Services (pending acquisition by Capital One, announced Feb 2024)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] Discover misclassified 5 million+ consumer cards as commercial for 17 years, overcharging merchants\nWHAT THE TERMS SAY: Discover misclassified more than five million consumer credit cards as commercial cards from 2007 to 2023, pushing those transactions into a higher interchange tier and overcharging merchants roughly 1% on every affected sale; many of those merchants were small family-owned businesses. The settlement is $1.225 billion with at least $540 million going to class members, a $10 minimum payment, and a claim deadline of May 18, 2026. Discover's then-CEO publicly acknowledged in July 2023 that the episode revealed weaknesses in risk management and oversight, and resigned shortly after; the SEC opened an investigation.\nWHY IT MATTERS: This was a 17-year, five-million-card misclassification that quietly raised costs for small merchants who had no way to detect the error themselves, and it triggered both a CEO resignation and an SEC investigation.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[OTHER · FL-1] Capital One is moving debit transactions onto Discover's network, which escapes Durbin Amendment fee caps\nWHAT THE TERMS SAY: Capital One completed its $35.3 billion acquisition of Discover in May 2025 and began migrating debit transactions onto the Discover network, which the tracker notes is exempt from the Durbin Amendment interchange caps that bind Visa and Mastercard.\nWHY IT MATTERS: Moving debit volume onto a network exempt from federal interchange-fee caps could mean higher embedded costs on debit transactions than the capped Visa/Mastercard rate, ultimately reflected in merchant pricing.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Two items found. Discover's historical role as a plaintiff against Visa's bylaws is a role-reversal worth noting but isn't a troubling practice by Discover itself, and its reference-only (not defendant) status in the Amex anti-steering settlement doesn't add a distinct company-specific finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The misclassification episode and settlement are documented with specific dates, dollar figures, and a claims deadline.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Discover Financial Services  <-  Discover Financial Services (pending acquisition by Capital One, announced Feb 2024)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Discover Financial Services takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:41:56Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Discover misclassified more than five million CONSUMER credit cards as commercial cards from 2007 to 2023 - seventeen years - which pushed those transactions into a higher interchange tier and overcharged merchants roughly 1% on every affected sale. Many of those merchants were small family-owned businesses paying a surcharge on a mistake nobody told them about. The settlement is $1.225 billion with at least $540 million going to class members, a $10 minimum payment, and a claim deadline of May 18, 2026. Discover's then-CEO publicly acknowledged in July 2023 that the episode revealed weaknesses in risk management and oversight, and resigned shortly after; the SEC opened an investigation. Capital One completed its $35.3 billion acquisition of Discover in May 2025 and began migrating debit transactions onto the Discover network - which is exempt from the Durbin Amendment interchange caps that bind Visa and Mastercard.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Credit Card Companies", "_row_id": 270, "_entity_id": 425, "_entity_slug": "discover-financial-services", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Synchrony Financial", "Category": "Card Issuer (private-label/store credit cards)", "Terms & Conditions URL": "synchrony.com/legal.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "synchrony.com/privacy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Synchrony is the largest issuer of PRIVATE-LABEL/STORE credit cards in the US (e.g., cards for Amazon, PayPal, CareCredit, Lowe's, and many other retail partners) — a structurally different business model from Visa/Mastercard/Amex/Discover, since Synchrony doesn't operate its own payment network but instead issues co-branded cards on behalf of hundreds of retail partners, meaning a single Synchrony privacy/security failure could simultaneously expose customer data tied to many different retailers' loyalty programs at once. Not independently confirmed this pass with a specific named lawsuit — recommend direct follow-up given Synchrony's unusually broad retail-partner footprint.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Synchrony's Cardholder Agreement. 60-day opt-out via written notice to PO Box 965012, Orlando FL 32896. Synchrony issues store credit cards for Amazon, Walmart, Lowe's, PayPal Credit, CareCredit, and 100+ other retailers — a single arbitration clause potentially affecting tens of millions of cardholders across brands. A consumer disputing a charge on their 'Walmart' or 'Amazon' store card is actually disputing with Synchrony under Synchrony's terms.", "Fees / Billing Flags": "Store/private-label credit cards (Synchrony's core business) are widely documented industry-wide for carrying SIGNIFICANTLY HIGHER interest rates than general-purpose cards (often 25–30%+ APR) — worth flagging as a structural cost concern distinct from privacy/data issues, particularly relevant to financial-empowerment-focused audiences.", "Notes": "Given Synchrony's role as the 'invisible' issuer behind many retailers' branded cards, a customer who has never heard of 'Synchrony' directly may still have significant financial exposure to the company through a retail card they associate only with the STORE brand, not Synchrony itself.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$9.7B", "Market Cap": "$23.7B", "Employees": "20,000", "HQ City": "Stamford", "HQ State": "Connecticut", "CEO": "Brian Doubles", "Ticker": "SYF", "Website (Corporate)": "synchrony.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 60, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (SYF). Service route: c/o General Counsel / Corporate Secretary, Stamford, Connecticut — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Connecticut' is a non-DMV US state", "Parent / Ultimate Owner": "Synchrony Financial", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Connecticut SOTS CONCORD — service.ct.gov/business/s/onlinebusinesssearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Synchrony Financial). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Synchrony's mandatory arbitration clause covers store cards for Amazon, Walmart, Lowe's and 100+ retailers at once\nWHAT THE TERMS SAY: Synchrony's Cardholder Agreement imposes mandatory binding arbitration with a class-action waiver, with a 60-day opt-out by written notice to a PO Box in Orlando, FL.\nWHY IT MATTERS: A consumer disputing a charge on a 'Walmart' or 'Amazon' store card is actually disputing with Synchrony under Synchrony's terms, so one clause potentially governs disputes across tens of millions of cardholders on many different-looking cards.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] Synchrony is the 'invisible' issuer behind retailer-branded cards, so disputes get misdirected to stores that can't act on them\nWHAT THE TERMS SAY: As the largest US issuer of private-label store cards, Synchrony issues, governs, reports to credit bureaus for, and collects on cards that carry a retailer's logo, while the consumer believes the relationship is with the store itself.\nWHY IT MATTERS: Customers who have never heard of Synchrony may have significant financial exposure through a card they associate only with the store, and disputes/data requests routinely go to the retailer, which cannot act on them.\n(evidence: SCARY | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[AUTO_RENEWAL_FEES · FL-1] Synchrony's core private-label card business carries store-card interest rates often cited at 25-30%+ APR\nWHAT THE TERMS SAY: Store/private-label credit cards, which are Synchrony's core business, are flagged as carrying significantly higher interest rates than general-purpose cards, often 25-30%+ APR.\nWHY IT MATTERS: Cardholders on retailer-branded Synchrony cards can face materially higher borrowing costs than they would on a general-purpose card, a structural cost distinct from any privacy issue.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration and fee terms are clearly stated, but no specific named lawsuit or breach was independently confirmed this pass.", "Exposure Score (0-100)": 27, "Exposure Band": "Low", "Sub: Dispute Rights /30": 22, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 22/30 (forced_arbitration+12, class_action_waiver+9, optout_60d+1) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Synchrony Financial  <-  Synchrony Financial", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Synchrony Financial you gave up your right to sue, your right to join a class action, and your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:42:00Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Synchrony is the largest issuer of private-label store credit cards in the US, and that is precisely the finding: the card with a retailer's logo on it is a Synchrony product, governed by Synchrony's terms, reported to credit bureaus by Synchrony, and collected on by Synchrony - while the consumer believes the relationship is with the store. Store cards also carry among the highest APRs in consumer credit and are frequently sold at the register during a purchase, which is close to the worst possible moment to evaluate a credit agreement. The misattribution matters practically: disputes, data requests and complaints routinely go to the retailer, which cannot act on them.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Credit Card Companies", "_row_id": 271, "_entity_id": 426, "_entity_slug": "synchrony-financial", "_issuer": "Synchrony Financial", "_issuer_slug": "synchrony-financial", "_ticker": "SYF", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Hertz", "Category": "Car Rental (also owns Dollar, Thrifty)", "Terms & Conditions URL": "hertz.com/rentacar/global/en_US/termsAndConditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "hertz.com/rentacar/global/en_US/privacyPolicy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED THIRD-PARTY VENDOR BREACH (2024-2025): Hertz confirmed customer data (across its Hertz, Dollar, and Thrifty brands) was accessed by an unauthorized third party that exploited ZERO-DAY VULNERABILITIES in a file-transfer platform run by Cleo Communications, a vendor Hertz used to move data between its own systems and third parties, during October and December 2024. Exposed data included names, DRIVER'S LICENSE NUMBERS, credit card information, and — notably — details related to WORKERS' COMPENSATION CLAIMS (an employee-adjacent data category, not typically found in a rental-car customer breach). Hertz did not publicly disclose the breach until April 2, 2025, months after confirming (Feb 2025) that its data had been compromised — the same 'delayed disclosure' pattern flagged for several other companies in this tracker (Sony/PSN, Marriott).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Hertz's Rental Terms and Conditions, AAA rules. 30-day opt-out. Covers all Hertz, Dollar, and Thrifty rentals (all Hertz Global Holdings brands). Hertz emerged from bankruptcy in 2021.", "Fees / Billing Flags": "Multiple class actions (Crawford v. Hertz Global Holdings, plus at least two others in Illinois/Florida federal courts) alleging negligence, breach of implied contract, and unjust enrichment — Hertz's own SEC filing confirms the parties reached a SETTLEMENT IN PRINCIPLE during mediation on March 12, 2026, pending court approval; final settlement terms/amount not yet available as of this research.", "Notes": "This is a clean, well-documented illustration of the 'breach originates through a third-party vendor, not the company's own systems' pattern already seen repeatedly elsewhere in this tracker (Target's HVAC vendor, Booking.com/Expedia's Prestige Software, Marriott, Chipotle's Workday) — Hertz's own statement explicitly confirms 'no evidence that Hertz's own network was affected.'", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$8.5B", "Market Cap": "$694.7M", "Employees": "26,000", "HQ City": "Estero", "HQ State": "Florida", "CEO": "Gil West", "Ticker": "HTZ", "Website (Corporate)": "hertz.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (HTZ). Service route: c/o General Counsel / Corporate Secretary, Estero, Florida — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "Hertz Global Holdings, Inc.", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Hertz Global Holdings, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Hertz confirmed a 2024-25 vendor breach exposed driver's license numbers and workers'-comp data, then delayed disclosure for months\nWHAT THE TERMS SAY: Hertz confirmed customer data across its Hertz, Dollar, and Thrifty brands was accessed via zero-day vulnerabilities in vendor Cleo Communications' file-transfer platform in October and December 2024, exposing names, driver's license numbers, credit card information, and workers'-compensation-claim details.\nWHY IT MATTERS: Hertz confirmed the compromise in February 2025 but did not publicly disclose it until April 2, 2025, leaving affected customers unaware and unable to protect themselves for months.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] A single mandatory arbitration clause with a 30-day opt-out covers all Hertz, Dollar, and Thrifty rentals\nWHAT THE TERMS SAY: Hertz's Rental Terms and Conditions impose mandatory binding arbitration under AAA rules with a class-action waiver, with a 30-day opt-out, covering all Hertz Global Holdings brands.\nWHY IT MATTERS: Customers renting under the Dollar or Thrifty name are bound by the same arbitration terms as Hertz itself, and must act within 30 days to preserve their right to sue.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[PENDING_LITIGATION · FL-2] Hertz reached a settlement in principle in multiple class actions, with terms and amount not yet available\nWHAT THE TERMS SAY: Multiple class actions (Crawford v. Hertz Global Holdings and at least two others) allege negligence, breach of implied contract, and unjust enrichment; Hertz's own SEC filing confirms a settlement in principle reached in mediation on March 12, 2026, pending court approval.\nWHY IT MATTERS: Affected customers do not yet know what compensation, if any, the settlement will provide, since final terms and amount are not yet available.\n(evidence: Fees; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach and arbitration terms are well documented, but Hertz delayed public disclosure for months and final settlement terms remain undisclosed.", "Exposure Score (0-100)": 31, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 7, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 7/20 (severity2+2, breach+3, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Hertz  <-  Hertz Global Holdings, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Hertz you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Hertz's 2024-25 exposure came through a third-party vendor, and rental car data is more revealing than the transaction suggests: a rental record ties a named person to a specific vehicle in a specific place on specific dates, and modern rental fleets are connected, generating telematics. Rental agreements also routinely capture a driver's licence scan and, for international renters, passport details. Cross-ref the Allstate/Arity finding in the Insurance tab for what happens to vehicle movement data once it leaves the vehicle.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Car Rental & Grocery-Restaurant", "_row_id": 272, "_entity_id": 428, "_entity_slug": "hertz", "_issuer": "Hertz Global Holdings, Inc.", "_issuer_slug": "hertz-global-holdings-inc", "_ticker": "HTZ", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Enterprise (Enterprise Holdings, incl. National, Alamo)", "Category": "Car Rental", "Terms & Conditions URL": "enterprise.com/en/help/legal/terms-of-use.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "enterprise.com/en/help/legal/privacy-statement.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or FTC action — recommend a direct follow-up given the strong data-breach pattern already established across the car-rental category in this tracker (Hertz's Cleo-vendor breach above; Avis's separate 2024 breach affecting ~300,000 customers via an unauthorized business-application access, referenced in Hertz breach coverage).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Enterprise's Terms of Use. Covers Enterprise, National Car Rental, and Alamo Rent A Car — all three brands under Enterprise Holdings (the largest rental car company in the world by fleet size and revenue). Single arbitration clause governs three brands that appear to be independent competitors.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Enterprise Holdings (privately held, unlike publicly traded Hertz) has a notably thinner public litigation/regulatory record in this research pass — this may reflect genuinely fewer incidents, or simply less public disclosure obligation as a private company; recommend a dedicated follow-up rather than assuming the thin record means a clean record.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Enterprise Holdings, Inc. (privately held, Taylor family)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] One arbitration clause governs Enterprise, National, and Alamo, brands that appear to be independent competitors\nWHAT THE TERMS SAY: Enterprise's Terms of Use impose mandatory binding arbitration with a class-action waiver, covering Enterprise, National Car Rental, and Alamo Rent A Car, all under Enterprise Holdings, the largest rental car company in the world by fleet size and revenue.\nWHY IT MATTERS: A customer choosing between Enterprise, National, or Alamo for price or service is not making any real choice about dispute rights, since a single clause governs all three brands.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] Enterprise, National, and Alamo are one company, and Enterprise dominates insurance-replacement rentals tied to accident claims\nWHAT THE TERMS SAY: Enterprise, National, and Alamo operate as a single company under Enterprise Holdings, and Enterprise is also described as the dominant provider of insurance-replacement rentals, meaning its records frequently tie a person to a specific accident date and insurance claim.\nWHY IT MATTERS: Customers who believe they are choosing between competing brands are in fact consolidating their driver's-license and rental history, including accident-linked records, with a single company.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data-sharing findings are 'not independently confirmed' and fees are 'not itemized' this pass; only the arbitration clause and the brand-consolidation structure are substantive enough to report, and the tracker itself calls the record 'unverified rather than clean.'", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No specific lawsuit, breach, or fee finding was independently confirmed this pass; the tracker explicitly flags Enterprise's thin public record as unverified rather than clean.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Enterprise (Enterprise Holdings, incl. National, Alamo)  <-  Enterprise Holdings, Inc. (privately held, Taylor family)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Enterprise (Enterprise Holdings, incl. National, Alamo) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. The structural note is brand consolidation: Enterprise, National and Alamo are one company, so a customer choosing between them for price or service made no choice at all about who holds their driver's licence scan and rental history. Enterprise is also the dominant provider of insurance-replacement rentals, which means its records frequently tie a person to a specific accident date and an insurance claim. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Car Rental & Grocery-Restaurant", "_row_id": 273, "_entity_id": 430, "_entity_slug": "enterprise-enterprise-holdings-incl-national-alamo", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Steak 'n Shake", "Category": "Restaurant", "Terms & Conditions URL": "steaknshake.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "steaknshake.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ACTIVE BIPA CLASS ACTION (Massel v. Steak N Shake Inc., N.D. Illinois): Steak 'n Shake introduced FACIAL-RECOGNITION SELF-ORDERING KIOSKS (from vendor PopID) in 2024 to speed up ordering and track loyalty rewards; the lawsuit alleges the chain collected customers' FACIAL GEOMETRY DATA without the written notice and consent Illinois' Biometric Information Privacy Act (BIPA) requires, and without publishing a legally required data retention/destruction policy. The complaint specifically emphasizes that facial geometry, unlike a password or even a Social Security number, is PERMANENT and cannot be changed if compromised. Plaintiff seeks to represent all Illinois customers whose biometric data was collected over the prior 5 years, with damages up to $5,000 per violation — potentially reaching into the millions given the kiosks' broad rollout. Illinois has since AMENDED BIPA so that repeated collections of the SAME biometric identifier from the SAME person via the SAME method now count as ONE violation rather than compounding per-scan, which may reduce (but not eliminate) the eventual damages exposure in this specific case.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is a clean, well-documented illustration of the growing wave of fast-food/restaurant BIPA litigation tied to facial-recognition ordering kiosks — worth flagging as an emerging pattern likely to affect other quick-service restaurants adopting similar kiosk technology.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] An active BIPA suit alleges Steak 'n Shake's facial-recognition kiosks scanned customers without required consent\nWHAT THE TERMS SAY: Massel v. Steak N Shake Inc. (N.D. Illinois) alleges the chain's PopID facial-recognition self-ordering kiosks, introduced in 2024, collected customers' facial geometry data without the written notice and consent Illinois' BIPA requires.\nWHY IT MATTERS: The complaint seeks to represent all Illinois customers whose biometric data was collected over the prior 5 years, with statutory damages up to $5,000 per violation, potentially reaching into the millions given the kiosks' broad rollout.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[RETENTION_PERIOD · FL-2] The BIPA suit also alleges Steak 'n Shake never published the retention/destruction policy the law requires for facial data\nWHAT THE TERMS SAY: The complaint specifically alleges Steak 'n Shake did not publish a legally required data retention/destruction policy for the facial geometry data collected at its kiosks.\nWHY IT MATTERS: Without a published retention policy, customers have no way to know how long their facial geometry data, which is permanent and cannot be changed if compromised, is kept.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration is unconfirmed ('standard...expected') and fees are 'not itemized' this pass; the SCARY field's discussion of employee biometric timeclocks is general industry context, not a Steak 'n Shake-specific finding, so only the BIPA kiosk allegations are reportable.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The BIPA kiosk lawsuit is well documented with a case name and court, but arbitration terms and fees are unconfirmed and only assumed to be standard.", "Exposure Score (0-100)": 16, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 6/30 (biometric_collection+6) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "Steak 'n Shake  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Steak 'n Shake you gave up your biometric identifiers. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The BIPA class action concerns fingerprint or facial timeclock systems - and this is the category worth understanding, because the plaintiffs in most restaurant BIPA cases are EMPLOYEES, not customers. Illinois requires informed written consent before collecting a biometric identifier, and a great many employers rolled out fingerprint timeclocks without it, on the reasonable-sounding theory that a punch-clock is an administrative tool rather than biometric collection. A worker cannot decline and keep the shift. Allegations, not findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Car Rental & Grocery-Restaurant", "_row_id": 274, "_entity_id": 431, "_entity_slug": "steak-n-shake", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Whole Foods Market (Amazon)", "Category": "Grocery", "Terms & Conditions URL": "wholefoodsmarket.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "wholefoodsmarket.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SETTLED BIPA CASE: Whole Foods (owned by Amazon since 2017) previously settled a biometric-privacy class action over its use of biometric technology in stores — specific settlement terms/amount not independently confirmed this pass, but the underlying legal theory (BIPA, facial/hand-geometry data collection without adequate notice/consent) matches the broader pattern of biometric-checkout/ordering litigation seen elsewhere in this tracker (Steak 'n Shake, Mercari). As an Amazon subsidiary, Whole Foods stores have also piloted 'Amazon One' palm-recognition payment technology and 'Just Walk Out' cashierless checkout systems in some locations, both of which involve biometric/continuous video tracking of shoppers — worth a direct follow-up on current opt-out mechanics for these specific technologies.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Whole Foods is an Amazon subsidiary, and Amazon removed its arbitration clause entirely in July 2021 after facing 75,000+ individual arbitration demands. Whole Foods' online ordering and delivery operate under Amazon's Conditions of Use. In-store purchases are governed by Whole Foods' own return/exchange policy, which does not include an arbitration clause.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up specifically on Amazon One palm-recognition and Just Walk Out cashierless checkout consent/opt-out mechanics given the settled BIPA history and the continuing rollout of new biometric technology in Whole Foods stores.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "PARENT ADDRESS ONLY — verify before using for legal notice. Whole Foods Market IP, L.P. is an Austin, Texas-headquartered subsidiary. Parent: Amazon.com, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210, USA", "Legal / Privacy Contact Email": "Not verified this pass — Amazon routes privacy requests through its in-account privacy portal", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Amazon.com, Inc.", "Years Referenced in Finding (heuristic)": "2017", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] Whole Foods settled one biometric-privacy suit while piloting Amazon One palm scans and cashierless tracking in stores\nWHAT THE TERMS SAY: Whole Foods previously settled a biometric-privacy class action over in-store biometric technology (settlement terms not confirmed this pass), and as an Amazon subsidiary has piloted Amazon One palm-recognition payment and 'Just Walk Out' cashierless checkout, both involving biometric or continuous video tracking of shoppers.\nWHY IT MATTERS: Current opt-out mechanics for Amazon One and Just Walk Out are not confirmed this pass, leaving unclear how shoppers can avoid biometric or continuous video tracking while shopping.\n(evidence: Data Sharing | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-2] Grocery purchases joined to an Amazon account and a biometric identifier form a very complete shopper profile\nWHAT THE TERMS SAY: Whole Foods has been owned by Amazon since 2017, and the row notes that grocery purchase history joined to an Amazon account joined to a biometric identifier produces a comprehensive consumer profile, with each data source added separately.\nWHY IT MATTERS: The tracker describes grocery purchase history joined to an Amazon account joined to a biometric identifier as the most complete consumer profile assembled anywhere in this tracker, with each piece added separately and reasonably.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Whole Foods has no mandatory arbitration clause, which is a pro-consumer fact rather than a troubling item, and the prior BIPA settlement's terms are unconfirmed, leaving two substantive items rather than three.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration status is clear (none), but the prior BIPA settlement's terms and current biometric opt-out mechanics for Amazon One/Just Walk Out are unconfirmed.", "Exposure Score (0-100)": 8, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 6/30 (biometric_collection+6) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "Whole Foods Market (Amazon)  <-  Amazon.com, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Whole Foods Market (Amazon) you gave up your biometric identifiers. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:42:11Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Whole Foods settled a BIPA case, and the row's more durable significance is ownership: Amazon acquired Whole Foods in 2017, and Amazon has piloted palm-recognition payment in its stores - cross-ref the Amazon One row in Travel & Transit Apps, where palm vein geometry is permanent and unreissuable. Grocery purchase history joined to an Amazon account joined to a biometric identifier is the most complete consumer profile assembled anywhere in this tracker, and each piece was added separately and reasonably.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Car Rental & Grocery-Restaurant", "_row_id": 275, "_entity_id": 432, "_entity_slug": "whole-foods-market-amazon", "_issuer": "Amazon.com, Inc.", "_issuer_slug": "amazon-com-inc", "_ticker": "AMZN", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Safeway (Albertsons)", "Category": "Grocery", "Terms & Conditions URL": "albertsons.com/terms-of-use.html (Albertsons/Safeway share corporate Terms)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "albertsons.com/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Safeway is one of 22 grocery banners (alongside Albertsons, Vons, Jewel-Osco, ACME, Shaw's, and others) operated by parent company Albertsons Companies, which explicitly discloses in its own 2026 SEC filing that it collects customer TRANSACTION AND ENGAGEMENT DATA through loyalty programs/digital platforms 'to support personalized offers, targeted marketing, and enhanced customer experiences' as well as internal merchandising/pricing/promotional decisions — a candid, company-acknowledged data-driven pricing/marketing model spanning 2,244 stores across 35 states.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "$5.95 MILLION SETTLEMENT (2026): Albertsons, Safeway, and related store banners settled claims that they sent UNSOLICITED MARKETING TEXT MESSAGES and, notably, CONTINUED TEXTING some consumers even AFTER THEY HAD OPTED OUT — the 'kept texting after opt-out' allegation is a more serious violation than simple unsolicited marketing, since it suggests the company's own opt-out mechanism either failed or was not honored.", "Notes": "The internal note about data-driven 'pricing and promotional decisions' (from Albertsons' own SEC filing) is worth flagging alongside Delta's 'surveillance pricing' finding (Consumer Apps tab) as part of a broader pattern of companies using customer data to personalize PRICES, not just marketing content — a practice that raises fairness questions distinct from traditional privacy concerns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] Albertsons/Safeway paid $5.95 million to settle claims it kept texting customers even after they opted out\nWHAT THE TERMS SAY: Albertsons, Safeway, and related banners settled claims for $5.95 million (2026) over sending unsolicited marketing text messages and continuing to text some consumers even after they had opted out.\nWHY IT MATTERS: Continuing to text after opt-out suggests the company's own opt-out mechanism either failed or was not honored, a more serious violation than simple unsolicited marketing.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SURVEILLANCE_PRICING · FL-2] Albertsons' SEC filing discloses loyalty data feeds personalized offers and internal pricing decisions\nWHAT THE TERMS SAY: Albertsons' 2026 SEC filing discloses it collects transaction and engagement data through loyalty programs and digital platforms to support personalized offers, targeted marketing, and internal merchandising/pricing/promotional decisions across 2,244 stores in 35 states.\nWHY IT MATTERS: The company itself acknowledges that loyalty-program and digital-platform data supports personalized offers and targeted marketing as well as its internal merchandising, pricing and promotional decisions, across 2,244 stores in 35 states.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] Safeway's 22-banner loyalty system places prescription records alongside grocery purchase history under Albertsons\nWHAT THE TERMS SAY: Safeway is one of 22 grocery banners (including Albertsons, Vons, Jewel-Osco, Acme, and Shaw's) sharing one loyalty infrastructure, and Albertsons also operates in-store pharmacies, placing prescription records alongside loyalty purchase history.\nWHY IT MATTERS: Switching between Safeway, Vons, or Jewel-Osco changes only the sign on the building, not the underlying data holder, and prescription records sit alongside the same loyalty profile as grocery purchases.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Data-driven pricing is confirmed via Albertsons' own SEC filing and the texting settlement is concrete, but arbitration terms are unconfirmed this pass.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Safeway (Albertsons)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Safeway (Albertsons) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "2026-09-08T19:42:14Z (HTTP 200, SHRANK)", "SCARY (most astonishing T&C item)": "Safeway is one of 22 grocery banners under Albertsons, which is the finding for a Mid-Atlantic shopper: Safeway, Vons, Jewel-Osco, Acme and the rest are one company with one loyalty infrastructure, so switching banners changes the sign on the building and nothing else. Albertsons also operates in-store pharmacies, which places prescription records alongside loyalty purchase history - the same combination flagged in the Kroger row. Grocery consolidation means the DMV has effectively three grocery data holders, not a dozen.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Car Rental & Grocery-Restaurant", "_row_id": 276, "_entity_id": 433, "_entity_slug": "safeway-albertsons", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Costco", "Category": "Online/Retail (membership warehouse)", "Terms & Conditions URL": "costco.com/terms-of-sale.html (or costco.com/terms-and-conditions.html for membership terms)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "costco.com/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ACTIVE CLASS ACTION (California, 2023-ongoing): four California plaintiffs allege Costco shared their ONLINE ACTIVITY AND HEALTH INFORMATION with Meta via the Meta/Facebook Pixel WITHOUT DISCLOSING this practice, despite the company assuring customers of data confidentiality/security — alleged to breach Washington State's specific privacy law prohibiting unauthorized sharing of user data (Costco is headquartered in Washington State). Meta itself, while not a named defendant, publicly stated its policies PROHIBIT advertisers from sending sensitive personal information through its Business Tools — meaning if the allegations are accurate, Costco's own implementation would have violated Meta's stated policy in addition to the state privacy law claim.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is the same Meta Pixel/health-data pattern documented for Kroger above and multiple other companies throughout this tracker (BetterHelp, GoodRx, MyFitnessPal, Chick-fil-A) — worth treating as one connected cross-industry finding rather than isolated incidents at each company.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$275.2B", "Market Cap": "$411.2B", "Employees": "333,000", "HQ City": "Issaquah", "HQ State": "Washington", "CEO": "Ron Vachris", "Ticker": "COST", "Website (Corporate)": "costco.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (COST). Service route: c/o General Counsel / Corporate Secretary, Issaquah, Washington — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Costco Wholesale Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Costco Wholesale Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Costco is accused of sharing customers' online activity and health information with Meta without disclosure\nWHAT THE TERMS SAY: An active California class action (2023-ongoing) alleges Costco shared customers' online activity and health information with Meta via the Meta/Facebook Pixel without disclosing the practice, allegedly violating Washington State's privacy law.\nWHY IT MATTERS: Meta itself has stated its policies prohibit advertisers from sending sensitive personal information through its Business Tools, meaning if the allegations are accurate, Costco's own implementation would have violated Meta's stated policy as well as state law.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration is unconfirmed and fees are 'not itemized' this pass; only the Meta Pixel health-data allegation is substantive, and it remains an allegation, not a confirmed finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Only the Meta Pixel health-data allegation is documented this pass; arbitration and fees remain unconfirmed.", "Exposure Score (0-100)": 21, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 11, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 11/30 (data_sold_or_shared_for_value+8, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Costco  <-  Costco Wholesale Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Costco you gave up your personal data sold onward. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The California class action alleges Costco's website shared customer activity with third parties in ways members did not agree to - and the reason it lands harder than the same allegation against an ordinary retailer is the membership model. Costco's proposition is explicitly that you pay an annual fee INSTEAD of being the product; the membership fee is the business model, and members reasonably read it as buying them out of the surveillance economy. Allegations, not findings. Costco also settled independently in the Visa/Mastercard interchange litigation rather than accepting the class settlement - cross-ref the Credit Card Companies tab.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Online Retailers (Top 10)", "_row_id": 277, "_entity_id": 312, "_entity_slug": "costco", "_issuer": "Costco Wholesale Corporation", "_issuer_slug": "costco-wholesale-corporation", "_ticker": "COST", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "The Home Depot", "Category": "Online/Retail (home improvement)", "Terms & Conditions URL": "homedepot.com/c/Terms_of_Use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "homedepot.com/privacy/privacy-and-security-statement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MOST EXTENSIVELY DOCUMENTED SURVEILLANCE-RELATED FINDINGS OF ANY COMPANY IN THIS TAB: (1) Home Depot's OWN 2026 proxy statement acknowledges it uses AUTOMATED LICENSE PLATE RECOGNITION (ALPR) cameras at stores and participates in the FLOCK SAFETY camera network — the same network reporting has directly linked to federal IMMIGRATION ENFORCEMENT (ICE) accessing driver location data through secret arrangements with local police departments, per Reuters/Bloomberg/404 Media reporting cited in Home Depot's own filing. TWO SEPARATE 2026 California class actions (McGinity, filed March; Schmierer, filed May) allege Home Depot's ALPR use violates California's specific ALPR privacy law and invades shopper privacy — split by a December 2025 policy change Home Depot made mid-stream. (2) Canada's Privacy Commissioner found (2023) that Home Depot shared E-RECEIPT DATA with Meta without valid consent. (3) An Illinois BIPA class action alleged Home Depot's SELF-CHECKOUT facial recognition cameras violated the state's biometric privacy law (this specific case was reportedly later DISMISSED, per a company shareholder filing — worth noting the outcome differs from the still-active ALPR cases). (4) Separate class actions allege Home Depot embedded 'SESSION REPLAY' software that 'intentionally intercepted' users' electronic communications (2023), secretly let GOOGLE 'wiretap' customer service calls without consent (2024), and embedded hidden tracking technology in MARKETING EMAILS (2024).", "Arbitration / Class Action Waiver": "A THIRD-PARTY SaaS VENDOR breach exposed private data of ~10,000 Home Depot EMPLOYEES; Senators Blumenthal and Markey formally called on the FTC to investigate whether Home Depot's security procedures meet a 'reasonable standard,' citing this breach as well as an EARLIER, much larger breach that exposed 60 MILLION customers to potential fraud. Home Depot's own 2026 proxy statement explicitly acknowledges a GOVERNANCE GAP: it depends on VENDOR-MANAGED surveillance networks and audit reports 'without independent verification,' which the filing itself states 'may create governance gaps that fail to detect risks of data misuse.'", "Fees / Billing Flags": "Not itemized separately from the above.", "Notes": "Home Depot's own securities filings candidly acknowledging governance gaps in vendor-managed surveillance is a rare instance in this entire audit of a company's OWN disclosure validating outside criticism rather than a plaintiff's allegation alone — worth citing precisely because it isn't just an adversarial claim, it's the company's own risk disclosure to its shareholders.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$164.7B", "Market Cap": "$349.8B", "Employees": "470,100", "HQ City": "Atlanta", "HQ State": "Georgia", "CEO": "Ted Decker", "Ticker": "HD", "Website (Corporate)": "homedepot.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (HD). Service route: c/o General Counsel / Corporate Secretary, Atlanta, Georgia — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Georgia' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2014", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Georgia SOS eCorp — ecorp.sos.ga.gov/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Home Depot's own filing admits it uses ALPR cameras and the Flock Safety network linked to ICE data access\nWHAT THE TERMS SAY: Home Depot's own 2026 proxy statement acknowledges it uses automated license plate recognition (ALPR) cameras and participates in the Flock Safety camera network, the same network reporting has linked to federal immigration enforcement (ICE) accessing driver location data through arrangements with local police.\nWHY IT MATTERS: Two separate 2026 California class actions (McGinity, Schmierer) allege this ALPR use violates California's ALPR privacy law, and Home Depot's own filing admits a governance gap: it depends on vendor-managed surveillance networks 'without independent verification.'\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Canada's Privacy Commissioner found Home Depot shared e-receipt data with Meta without valid consent\nWHAT THE TERMS SAY: Canada's Privacy Commissioner found (2023) that Home Depot shared e-receipt data with Meta without valid consent.\nWHY IT MATTERS: Unlike the still-active ALPR lawsuits, this is a confirmed regulatory finding that Home Depot shared customer purchase data with an advertising platform without proper consent.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CONFIRMED_BREACH · FL-2] Home Depot's 2014 breach was among the largest on record; a newer vendor breach hit ~10,000 employees\nWHAT THE TERMS SAY: Home Depot's 2014 payment-card breach is cited as among the largest retail breaches on record; separately, a third-party SaaS vendor breach exposed private data of about 10,000 Home Depot employees, prompting Senators Blumenthal and Markey to call on the FTC to investigate whether Home Depot's security procedures meet a 'reasonable standard,' citing that breach as well as an earlier, much larger breach that exposed 60 million customers to potential fraud.\nWHY IT MATTERS: Home Depot has a repeated pattern of large-scale exposure, both of customers and employees, across a decade, and lawmakers are now pressing federal regulators over whether its security practices meet a 'reasonable standard.'\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=Y; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Home Depot's practices are unusually well documented, via its own SEC/proxy filings, a foreign regulator's finding, and multiple active lawsuits, rather than hidden or unconfirmed.", "Exposure Score (0-100)": 31, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 18, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 18/30 (data_sold_or_shared_for_value+8, biometric_collection+6, precise_location_tracking+4) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "The Home Depot  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (10 of 13): your content used as AI training data; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using The Home Depot you gave up your personal data sold onward, your biometric identifiers, and your physical movements. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:43:27Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Home Depot has the most extensively documented surveillance-related findings of any retailer in this tracker, and the structural reason is that a home improvement retailer sits at an unusually revealing intersection: purchase history reveals whether you are renovating, what you are building, and by inference your property, your finances and your plans. Combine that with in-store analytics, loyalty data and website tracking and the profile is considerably richer than the transaction log suggests. Home Depot's 2014 payment card breach was also among the largest retail breaches on record. See the Data Sharing column for the itemised findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Online Retailers (Top 10)", "_row_id": 278, "_entity_id": 434, "_entity_slug": "the-home-depot", "_issuer": "The Home Depot", "_issuer_slug": "the-home-depot", "_ticker": "HD", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Lowe's", "Category": "Online/Retail (home improvement)", "Terms & Conditions URL": "lowes.com/l/about/terms-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "lowes.com/l/about/privacy-security-statement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ACTIVE MASS ARBITRATION INVESTIGATION (2026): attorneys believe Lowes.com uses tracking software to secretly collect data about which items customers look to purchase and may share this data with PAYPAL without users' knowledge/permission — the same pattern documented for Newegg (above) and Poshmark elsewhere in this tracker, part of a larger, named investigation list spanning dozens of retail/restaurant sites (Aaron's, Aeropostale, Best Buy, Zappos, and many others).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Lowe's and Home Depot (documented separately above) are the two dominant home-improvement retailers — worth noting Home Depot's findings in this tracker are considerably more extensive (ALPR/ICE data-sharing, BIPA, employee breach) than what was found for Lowe's this pass, though that may reflect available public documentation rather than an actual difference in practices.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$86.3B", "Market Cap": "$124.4B", "Employees": "215,500", "HQ City": "Mooresville", "HQ State": "North Carolina", "CEO": "Marvin Ellison", "Ticker": "LOW", "Website (Corporate)": "lowes.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (LOW). Service route: c/o General Counsel / Corporate Secretary, Mooresville, North Carolina — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'North Carolina' is a non-DMV US state", "Parent / Ultimate Owner": "Lowe's Companies, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NC SOS Business Registration Search — sosnc.gov/online_services/search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Lowe's Companies, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] An active 2026 investigation alleges Lowes.com secretly tracks browsing and may share data with PayPal\nWHAT THE TERMS SAY: An active 2026 mass-arbitration investigation asserts Lowes.com uses tracking software to secretly collect data on items customers look to purchase and may share this data with PayPal without users' knowledge or permission.\nWHY IT MATTERS: Attorneys believe Lowes.com secretly shares data about items customers looked to purchase with PayPal without users' knowledge or permission, mirroring the same tracking-and-sharing pattern already documented for Newegg and Poshmark elsewhere in the tracker; specific eligibility criteria for Lowe's customers were not detailed this pass.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity pass 1: Cross-ref leak corrected) (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Lowe's faces a mass-arbitration investigation, the tactic used when class waivers block class actions\nWHAT THE TERMS SAY: The tracker describes Lowe's as facing an active mass-arbitration investigation, a tactic where attorneys file thousands of individual arbitration demands, each requiring the company to pay filing fees, because a class-action waiver had successfully blocked a traditional class action.\nWHY IT MATTERS: The tracker notes mass arbitration is what plaintiffs' lawyers do when a company's own arbitration clause has successfully eliminated class actions: they file thousands of individual arbitrations instead, each of which the company must pay filing fees for, and Lowe's is currently on the receiving end of it.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees are not itemized this pass, and the arbitration clause's existence is only inferred from the mass-arbitration dynamic described (the dedicated Arbitration field calls it unconfirmed); no third distinct finding is present.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The tracking/PayPal-sharing claim is at the investigation stage and arbitration terms are unconfirmed, though the pattern matches the confirmed Newegg and Poshmark cases.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Lowe's  <-  Lowe's Companies, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Lowe's you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "An active 2026 mass arbitration investigation alleges Lowes.com uses tracking technologies without adequate consent - and the procedural posture is the interesting part. Mass arbitration is what plaintiffs' lawyers do when a company's own arbitration clause has successfully eliminated class actions: they file thousands of individual arbitrations instead, each of which the company must pay filing fees for. The tactic exists entirely because the class waiver worked. Companies that wrote arbitration clauses to make litigation uneconomical discovered the clause could be turned around, and Lowe's is currently on the receiving end of it. Lowe's also settled independently in the Visa/Mastercard interchange case.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Online Retailers (Top 10)", "_row_id": 279, "_entity_id": 436, "_entity_slug": "lowe-s", "_issuer": "Lowe's Companies, Inc.", "_issuer_slug": "lowe-s-companies-inc", "_ticker": "LOW", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Kroger", "Category": "Online/Retail (grocery)", "Terms & Conditions URL": "kroger.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "kroger.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MULTIPLE SEPARATE, SERIOUS FINDINGS: (1) TWO pharmacy-specific class actions (Jane Doe v. The Kroger Co., S.D. Ohio) allege Kroger installed the Meta/Facebook Pixel AND Facebook's Conversions API (CAPI) on its pharmacy website — the CAPI addition specifically let Kroger route around ad-blockers and browser privacy controls that would otherwise have stopped the Pixel from collecting data, according to the complaint. The pixel allegedly transmitted patients' names, appointment details, prescriptions, and health information to Meta without the 'express written authorization' HIPAA requires, since Kroger has positioned itself as a healthcare provider through its pharmacy operations. (2) A CONFIRMED 2023 THIRD-PARTY VENDOR BREACH (Accellion file-transfer platform, the same category of vendor-breach pattern seen elsewhere in this tracker) exposed an estimated 3.5 MILLION prescription/health records. (3) SEPARATE PHARMACY OVERCHARGING claims allege Kroger charged cash-pay pharmacy customers MORE than the discounted price available through GoodRx or similar discount programs, without disclosing that cheaper options existed.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "FEDERAL REGULATORS BLOCKED Kroger's proposed $25 BILLION MERGER with Albertsons (2024) on antitrust grounds — legal fallout from the blocked merger is reportedly still generating consequences in 2026 (specific ongoing matters not independently detailed this pass). Kroger serves over 60 MILLION households as the largest US supermarket chain by revenue, meaning any of the above findings has an unusually large potential customer footprint.", "Notes": "Kroger has THREE separate, serious issue categories (pixel/HIPAA pharmacy tracking, a multi-million-record vendor breach, and pharmacy price-transparency allegations) plus a blocked mega-merger — among the more extensively documented findings in this entire tracker for a single grocery company.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$147.6B", "Market Cap": "$34.5B", "Employees": "409,000", "HQ City": "Cincinnati", "HQ State": "Ohio", "CEO": "Greg Foran", "Ticker": "KR", "Website (Corporate)": "thekrogerco.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (KR). Service route: c/o General Counsel / Corporate Secretary, Cincinnati, Ohio — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Ohio' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Kroger's pharmacy site allegedly used a Meta tool to route around ad-blockers and send health data to Meta\nWHAT THE TERMS SAY: Two pharmacy-specific class actions (Jane Doe v. The Kroger Co., S.D. Ohio) allege Kroger installed the Meta/Facebook Pixel plus Facebook's Conversions API (CAPI) on its pharmacy website, with CAPI specifically letting Kroger route around ad-blockers and browser privacy controls, transmitting patients' names, appointment details, prescriptions, and health information to Meta without HIPAA-required written authorization.\nWHY IT MATTERS: Because Kroger has positioned itself as a healthcare provider through its pharmacy operations, the alleged transmission implicates HIPAA's stricter authorization requirement, not just ordinary ad-tracking rules.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] A confirmed 2023 vendor breach exposed an estimated 3.5 million Kroger prescription and health records\nWHAT THE TERMS SAY: A confirmed 2023 third-party vendor breach, via the Accellion file-transfer platform, exposed an estimated 3.5 million prescription/health records.\nWHY IT MATTERS: This is a confirmed exposure of health-adjacent records at large scale, distinct from the still-litigated pixel-tracking allegations.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-1] Separate claims allege Kroger charged cash-pay pharmacy customers more than available GoodRx discount prices\nWHAT THE TERMS SAY: Separate pharmacy overcharging claims allege Kroger charged cash-pay pharmacy customers more than the discounted price available through GoodRx or similar discount programs, without disclosing that cheaper options existed.\nWHY IT MATTERS: Customers who were not told a cheaper option existed may have overpaid for prescriptions they could have gotten for less elsewhere.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The pharmacy Meta-Pixel lawsuits and the Accellion breach are well documented, but arbitration terms are unconfirmed and the blocked merger's ongoing legal fallout is not detailed.", "Exposure Score (0-100)": 18, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 11, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 7, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 11/30 (data_sold_or_shared_for_value+8, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 7/20 (severity2+2, breach+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Kroger  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Kroger you gave up your personal data sold onward. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Two pharmacy-specific class actions is the detail that separates Kroger from other grocers in this tracker: a supermarket that operates pharmacies holds prescription records alongside the loyalty data tracking everything else you buy, and the combination is far more revealing than either alone. Grocery purchase history is already sensitive enough to infer pregnancy, chronic illness and religious observance; adding the pharmacy record removes the inference step. Kroger's loyalty programme is also effectively mandatory in practice, since shelf prices are structured so that declining the card means paying materially more.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Online Retailers (Top 10)", "_row_id": 280, "_entity_id": 437, "_entity_slug": "kroger", "_issuer": "Kroger", "_issuer_slug": "kroger", "_ticker": "KR", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Apple Store (online)", "Category": "Online/Retail (electronics)", "Terms & Conditions URL": "apple.com/legal/internet-services/terms/site.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "apple.com/legal/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit against the Apple ONLINE STORE specifically (as distinct from Apple's broader product/service privacy record, e.g., App Store antitrust matters, which fall outside a strict 'online retailer' scope). Apple's general privacy positioning is widely regarded as more restrictive toward third-party data sharing than most other companies in this tracker, though this was not independently verified against a specific enforcement action for the online store itself this pass.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up specifically distinguishing Apple's online RETAIL store practices from its broader device/App Store ecosystem, since most public scrutiny of Apple's data practices targets the latter rather than apple.com purchases specifically.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$416.2B", "Market Cap": "$4.8T", "Employees": "164,000", "HQ City": "Cupertino", "HQ State": "California", "CEO": "Tim Cook", "Ticker": "AAPL", "Website (Corporate)": "apple.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AAPL). Service route: c/o General Counsel / Corporate Secretary, Cupertino, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — No lawsuit or enforcement action specific to Apple's online retail store was confirmed this pass; the row's own SCARY text states 'nothing confirmed this pass against the online store specifically,' and the counterweight facts about Apple's advertising business are attributed to 'the Apple rows elsewhere in this tracker,' not this row.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No company-specific findings for Apple's online retail store were confirmed this pass; only general ecosystem context documented elsewhere in the tracker is available.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Apple Store (online)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Apple Store (online) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "2026-09-08T19:44:42Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass against the online store specifically. Apple's overall position is genuinely stronger than most retailers here - it does not run an advertising business of the scale that shapes its competitors' incentives, and App Tracking Transparency measurably reduced third-party tracking across the industry. The honest counterweight, recorded in the Apple rows elsewhere in this tracker: Apple's own advertising business grew as third-party tracking shrank, and its privacy protections apply to other companies' collection more completely than to its own. Both facts belong in an accurate assessment.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Online Retailers (Top 10)", "_row_id": 281, "_entity_id": 438, "_entity_slug": "apple-store-online", "_issuer": "Apple Store (online)", "_issuer_slug": "apple-store-online", "_ticker": "AAPL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Chewy", "Category": "Online/Retail (pet supplies)", "Terms & Conditions URL": "chewy.com/app/content/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "chewy.com/app/content/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MULTIPLE SEPARATE FINDINGS: (1) A Pennsylvania class action (2022, joined with similar suits against Michaels and AutoZone) alleged Chewy used undisclosed 'SESSION REPLAY' software to record visitors' mouse movements, clicks, KEYSTROKES, search terms, and viewed content without consent — a more invasive tracking method than a typical ad pixel, since it can capture information a user typed but never actually submitted. (2) A separate VPPA/CCPA class action (Hernandez v. Chewy, California) alleges Chewy disclosed customers' personal information to GOOGLE without consent and failed to honor CCPA opt-out/deletion rights, with potential damages of at least $2,500 PER VIOLATION. (3) A CONFIRMED DATA BREACH led to a class action settlement (deadline referenced as May 2024, specific breach details/scope not independently confirmed this pass). (4) SEPARATELY, unrelated to privacy: a product-safety class action alleges certain Chewy dog-grooming products and ceramic pet-food dishes contained harmful levels of LEAD and DEHP without adequate warnings.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Chewy has FOUR separate documented issue categories (session-replay tracking, VPPA/CCPA data sharing, a confirmed breach, and a product-safety lead/DEHP claim) — an unusually broad spread of distinct legal exposure for a single company in this tab.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$12.6B", "Market Cap": "$8.8B", "Employees": "18,000", "HQ City": "Plantation", "HQ State": "Florida", "CEO": "Sumit Singh", "Ticker": "CHWY", "Website (Corporate)": "chewy.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (CHWY). Service route: c/o General Counsel / Corporate Secretary, Plantation, Florida — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] A 2022 suit alleges Chewy secretly used session-replay software to record mouse movements, clicks, and keystrokes\nWHAT THE TERMS SAY: A Pennsylvania class action (2022, joined with similar suits against Michaels and AutoZone) alleged Chewy used undisclosed session-replay software to record visitors' mouse movements, clicks, keystrokes, search terms, and viewed content without consent.\nWHY IT MATTERS: Session-replay is more invasive than a typical ad pixel because it can capture information a user typed but never actually submitted.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] A VPPA/CCPA suit alleges Chewy disclosed customer data to Google and ignored CCPA opt-out requests\nWHAT THE TERMS SAY: A separate VPPA/CCPA class action (Hernandez v. Chewy, California) alleges Chewy disclosed customers' personal information to Google without consent and failed to honor CCPA opt-out and deletion rights, with potential damages of at least $2,500 per violation.\nWHY IT MATTERS: Failing to honor opt-out/deletion requests means customers who tried to exercise their CCPA rights may not have had them respected.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CONFIRMED_BREACH · FL-2] A confirmed Chewy data breach led to a class-action settlement, though its scope is not detailed this pass\nWHAT THE TERMS SAY: A confirmed data breach led to a class-action settlement, with a claims deadline referenced as May 2024; specific breach details and scope are not independently confirmed this pass.\nWHY IT MATTERS: The tracker records a claims deadline referenced as May 2024 but cannot say how much data or how many customers were involved, since the breach's specific details and scope were not independently confirmed this pass.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Multiple lawsuits are documented, but the confirmed breach's scope and arbitration terms remain unconfirmed this pass.", "Exposure Score (0-100)": 21, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (data_sold_or_shared_for_value+8) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Chewy  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Chewy you gave up your personal data sold onward. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:44:45Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Multiple separate findings including a Pennsylvania class action. The category note worth recording is that pet retail data is health data by proxy - prescription diets, medications, incontinence products and mobility aids describe an animal's medical condition, and auto-shipment schedules describe a household's routine and absence patterns precisely. None of that is protected health information because the patient is a dog, so it sits entirely outside the health-privacy perimeter while being just as revealing about the household. Cross-ref the Trupanion and Healthy Paws rows in the Insurance tab.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Online Retailers (Top 10)", "_row_id": 282, "_entity_id": 314, "_entity_slug": "chewy", "_issuer": "Chewy", "_issuer_slug": "chewy", "_ticker": "CHWY", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Newegg", "Category": "Online/Retail (electronics)", "Terms & Conditions URL": "newegg.com/help/troubleshooting/33", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "newegg.com/help/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ACTIVE MASS ARBITRATION INVESTIGATION (2026): attorneys believe Newegg.com uses tracking technology to secretly collect data about which items customers look to purchase and may share this data with PAYPAL without adequate consent — the SAME 'shares data with a payment processor regardless of whether it's used' pattern already documented for Poshmark elsewhere in this tracker, here applied to electronics shopping rather than resale fashion. Eligible customers: those in California, Pennsylvania, Florida, Washington, or Massachusetts with a PayPal account who added items to a Newegg.com cart within the past two years.", "Arbitration / Class Action Waiver": "SEPARATE, LONG-RUNNING DECEPTIVE-ADVERTISING CASE (filed Dec 2014, still unresolved as of recent corporate filings): a California plaintiff alleged Newegg.com Americas engaged in deceptive advertising practices; after the trial court initially dismissed the claims, a 2018 APPELLATE COURT REVERSAL reinstated the case, adding parent company Newegg Inc. as a defendant — illustrating how a single consumer complaint can take a DECADE OR MORE to resolve through the court system, with Newegg's own securities filings acknowledging an unfavorable result 'could materially affect' the company's finances.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The decade-plus timeline of the deceptive-advertising case (2014 filing, still pending as of recent SEC filings) is a useful illustration of how long consumer litigation can genuinely take to resolve, distinct from the faster-moving mass-arbitration/settlement patterns seen in most other findings in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] An active 2026 investigation alleges Newegg.com secretly tracks cart items and may share data with PayPal\nWHAT THE TERMS SAY: An active 2026 mass-arbitration investigation asserts Newegg.com uses tracking technology to secretly collect data about which items customers look to purchase and may share this data with PayPal without adequate consent, open to customers in California, Pennsylvania, Florida, Washington, or Massachusetts with a PayPal account who added items to a cart in the past two years.\nWHY IT MATTERS: This is the same pattern already documented for Lowe's and Poshmark elsewhere in the tracker, here applied to electronics shopping.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[PENDING_LITIGATION · FL-1] A deceptive-advertising case against Newegg, filed in 2014, remains unresolved a decade later\nWHAT THE TERMS SAY: A California plaintiff alleged Newegg.com Americas engaged in deceptive advertising practices in a case filed December 2014; after the trial court dismissed the claims, a 2018 appellate reversal reinstated the case and added parent company Newegg Inc. as a defendant.\nWHY IT MATTERS: Newegg's own securities filings acknowledge an unfavorable result 'could materially affect' the company's finances, and the case remains unresolved more than a decade after filing.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Newegg is facing mass arbitration, the same tactic used against Lowe's when class-action waivers work too well\nWHAT THE TERMS SAY: The tracker notes the mass-arbitration investigation against Newegg mirrors the one against Lowe's, a posture that exists because the underlying class waiver successfully removed the class action as a remedy.\nWHY IT MATTERS: For consumers, this means arbitration clauses do not eliminate liability, they change its shape into something slower and less visible than a class action.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The PayPal tracking-sharing claim is at the investigation stage, and the decade-old deceptive-advertising case remains unresolved with no final outcome disclosed.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Newegg  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Newegg you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "An active 2026 mass arbitration investigation over website tracking technologies - the same posture as Lowe's, and the pairing is instructive. Two very different retailers, the same alleged conduct, the same procedural response, and the response exists because arbitration clauses successfully removed the class action as a remedy. For consumers the practical takeaway is that arbitration clauses do not eliminate liability; they change its shape, and the new shape is slower, more expensive to administer and far less visible to the public than a class action would have been.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Online Retailers (Top 10)", "_row_id": 283, "_entity_id": 439, "_entity_slug": "newegg", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "QVC / QVC Group (incl. HSN)", "Category": "Online/Retail (TV/e-commerce)", "Terms & Conditions URL": "qvc.com/content/customer-service/terms-of-use.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "qvc.com/content/customer-service/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ACTIVE VPPA/TRACKING INVESTIGATION: a law firm (Labaton Keller Sucharow) has been soliciting QVC customers who watched a video and then made a purchase, offering potential compensation up to $2,500 — consistent with the Video Privacy Protection Act (VPPA) tracking-pixel litigation pattern documented elsewhere in this tracker (Chick-fil-A, Paramount+). Notably, QVC's own customer community forum shows customers mistaking this LEGITIMATE legal outreach for a phishing scam, illustrating how the volume of real mass-arbitration/class-action solicitation has made customers reasonably suspicious of ALL such outreach — a secondary consumer-trust harm distinct from the underlying privacy claim itself.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "MAJOR CORPORATE FINANCIAL DISTRESS (2026): QVC Group filed for CHAPTER 11 BANKRUPTCY in 2026, cancelling $6.5 BILLION of prepetition debt through a 'prepack' restructuring, following a $2.4 BILLION non-cash impairment charge (including writing off $930 million+ of QVC/HSN brand-name value) driven by cord-cutting, tariffs, and a covenant breach. Digital platforms now represent 66.9% of revenue (up from 61.8% in 2023), with ~91% of shipped sales coming from repeat customers — QVC still reaches 200+ million households daily across 15 TV channels and 12+ million customers. SEPARATE, unrelated $30 MILLION lawsuit (Feb 2026): a longtime vendor (Antthony Design Originals, a 31-year QVC/HSN partner) sued alleging QVC/HSN abruptly ended the relationship to prioritize social-media-based live shopping instead, and dumped the vendor's product at steep discounts — a vendor/business dispute rather than a customer-privacy issue.", "Notes": "The Chapter 11 filing is a major operational-status change worth flagging prominently: customers with outstanding gift cards, store credit, warranties, or pending returns/exchanges at QVC/HSN may face different treatment than customers of a financially stable company — recommend checking QVC Group's current bankruptcy-case status directly given how quickly Chapter 11 proceedings can change customer-facing terms.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "1988", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[OTHER · FL-2] A law firm is soliciting QVC customers over alleged video-tracking violations tied to purchases\nWHAT THE TERMS SAY: A law firm (Labaton Keller Sucharow) is actively soliciting QVC customers who watched a video and then made a purchase, offering potential compensation up to $2,500, consistent with the Video Privacy Protection Act tracking-pixel litigation pattern.\nWHY IT MATTERS: QVC's video-commerce model means its website video content brings it into VPPA scope in a way an ordinary retailer's would not, and VPPA provides statutory damages without requiring proof of harm.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[TERMINATION_CONFISCATION · FL-4] QVC Group's 2026 Chapter 11 filing puts customers' gift cards, credit, and pending returns at risk of different treatment\nWHAT THE TERMS SAY: QVC Group filed for Chapter 11 bankruptcy in 2026, cancelling $6.5 billion of prepetition debt through a 'prepack' restructuring following a $2.4 billion non-cash impairment charge, including writing off $930 million+ of QVC/HSN brand value.\nWHY IT MATTERS: Customers with outstanding gift cards, store credit, warranties, or pending returns/exchanges may face different treatment than customers of a financially stable company as the bankruptcy case proceeds.\n(evidence: Fees | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms are unconfirmed this pass, and the separate vendor lawsuit and customer phishing-confusion note are not consumer-facing terms issues; only the VPPA video-tracking investigation and the bankruptcy's effect on customer commitments are substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The VPPA claim is at the investigation/solicitation stage and the bankruptcy case is actively unfolding, so customer-facing terms may change quickly.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 4/20 (termination_or_confiscation+4) | Record 10/20 (severity3+8, litigation+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "QVC / QVC Group (incl. HSN)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using QVC / QVC Group (incl. HSN) you gave up your right to keep what you paid for. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The active investigation concerns the Video Privacy Protection Act - a 1988 statute passed after a newspaper obtained a Supreme Court nominee's video rental records, which has become one of the most productive consumer privacy tools of the streaming era because it provides statutory damages without requiring proof of harm. QVC is a video-commerce business, so its website video content brings it into VPPA scope in a way an ordinary retailer's would not. NOTE FOR THE TRACKER: QVC appears under multiple name variants and is a known cross-tab duplicate risk - fuzzy-match before adding any new QVC row.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Online Retailers (Top 10)", "_row_id": 284, "_entity_id": 440, "_entity_slug": "qvc-qvc-group-incl-hsn", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Zappos (Amazon)", "Category": "Online/Retail (footwear/apparel)", "Terms & Conditions URL": "zappos.com/c/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "zappos.com/c/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ACTIVE CLASS ACTION (Dec 2025): alleges Zappos secretly allowed META to 'eavesdrop' on customers' online shopping activity through tracking technology embedded on its website, without adequate consent — the same Meta Pixel-driven pattern documented for Costco and Kroger elsewhere in this tracker, applied here to a general apparel/footwear retailer rather than a health-adjacent one, meaning the underlying data here is shopping/browsing behavior rather than health information specifically.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected; as an Amazon subsidiary, Zappos may share infrastructure/policies with Amazon's broader account system (see Amazon row, Consumer Apps tab).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Zappos was historically known for a famously customer-friendly return policy and culture — worth noting the contrast between that reputation and this newer tracking-technology allegation.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "PARENT ADDRESS ONLY — verify before using for legal notice. Zappos.com LLC is a Las Vegas, Nevada-headquartered subsidiary. Parent: Amazon.com, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210, USA", "Legal / Privacy Contact Email": "Not verified this pass — Amazon routes privacy requests through its in-account privacy portal", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Amazon.com, Inc.", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] A December 2025 suit alleges Zappos let Meta 'eavesdrop' on shoppers' site activity in real time\nWHAT THE TERMS SAY: An active class action (Dec 2025) alleges Zappos secretly allowed Meta to 'eavesdrop' on customers' online shopping activity through tracking technology embedded on its website, without adequate consent.\nWHY IT MATTERS: The allegation is that a third party received a live feed of what the customer did on the page, rather than an after-the-fact analytics summary.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] Zappos' data governance is set at parent Amazon's level, not by the brand customers associate with its service culture\nWHAT THE TERMS SAY: Zappos is owned by Amazon, and as an Amazon subsidiary it may share infrastructure and account policies with Amazon's broader system, with data governance set at the parent level.\nWHY IT MATTERS: Customers who chose Zappos for its distinctive service culture may not realize the brand's data practices are governed by the largest retail data operation in the world.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms are unconfirmed this pass; only the Meta tracking allegation and the Amazon-parent data-governance structure are substantive, and the tracking claim remains an allegation, not a confirmed finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Meta-tracking claim is an active but unproven allegation, and arbitration terms are unconfirmed this pass.", "Exposure Score (0-100)": 18, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (data_sold_or_shared_for_value+8) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only", "Entity Type": "App / Service", "Ownership Path": "Zappos (Amazon)  <-  Amazon.com, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Zappos (Amazon) you gave up your personal data sold onward. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:44:52Z (HTTP 200, CHANGED)", "SCARY (most astonishing T&C item)": "The December 2025 class action alleges Zappos allowed Meta to eavesdrop on customer interactions with the site - the session-replay and pixel category, where the allegation is that a third party received a live feed of what the customer did on the page rather than an after-the-fact analytics summary. Zappos is owned by Amazon, which is the detail most customers do not carry in mind while shopping: the brand they chose for its distinctive service culture is a subsidiary of the largest retail data operation in the world, and the data governance is set at the parent level. Allegations, not findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Online Retailers (Top 10)", "_row_id": 285, "_entity_id": 441, "_entity_slug": "zappos-amazon", "_issuer": "Amazon.com, Inc.", "_issuer_slug": "amazon-com-inc", "_ticker": "AMZN", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Nike (online store)", "Category": "Online/Retail (apparel/footwear)", "Terms & Conditions URL": "nike.com/help/a/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "nike.com/help/a/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "TWO SEPARATE, SERIOUS FINDINGS: (1) A CONFIRMED JANUARY 2026 DATA BREACH: a ransomware group accessed Nike's files through a THIRD-PARTY vendor portal and published approximately 1.4 TERABYTES of stolen data, including names, emails, billing addresses, phone numbers, transaction information, and payment card details. Nike did not notify affected customers until February 25, 2026 — more than a MONTH after discovering the breach on January 21, 2026, which the lawsuit argues 'further exacerbated' the harm since customers had no chance to protect themselves during that window. (2) SEPARATE TRACKING/DATA-SHARING LAWSUITS (Magenheim v. Nike, S.D. Florida; Jurdi v. Nike, C.D. California) allege Nike's website automatically installs tracking software on visitors' browsers WITHOUT CONSENT, sending behavioral data to Google and Meta for commercial/advertising purposes — one analysis estimated that if Nike tracked as few as 100,000 California residents without consent, potential STATUTORY DAMAGES under California's $5,000-per-violation framework could reach $500 MILLION, illustrating how quickly per-violation statutory damages can scale against a company with Nike's website traffic.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The $500 million POTENTIAL statutory-damages estimate (not an actual verdict or settlement, just a plaintiff-side calculation of maximum exposure) is a useful illustration of how large California's per-violation privacy-statute framework can scale for any company with a large enough customer base — worth being precise that this is a hypothetical ceiling, not a confirmed judgment.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$46.4B", "Market Cap": "$62.6B", "Employees": "79,400", "HQ City": "Beaverton", "HQ State": "Oregon", "CEO": "Elliott Hill", "Ticker": "NKE", "Website (Corporate)": "nike.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (NKE). Service route: c/o General Counsel / Corporate Secretary, Beaverton, Oregon — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Oregon' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Oregon) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Oregon. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] A confirmed January 2026 ransomware breach exposed 1.4TB of Nike customer data, and notification came a month late\nWHAT THE TERMS SAY: A ransomware group accessed Nike's files through a third-party vendor portal and published approximately 1.4 terabytes of stolen data, including names, emails, billing addresses, phone numbers, transaction information, and payment card details.\nWHY IT MATTERS: Nike discovered the breach on January 21, 2026 but did not notify affected customers until February 25, 2026, over a month later, a delay the resulting lawsuit argues 'further exacerbated' the harm.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Separate suits allege Nike's site installs tracking software without consent, with potential CA damages up to $500 million\nWHAT THE TERMS SAY: Separate lawsuits (Magenheim v. Nike, S.D. Florida; Jurdi v. Nike, C.D. California) allege Nike's website automatically installs tracking software on visitors' browsers without consent, sending behavioral data to Google and Meta for advertising.\nWHY IT MATTERS: One analysis estimated that if Nike tracked as few as 100,000 California residents without consent, potential statutory damages under California's $5,000-per-violation framework could reach $500 million, a hypothetical ceiling, not a confirmed judgment.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[LOCATION_TRACKING · FL-2] Nike's Run Club and SNKRS apps collect location and workout data that can reveal a runner's home address\nWHAT THE TERMS SAY: The tracker notes Nike's Run Club and SNKRS ecosystem collects location traces, workout patterns, and biometric-adjacent performance data beyond what a retailer needs to sell shoes.\nWHY IT MATTERS: A route logged daily from the same starting point can identify a home address and a reliable absence window, a pattern the tracker says has produced real-world security incidents elsewhere in the industry.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The January 2026 breach is well documented with specifics, but Nike delayed customer notification for over a month, and the tracking lawsuits remain unresolved allegations.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, precise_location_tracking+4) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "App / Service", "Ownership Path": "Nike (online store)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Nike (online store) you gave up your personal data sold onward and your physical movements. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T19:44:57Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Nike had a confirmed January 2026 ransomware-attributed breach plus a second separate finding, and the row is worth reading alongside the Nike Run Club and SNKRS ecosystem: an athletic brand's app collects location traces, workout patterns and biometric-adjacent performance data far beyond what a retailer needs to sell shoes. Running route data specifically has produced real-world security incidents elsewhere in the industry, because a route logged daily from the same starting point identifies a home address and a reliable absence window. See the Data Sharing column for the itemised findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Online Retailers (Top 10)", "_row_id": 286, "_entity_id": 442, "_entity_slug": "nike-online-store", "_issuer": "Nike (online store)", "_issuer_slug": "nike-online-store", "_ticker": "NKE", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ryanair", "Category": "Airline (Europe, ULCC)", "Terms & Conditions URL": "ryanair.com/gb/en/useful-info/terms-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "ryanair.com/gb/en/useful-info/terms-conditions/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MULTIPLE ACTIVE, SUBSTANTIAL GDPR COMPLAINTS: (1) Vienna-based digital-rights group noyb filed a complaint (2024-2025) alleging Ryanair's mandatory account-verification system — which can require 'invasive biometrics' (facial recognition) — violates GDPR, seeking a fine reportedly up to $450 MILLION; noyb specifically argues Ryanair could use a less-intrusive method (e.g., two-factor authentication) instead of collecting biometric data, and separately alleges the verification system discourages bookings through independent online travel agencies (OTAs) in favor of direct Ryanair bookings, potentially reducing competition — an issue the complaint links to a related, PRE-EXISTING investigation by the Italian Competition Authority into Ryanair limiting air-travel competition. A SEPARATE, earlier lawsuit specifically over the facial-recognition requirement itself sought a $210 million GDPR fine. (2) The complaint also raises GDPR Article 17 ('right to erasure') concerns about account deletion. Ryanair's own defense: it argues the verification step is necessary because independent OTAs sometimes 'scrape' Ryanair's inventory, mis-sell flights with hidden markups, and provide incorrect customer contact/payment details — framing the biometric requirement as a customer-protection measure rather than a competition-limiting one. (3) SEPARATE, MOST RECENT (2026): a hacker forum listing claims to be selling stolen Ryanair legal emails, flight data, and banking details — part of a broader 2025-2026 surge in cyberattacks against airlines/aviation suppliers (WestJet, Hawaiian Airlines, Collins Aerospace, Malaysia Airlines, and others all separately confirmed breaches in the same window, per Cybernews reporting).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected; UK/EU GDPR framework applies to the complaints above.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Ryanair's OWN stated justification for its biometric-verification system (protecting customers from OTA mis-selling) is a genuinely two-sided issue worth presenting evenhandedly — the same system is simultaneously defended by Ryanair as consumer protection and attacked by digital-rights advocates as excessive data collection with a competition-limiting side effect.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Dublin", "HQ State": "Ireland", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Ryanair Holdings plc", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Ireland) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Ireland. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[BIOMETRICS · FL-2] Ryanair requires a facial scan to verify bookings made through travel agents, but not direct bookings\nWHAT THE TERMS SAY: noyb's GDPR complaint alleges Ryanair's mandatory account-verification system can require 'invasive biometrics' (facial recognition), and specifically that passengers who book through third-party travel agents face this requirement while direct bookers do not; the complaint seeks a fine reportedly up to $450 million, with an earlier separate suit seeking $210 million.\nWHY IT MATTERS: Under GDPR, biometric data is a special category requiring an unusually high bar for lawful processing, and noyb argues a less-intrusive method like two-factor authentication could be used instead.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-2] The same GDPR complaint raises concerns about Ryanair's account-deletion process under the right to erasure\nWHAT THE TERMS SAY: The complaint also raises GDPR Article 17 (right to erasure) concerns about Ryanair's account deletion process.\nWHY IT MATTERS: If account deletion does not fully honor the right to erasure, customers may be unable to fully remove their data from Ryanair's systems.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] A 2026 hacker-forum listing claims to sell stolen Ryanair legal emails, flight data, and banking details\nWHAT THE TERMS SAY: A hacker forum listing claims to be selling stolen Ryanair legal emails, flight data, and banking details, part of a broader 2025-2026 surge in cyberattacks against airlines and aviation suppliers; Ryanair has not detailed or confirmed the claim.\nWHY IT MATTERS: This is an attacker assertion, not an established fact, but if accurate it would expose sensitive financial and legal correspondence data.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The biometric-verification practice and GDPR complaints are well documented with specific amounts, but the 2026 breach claim is unconfirmed and no regulator has yet ruled.", "Exposure Score (0-100)": 19, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 9/30 (biometric_collection+6, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Ryanair  <-  Ryanair Holdings plc", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ryanair you gave up your biometric identifiers. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:45:00Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Ryanair's facial-recognition verification requirement is the finding: passengers who book through third-party travel agents have been pushed to submit a biometric facial scan to access their own booking, a step not required of people who book direct. That converts a privacy intrusion into a commercial weapon - the biometric demand functions as friction aimed at a distribution channel Ryanair dislikes, with passengers as the leverage. Multiple substantial GDPR complaints are active, including from a Vienna-based digital rights group. Under GDPR, biometric data is a special category requiring an unusually high bar for lawful processing, and 'we would prefer you had booked directly' is not one of the recognised bases.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 287, "_entity_id": 444, "_entity_slug": "ryanair", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "easyJet", "Category": "Airline (Europe, LCC)", "Terms & Conditions URL": "easyjet.com/en/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "easyjet.com/en/privacy-notice", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MAJOR DATA BREACH with a POTENTIALLY MASSIVE (though still unresolved) damages claim: a confirmed breach exposed personal data; law firm PGMBM is pursuing a 'representative claim' (the closest UK equivalent to a US class action) in the English High Court, arguing claimants could each receive 'up to £2,000 or €2,000' — which, extrapolated across easyJet's full affected customer base, could theoretically reach approximately €19 BILLION (~$22.4 billion) in TOTAL POTENTIAL damages, though this is a plaintiff-side calculation of maximum theoretical exposure, NOT a confirmed judgment or settlement amount, and English law has historically been much less receptive to US-style class actions, making the ultimate outcome genuinely uncertain.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected; UK/EU jurisdiction applies (see British Airways row for the general GDPR fine framework that would also apply here).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The €19 billion figure is a THEORETICAL CEILING calculated by claimant lawyers, not an actual verdict — worth being precise about this distinction if citing the figure, since it's easy to mistake for a confirmed award.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Luton", "HQ State": "United Kingdom", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "easyJet plc (LSE: EZJ)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (United Kingdom) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in United Kingdom. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] A confirmed easyJet breach exposed data for roughly 9 million customers, including credit card details for some\nWHAT THE TERMS SAY: A confirmed easyJet breach exposed personal data, with roughly nine million customers affected, including credit card details for a subset.\nWHY IT MATTERS: Customers whose card details were exposed faced a fraud-risk window with no way to know in advance whether their own data was among the subset affected.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-2] A UK representative claim could theoretically reach ~19 billion euros, though the outcome remains uncertain\nWHAT THE TERMS SAY: Law firm PGMBM is pursuing a 'representative claim' in the English High Court, arguing claimants could each receive up to £2,000/€2,000; extrapolated across easyJet's affected customer base this could theoretically reach approximately €19 billion in total, though this is a plaintiff-side calculation of maximum exposure, not a confirmed judgment or settlement.\nWHY IT MATTERS: English law has historically been much less receptive to US-style class actions, so the ultimate outcome is genuinely uncertain, and the ~19 billion euro figure is a plaintiff-side calculation of maximum theoretical exposure, not a confirmed judgment or settlement.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms are unconfirmed and fees are not itemized this pass; only the confirmed breach and the resulting representative claim are substantive, and the claim's ultimate outcome remains uncertain under English law.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach and its scale are confirmed, but the litigation's ultimate outcome and any final damages remain unresolved years later.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "easyJet  <-  easyJet plc (LSE: EZJ)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, easyJet takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Roughly nine million customers had data exposed, including credit card details for a subset, and the litigation that followed carried claimed exposure in the hundreds of millions of pounds - a figure that has never been fully resolved. The structural lesson easyJet illustrates best is timing: the gap between when an intrusion occurs, when the airline detects it, and when passengers are told is where all the actual consumer harm accumulates, because every day in that gap is a day you are not freezing a card you do not know was taken.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 288, "_entity_id": 446, "_entity_slug": "easyjet", "_issuer": "easyJet plc", "_issuer_slug": "easyjet-plc", "_ticker": "EZJ", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Wizz Air", "Category": "Airline (Europe, ULCC)", "Terms & Conditions URL": "wizzair.com/en-gb/information-and-services/legal/general-conditions-of-carriage", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "wizzair.com/en-gb/information-and-services/privacy-notice", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CLAIMED BREACH (April-May 2025, NOT independently confirmed by Wizz Air): Wizz Air and its Wizz Air Abu Dhabi joint venture were named on criminal 'leak site' forums, with hackers claiming to have stolen 22 GIGABYTES of corporate and operational data — the airline has made no detailed public confirmation of the claim, illustrating the broader challenge (also seen with the United Airlines '272 million SMS records' claim referenced in the same research) of separating genuine breach claims from unverified or exaggerated criminal-forum postings.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — GDPR applies as a Hungary/EU-based carrier rather than a US-style arbitration clause.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is a genuinely UNCONFIRMED claim, distinct from the fully-confirmed breaches documented for British Airways, easyJet, and Air France/KLM elsewhere in this tab — worth being precise about this distinction rather than treating all leak-site claims as equally verified.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Budapest", "HQ State": "Hungary", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Wizz Air Holdings Plc (Jersey-registered)", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Hungary) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Hungary. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Hackers claim to have stolen 22GB of Wizz Air data, but the airline has not confirmed the breach\nWHAT THE TERMS SAY: Wizz Air and its Wizz Air Abu Dhabi joint venture were named on criminal leak-site forums (April-May 2025), with hackers claiming to have stolen 22 gigabytes of corporate and operational data; the airline has made no detailed public confirmation.\nWHY IT MATTERS: This is an unconfirmed criminal-forum claim, not an established fact, illustrating the broader challenge of separating genuine breach claims from unverified or exaggerated postings.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[AUTO_RENEWAL_FEES · FL-1] Wizz Air's unbundled fares mean the advertised price is only a fraction of what a passenger actually pays\nWHAT THE TERMS SAY: Wizz Air's business model is built on unbundling, where the advertised fare is a fraction of the total cost, with the remainder arriving through seat selection, bag sizing, priority boarding, and check-in penalties; the airport check-in fee for missing an online check-in window can exceed the ticket price itself.\nWHY IT MATTERS: The contract term that matters most to an ultra-low-cost passenger is rarely a privacy clause; it is a fee structure that can cost more than the flight itself.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The claimed 2025 breach is explicitly unconfirmed by the airline, and no arbitration clause or lawsuit is documented for Wizz Air this pass; only the breach claim and the unbundled fee structure are substantive to report.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The only breach signal is an unconfirmed criminal leak-site claim with no airline confirmation, and no other terms or litigation are documented this pass.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Wizz Air  <-  Wizz Air Holdings Plc (Jersey-registered)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Wizz Air you gave up your right to stop paying by inaction. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The claimed 2025 breach has never been independently confirmed by Wizz Air, and that is the honest state of this row - an attacker assertion, not an established fact. What can be said without qualification is that Wizz Air's business model is built on unbundling, where the advertised fare is a fraction of what you actually pay and the remainder arrives through seat selection, bag sizing, priority boarding and check-in penalties. The contract term that matters most to an ultra-low-cost passenger is rarely a privacy clause; it is the airport check-in fee that can exceed the ticket price for a passenger who missed an online window.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 289, "_entity_id": 448, "_entity_slug": "wizz-air", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Lufthansa", "Category": "Airline (Europe, legacy)", "Terms & Conditions URL": "lufthansa.com/us/en/general-conditions-carriage", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "lufthansa.com/us/en/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED BREACH DISCLOSURE (early 2025, via Hungary's data protection authority): passenger data from CANCELLED FLIGHTS between 2019 and 2024 was found to have been exposed — notably, the exposure came to light only years after the underlying data was originally collected, illustrating how a breach affecting historical/archived records can surface long after the fact rather than immediately following the original incident. Specific details of how the breach occurred were not made public.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — GDPR applies as a Germany/EU-based carrier rather than a US-style arbitration clause.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The multi-year gap between when the underlying data was collected (2019-2024 cancelled-flight records) and when the exposure was disclosed (2025) is a useful illustration of how long dormant/archived customer data can remain a live security risk long after its original collection purpose has passed.\n\nARC CROSS-REFERENCE (verified this pass): the Airlines Reporting Corporation is a ticket-settlement clearinghouse owned by major carriers, with Delta, Southwest, United, American, Alaska, JetBlue, Lufthansa, Air France and Air Canada all holding seats on its board. 240+ airlines use ARC for ticket settlement. Via its Travel Intelligence Program (TIP), ARC sold access to US travelers' domestic flight records - names, itineraries and financial information - to Customs and Border Protection. Per CBP documents obtained by 404 Media under FOIA, the contract barred CBP from disclosing where the data came from. CBP's stated purpose was supporting federal, state and local law enforcement in identifying persons of interest's domestic air ticketing information. Treat as ONE connected story across every carrier row with an ARC board seat, not as separate incidents.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cologne", "HQ State": "Germany", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Germany) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Germany. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SALE · FL-4] Lufthansa sits on the board of ARC, which sold US travelers' flight records to CBP under a source-concealment clause\nWHAT THE TERMS SAY: Lufthansa holds a board seat on the Airlines Reporting Corporation (ARC), a ticket-settlement clearinghouse used by 240+ airlines; via its Travel Intelligence Program, ARC sold US travelers' domestic flight records, names, itineraries, and financial information, to Customs and Border Protection under a contract that reportedly barred CBP from disclosing where the data came from.\nWHY IT MATTERS: This is a governance finding, not a breach: nobody was hacked, the data was sold, and concealment of the source was written into the deal, per CBP documents obtained via FOIA.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] Lufthansa disclosed in early 2025 that cancelled-flight passenger data from 2019-2024 had been exposed\nWHAT THE TERMS SAY: Lufthansa confirmed via Hungary's data protection authority (early 2025) that passenger data from cancelled flights between 2019 and 2024 was found to have been exposed; how the breach occurred was not made public.\nWHY IT MATTERS: The exposure surfaced years after the underlying data was originally collected, showing that dormant or archived records can remain a live security risk long after their original purpose has passed.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-4] One Lufthansa Group data-protection decision governs Lufthansa, SWISS, and Austrian Airlines at once\nWHAT THE TERMS SAY: The Lufthansa Group's shared data-protection framework also covers SWISS and Austrian Airlines, so a single group-level decision propagates across three carriers a passenger thinks of as distinct.\nWHY IT MATTERS: Passengers choosing between what look like separate airlines are not making an independent choice about who holds their data or sets its protection policy.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=N; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The ARC data-sale arrangement is independently verified via FOIA documents, but the mechanics of the 2025 breach disclosure were never made public.", "Exposure Score (0-100)": 23, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Lufthansa  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (10 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Lufthansa you gave up your personal data sold onward and your data shared corporate-wide. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Lufthansa holds a seat on the board of ARC, the airline-owned clearinghouse that sold US travelers' domestic flight records - names, itineraries, financial information - to Customs and Border Protection under a contract that reportedly forbade CBP from revealing where the data came from. That is the sharpest finding attached to this row, and it is a governance finding rather than a breach: nobody was hacked, the data was sold, and the concealment of the source was written into the deal. Lufthansa separately disclosed a 2025 breach through Hungary's data protection authority. The Lufthansa Group's shared data-protection framework also covers SWISS and Austrian Airlines, so a single group-level decision propagates across three carriers a passenger thinks of as distinct.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 290, "_entity_id": 449, "_entity_slug": "lufthansa", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "British Airways", "Category": "Airline (Europe, legacy)", "Terms & Conditions URL": "britishairways.com/en-gb/information/legal/general-conditions-of-carriage", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "britishairways.com/en-gb/information/legal/british-airways/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ONE OF THE MOST-STUDIED GDPR CASES IN AVIATION: a 2018 breach (via a supply-chain attack — stolen login credentials from third-party cargo handler Swissport, whose compromised account lacked multi-factor authentication) exposed personal/financial details of approximately 429,612 individuals, including ~244,000 customers' names, addresses, full payment card numbers, expiry dates, and CVV security codes. The UK Information Commissioner's Office (ICO) initially announced intent to fine BA £183.39 MILLION (the largest GDPR fine proposed at the time), but REDUCED it to £20 million (≊$26 million) after considering BA's response and COVID-19-related mitigating factors — still the largest fine the ICO had issued at that point. The ICO specifically found BA used HARDCODED, UNENCRYPTED PLAIN-TEXT PASSWORDS, among other basic security failures. Separately, group litigation on behalf of affected customers (described by claimant law firms as the LARGEST personal-data group action in UK history) was settled out of court in 2021.", "Arbitration / Class Action Waiver": "NO CLASS ACTION WAIVER — British Airways' Conditions of Carriage are governed by UK/EU law, which does not recognize US-style class action waivers. UK passengers can bring group litigation orders (GLOs) or use the UK Civil Aviation Authority's Alternative Dispute Resolution scheme. The 2018 breach (GBP 20M ICO fine, reduced from a proposed GBP 183M) was litigated as a group action in the UK courts.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The 90% REDUCTION from the initial £183M proposed fine to the final £20M is a useful, concrete illustration of how much a company's response/cooperation and external circumstances (here, COVID-19) can affect a GDPR penalty's final size — worth noting this isn't unique leniency, but a structured part of the GDPR's own Article 83(2) mitigating-factors framework.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "London", "HQ State": "United Kingdom", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://iapp.org/news/a/ico-finalizes-20m-gbp-fine-against-british-airways", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "International Airlines Group (IAG, London/Madrid)", "Years Referenced in Finding (heuristic)": "2018", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (United Kingdom) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in United Kingdom. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2018 breach exposed full card numbers/CVVs for ~244K of ~430K affected, after BA used unencrypted passwords\nWHAT THE TERMS SAY: A supply-chain attack via cargo-handler Swissport's non-MFA account let attackers access BA's systems and harvest personal/financial details of approximately 429,612 individuals, including names, addresses, full payment card numbers, expiry dates, and CVV codes for roughly 244,000 of those customers; the ICO specifically found BA used hardcoded, unencrypted plain-text passwords among other basic security failures.\nWHY IT MATTERS: Full card numbers and CVVs, harvested in real time as customers typed them, are the ingredients for direct financial fraud, and the cited failures are basic security hygiene lapses rather than a sophisticated attack.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-2] ICO's proposed 183M pound fine was cut 89% to 20M pounds after BA cited COVID-19 financial hardship\nWHAT THE TERMS SAY: The ICO initially announced intent to fine BA 183.39 million pounds, the largest GDPR fine proposed at the time, but reduced it to 20 million pounds (~$26M) after considering BA's response and COVID-19-related mitigating factors, still the largest fine the ICO had issued at that point.\nWHY IT MATTERS: As the tracker's own notes explain, the size of a regulatory penalty tracked BA's ability to pay at the time of assessment rather than the scale of harm to affected customers.\n(evidence: Data Sharing | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees/Billing and Key Provisions fields are empty or 'not itemized'; the settled group litigation is a consequence of the same breach already captured under CONFIRMED_BREACH rather than a distinct type of harm, so only two distinct items were found this pass.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "ICO enforcement findings, exact figures, and the litigation outcome are all specifically documented in the tracker.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "British Airways  <-  International Airlines Group (IAG, London/Madrid)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, British Airways takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:46:18Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The 2018 breach is the most-studied GDPR case in aviation because of what the regulator found: attackers reached BA's systems and harvested payment card details in real time as customers typed them, and the ICO concluded BA had processed a significant amount of personal data without adequate security. The penalty history is the part worth remembering - the ICO announced an intention to fine roughly £183 million and ultimately imposed £20 million, a reduction of about 89%, driven substantially by pandemic-era representations about the airline's financial position. For a consumer, the practical translation is that the size of a regulatory penalty tracks the company's ability to pay at the moment of assessment, not the scale of the harm done to you.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 291, "_entity_id": 451, "_entity_slug": "british-airways", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Air France", "Category": "Airline (Europe, legacy)", "Terms & Conditions URL": "wwws.airfrance.us/legal/general-conditions-of-carriage", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "wwws.airfrance.us/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED 2025 BREACH, part of a MAJOR CROSS-INDUSTRY ATTACK CAMPAIGN: hackers (linked to the ShinyHunters extortion group, using voice-phishing/social-engineering against customer-support staff) accessed a THIRD-PARTY customer-service platform (widely reported to be Salesforce-based) shared with sister airline KLM, exposing names, phone numbers, emails, Flying Blue loyalty numbers/status, and support-ticket subject lines for an undisclosed number of customers — the airlines state passwords, travel details, Flying Blue MILES, and passport/credit card data were NOT affected. Notified French (CNIL) and Dutch data protection authorities. This was part of a much broader 2025 wave using the same attack technique against Google, Chanel, Louis Vuitton, Dior, Tiffany & Co., Adidas, Allianz Life, LVMH, and Pandora — illustrating how one vulnerable THIRD-PARTY CRM platform can cascade into dozens of otherwise-unrelated companies' breaches simultaneously.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — as a French/EU carrier, GDPR applies rather than a US-style consumer arbitration clause.", "Fees / Billing Flags": "ACTIVE US CLASS ACTION (Allison & Soofiani v. Air France, S.D.N.Y., filed Oct 2025): alleges Air France failed to implement 'reasonable cybersecurity safeguards,' failed to adequately train IT/security staff, and that the complimentary credit-monitoring offered to affected customers doesn't 'adequately address the lifelong harm' from the breach. Note one commenter on the coverage pointed out that TWO named plaintiffs alone does not constitute a certified US-style class action — the case still needs class certification to proceed as a broader group claim.", "Notes": "This breach is a clean illustration of the SAME third-party-vendor/supply-chain pattern seen repeatedly throughout this tracker (Target's HVAC vendor, Marriott/Starwood, Hertz's Cleo vendor, Booking.com's Prestige Software) — here affecting an entire wave of unrelated luxury/tech/airline brands through one shared CRM platform simultaneously.\n\nARC CROSS-REFERENCE (verified this pass): the Airlines Reporting Corporation is a ticket-settlement clearinghouse owned by major carriers, with Delta, Southwest, United, American, Alaska, JetBlue, Lufthansa, Air France and Air Canada all holding seats on its board. 240+ airlines use ARC for ticket settlement. Via its Travel Intelligence Program (TIP), ARC sold access to US travelers' domestic flight records - names, itineraries and financial information - to Customs and Border Protection. Per CBP documents obtained by 404 Media under FOIA, the contract barred CBP from disclosing where the data came from. CBP's stated purpose was supporting federal, state and local law enforcement in identifying persons of interest's domestic air ticketing information. Treat as ONE connected story across every carrier row with an ARC board seat, not as separate incidents.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Tremblay-en-France", "HQ State": "France", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Air France-KLM Group", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (France) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in France. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SALE · FL-4] Air France sits on the board of ARC, which sold US travelers' flight records to CBP under a contract barring disclosure of the source\nWHAT THE TERMS SAY: Air France holds a board seat on the Airlines Reporting Corporation (ARC), a ticket-settlement clearinghouse used by 240+ airlines; via its Travel Intelligence Program, ARC sold US travelers' names, itineraries, and financial information to Customs and Border Protection under a contract that, per CBP documents obtained via FOIA, barred CBP from disclosing where the data came from.\nWHY IT MATTERS: Consumers' domestic flight records reached a federal law-enforcement agency through a paid arrangement they never see, with the source of the data contractually concealed from disclosure.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] 2025 breach via a shared vendor platform exposed Flying Blue loyalty numbers and support-ticket contents\nWHAT THE TERMS SAY: Hackers linked to the ShinyHunters group used voice-phishing against customer-support staff to access a third-party customer-service platform (reportedly Salesforce-based) shared with KLM, exposing names, phone numbers, emails, Flying Blue loyalty numbers/status, and support-ticket subject lines; Air France states passwords, travel details, miles, and passport/credit card data were not affected.\nWHY IT MATTERS: Even with financial and travel details reportedly untouched, exposed contact and loyalty data combined with real support-ticket detail gives scammers convincing material for follow-on phishing.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[PENDING_LITIGATION · FL-3] SDNY class action alleges Air France's post-breach credit monitoring doesn't address the 'lifelong harm,' though only two plaintiffs have filed so far\nWHAT THE TERMS SAY: An active US case (Allison & Soofiani v. Air France, filed Oct 2025) alleges Air France failed to implement reasonable cybersecurity safeguards and adequately train IT/security staff, and that the credit monitoring offered doesn't adequately address the lifelong harm from the breach; the tracker notes two named plaintiffs alone do not constitute a certified class action.\nWHY IT MATTERS: The allegations, if proven, would mean the remedy offered to breach victims was inadequate to the harm alleged, though the case still needs class certification to bind a broader group.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Breach scope ('undisclosed number of customers') and arbitration status are unconfirmed, though the ARC data-sale finding and breach mechanics are specifically documented.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Air France  <-  Air France-KLM Group", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Air France you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Air France sits on the board of ARC, the carrier-owned clearinghouse that sold US travelers' flight records to Customs and Border Protection under a contract that reportedly prohibited CBP from disclosing the source. Separately, Air France confirmed a 2025 breach that was part of a much larger cross-industry attack campaign - the same social-engineering wave running through dozens of rows across this tracker. Two different exposure mechanisms in one company: one where criminals took the data, and one where the industry sold it and contracted for silence about having done so.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 292, "_entity_id": 453, "_entity_slug": "air-france", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "KLM", "Category": "Airline (Europe, legacy)", "Terms & Conditions URL": "klm.com/travel/us_en/customer_services/general_conditions/index.htm", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "klm.com/travel/us_en/customer_services/privacy/index.htm", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SAME 2025 breach as Air France (see that row) — KLM and Air France share the same Air France-KLM Group parent and were breached through the same shared third-party customer-service platform. KLM specifically reported the incident to the Dutch Data Protection Authority and separately advised customers to watch for PHISHING attempts exploiting the stolen contact information.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — GDPR/Dutch data protection law applies rather than a US-style arbitration clause.", "Fees / Billing Flags": "See the Air France row for the related US class action, which names KLM as a co-defendant alongside Air France and the Air France-KLM Group.", "Notes": "See Air France row for the shared breach details and broader third-party-vendor pattern.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Amstelveen", "HQ State": "Netherlands", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Air France-KLM Group", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Netherlands) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Netherlands. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] KLM's 2025 breach hit the same vendor platform as Air France; it warned customers to watch for phishing\nWHAT THE TERMS SAY: KLM was breached through the same shared third-party customer-service platform as Air France, reported the incident to the Dutch Data Protection Authority, and separately advised customers to watch for phishing attempts exploiting the stolen contact information.\nWHY IT MATTERS: KLM reported the incident to the Dutch Data Protection Authority and separately advised customers to watch for phishing attempts exploiting the stolen contact information.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] KLM is named as a co-defendant, alongside Air France, in an active US class action over the shared breach\nWHAT THE TERMS SAY: The Air France row's US class action (Allison & Soofiani v. Air France, filed Oct 2025) names KLM as a co-defendant alongside Air France and the Air France-KLM Group.\nWHY IT MATTERS: KLM customers, not only Air France's, are implicated in litigation alleging inadequate cybersecurity safeguards and inadequate breach remediation.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Booking with KLM instead of Air France doesn't isolate your data - both share the same customer-data environment\nWHAT THE TERMS SAY: KLM and Air France share the same Air France-KLM Group parent and use a shared customer-service data environment, such that a single intrusion reaches both airlines' customers simultaneously.\nWHY IT MATTERS: This consolidation isn't disclosed to passengers at the point of booking, so choosing one airline within the group over the other doesn't meaningfully change data-exposure risk.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach is confirmed and reported to the Dutch DPA, but scope/numbers are not restated in this row, and arbitration status is unconfirmed.", "Exposure Score (0-100)": 17, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "KLM  <-  Air France-KLM Group", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using KLM you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "KLM was hit by the same 2025 breach as Air France - the two share systems and a customer data environment, so a single intrusion reaches both. That is the finding a passenger cannot see from the outside: booking with KLM rather than Air France feels like choosing a different company, and for data-exposure purposes it is not. Airline group structures consolidate customer data far more aggressively than the consumer-facing branding suggests, and no privacy policy makes the shared blast radius legible at the point of booking.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 293, "_entity_id": 454, "_entity_slug": "klm", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Turkish Airlines", "Category": "Airline (Europe/Middle East, legacy)", "Terms & Conditions URL": "turkishairlines.com/en-int/legal-notice/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "turkishairlines.com/en-int/legal-notice/protection-of-personal-data-announcement/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "RELATED-COMPANY FINDING: Pegasus Airlines (a separate Turkish carrier, not Turkish Airlines itself) suffered a confirmed breach exposing 6.5 TERABYTES of Electronic Flight Bag data, including flight details, source code, and staff data — relevant context for the Turkish aviation sector broadly, though NOT a Turkish Airlines-specific incident and should not be conflated with it. No Turkish Airlines-specific breach or lawsuit independently confirmed this pass.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; Turkey's own data protection law (LPPD) applies domestically, GDPR applies for EU passengers.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Be careful to distinguish TURKISH AIRLINES from PEGASUS AIRLINES (a separate, unrelated Turkish carrier) when referencing Turkish aviation-sector breaches — they are frequently conflated in casual reporting.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Istanbul", "HQ State": "Turkey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Turkey) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Turkey. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No confirmed Turkish Airlines-specific incident this pass - but that likely reflects a thin disclosure regime, not a clean record\nWHAT THE TERMS SAY: No Turkish Airlines-specific breach or lawsuit was independently confirmed this pass; a documented breach at Pegasus Airlines, a separate Turkish carrier, is explicitly flagged as unrelated and should not be conflated with Turkish Airlines.\nWHY IT MATTERS: Turkish Airlines is majority state-connected, and a passenger's practical recourse depends on whether an independent regulator exists willing to act against a national flag carrier; the tracker frames the absence of findings as an absence of a disclosure/enforcement regime rather than evidence of a clean record.\n(evidence: SCARY | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only a jurisdictional/disclosure-gap observation is supported by this row's own text; the one documented breach in Turkish aviation belongs to Pegasus Airlines, a separate company, and is explicitly flagged as not a Turkish Airlines finding, so it cannot be counted here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No confirmed findings and no evidence of an independent disclosure/enforcement regime for this carrier.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Turkish Airlines  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Turkish Airlines takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing independently confirmed against Turkish Airlines itself this pass - the documented breach belongs to Pegasus Airlines, a separate Turkish carrier, and conflating the two would be exactly the error this tracker exists to avoid. The genuine finding is jurisdictional: Turkish Airlines is majority state-connected, and a passenger's practical recourse against a flag carrier depends far less on the terms they accepted than on whether an independent regulator exists that is willing to act against a national champion. Absence of findings here should be read as absence of a disclosure and enforcement regime, not as evidence of a clean record.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 294, "_entity_id": 455, "_entity_slug": "turkish-airlines", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Iberia (IAG)", "Category": "Airline (Europe, legacy)", "Terms & Conditions URL": "iberia.com/us/legal-notice/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "iberia.com/us/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED BREACH/EXTORTION ATTEMPT (disclosed Jan 2026, tied to a November 2025 incident): a threat actor demanded $150,000 for allegedly stolen customer data — Iberia confirmed the breach claims relate to this Nov 2025 incident rather than treating it as a new attack. SEPARATELY, GDPR case-law research documents Iberia (part of IAG, the same parent group as British Airways — see that row) among a cluster of EU airlines cited for GDPR violations, specifically including FAILURES TO RESPOND TO 'SUBJECT ACCESS REQUESTS' (SARs) — the GDPR right allowing individuals to obtain confirmation of what personal data a company holds about them — and failures to honor 'right to erasure' requests, both foundational GDPR consumer rights that Iberia was specifically found to have not honored properly.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — GDPR applies as a Spanish/EU carrier (part of IAG, alongside British Airways and Vueling) rather than a US-style consumer arbitration clause.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Iberia shares IAG parent-company GDPR exposure with British Airways (documented elsewhere in this tab) — the SAR/erasure-request failures are a genuinely different category of violation from a data BREACH: this is about the company failing to honor customers' AFFIRMATIVE data-rights REQUESTS, not about unauthorized third-party access.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Iberia disclosed a breach and $150,000 extortion demand in Jan 2026 - traced to an intrusion from two months earlier\nWHAT THE TERMS SAY: A threat actor demanded $150,000 for allegedly stolen Iberia customer data, disclosed in Jan 2026 and tied to a Nov 2025 incident, with Iberia confirming the claims relate to that earlier incident rather than a new attack.\nWHY IT MATTERS: The roughly two-month gap between the initial intrusion and public disclosure meant customers had no notice of a potential compromise for an extended period.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] Case-law research finds Iberia among EU carriers that failed to honor GDPR access and erasure requests\nWHAT THE TERMS SAY: GDPR case-law research documents Iberia, part of IAG alongside British Airways, among a cluster of EU airlines specifically cited for failing to respond to Subject Access Requests and failing to honor right-to-erasure requests.\nWHY IT MATTERS: These are foundational GDPR rights - the ability to find out what data a company holds and to have it deleted - and the tracker frames this as a distinct category of violation from a data breach: the company not honoring customers' own affirmative requests.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only the breach/extortion incident and the SAR/erasure-request failures are distinct, company-specific findings in this row's text; other fields (Fees, Key Provisions) are empty or unconfirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach and SAR/erasure failures are specifically documented, but other terms and confirmation details remain thin.", "Exposure Score (0-100)": 11, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Iberia (IAG)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Iberia (IAG) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Iberia disclosed a breach and extortion attempt in January 2026 traced to a November intrusion - meaning the attackers had roughly two months inside before customers learned anything. Iberia sits inside International Airlines Group alongside British Airways, so the group that produced aviation's most-studied GDPR enforcement case was running a second carrier that took months to surface its own incident. The recurring pattern across this tab is that regulatory penalties land on one brand while the underlying group practices continue elsewhere under a different name.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 295, "_entity_id": 456, "_entity_slug": "iberia-iag", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Swiss International Air Lines", "Category": "Airline (Europe, legacy)", "Terms & Conditions URL": "swiss.com/us/en/legal/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "swiss.com/us/en/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED 2025 BREACH (self-disclosed, employee-facing): SWISS confirmed sensitive PILOT ASSESSMENT data was left accessible for approximately TWO MONTHS due to a SharePoint permissions misconfiguration — exposed internally to a large group of staff plus a limited circle of PARTNER COMPANY personnel who should not have had access. An employee, not SWISS's own monitoring systems, first reported the issue. SWISS states passenger data and other employees' data were NOT affected — this was specifically pilot-assessment records.", "Arbitration / Class Action Waiver": "SWISS is part of the LUFTHANSA GROUP (alongside Lufthansa, Austrian Airlines, Eurowings, and others), sharing a common 'Travel ID' data-protection framework across all Group airlines — GDPR applies via each airline's home-country data protection authority (Switzerland's DSG for SWISS specifically, since Switzerland is not EU but has its own comparable law).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "SWISS notably explicitly states it will NOT respond to data-protection-rights requests that are actually about REBOOKING OR REFUNDS — redirecting those to customer support instead — a small but practical detail about how to correctly route different types of requests to this airline specifically.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Basel", "HQ State": "Switzerland", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Switzerland) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Switzerland. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] SWISS left pilot-assessment data exposed for about two months, caught by an employee not by its own monitoring\nWHAT THE TERMS SAY: A SharePoint permissions misconfiguration left sensitive pilot-assessment data accessible for approximately two months to a large group of staff plus a limited circle of partner-company personnel who should not have had access; an employee, not SWISS's monitoring systems, first reported the issue. SWISS states passenger data and other employees' data were not affected.\nWHY IT MATTERS: The tracker notes employee data breaches like this get far less scrutiny than passenger-facing ones despite exposing people who cannot simply switch providers, and the detection came from a person noticing, not from a security control.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] SWISS's data-protection decisions are made under a shared Lufthansa Group framework, not by SWISS in Switzerland alone\nWHAT THE TERMS SAY: SWISS is part of the Lufthansa Group, sharing a common 'Travel ID' data-protection framework across Lufthansa, Austrian Airlines, Eurowings, and other group carriers, with Switzerland's own DSG applying since Switzerland is not in the EU.\nWHY IT MATTERS: The governing decisions about how a passenger's data is handled are made at a parent level in a different country from the airline whose flag is on the aircraft, an arrangement no passenger-facing document explains.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees/Billing and Key Provisions fields are not itemized; the note about routing rebooking/refund requests is a practical clarification, not a distinct harm.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Breach is self-disclosed with specifics, but the governing data-protection decisions sit at an undisclosed parent-group level.", "Exposure Score (0-100)": 15, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Swiss International Air Lines  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Swiss International Air Lines you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "SWISS self-disclosed a 2025 breach that was employee-facing rather than passenger-facing - worth recording precisely, because employee data breaches at airlines get far less scrutiny while exposing people who cannot simply switch providers. SWISS operates under the Lufthansa Group's shared data-protection framework, so the governing decisions about how its data is handled are made at a parent level in a different country from the one whose flag is on the aircraft. Swiss data protection law, EU GDPR and the group's internal framework interact here in ways no passenger-facing document explains.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 296, "_entity_id": 457, "_entity_slug": "swiss-international-air-lines", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Austrian Airlines", "Category": "Airline (Europe, legacy)", "Terms & Conditions URL": "austrian.com/us/en/legal-information", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "austrian.com/us/en/datenschutz", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same LUFTHANSA GROUP shared data-protection framework as Lufthansa and SWISS (see those rows) — no Austrian-specific breach or lawsuit independently confirmed this pass; Austrian's own data protection authority is the Austrian DPA in Vienna specifically (distinct from Germany's or Switzerland's regulators, since each Lufthansa Group airline is registered/regulated in its own home country despite sharing group-wide data infrastructure).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — GDPR applies via the Austrian Data Protection Authority.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up on any Austrian-specific incidents; the shared Lufthansa Group infrastructure means findings for Lufthansa/SWISS elsewhere in this tab plausibly extend here, though no Austrian-specific incident was independently confirmed this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] No Austrian-specific incident confirmed - but the airline is barely an independent data controller within Lufthansa Group\nWHAT THE TERMS SAY: No Austrian-specific breach or lawsuit was independently confirmed this pass, and Austrian shares the same Lufthansa Group data-protection framework as Lufthansa and SWISS while being separately registered with Austria's own DPA in Vienna.\nWHY IT MATTERS: A passenger choosing Austrian over Lufthansa has, for privacy purposes, made no real choice - the meaningful unit of analysis is the parent group, whose infrastructure and incidents Austrian shares.\n(evidence: Data Sharing | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No Austrian-specific breach, lawsuit, or penalty is confirmed this pass; the row's only substantive point is its structural dependence on the shared Lufthansa Group data framework, and the tracker explicitly flags that other group carriers' incidents are not independently confirmed as extending to Austrian.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No independently confirmed Austrian-specific incident, and the airline's own data-protection posture is indistinguishable from its parent group's.", "Exposure Score (0-100)": 12, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Austrian Airlines  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Austrian Airlines you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "There is no Austrian Airlines-specific finding this pass, and the reason is itself the finding: Austrian operates under the same Lufthansa Group data-protection framework as Lufthansa and SWISS, so it barely exists as an independent data controller in practice. A passenger booking Austrian because they prefer it to Lufthansa has, for privacy purposes, made no choice at all. Group-level consolidation means the meaningful unit of analysis for this row is the parent, and the parent's ARC board seat and 2025 breach disclosure apply here by inheritance.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 297, "_entity_id": 458, "_entity_slug": "austrian-airlines", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "TAP Air Portugal", "Category": "Airline (Europe, legacy)", "Terms & Conditions URL": "flytap.com/en-us/legal/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "flytap.com/en-us/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED 2022 RANSOMWARE BREACH (Ragnar Locker gang): exposed OVER 5 MILLION unique email addresses plus names, genders, birthdates, phone numbers, and physical addresses — the gang publicly leaked the data via a dark-web site after 'naming and shaming' the airline. A SEPARATE extortion attempt (GhostSec group, 2023) claimed to have exfiltrated 350GB of data and demanded a $250,000 ransom, mockingly calling the incident 'A Race for Data' and accusing the airline of 'corruption.' MOST RECENTLY (May 2026), a NEW, separate, UNCONFIRMED breach claim surfaced on a hacker forum alleging a fresh customer-database exfiltration including passport details and payment information — not independently verified by TAP as of this research, following the same 'claimed but unconfirmed' pattern seen for Wizz Air elsewhere in this tab.", "Arbitration / Class Action Waiver": "NO CLASS ACTION WAIVER — TAP's Conditions of Carriage are governed by Portuguese/EU law. EU Regulation 261/2004 provides automatic passenger compensation rights for delays/cancellations that cannot be waived by contract — structurally more protective than US contract-of-carriage terms. The Aug 2022 Ragnar Locker ransomware breach was handled under Portugal's CNPD (data protection authority).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "TAP has now been the subject of THREE SEPARATE breach/extortion claims across 2022, 2023, and 2026 — a persistent pattern of attacker attention, though only the 2022 Ragnar Locker incident is fully confirmed; the 2023 and 2026 claims remain unconfirmed/disputed extortion attempts.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Lisbon", "HQ State": "Portugal", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://haveibeenpwned.com/Breach/TAPAirPortugal", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "TAP SGPS, S.A. (Portuguese state-owned, 72.5%)", "Years Referenced in Finding (heuristic)": "2022", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Portugal) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Portugal. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2022 Ragnar Locker ransomware breach exposed over 5 million people's data, published after TAP refused to pay\nWHAT THE TERMS SAY: The 2022 Ragnar Locker ransomware attack exposed over 5 million unique email addresses plus names, genders, birthdates, phone numbers, and physical addresses; the gang publicly leaked the data on a dark-web site after 'naming and shaming' the airline.\nWHY IT MATTERS: As the tracker notes, refusing to pay is defensible policy, but it meant the harm was transferred wholesale onto passengers, who had no say in the decision and ended up with a published dataset rather than a quietly ransomed one.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-2] Two more unconfirmed breach/extortion claims (2023, 2026) allege additional TAP data theft including passport and payment details\nWHAT THE TERMS SAY: A 2023 extortion attempt (GhostSec) claimed to have exfiltrated 350GB of data and demanded $250,000, and a May 2026 hacker-forum claim alleges a fresh customer-database exfiltration including passport and payment information; neither was independently verified by TAP as of this research.\nWHY IT MATTERS: Even unconfirmed, three separate breach/extortion claims across 2022, 2023, and 2026 reflect a persistent pattern of attacker attention to TAP's systems, per the tracker's own framing.\n(evidence: Data Sharing | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only the confirmed 2022 Ragnar Locker breach and the pattern of unconfirmed follow-on extortion claims are substantive; the row explicitly states there is no class-action waiver (a favorable term, not a harm) and Fees/Billing is not itemized.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2022 breach is fully confirmed with specifics, but two later extortion claims (2023, 2026) remain unverified.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "TAP Air Portugal  <-  TAP SGPS, S.A. (Portuguese state-owned, 72.5%)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, TAP Air Portugal takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T19:50:00Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The Ragnar Locker ransomware crew took data on more than 5 million people from a state-owned flag carrier in 2022 and published it when TAP refused to pay. That refusal is defensible policy - paying funds the next attack - but it also means the harm was transferred wholesale onto passengers, who had no vote in the decision and received a published dataset rather than a quietly ransomed one. Nothing in a ticket contract gives a passenger any say in how their carrier responds to an extortion demand, though the response determines whether their data ends up public.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 298, "_entity_id": 460, "_entity_slug": "tap-air-portugal", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Finnair", "Category": "Airline (Europe, legacy)", "Terms & Conditions URL": "finnair.com/us-en/conditions-of-carriage", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "finnair.com/us-en/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED THIRD-PARTY VENDOR BREACH (2021, via SITA, a major global aviation IT services provider used by dozens of airlines): frequent-flyer program data was exposed as part of a broader SITA breach that also affected British Airways, Singapore Airlines, and multiple other carriers simultaneously — Finnair confirmed this was NOT a breach of its own internal IT systems, and that the exposed data cannot be used to access Finnair Plus accounts directly since password data was not shared/exposed among the affected airlines. This illustrates how a single shared industry vendor (SITA, in this case handling frequent-flyer data-sharing BETWEEN partner airlines) can simultaneously expose multiple otherwise-unrelated carriers' loyalty program members.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — GDPR applies as a Finland/EU-based carrier.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This SITA breach is a clean, airline-industry-specific illustration of the third-party-vendor pattern seen repeatedly throughout this tracker, but distinctively affecting MULTIPLE COMPETING AIRLINES simultaneously through one shared industry back-end system — worth cross-referencing with British Airways' row, which confirms the same SITA incident from that airline's side.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Vantaa", "HQ State": "Finland", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2021", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Finland) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Finland. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2021 SITA vendor breach exposed Finnair Plus frequent-flyer data alongside British Airways and Singapore Airlines\nWHAT THE TERMS SAY: Finnair's frequent-flyer program data was exposed via a breach at SITA, a shared aviation IT vendor used across the industry, that simultaneously affected British Airways, Singapore Airlines and multiple other carriers; Finnair confirmed it was not a breach of its own internal systems and that exposed data cannot be used to access Finnair Plus accounts directly since password data was not shared.\nWHY IT MATTERS: A single vulnerable industry vendor can expose loyalty-program members at competing airlines simultaneously, so switching airlines for privacy reasons doesn't necessarily reduce exposure to this specific vendor risk.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Star Alliance and oneworld membership mean frequent-flyer data moves between competing carriers by design\nWHAT THE TERMS SAY: Alliance loyalty-program infrastructure routinely shares frequent-flyer data between partner airlines, which is why one vendor's 2021 breach reached Finnair, SAS, Singapore Airlines, Japan Airlines, Air India and others simultaneously.\nWHY IT MATTERS: A privacy-conscious traveler switching between alliance carriers to avoid one airline's practices was, per the tracker, still exposed to the same shared vendor and data flows.\n(evidence: SCARY | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only the SITA breach and the underlying alliance-wide data-sharing structure are supported by this row's text; Arbitration and Fees fields are unconfirmed/not itemized.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The SITA breach is confirmed and well-described, but arbitration/fee terms remain unconfirmed.", "Exposure Score (0-100)": 15, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Finnair  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Finnair you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Finnair's exposure came through SITA, an aviation IT provider most passengers have never heard of that processes frequent-flyer data for a large share of the world's airlines. A single 2021 intrusion at SITA propagated simultaneously into Finnair, SAS, Singapore Airlines, Japan Airlines, Air India and others - carriers that compete with each other and that a privacy-conscious traveler might switch between for exactly this kind of reason, all sharing one point of failure. Star Alliance and oneworld membership means frequent-flyer data moves between carriers by design. Choosing a different airline did not diversify the risk; it was the same vendor either way.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 299, "_entity_id": 461, "_entity_slug": "finnair", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "SAS (Scandinavian Airlines)", "Category": "Airline (Europe, legacy)", "Terms & Conditions URL": "flysas.com/en/legal-notice/conditions-of-carriage/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "flysas.com/en/legal-notice/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED PARTICIPANT in the SAME 2021 SITA multi-airline breach as Finnair/Singapore Airlines/Cathay Pacific/JAL (see those rows) — SAS was specifically named among the ~10 airlines whose frequent-flyer members were affected. SAS also went through CHAPTER 11 BANKRUPTCY restructuring (2022-2024, emerged under new majority ownership including Air France-KLM) — a major operational/ownership change worth noting for any customer with historical SAS EuroBonus loyalty points or credits.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; as a Scandinavian carrier, GDPR applies via Sweden/Denmark/Norway's respective data protection authorities.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "SAS's bankruptcy restructuring (now partly owned by Air France-KLM) means it shares some ownership connection with Air France/KLM documented elsewhere in this tab — worth noting this evolving corporate relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2021", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] SAS frequent-flyer data was exposed in the same 2021 SITA vendor breach that hit Finnair and Singapore Airlines\nWHAT THE TERMS SAY: SAS was specifically named among roughly 10 airlines whose frequent-flyer members were affected by the 2021 SITA breach.\nWHY IT MATTERS: GDPR governs what SAS does with a passenger's data directly but doesn't determine the security of every alliance partner and vendor that data reaches, so a strong regulatory regime doesn't fully protect against vendor-side exposure.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] SAS's 2022-2024 Chapter 11 restructuring is a customer-relevant ownership change for EuroBonus point holders\nWHAT THE TERMS SAY: SAS went through Chapter 11 bankruptcy restructuring from 2022-2024, emerging under new majority ownership that includes Air France-KLM.\nWHY IT MATTERS: A major ownership and financial restructuring is worth flagging for customers holding historical EuroBonus loyalty points or credits, per the tracker's own note.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only the shared SITA breach and the bankruptcy/ownership change are supported by this row's text; arbitration and fee fields are unconfirmed/not itemized.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The SITA breach and bankruptcy/ownership change are documented, but arbitration and fee terms are unconfirmed.", "Exposure Score (0-100)": 15, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "SAS (Scandinavian Airlines)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using SAS (Scandinavian Airlines) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "SAS was swept up in the same 2021 SITA vendor breach as Finnair, Singapore Airlines, Japan Airlines and Air India - one intrusion at one aviation IT provider reaching frequent-flyer data across competing carriers on multiple continents. For a Scandinavian carrier operating under some of the world's more protective privacy expectations, the practical point is that GDPR governs what SAS may do with your data but does not determine the security of every alliance partner and vendor that data reaches. The strongest regulatory regime in the world is only as good as the weakest processor in the chain.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 300, "_entity_id": 462, "_entity_slug": "sas-scandinavian-airlines", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Virgin Atlantic", "Category": "Airline (Europe, legacy)", "Terms & Conditions URL": "virginatlantic.com/gbr/en/legal/conditions-of-carriage.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "virginatlantic.com/gbr/en/legal/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Airline — collects passenger name records (PNRs), passport/ID data, payment information, frequent-flyer activity, seat preferences, meal selections, and increasingly, facial recognition for boarding. PNR data shared with CBP (Customs and Border Protection) under federal mandate. International flights subject to EU PNR Directive and destination-country data-sharing requirements.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; UK GDPR/Data Protection Act applies as a UK-based carrier (same ICO regulator that penalized British Airways — see that row for the applicable enforcement framework and precedent).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up; note the SEPARATE Alaska Airlines/Virgin Group trademark dispute (Global Airlines tab, Alaska Airlines row) involves Virgin Group's brand licensing business, not Virgin Atlantic's own airline operations specifically — avoid conflating the two.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Crawley", "HQ State": "United Kingdom", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (United Kingdom) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in United Kingdom. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] Virgin Atlantic increasingly uses facial recognition for boarding and shares PNR data with CBP by mandate\nWHAT THE TERMS SAY: Virgin Atlantic collects passport/ID data, payment information, frequent-flyer activity, seat and meal preferences, and increasingly facial recognition for boarding, with PNR data shared with Customs and Border Protection under federal mandate and international flights subject to the EU PNR Directive and destination-country data-sharing requirements.\nWHY IT MATTERS: PNR data is shared with Customs and Border Protection under federal mandate, and international flights are subject to the EU PNR Directive and destination-country data-sharing requirements.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-4] Virgin Atlantic's Delta joint venture may route passenger data into the ARC arrangement that sold traveler data to CBP - unconfirmed\nWHAT THE TERMS SAY: The tracker notes Virgin Atlantic is part-owned by Delta and deeply integrated into a transatlantic joint venture, meaning passenger data moves into a US carrier's environment and therefore potentially into scope of the ARC data-sharing arrangement documented elsewhere in this tracker for other carriers; this is flagged as an open follow-up question, not a confirmed fact for Virgin Atlantic specifically.\nWHY IT MATTERS: If confirmed, it would mean Virgin Atlantic passengers' data could reach the same CBP data-sale arrangement affecting other carriers' passengers, without any Virgin Atlantic-specific disclosure.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No Virgin Atlantic-specific breach, penalty, or litigation is confirmed this pass; the row is a null result beyond baseline data-collection practices and an open question about ARC exposure via the Delta joint venture.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No confirmed incident this pass, and even baseline questions like ARC exposure via the Delta joint venture remain open.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "Virgin Atlantic  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Virgin Atlantic you gave up your biometric identifiers and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing independently confirmed for Virgin Atlantic this pass - a genuine null result, recorded as unverified rather than clean. The structural note worth carrying is that Virgin Atlantic is part-owned by Delta and deeply integrated into a transatlantic joint venture, which means passenger data moves into a US carrier's environment and therefore into scope of the ARC arrangement documented elsewhere in this tab. Recommend a follow-up on whether Virgin Atlantic passenger data reaches ARC through its joint-venture partner.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 301, "_entity_id": 463, "_entity_slug": "virgin-atlantic", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Aeroflot", "Category": "Airline (Russia, legacy)", "Terms & Conditions URL": "aeroflot.ru/ru-en/information/legal (Terms not independently confirmed as direct URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "aeroflot.ru/ru-en/information/legal/privacy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "CONFIRMED 2025 CYBERATTACK: a cyberattack on Russia's flag carrier resulted in the CANCELLATION OF MORE THAN 60 FLIGHTS and severe delays to additional flights — one of the more operationally disruptive (as opposed to purely data-exposing) airline cyberattacks documented in this tracker, directly grounding passengers rather than only exposing their data.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; as a Russian carrier operating under Russian jurisdiction, typical US/EU consumer-protection frameworks (GDPR, US arbitration law) do not straightforwardly apply.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Given Russia's post-2022 international standing, Aeroflot's US/EU flight network has been severely curtailed — relevant primarily to travelers with historical Aeroflot bookings/data rather than current US-originating travel.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Moscow", "HQ State": "Russia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "PJSC Aeroflot (Russian state majority owner)", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Russia) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Russia. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-3] 2025 cyberattack on Aeroflot canceled 60+ flights - a disruption attack, not a data-theft one\nWHAT THE TERMS SAY: A 2025 cyberattack on Russia's flag carrier resulted in the cancellation of more than 60 flights and severe delays to additional flights, an operationally disruptive attack rather than a primarily data-exposing one.\nWHY IT MATTERS: This attack aimed at grounding passengers rather than monetizing stolen data - a different risk profile from most breaches in this tracker.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-3] Aeroflot passengers have the most theoretical recourse in this tracker - no independent regulator, state ownership, sanctions\nWHAT THE TERMS SAY: Aeroflot operates under Russian jurisdiction where US/EU consumer-protection frameworks like GDPR and US arbitration law do not straightforwardly apply; the tracker notes sanctions, state ownership, and the absence of an independent data protection authority.\nWHY IT MATTERS: As the tracker states, the terms a passenger accepts are effectively unenforceable by that passenger given the lack of an independent regulator and Aeroflot's state ownership.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only the 2025 operational cyberattack and the structural absence of enforceable consumer recourse are supported by this row's text; no data-specific breach scope or financial terms are stated.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No independent data protection authority or enforcement regime exists to generate disclosures for this carrier.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Aeroflot  <-  PJSC Aeroflot (Russian state majority owner)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Aeroflot takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2025 cyberattack on Russia's flag carrier was destructive rather than acquisitive - the objective was disruption, not data theft for resale. That distinction matters for how a passenger should think about risk: most rows in this tracker involve data being taken to be monetised, whereas a geopolitically motivated attack aims at the systems themselves. Aeroflot is also the row where consumer recourse is most theoretical. Sanctions, state ownership and the absence of an independent data protection authority mean the terms a passenger accepts are effectively unenforceable by that passenger.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 302, "_entity_id": 465, "_entity_slug": "aeroflot", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Emirates", "Category": "Airline (Middle East, legacy)", "Terms & Conditions URL": "emirates.com/us/english/help/terms-and-conditions/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "emirates.com/us/english/help/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED GDPR FINE (Italy's Garante, June 17, 2026): €180,000 penalty for severe compliance gaps in handling passenger MEDICAL DATA — specifically over Emirates' digital handling of the industry-standard 'MEDIF' (Medical Information for Fitness to Travel) form. The Garante found Emirates forced passengers requesting only MINOR MOBILITY ASSISTANCE to complete highly invasive, clinical medical forms disproportionate to the actual assistance requested, and separately found Emirates illegally STORED passenger medical files for up to SEVEN YEARS, when the Montreal Convention's 2-year statute of limitations for aviation legal claims meant no legitimate legal-defense justification existed beyond that window. Emirates is now legally required to cut its medical-data retention to 3 years maximum and permanently delete all older files.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — as a UAE-based carrier, Emirates is not directly headquartered in the EU, but this Italian Garante enforcement action confirms GDPR's extraterritorial reach applies to any airline processing EU passengers' data, regardless of the airline's home country.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The MEDIF medical-data retention finding is a genuinely useful, specific illustration of how GDPR's data-minimization principle collides with airlines' instinct to over-retain data 'just in case' of future legal claims — worth flagging as likely relevant to OTHER airlines using the same industry-standard MEDIF form, not just Emirates specifically.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Dubai", "HQ State": "UAE", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (UAE) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in UAE. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[RETENTION_PERIOD · FL-2] Emirates illegally retained passenger medical files for up to 7 years - more than triple the legal claims window\nWHAT THE TERMS SAY: Italy's Garante found Emirates illegally stored passenger medical files for up to seven years, when the Montreal Convention's 2-year statute of limitations for aviation legal claims meant no legitimate legal-defense justification existed beyond that window; Emirates must now cut retention to 3 years maximum and delete older files.\nWHY IT MATTERS: Sensitive medical records were kept years longer than any legal purpose required, expanding the window in which that data could be exposed, misused, or mishandled.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Emirates forced passengers requesting only minor mobility assistance to fill out invasive clinical medical forms\nWHAT THE TERMS SAY: The Garante found Emirates forced passengers requesting only minor mobility assistance to complete highly invasive, clinical medical forms disproportionate to the actual assistance requested, via the industry-standard MEDIF form.\nWHY IT MATTERS: Passengers seeking modest accommodations had to disclose clinical medical detail beyond what the request justified, per the regulator's own finding of disproportionality.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[REGULATORY_PENALTY · FL-2] 180,000 euro Garante fine over medical-data mishandling is, by the tracker's own framing, a filing fee for an airline Emirates' size\nWHAT THE TERMS SAY: Italy's Garante fined Emirates 180,000 euros in June 2026 for the MEDIF medical-data handling failures, described as a real enforcement action but the tracker notes the fine's size relative to a Gulf state carrier headquartered outside EU jurisdiction.\nWHY IT MATTERS: A penalty this size against an airline of Emirates' scale does not function as a deterrent, which the tracker suggests explains why the same categories of complaint keep recurring across similarly positioned carriers.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Garante's findings, the fine amount, and required remediation are all specifically documented.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 11/20 (severity3+8, penalty+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Emirates  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Emirates takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Italy's Garante fined Emirates €180,000 in June 2026 - a real enforcement action, and a useful illustration of how little leverage a national regulator has over a state-owned carrier headquartered outside its jurisdiction. €180,000 against an airline of Emirates' scale is not a deterrent; it is a filing fee. The finding is not that Emirates was uniquely bad but that the enforcement architecture available to European regulators against Gulf state carriers produces penalties that do not change behaviour, which is why the same categories of complaint keep recurring.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 303, "_entity_id": 466, "_entity_slug": "emirates", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Qatar Airways", "Category": "Airline (Middle East, legacy)", "Terms & Conditions URL": "qatarairways.com/en/legal/terms-and-conditions.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "qatarairways.com/en/legal/privacy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Airline — collects passenger name records (PNRs), passport/ID data, payment information, frequent-flyer activity, seat preferences, meal selections, and increasingly, facial recognition for boarding. PNR data shared with CBP (Customs and Border Protection) under federal mandate. International flights subject to EU PNR Directive and destination-country data-sharing requirements.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; Qatar Airways is privately held (Qatari government ownership) and not subject to GDPR directly as a non-EU carrier, though GDPR applies for EU passenger data.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up; Qatar Airways has one of the strongest post-2026 Middle East route recovery/expansion positions among Gulf carriers per recent industry reporting, relevant to overall operational reliability rather than privacy specifically.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Doha", "HQ State": "Qatar", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Qatar) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Qatar. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[BIOMETRICS · FL-2] Qatar Airways increasingly uses facial recognition for boarding and shares PNR data with CBP by mandate\nWHAT THE TERMS SAY: Qatar Airways collects passenger name records, passport/ID data, payment information, frequent-flyer activity, seat and meal preferences, and increasingly facial recognition for boarding, with PNR data shared with Customs and Border Protection under federal mandate.\nWHY IT MATTERS: PNR data is shared with Customs and Border Protection under federal mandate, and international flights are subject to the EU PNR Directive and destination-country data-sharing requirements.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-3] No findings exist because no institution exists to produce them - Qatar Airways has no independent regulator or breach-notification law\nWHAT THE TERMS SAY: Qatar Airways is wholly state-owned; Qatar has no independent data protection authority of the kind that generates the public enforcement record this tracker relies on, and there is no mandatory breach-notification regime producing disclosures.\nWHY IT MATTERS: As the tracker states, a blank row here should be read as a measurement failure rather than a clean record - the absence of findings reflects the absence of a disclosure regime, not the absence of incidents.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No Qatar Airways-specific breach, penalty, or litigation is confirmed this pass; only baseline data-collection practices and the structural absence of a disclosure regime are supported by this row's text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No independent data protection authority or breach-notification regime exists for this carrier, per the tracker.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "Qatar Airways  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Qatar Airways you gave up your biometric identifiers and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing independently confirmed this pass, and the reason is structural rather than reassuring: Qatar Airways is wholly state-owned, Qatar has no independent data protection authority of the kind that generates the public enforcement record this tracker relies on, and there is no mandatory breach-notification regime producing disclosures. Every finding elsewhere in this tab exists because some regulator, court or notification law forced it into daylight. Where none of those mechanisms exist, silence is the expected output regardless of what has actually happened, and a blank row should be read as a measurement failure rather than a clean record.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 304, "_entity_id": 467, "_entity_slug": "qatar-airways", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Etihad Airways", "Category": "Airline (Middle East, legacy)", "Terms & Conditions URL": "etihad.com/en-us/legal/conditions-of-carriage", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "etihad.com/en-us/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Airline — collects passenger name records (PNRs), passport/ID data, payment information, frequent-flyer activity, seat preferences, meal selections, and increasingly, facial recognition for boarding. PNR data shared with CBP (Customs and Border Protection) under federal mandate. International flights subject to EU PNR Directive and destination-country data-sharing requirements.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; Etihad is UAE government-owned and not directly subject to GDPR, though GDPR applies for EU passenger data (see Emirates row for a comparable Gulf-carrier GDPR enforcement precedent that may be instructive here).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Emirates row's MEDIF medical-data-retention finding as a plausible industry-wide pattern worth checking against Etihad's own practices given the shared Gulf-carrier medical-assistance documentation requirements.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] Etihad increasingly uses facial recognition for boarding and shares PNR data with CBP under federal mandate\nWHAT THE TERMS SAY: Etihad collects passenger name records, passport/ID data, payment information, frequent-flyer activity, seat and meal preferences, and increasingly facial recognition for boarding, with PNR data shared with Customs and Border Protection under federal mandate.\nWHY IT MATTERS: PNR data is shared with Customs and Border Protection under federal mandate, and international flights are subject to the EU PNR Directive and destination-country data-sharing requirements.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-3] No confirmed findings for Etihad - sovereign immunity and no independent regulator make consumer recourse largely theoretical\nWHAT THE TERMS SAY: Etihad is wholly owned by the Abu Dhabi government, with no independent supervisory authority, no mandatory breach notification producing a public record, and sovereign immunity considerations complicating any legal recourse by a foreign passenger.\nWHY IT MATTERS: As the tracker states, a European or US passenger's GDPR or state-law rights against a Gulf state carrier are far more theoretical than the privacy policy implies.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No Etihad-specific breach, penalty, or litigation is confirmed this pass; only baseline data-collection practices and the structural absence of a disclosure regime are supported by this row's text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No independent supervisory authority or breach-notification regime exists, and sovereign immunity complicates recourse, per the tracker.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "Etihad Airways  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Etihad Airways you gave up your biometric identifiers and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "No confirmed findings this pass. Etihad is wholly owned by the Abu Dhabi government, and the same disclosure-regime gap that applies to Qatar Airways applies here: no independent supervisory authority, no mandatory breach notification producing a public record, and sovereign immunity considerations that complicate any attempt at legal recourse by a foreign passenger. The honest entry is that this row is unverified rather than clean, and that a European or US passenger's GDPR or state-law rights against a Gulf state carrier are far more theoretical than the privacy policy implies.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 305, "_entity_id": 468, "_entity_slug": "etihad-airways", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Saudia (Saudi Arabian Airlines)", "Category": "Airline (Middle East, legacy)", "Terms & Conditions URL": "saudia.com/before-flying/policies/conditions-of-carriage", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "saudia.com/before-flying/policies/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Airline — collects passenger name records (PNRs), passport/ID data, payment information, frequent-flyer activity, seat preferences, meal selections, and increasingly, facial recognition for boarding. PNR data shared with CBP (Customs and Border Protection) under federal mandate. International flights subject to EU PNR Directive and destination-country data-sharing requirements.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; Saudia is Saudi state-owned and not directly subject to GDPR, though GDPR applies for EU passenger data.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] Saudia increasingly uses facial recognition for boarding and shares PNR data with CBP under federal mandate\nWHAT THE TERMS SAY: Saudia collects passenger name records, passport/ID data, payment information, frequent-flyer activity, seat and meal preferences, and increasingly facial recognition for boarding, with PNR data shared with Customs and Border Protection under federal mandate.\nWHY IT MATTERS: PNR data is shared with Customs and Border Protection under federal mandate, and international flights are subject to the EU PNR Directive and destination-country data-sharing requirements.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-3] No confirmed findings for Saudia - Saudi Arabia's data protection law is too new for an enforcement track record to exist\nWHAT THE TERMS SAY: Saudia is state-owned, and Saudi Arabia's Personal Data Protection Law is recent enough that its enforcement record against a national flag carrier is essentially untested; the tracker recommends treating the three Gulf carrier rows (Qatar Airways, Etihad, Saudia) as one open research question rather than three independent clean records.\nWHY IT MATTERS: Absence of documented incidents tracks the absence of institutions that would document them, per the tracker's own framing - not evidence of a clean privacy record.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No Saudia-specific breach, penalty, or litigation is confirmed this pass; only baseline data-collection practices and the structural absence of a disclosure regime are supported by this row's text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Saudi Arabia's data protection law is too recent to have generated an enforcement record for this carrier, per the tracker.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "Saudia (Saudi Arabian Airlines)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Saudia (Saudi Arabian Airlines) you gave up your biometric identifiers and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:52:37Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "No confirmed findings this pass. Saudia is state-owned, and Saudi Arabia's Personal Data Protection Law is recent enough that its enforcement record against a national flag carrier is essentially untested. The pattern across the Gulf carriers in this tab is consistent and worth stating plainly rather than repeating row by row: absence of documented incidents tracks the absence of institutions that would document them. Recommend treating all three Gulf rows as a single open research question rather than three independent clean records.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 306, "_entity_id": 469, "_entity_slug": "saudia-saudi-arabian-airlines", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Singapore Airlines", "Category": "Airline (Asia, legacy)", "Terms & Conditions URL": "singaporeair.com/en_UK/us/legal/conditions-of-carriage/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "singaporeair.com/en_UK/us/legal/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED PARTICIPANT IN THE 2021 SITA MULTI-AIRLINE BREACH (see Finnair and British Airways rows for full details): Singapore Airlines was one of at least TEN airlines — spanning both the Star Alliance AND OneWorld alliance networks — whose frequent-flyer program members' data was exposed through a single shared SITA passenger-data-sharing system, affecting more than 2 MILLION travelers combined across all participating carriers. This illustrates how deeply INTERCONNECTED airline loyalty-program infrastructure is: a single vulnerable third-party vendor can simultaneously compromise data at directly COMPETING airlines that have no other business relationship with each other beyond shared alliance membership.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — GDPR applies for EU passengers; Singapore's own Personal Data Protection Act (PDPA) applies domestically.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Cathay Pacific and Finnair rows for the fullest treatment of, respectively, an airline-specific breach (Cathay) versus this SAME shared-vendor SITA incident from a different angle.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Singapore", "HQ State": "Singapore", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2021", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Singapore) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Singapore. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2021 SITA breach exposed KrisFlyer data despite Singapore's comparatively strong PDPA privacy regime\nWHAT THE TERMS SAY: Singapore Airlines was one of at least 10 airlines across both Star Alliance and oneworld affected by the 2021 SITA breach, which exposed more than 2 million travelers' frequent-flyer data combined across all participating carriers.\nWHY IT MATTERS: Even a well-regulated carrier in a well-regulated jurisdiction (Singapore's PDPA) still exported its members' data into a shared vendor environment where one intrusion reached six airlines at once.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Alliance loyalty programs are the mechanism - member data has to move between carriers for miles to work\nWHAT THE TERMS SAY: Alliance loyalty programs require member data to move between carriers for mileage/status to function, which is how a single vendor breach reached competing airlines with no other business relationship beyond shared alliance membership.\nWHY IT MATTERS: This is a structural feature of how loyalty programs operate, not an isolated lapse - the sharing is by design, per the tracker.\n(evidence: SCARY | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only the shared SITA breach and its structural cause (alliance-wide data sharing) are supported by this row's text; arbitration and fee terms remain unconfirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The SITA breach and its scale are documented, but arbitration and fee terms are unconfirmed.", "Exposure Score (0-100)": 15, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Singapore Airlines  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Singapore Airlines you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Singapore Airlines was caught in the 2021 SITA vendor breach alongside Finnair, SAS, Japan Airlines and Air India - frequent-flyer data for KrisFlyer members exposed through a processor the airline itself chose and the passenger never saw named. Singapore has a comparatively strong data protection regime in the PDPA, which makes the row instructive: a well-regulated carrier in a well-regulated jurisdiction still exported its members' data into a shared vendor environment where a single intrusion reached six airlines at once. Alliance loyalty programmes are the mechanism - the data has to move between carriers for the miles to work.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 307, "_entity_id": 470, "_entity_slug": "singapore-airlines", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cathay Pacific", "Category": "Airline (Asia, legacy)", "Terms & Conditions URL": "cathaypacific.com/cx/en_US/legal/conditions-of-carriage.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "cathaypacific.com/cx/en_US/legal/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ONE OF THE MOST THOROUGHLY DOCUMENTED AIRLINE BREACHES FOUND IN THIS ENTIRE TRACKER (2018): hackers accessed passport numbers, Hong Kong ID numbers, credit card numbers, names, and travel history for 9.4 MILLION passengers across 260+ jurisdictions — the breach involved MULTIPLE vulnerabilities across FOUR separate systems (customer loyalty, a shared back-end database, a reporting tool, and the Asia Miles redemption database) and had been underway for an extended period before detection. Hong Kong's Privacy Commissioner (PCPD) issued a formal enforcement notice finding SPECIFIC, NAMED FAILURES: (1) a 2017 vulnerability scan failed to catch a critical, WIDELY PUBLICIZED (since 2007!) vulnerability even though Cathay's own scanning tool had been capable of detecting it since 2013; (2) the vulnerability scan itself was conducted only ANNUALLY, too infrequently; (3) an administrator console was accessible from the EXTERNAL internet rather than restricted to internal network access; (4) MULTI-FACTOR AUTHENTICATION was required only for Cathay's own IT support staff, not other remote system access, until finally fixed in July 2018; (5) database backup files used for migrations (2016-2018) were NOT ENCRYPTED; (6) a personal-data INVENTORY was not even STARTED until August 2017 and remained incomplete when the breach was discovered. Cathay delayed public disclosure for months after detecting the breach in March 2018 and confirming it in early May, not revealing it publicly until October 2018.", "Arbitration / Class Action Waiver": "NO CLASS ACTION WAIVER — Cathay Pacific's Conditions of Carriage are governed by Hong Kong law. The GBP 500K ICO fine (2020, max under pre-GDPR Data Protection Act 1998) was a UK regulatory action, not a class action. Hong Kong does not have a US-style class action mechanism.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is arguably the single most granular, item-by-item documented list of SPECIFIC security failures found anywhere in this entire 400+ company audit — the Hong Kong PCPD's enforcement notice reads almost like a checklist of 'everything a company can do wrong,' making it a uniquely instructive case study distinct from most other breach entries in this tracker, which tend to describe the HARM more than the specific TECHNICAL failures that caused it.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Hong Kong", "HQ State": "China", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.hunton.com/privacy-and-cybersecurity-law-blog/ico-fines-international-airline-cathay-pacific-gbp-500000-maximum-available-for-failing-to-secure-customers-personal-data", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Swire Pacific Limited (Hong Kong, 45% stake) + Air China (29.99%)", "Years Referenced in Finding (heuristic)": "2014, 2018", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (China) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in China. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Cathay Pacific's 2018 breach exposed 9.4 million passengers' passport and ID numbers after four years of undetected access\nWHAT THE TERMS SAY: Attackers accessed passport numbers, Hong Kong ID numbers, credit card numbers, names, and travel history for 9.4 million passengers across 260+ jurisdictions, with access dating to around October 2014, detection in March 2018, scope confirmed in May 2018, and public disclosure not until October 2018.\nWHY IT MATTERS: Passport and identity-card numbers, unlike a credit card, cannot be cancelled and reissued in a week - the tracker notes roughly four years of undetected exposure followed by about seven months of internal knowledge before customers were told.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-2] Hong Kong's PCPD enforcement notice reads as a checklist of basic security failures Cathay left uncorrected for years\nWHAT THE TERMS SAY: The PCPD found Cathay's 2017 vulnerability scan missed a critical, publicly known (since 2007) flaw its own scanning tool had been capable of detecting since 2013; that scans ran only annually; that an admin console was reachable from the external internet; that multi-factor authentication applied only to IT support staff until July 2018; that database backups were unencrypted from 2016-2018; and that a personal-data inventory wasn't started until August 2017 and remained incomplete when the breach was discovered.\nWHY IT MATTERS: Each of these is a well-known, low-cost security control that was either missing or badly implemented for years, not a novel or sophisticated attack technique.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[REGULATORY_PENALTY · FL-2] UK ICO's 500,000 pound fine - the maximum available at the time - worked out to about five pence per affected passenger\nWHAT THE TERMS SAY: The ICO fined Cathay 500,000 pounds in 2020, the maximum available under the pre-GDPR Data Protection Act 1998, for a breach affecting roughly 9.4 million people - the tracker calculates this as roughly five pence per affected passenger.\nWHY IT MATTERS: As the tracker frames it, the maximum available penalty under the applicable law was trivial relative to the scale of the breach, illustrating a regulatory-cap problem rather than a proportionate response.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The breach mechanics, specific technical failures, and enforcement outcome are all documented in unusually granular detail.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Cathay Pacific  <-  Swire Pacific Limited (Hong Kong, 45% stake) + Air China (29.99%)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Cathay Pacific takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T19:53:49Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Cathay is the most thoroughly documented airline breach in this tab, and the timeline is why: attackers had access from roughly October 2014, Cathay detected suspicious activity in March 2018, confirmed the scope in May, and told the public in October 2018 - four years of exposure followed by about seven months of internal knowledge before disclosure. Around 9.4 million passengers were affected, including passport numbers and identity card numbers, which unlike a credit card cannot be cancelled and reissued in a week. The UK ICO fine was £500,000, the maximum available under the pre-GDPR regime - roughly five pence per affected passenger.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 308, "_entity_id": 472, "_entity_slug": "cathay-pacific", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "ANA (All Nippon Airways)", "Category": "Airline (Asia, legacy)", "Terms & Conditions URL": "ana.co.jp/en/us/international/guide/conditions-of-carriage/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "ana.co.jp/en/us/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Airline — collects passenger name records (PNRs), passport/ID data, payment information, frequent-flyer activity, seat preferences, meal selections, and increasingly, facial recognition for boarding. PNR data shared with CBP (Customs and Border Protection) under federal mandate. International flights subject to EU PNR Directive and destination-country data-sharing requirements.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; Japan's APPI applies domestically, GDPR for EU passengers.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up confirming whether ANA was specifically among the SITA-breach-affected carriers documented for its Star Alliance partners elsewhere in this tab.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] ANA increasingly uses facial recognition for boarding and shares PNR data with CBP under federal mandate\nWHAT THE TERMS SAY: ANA collects passenger name records, passport/ID data, payment information, frequent-flyer activity, seat and meal preferences, and increasingly facial recognition for boarding, with PNR data shared with Customs and Border Protection under federal mandate.\nWHY IT MATTERS: PNR data is shared with Customs and Border Protection under federal mandate, and international flights are subject to the EU PNR Directive and destination-country data-sharing requirements.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] ANA's Star Alliance membership carries the same structural SITA-vendor exposure documented for its alliance partners - not independently confirmed for ANA itself\nWHAT THE TERMS SAY: ANA is a Star Alliance member with the same structural exposure the SITA breach demonstrated across the tab (frequent-flyer data circulating among alliance partners and shared aviation IT vendors by design), but no ANA-specific finding was confirmed this pass; the tracker recommends a follow-up on whether ANA was among the SITA-affected carriers.\nWHY IT MATTERS: An airline's own security posture is only one input into whether its members' data leaks when alliance infrastructure is shared; Japan's APPI does generate enforcement, so this null result carries somewhat more weight than in an unregulated jurisdiction, but it remains unverified rather than confirmed-clean.\n(evidence: SCARY | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No ANA-specific breach, penalty, or litigation is confirmed this pass; only baseline data-collection practices and an open question about SITA-breach exposure are supported by this row's text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "No ANA-specific incident is confirmed, though Japan's APPI provides a functioning enforcement backdrop unlike several other rows in this tab.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "ANA (All Nippon Airways)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using ANA (All Nippon Airways) you gave up your biometric identifiers and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "No ANA-specific finding confirmed this pass. ANA is a Star Alliance member with the same structural exposure the SITA breach demonstrated across this tab: frequent-flyer data circulates among alliance partners and shared aviation IT vendors by design, so an airline's own security posture is only one input into whether its members' data leaks. Japan's Act on the Protection of Personal Information governs here and does generate enforcement, so the null result carries somewhat more weight than it would for a carrier in a jurisdiction without a functioning regulator - but it is still unverified rather than verified-clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 309, "_entity_id": 473, "_entity_slug": "ana-all-nippon-airways", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Japan Airlines (JAL)", "Category": "Airline (Asia, legacy)", "Terms & Conditions URL": "jal.co.jp/jp/en/other/conditions_of_carriage/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "jal.co.jp/jp/en/other/privacy_policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SAME 2021 SITA MULTI-AIRLINE BREACH as Singapore Airlines/Finnair (see those rows). SEPARATELY, a MORE RECENT, DISTINCT incident (Feb 2026): JAL's 'Same-Day Baggage Delivery Service' reservation system was accessed illegitimately, with personal information of up to 28,000 users potentially leaked — JAL detected the issue quickly (staff noticed a service outage at 9am, traced unauthorized access to roughly 7 hours earlier, and suspended the reservation function within about 90 minutes of the initial report), a notably FASTER detection-and-response timeline than several other breaches documented elsewhere in this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — Japan's Act on the Protection of Personal Information (APPI) applies domestically; GDPR applies for EU passengers.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The 2026 baggage-service breach's relatively fast internal detection-to-suspension timeline (roughly 90 minutes from initial staff report to shutting down the vulnerable system) is a useful positive point of comparison against the much slower response timelines documented for Cathay Pacific, Sony/PSN, and Marriott elsewhere in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2021", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Feb 2026 breach of JAL's baggage-delivery reservation system may have leaked personal data for up to 28,000 users\nWHAT THE TERMS SAY: JAL's 'Same-Day Baggage Delivery Service' reservation system was accessed illegitimately in Feb 2026, with personal information of up to 28,000 users potentially leaked; JAL detected the issue quickly - staff noticed a service outage at 9am, traced unauthorized access to roughly 7 hours earlier, and suspended the reservation function within about 90 minutes of the initial report.\nWHY IT MATTERS: Up to 28,000 users' personal data was potentially exposed, though the tracker notes JAL's roughly 90-minute detection-to-suspension response was notably faster than several other breaches documented elsewhere in the tracker.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-2] JAL was also swept into the 2021 SITA vendor breach that hit Finnair, SAS and Singapore Airlines\nWHAT THE TERMS SAY: JAL was part of the same 2021 SITA multi-airline breach documented for Singapore Airlines and Finnair, a separate incident from the 2026 baggage-service breach.\nWHY IT MATTERS: JAL and ANA are direct competitors under the same Japanese privacy law, yet JAL appears in the SITA-breach cluster and ANA does not - a difference driven by vendor selection, not by any security decision a passenger could evaluate before booking.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Both confirmed breaches (2021 SITA, 2026 baggage-service) are distinct incidents of the same underlying harm type (unauthorized data access); no separate substantive item on arbitration, fees, or penalties is supported by this row's text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Both breaches are specifically documented, but arbitration and fee terms remain unconfirmed.", "Exposure Score (0-100)": 15, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Japan Airlines (JAL)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Japan Airlines (JAL) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "JAL was part of the 2021 SITA multi-airline breach that also reached Finnair, SAS, Singapore Airlines and Air India. The row's value in this tracker is comparative rather than dramatic: JAL and ANA are direct competitors in the same country under the same privacy law, one appears in the SITA cluster and one does not, and the difference came down to which aviation IT vendor each had contracted with rather than to any security decision a passenger could observe or evaluate before booking.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 310, "_entity_id": 474, "_entity_slug": "japan-airlines-jal", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Korean Air", "Category": "Airline (Asia, legacy)", "Terms & Conditions URL": "koreanair.com/us/en/footer/conditions-of-carriage", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "koreanair.com/us/en/footer/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Airline — collects passenger name records (PNRs), passport/ID data, payment information, frequent-flyer activity, seat preferences, meal selections, and increasingly, facial recognition for boarding. PNR data shared with CBP (Customs and Border Protection) under federal mandate. International flights subject to EU PNR Directive and destination-country data-sharing requirements.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; South Korea's Personal Information Protection Act (PIPA) applies domestically — one of the strictest data protection regimes in Asia, with meaningful private right of action; GDPR applies for EU passengers.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Seoul", "HQ State": "South Korea", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (South Korea) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in South Korea. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Korean Air collects PNRs, passport/ID and payment data; PNR data shared with CBP under federal mandate\nWHAT THE TERMS SAY: The row states Korean Air collects PNRs, passport/ID data, payment information, frequent-flyer activity, seat/meal preferences and increasingly facial recognition for boarding, with PNR data shared with CBP under federal mandate and international flights subject to the EU PNR Directive.\nWHY IT MATTERS: This is a wide set of identity, financial and biometric data points flowing to third parties and government agencies as routine practice, not a discrete incident.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[BIOMETRICS · FL-2] Facial recognition boarding is 'increasingly' used alongside passport and payment data collection\nWHAT THE TERMS SAY: The row states Korean Air's data collection is 'increasingly' including facial recognition for boarding.\nWHY IT MATTERS: Biometric identifiers, unlike passwords, cannot be reset once compromised.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-2] SkyTeam membership and post-merger Asiana integration expand Korean Air's data-sharing footprint\nWHAT THE TERMS SAY: The row notes Korean Air is a SkyTeam member, inside the same alliance data-sharing architecture that made the SITA breach reach six carriers at once, and recommends a follow-up on post-merger integration with Asiana, which consolidates two carriers' passenger databases into one.\nWHY IT MATTERS: Alliance-wide architecture and database consolidation both increase the number of systems through which a passenger's data can be exposed, though no Korean Air-specific breach is confirmed.\n(evidence: SCARY; Tracker says unconfirmed (firewall-edited: unverifiable figure removed) (fidelity pass 1: Wrong corrected) (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration, fees and breach status are all explicitly unconfirmed this pass; only generic industry-standard data-collection practices are described.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "Korean Air  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Korean Air you gave up your biometric identifiers and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "No Korean Air-specific breach confirmed this pass. Worth recording that South Korea's Personal Information Protection Commission is among the more active data protection regulators globally - it has pursued major platforms aggressively - so a null result in this jurisdiction is more meaningful than a null result in one without an enforcing authority. Korean Air is also a SkyTeam member and therefore inside the same alliance data-sharing architecture that made the SITA breach reach six carriers at once. Recommend a follow-up on Korean Air's post-merger integration with Asiana, which consolidates two carriers' passenger databases into one.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 311, "_entity_id": 475, "_entity_slug": "korean-air", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "China Southern Airlines", "Category": "Airline (Asia, legacy)", "Terms & Conditions URL": "csair.com/en/service/agreement/", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "csair.com/en/service/privacy/", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Airline — collects passenger name records (PNRs), passport/ID data, payment information, frequent-flyer activity, seat preferences, meal selections, and increasingly, facial recognition for boarding. PNR data shared with CBP (Customs and Border Protection) under federal mandate. International flights subject to EU PNR Directive and destination-country data-sharing requirements.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; China's Personal Information Protection Law (PIPL) applies domestically — a comprehensive law with data-localization requirements distinct from GDPR's model; GDPR applies separately for EU passengers.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "As a Chinese state-linked carrier, data-sovereignty considerations under PIPL (data localization within China) apply distinctly from the GDPR/CCPA frameworks governing most other airlines in this tab — recommend a direct follow-up given thin English-language litigation coverage.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$29.6B", "Market Cap": "$107.2B", "Employees": "28,457", "HQ City": "Atlanta", "HQ State": "Georgia", "CEO": "Christopher Womack", "Ticker": "SO", "Website (Corporate)": "southerncompany.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (SO). Service route: c/o General Counsel / Corporate Secretary, Atlanta, Georgia — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Georgia' is a non-DMV US state", "Parent / Ultimate Owner": "China Southern Air Holding (state-owned)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Georgia SOS eCorp — ecorp.sos.ga.gov/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: China Southern Air Holding (state-owned)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] China Southern collects PNRs, passport/ID and payment data; PNR data shared with CBP under federal mandate\nWHAT THE TERMS SAY: The row states China Southern collects PNRs, passport/ID data, payment information, frequent-flyer activity, seat/meal preferences and increasingly facial recognition for boarding, with PNR data shared with CBP under federal mandate and EU PNR Directive obligations on international flights.\nWHY IT MATTERS: This is a broad set of identity, financial and biometric data points moving to third parties and government agencies as routine practice.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[BIOMETRICS · FL-2] Facial recognition boarding is 'increasingly' used in China Southern's passenger data collection\nWHAT THE TERMS SAY: The row states data collection is 'increasingly' including facial recognition for boarding.\nWHY IT MATTERS: Biometric identifiers cannot be reset the way a password can if compromised.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-3] As a Chinese state-linked carrier, China Southern's privacy policy says nothing about state access to passenger data\nWHAT THE TERMS SAY: The row states PIPL applies domestically but operates alongside national security and intelligence laws obliging Chinese organizations to cooperate with state requests; for a state-owned airline the privacy policy governs only commercial data handling, not state access.\nWHY IT MATTERS: No contractual privacy term can constrain government data requests under China's national security framework, so PIPL protections may not extend to state access.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No confirmed public finding exists this pass, and the tracker notes thin English-language litigation coverage; only generic data practices and structural jurisdictional context are stated.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "China Southern Airlines  <-  China Southern Air Holding (state-owned)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using China Southern Airlines you gave up your biometric identifiers and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "No confirmed public finding this pass, and the framing matters more here than the result. China's Personal Information Protection Law is on paper one of the more demanding privacy statutes in the world, but it operates alongside national security and intelligence laws that oblige Chinese organisations to cooperate with state requests - the same structural point documented in the DeepSeek and Moonshot rows of the LLM Providers tab. For a state-owned airline, the privacy policy governs the company's commercial handling of your data and says nothing meaningful about state access to it, and no contractual term can.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 312, "_entity_id": 477, "_entity_slug": "china-southern-airlines", "_issuer": "China Southern Air Holding", "_issuer_slug": "china-southern-air-holding", "_ticker": "SO", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "China Eastern Airlines", "Category": "Airline (Asia, legacy)", "Terms & Conditions URL": "us.ceair.com/en/agreement/", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "us.ceair.com/en/privacy/", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Airline — collects passenger name records (PNRs), passport/ID data, payment information, frequent-flyer activity, seat preferences, meal selections, and increasingly, facial recognition for boarding. PNR data shared with CBP (Customs and Border Protection) under federal mandate. International flights subject to EU PNR Directive and destination-country data-sharing requirements.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; same PIPL data-sovereignty considerations as China Southern apply (see that row).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See China Southern row for shared PIPL/data-localization context applicable to Chinese carriers broadly.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Shanghai", "HQ State": "China", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "China Eastern Air Holding (state-owned)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (China) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in China. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] China Eastern collects PNRs, passport/ID and payment data; PNR data shared with CBP under federal mandate\nWHAT THE TERMS SAY: The row states China Eastern collects PNRs, passport/ID data, payment information, frequent-flyer activity, seat/meal preferences and increasingly facial recognition for boarding, with PNR data shared with CBP under federal mandate and EU PNR Directive obligations on international flights.\nWHY IT MATTERS: This is a broad set of identity, financial and biometric data points moving to third parties and government agencies as routine practice.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[BIOMETRICS · FL-2] Facial recognition boarding is 'increasingly' used in China Eastern's passenger data collection\nWHAT THE TERMS SAY: The row states data collection is 'increasingly' including facial recognition for boarding.\nWHY IT MATTERS: Biometric identifiers cannot be reset the way a password can if compromised.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The SCARY field explicitly states the PIPL/state-access structural analysis is identical to China Southern's and warns against recording three near-identical Chinese-carrier rows as if they were three independent assessments; no China Eastern-specific breach or arbitration term is confirmed this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No confirmed public finding exists this pass; the row explicitly defers its structural analysis to the China Southern row rather than presenting an independent one.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "China Eastern Airlines  <-  China Eastern Air Holding (state-owned)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using China Eastern Airlines you gave up your biometric identifiers and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T19:56:23Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "No confirmed public finding this pass. The analysis is identical to China Southern and should be read together: state-owned carrier, PIPL on paper, national security and intelligence law obligations underneath, and no independent breach-notification pipeline generating the kind of public record the rest of this tab is built from. Recording three near-identical Chinese carrier rows separately risks implying three independent assessments were made; they were not, and the honest statement is that one structural finding applies to all three.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 313, "_entity_id": 479, "_entity_slug": "china-eastern-airlines", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Air China", "Category": "Airline (Asia, legacy)", "Terms & Conditions URL": "airchina.us/US/GB/Info/agreement", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "airchina.us/US/GB/Info/privacy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Airline — collects passenger name records (PNRs), passport/ID data, payment information, frequent-flyer activity, seat preferences, meal selections, and increasingly, facial recognition for boarding. PNR data shared with CBP (Customs and Border Protection) under federal mandate. International flights subject to EU PNR Directive and destination-country data-sharing requirements.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; same PIPL data-sovereignty considerations as China Southern/China Eastern apply.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See China Southern row for shared PIPL/data-localization context applicable to Chinese carriers broadly; as China's FLAG carrier specifically, Air China may carry additional state-affiliation considerations distinct from China Southern/Eastern's more commercially-oriented positioning.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Beijing", "HQ State": "China", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "China National Aviation Holding (state-owned)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (China) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in China. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Air China collects PNRs, passport/ID and payment data; PNR data shared with CBP under federal mandate\nWHAT THE TERMS SAY: The row states Air China collects PNRs, passport/ID data, payment information, frequent-flyer activity, seat/meal preferences and increasingly facial recognition for boarding, with PNR data shared with CBP under federal mandate and EU PNR Directive obligations on international flights.\nWHY IT MATTERS: This is a broad set of identity, financial and biometric data points moving to third parties and government agencies as routine practice.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[BIOMETRICS · FL-2] Facial recognition boarding is 'increasingly' used in Air China's passenger data collection\nWHAT THE TERMS SAY: The row states data collection is 'increasingly' including facial recognition for boarding.\nWHY IT MATTERS: Biometric identifiers cannot be reset the way a password can if compromised.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-2] Star Alliance membership puts Air China in routine two-way data flow with European and North American carriers\nWHAT THE TERMS SAY: The row states Air China is China's flag carrier and a Star Alliance member, inside the alliance's frequent-flyer data-sharing architecture alongside Lufthansa, ANA and Singapore Airlines, meaning passenger data flows between a Chinese state-owned carrier and European/North American carriers as a routine matter of loyalty-programme operation, in both directions.\nWHY IT MATTERS: Alliance membership means passenger data flows in both directions between a Chinese state-owned carrier and European and North American carriers as a routine matter of loyalty-programme operation, not as an incident.\n(evidence: SCARY; Stated in tracker (fidelity pass 1: Overstated corrected) (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No Air China-specific breach or arbitration term is confirmed; the alliance data-flow detail is the only genuinely company-specific fact beyond generic industry practice.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "Air China  <-  China National Aviation Holding (state-owned)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Air China you gave up your biometric identifiers and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "No confirmed public finding this pass - see the China Southern and China Eastern rows for the shared structural analysis. Air China is the flag carrier and a Star Alliance member, which places it inside the alliance frequent-flyer data-sharing architecture alongside Lufthansa, ANA, Singapore Airlines and others. That is the one genuinely notable detail: alliance membership means passenger data flows between a Chinese state-owned carrier and European and North American carriers as a routine matter of loyalty-programme operation, in both directions.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 314, "_entity_id": 481, "_entity_slug": "air-china", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "IndiGo", "Category": "Airline (Asia, LCC)", "Terms & Conditions URL": "goindigo.in/information/conditions-of-carriage.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "goindigo.in/information/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Airline — collects passenger name records (PNRs), passport/ID data, payment information, frequent-flyer activity, seat preferences, meal selections, and increasingly, facial recognition for boarding. PNR data shared with CBP (Customs and Border Protection) under federal mandate. International flights subject to EU PNR Directive and destination-country data-sharing requirements.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; India's Digital Personal Data Protection Act (DPDPA) applies domestically.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "As India's largest airline by domestic market share, IndiGo carries a very large share of India's overall air travel — recommend a direct follow-up given thin verification this pass relative to its market significance.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Gurugram", "HQ State": "India", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "InterGlobe Aviation Limited", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (India) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in India. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] IndiGo collects PNRs, passport/ID and payment data; PNR data shared with CBP under federal mandate\nWHAT THE TERMS SAY: The row states IndiGo collects PNRs, passport/ID data, payment information, frequent-flyer activity, seat/meal preferences and increasingly facial recognition for boarding, with PNR data shared with CBP under federal mandate and EU PNR Directive obligations on international flights.\nWHY IT MATTERS: This is a broad set of identity, financial and biometric data points moving to third parties and government agencies as routine practice.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[BIOMETRICS · FL-2] Facial recognition boarding is 'increasingly' used in IndiGo's passenger data collection\nWHAT THE TERMS SAY: The row states data collection is 'increasingly' including facial recognition for boarding.\nWHY IT MATTERS: Biometric identifiers cannot be reset the way a password can if compromised.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[NO_DISCLOSURE_THICK_FOG · FL-3] IndiGo's scale makes the absence of a confirmed breach notable, not reassuring, while India's new data law was still standing up enforcement\nWHAT THE TERMS SAY: The row states no IndiGo-specific breach is confirmed this pass but frames the absence as notable given IndiGo's position as India's largest domestic airline, and notes India's Digital Personal Data Protection Act is recent, with enforcement machinery still being stood up during this period.\nWHY IT MATTERS: A newly-enforced privacy law may not yet be generating the public breach record this tracker relies on, so a clean-looking row may reflect weak enforcement rather than strong security.\n(evidence: Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No IndiGo-specific breach or arbitration term is confirmed, and the tracker notes India's DPDPA enforcement regime was still being established during this period.", "Exposure Score (0-100)": 18, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "IndiGo  <-  InterGlobe Aviation Limited", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using IndiGo you gave up your biometric identifiers and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "No IndiGo-specific breach confirmed this pass. IndiGo is India's dominant domestic carrier by a wide margin, which makes the absence notable rather than reassuring - a carrier of that scale is a proportionally large target. India's Digital Personal Data Protection Act is recent and its enforcement machinery was still being stood up through this period, so the window in which an incident would have been forced into public view was narrow. Recommend a targeted follow-up once DPDP Act enforcement produces a track record.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 315, "_entity_id": 483, "_entity_slug": "indigo", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Air India (Tata Group)", "Category": "Airline (Asia, legacy)", "Terms & Conditions URL": "airindia.com/in/en/important-information/conditions-of-carriage.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "airindia.com/in/en/important-information/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED PARTICIPANT IN THE SAME 2021 SITA MULTI-AIRLINE BREACH as Singapore Airlines/Finnair/JAL (see those rows), but at a MUCH LARGER SCALE for Air India specifically: approximately 4.5 MILLION passengers' personal data was compromised, including passport and payment card details, spanning roughly 10 YEARS of accumulated passenger data (2011-2021). An individual passenger (journalist Ritika Handoo) filed a lawsuit seeking approximately $403,000 in compensation, with her attorney specifically invoking a 'right to be forgotten' and 'informational autonomy' framework — arguing that having personal data STOLEN (as opposed to merely collected) represents a total loss of control over one's own information.", "Arbitration / Class Action Waiver": "NO CLASS ACTION WAIVER — Air India's Conditions of Carriage are governed by Indian law. The SITA PSS breach (Feb 2021, 4.5M passengers) was a third-party vendor incident affecting multiple Star Alliance airlines. Indian consumer protection law (Consumer Protection Act, 2019) does not recognize US-style class action waivers.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The 10-year accumulated data window (2011-2021) affected by this single breach illustrates how airline loyalty/passenger data retention can compound risk over a very long period — a breach doesn't just expose recent activity, it can expose a decade or more of accumulated travel history at once.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New Delhi", "HQ State": "India", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://therecord.media/air-india-says-data-breach-impacts-4-5-million-former-passengers", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Tata Sons Private Limited (Mumbai, India)", "Years Referenced in Finding (heuristic)": "2021", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (India) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in India. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2021 SITA breach exposed roughly 4.5 million Air India passengers' passport and payment data across a decade of records\nWHAT THE TERMS SAY: The row states Air India was part of the Feb 2021 SITA multi-airline breach, with roughly 4.5 million passengers' data compromised including passport and payment card details, spanning approximately 10 years of accumulated passenger data (2011-2021).\nWHY IT MATTERS: A single vendor breach exposed a decade of accumulated travel history at once, including non-resettable identifiers like passport numbers.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] A passenger sued Air India for roughly $403,000 over the SITA breach, arguing stolen data means total loss of informational control\nWHAT THE TERMS SAY: The row states journalist Ritika Handoo filed a lawsuit seeking approximately $403,000 in compensation, with her attorney invoking a 'right to be forgotten' and 'informational autonomy' framework, arguing that data being stolen represents a total loss of control over one's information.\nWHY IT MATTERS: This is an individual suit testing whether Indian law recognizes a remedy for loss-of-control harm distinct from provable financial loss; it is an allegation, not a ruling.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-4] Privatization from state-owned to Tata Group created an accountability gap for the SITA breach\nWHAT THE TERMS SAY: The row states Air India was state-owned at the time of the breach and has since been privatized under Tata Group, so the entity that made the security decisions and the entity a passenger would now pursue are not the same organization.\nWHY IT MATTERS: The ownership transfer did not transfer any practical remedy to the people whose passport numbers were exposed.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2021 SITA breach and the resulting lawsuit are documented with specific figures, but broader contract terms such as fees are not addressed this pass.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Air India (Tata Group)  <-  Tata Sons Private Limited (Mumbai, India)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Air India (Tata Group) you gave up your data shared corporate-wide. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T19:58:48Z (HTTP 200, CHANGED)", "SCARY (most astonishing T&C item)": "Air India was part of the 2021 SITA breach, and its exposure is the most severe in that cluster: roughly 4.5 million passengers, with data including passport details and, for a subset, credit card information. The exposure window ran for years before disclosure. Air India was state-owned at the time and has since been privatised under the Tata Group, which creates a genuine accountability gap - the entity that made the security decisions and the entity a passenger would now pursue are not the same organisation, and the transfer of ownership did not transfer any practical remedy to the people whose passport numbers were taken.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 316, "_entity_id": 485, "_entity_slug": "air-india-tata-group", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Vietnam Airlines", "Category": "Airline (Asia, legacy)", "Terms & Conditions URL": "vietnamairlines.com/vn/en/legal-notice", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "vietnamairlines.com/vn/en/privacy-policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Airline — collects passenger name records (PNRs), passport/ID data, payment information, frequent-flyer activity, seat preferences, meal selections, and increasingly, facial recognition for boarding. PNR data shared with CBP (Customs and Border Protection) under federal mandate. International flights subject to EU PNR Directive and destination-country data-sharing requirements.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; Vietnam's Personal Data Protection Decree applies domestically.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin English-language litigation coverage this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Hanoi", "HQ State": "Vietnam", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Vietnamese state majority owner", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Vietnam) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Vietnam. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Vietnam Airlines collects PNRs, passport/ID and payment data; PNR data shared with CBP under federal mandate\nWHAT THE TERMS SAY: The row states Vietnam Airlines collects PNRs, passport/ID data, payment information, frequent-flyer activity, seat/meal preferences and increasingly facial recognition for boarding, with PNR data shared with CBP under federal mandate and EU PNR Directive obligations on international flights.\nWHY IT MATTERS: This is a broad set of identity, financial and biometric data points moving to third parties and government agencies as routine practice.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[BIOMETRICS · FL-2] Facial recognition boarding is 'increasingly' used in Vietnam Airlines' passenger data collection\nWHAT THE TERMS SAY: The row states data collection is 'increasingly' including facial recognition for boarding.\nWHY IT MATTERS: Biometric identifiers cannot be reset the way a password can if compromised.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[NO_DISCLOSURE_THICK_FOG · FL-3] Vietnam Airlines: majority state-owned, under a recent data-protection decree largely untested on a carrier\nWHAT THE TERMS SAY: The row states Vietnam Airlines is majority state-owned and operates under a data protection decree that is recent and largely untested against a national carrier, and that the honest reading is the row is unverified rather than clean.\nWHY IT MATTERS: Without regulators, courts or mandatory notification producing a public record, consumers have no independent way to confirm how their data is handled.\n(evidence: SCARY; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Only generic industry data practices are confirmed; arbitration, breach status and enforcement track record are all explicitly unconfirmed.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "Vietnam Airlines  <-  Vietnamese state majority owner", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Vietnam Airlines you gave up your biometric identifiers and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "No confirmed finding this pass. Vietnam Airlines is majority state-owned and operates under a data protection decree that is recent and largely untested against a national carrier. As with the Gulf and Chinese carriers in this tab, the honest reading is that the row is unverified rather than clean: the public record this tracker depends on is produced by regulators, courts and mandatory notification laws, and where those are absent or newly established, a blank row measures the institutions rather than the airline.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 317, "_entity_id": 487, "_entity_slug": "vietnam-airlines", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "AirAsia", "Category": "Airline (Asia, LCC)", "Terms & Conditions URL": "airasia.com/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "airasia.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "HISTORICAL CONFIRMED BREACH (2022, disclosed by researchers): AirAsia suffered a ransomware attack (by the Daixin Team group) that reportedly compromised personal data of both employees and up to 5 million unique passengers — the airline reportedly did not pay the ransom demanded.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; Malaysia's Personal Data Protection Act applies domestically.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up to confirm current status/resolution of this 2022 incident given the scale (up to 5 million passengers potentially affected).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Sepang", "HQ State": "Malaysia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Capital A Berhad", "Years Referenced in Finding (heuristic)": "2022", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Malaysia) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Malaysia. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2022 Daixin Team ransomware attack reportedly compromised data of up to 5 million AirAsia passengers and staff\nWHAT THE TERMS SAY: The row states a 2022 ransomware attack by the Daixin Team group reportedly compromised personal data of employees and up to 5 million unique passengers; AirAsia reportedly did not pay the ransom demanded.\nWHY IT MATTERS: A breach of this scale, reportedly involving both staff and millions of passengers, creates a large pool of people exposed to identity-theft and fraud risk.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-2] AirAsia's breach was disclosed by security researchers and the attackers, not by AirAsia itself\nWHAT THE TERMS SAY: The row states the breach was disclosed by security researchers rather than AirAsia, and that the ransomware group publicly criticized the state of AirAsia's internal network.\nWHY IT MATTERS: When disclosure comes from attackers rather than the company, affected passengers lose early, accurate notice while there is still time to act.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and class-action terms are explicitly unconfirmed this pass, and no additional distinct company-specific harm beyond the breach and its disclosure pathway is stated in the row.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach and its disclosure pathway are clearly stated, but scope figures are hedged as 'reportedly' and arbitration/fee terms are not addressed.", "Exposure Score (0-100)": 11, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "AirAsia  <-  Capital A Berhad", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, AirAsia takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "2026-09-08T19:58:55Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The 2022 AirAsia breach was disclosed by security researchers rather than by AirAsia, and the ransomware group involved made a point of publicly criticising the state of AirAsia's internal network. That inversion is the finding: passengers learned from third parties, and the most detailed public account of a carrier's security posture came from the people who broke into it. When disclosure is driven by researchers and attackers rather than by the company, passengers lose the one thing that actually helps them - early, accurate notice while there is still time to act.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 318, "_entity_id": 489, "_entity_slug": "airasia", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Qantas", "Category": "Airline (Oceania, legacy)", "Terms & Conditions URL": "qantas.com/us/en/support/conditions-of-carriage.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "qantas.com/us/en/support/privacy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ONE OF THE LARGEST AUSTRALIAN DATA BREACHES IN RECENT HISTORY: on June 30, 2025, Qantas detected unusual activity on a third-party customer-service platform used by its Manila-based contact center, ultimately affecting approximately 5.7–6 MILLION customers — for about 4 million, exposed data was limited to names, emails, and frequent flyer numbers; for a further ~1.7 million, exposed data also included addresses, phone numbers, birth dates, gender, and MEAL PREFERENCES. Qantas confirmed credit card details, passport information, and frequent-flyer PASSWORDS were not stored on the compromised system and remained secure. The breach is suspected (though not formally confirmed by Qantas) to be the work of the 'Scattered Spider' cybercriminal group, which the FBI specifically warned (June 27, 2025) was expanding into the AIRLINE SECTOR — using social engineering to impersonate employees/contractors and trick IT help desks into granting system access, rather than a traditional technical hack. Qantas's breach came within WEEKS of nearly identical attacks on Hawaiian Airlines and Canada's WestJet, all attributed to the same threat actor/technique, and triggered an investigation by the Australian Federal Police.", "Arbitration / Class Action Waiver": "NO CLASS ACTION WAIVER — Qantas' Conditions of Carriage are governed by Australian law (Australian Consumer Law, Competition and Consumer Act 2010). The AUD $100M 'ghost flights' penalty (Oct 2024) was brought by the ACCC as a regulatory action, not a class action. Australian consumer law provides stronger statutory protections than US contracts of carriage.", "Fees / Billing Flags": "ACTIVE CLASS ACTION (Australia, referenced 2025): customers are being invited to register for a class action over the breach; specific settlement terms not yet available as of this research.", "Notes": "This breach is part of a documented, THREE-AIRLINE CLUSTER (Qantas, Hawaiian Airlines, WestJet) hit by the same attacker group within a three-week window in mid-2025 — a genuinely coordinated, sector-wide campaign rather than three unrelated incidents, illustrating how a single threat actor's technique (social-engineering IT help desks) can rapidly compromise multiple major airlines in quick succession.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mascot", "HQ State": "Australia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Fetched - awaiting document verification", "Region Tag": "National", "Primary Source URL": "https://www.accc.gov.au/media-release/federal-court-orders-qantas-to-pay-100m-in-penalties-for-misleading-consumers", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Qantas Airways Limited (Sydney, Australia)", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Australia) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Australia. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2025 breach exposed up to 6 million Qantas customers via a hacked third-party contact-center platform, part of a 3-airline cluster\nWHAT THE TERMS SAY: The row states that on June 30, 2025 Qantas detected unusual activity on a third-party customer-service platform at its Manila contact center, ultimately affecting approximately 5.7-6 million customers - about 4 million had names, emails and frequent-flyer numbers exposed, and roughly 1.7 million also had addresses, phone numbers, birth dates, gender and meal preferences exposed; credit card, passport and password data were not on the compromised system. The attack is suspected, though not formally confirmed by Qantas, to be the work of the 'Scattered Spider' group.\nWHY IT MATTERS: Even the lower-severity tier of exposure affecting 4 million people is enough for targeted phishing, and the breach is part of a documented pattern also hitting Hawaiian Airlines and WestJet within weeks, attributed to social-engineering of IT help desks rather than a technical exploit.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] Australian customers are being invited to join an active class action over the 2025 Qantas data breach\nWHAT THE TERMS SAY: The row states an active class action in Australia (referenced 2025) is inviting customers to register over the breach, with settlement terms not yet available; Qantas's Conditions of Carriage carry no class-action waiver under Australian law.\nWHY IT MATTERS: Because Australian law does not allow US-style class waivers, affected customers retain a class-action path that customers of a US carrier bound by a waiver might not.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[REGULATORY_PENALTY · FL-1] Qantas was fined A$100 million for knowingly selling tickets on flights it had already cancelled, misleading over 970,000 people\nWHAT THE TERMS SAY: The row states Australia's Federal Court ordered Qantas to pay A$100 million in October 2024 for selling tickets on 70,543 already-cancelled flights, on sale an average of eleven days and in some cases up to 62 days after cancellation, booking 86,597 people onto flights that did not exist and failing to promptly notify 883,977 more; the ACCC found senior managers were aware and did not act, and Qantas admitted it profited from customers who would have chosen a cheaper Qantas flight or a competitor had they known. Compensation was A$225 domestic and A$450 international.\nWHY IT MATTERS: Consumers paid for and planned around flights Qantas had already decided to cancel, and the row records that senior managers responsible for those systems knew cancelled flights had not been pulled from sale and did not act.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Both the 2025 breach and the 2024 ACCC penalty are described with specific, sourced figures rather than hedged language.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Qantas  <-  Qantas Airways Limited (Sydney, Australia)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Qantas you gave up your data shared corporate-wide. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "2026-09-08T20:00:07Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Qantas was ordered by Australia's Federal Court to pay A$100 million in October 2024 for selling tickets on flights it had already decided to cancel. The specifics are worse than the headline: 70,543 flights, tickets still on sale an average of eleven days after cancellation and in some cases up to 62 days, 86,597 people booked onto flights that did not exist, and 883,977 more misled by Qantas failing to promptly tell them their flight was cancelled. The ACCC found senior managers responsible for those systems were AWARE cancelled flights had not been pulled from sale and did not act, and Qantas admitted it profited from customers who would have chosen a cheaper Qantas flight or a competitor had they known. Qantas defended itself by arguing it does not sell specific flights at all, only a bundle of rights. Compensation was A$225 domestic, A$450 international.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 319, "_entity_id": 491, "_entity_slug": "qantas", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Air Canada", "Category": "Airline (North America, legacy)", "Terms & Conditions URL": "aircanada.com/ca/en/aco/home/legal/conditions-of-carriage.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "aircanada.com/ca/en/aco/home/legal/privacy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Air Canada is a co-owner of the SAME ARC data-brokerage entity discussed in the JetBlue row (Travel Intelligence Program, selling passenger ticketing data to CBP/ICE/Secret Service/DEA) — relevant specifically because Air Canada is the only NON-US carrier among ARC's ownership group named in that research, meaning Canadian passenger data may flow into this US surveillance-adjacent system.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — Canadian consumer protection law and the Canadian Transportation Agency (CTA) complaint process apply rather than a US-style arbitration clause.", "Fees / Billing Flags": "MAJOR TRANSPARENCY FINDING (July 2026): Air Canada, alongside WestJet, Air Transat, Jazz Aviation, and their industry association, formally OPPOSED a court challenge to the CTA's confidentiality rule for air-travel complaints — arguing that keeping complaint outcomes confidential (unless BOTH the passenger AND airline agreed to waive it) protected 'commercial interests' and passenger/employee privacy. An Ontario Superior Court judge REJECTED this argument, ruling the confidentiality requirement unconstitutional (violating Canada's Charter of Rights) and finding NO EVIDENCE it was 'necessary or required' for the process to function — a passenger-rights advocate had called the rule a 'gag order' that let airlines keep their 'dirty laundry' out of public view, noting a backlog of nearly 100,000 unresolved complaints had built up under the confidential system.", "Notes": "This is a genuinely significant finding: Air Canada (and Canada's other major airlines) actively fought IN COURT to keep consumer-complaint outcomes confidential, and LOST — worth flagging prominently as a rare instance in this tracker of a company's own litigation position (favoring secrecy) being explicitly rejected by a court on constitutional grounds.\n\nARC CROSS-REFERENCE (verified this pass): the Airlines Reporting Corporation is a ticket-settlement clearinghouse owned by major carriers, with Delta, Southwest, United, American, Alaska, JetBlue, Lufthansa, Air France and Air Canada all holding seats on its board. 240+ airlines use ARC for ticket settlement. Via its Travel Intelligence Program (TIP), ARC sold access to US travelers' domestic flight records - names, itineraries and financial information - to Customs and Border Protection. Per CBP documents obtained by 404 Media under FOIA, the contract barred CBP from disclosing where the data came from. CBP's stated purpose was supporting federal, state and local law enforcement in identifying persons of interest's domestic air ticketing information. Treat as ONE connected story across every carrier row with an ARC board seat, not as separate incidents.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Montreal", "HQ State": "Canada", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Canada) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Canada. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[DATA_SALE · FL-2] Air Canada co-owns ARC, which sold US travelers' flight records to CBP under a contract barring CBP from naming the source\nWHAT THE TERMS SAY: The row states Air Canada holds a board seat at ARC, a carrier-owned ticket-settlement clearinghouse whose Travel Intelligence Program sold US travelers' domestic flight records - names, itineraries, financial information - to Customs and Border Protection, per CBP documents obtained under FOIA, under a contract reportedly barring CBP from disclosing where the data came from; Air Canada is named as the only non-US carrier in ARC's ownership group.\nWHY IT MATTERS: A passenger has no way to know their booking data reached a law-enforcement agency, or that the agency was contractually barred from naming its source.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-3] Air Canada fought in court to keep airline complaint outcomes confidential and an Ontario judge ruled the secrecy rule unconstitutional\nWHAT THE TERMS SAY: The row states Air Canada, alongside WestJet, Air Transat, Jazz and their industry association, opposed a court challenge to the CTA's confidentiality rule for complaints, arguing secrecy protected commercial interests; an Ontario Superior Court judge rejected this, ruling the rule violated Canada's Charter and finding no evidence it was necessary, amid a backlog of nearly 100,000 unresolved complaints.\nWHY IT MATTERS: The airline's own litigation position favored keeping complaint outcomes hidden from the public, and a court found no legitimate need for that secrecy.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[LIABILITY_CAP_INDEMNITY · FL-1] Air Canada argued in tribunal its own website chatbot was a separate legal entity not responsible for its answers - and lost\nWHAT THE TERMS SAY: The row states in Moffatt v. Air Canada the airline argued its chatbot was 'a separate legal entity responsible for its own actions' after it gave a grieving passenger wrong information about bereavement fares; the tribunal called the argument remarkable, rejected it, and held Air Canada responsible for everything on its website - the first ruling of its kind.\nWHY IT MATTERS: The company tried to disclaim liability for its own AI tool's mistake before a tribunal shut that argument down, showing the instinct to shift risk onto the customer.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The ARC data-brokerage arrangement and two court rulings are documented with sources, but Air Canada's own consumer arbitration terms are not independently confirmed this pass.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Air Canada  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n\nNOT YET DETERMINED (10 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Air Canada you gave up your personal data sold onward, your data shared corporate-wide, and your right to meaningful compensation. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Two findings, and the second is the one with legs. Air Canada holds a board seat at ARC, the carrier-owned clearinghouse that sold US travelers' domestic flight records to Customs and Border Protection under a contract reportedly barring CBP from naming the source. Separately, in Moffatt v. Air Canada the airline argued in a tribunal that its own website chatbot was 'a separate legal entity responsible for its own actions' after the bot gave a grieving passenger wrong information about bereavement fares. The tribunal called the submission remarkable and rejected it outright, holding that a company is responsible for everything on its website and that customers cannot be expected to cross-check one part of a company's site against another. It is the first ruling of its kind and the reason no company can now disclaim its own AI.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 320, "_entity_id": 492, "_entity_slug": "air-canada", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Alaska Airlines", "Category": "Airline (North America, legacy)", "Terms & Conditions URL": "alaskaair.com/content/legal/contract-of-carriage", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "alaskaair.com/content/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ACTIVE TRACKING/PRIVACY INVESTIGATION (2026): attorneys are investigating whether Alaska Airlines collects and shares website visitors' data with third parties without adequate consent, evaluating a potential California-specific class action. Alaska Airlines is one of the CO-OWNERS of the ARC data-brokerage entity that sold passenger data to CBP under the Travel Intelligence Program (see JetBlue row for full details on this billion-record, cross-industry finding).", "Arbitration / Class Action Waiver": "CLASS ACTION WAIVER in Contract of Carriage. NO mandatory arbitration. Alaska completed its acquisition of Hawaiian Airlines in Sept 2024. The combined carrier's CC terms may not yet be fully harmonized — check which CC governs a specific ticket.", "Fees / Billing Flags": "SEPARATE, UNRELATED CONTRACT DISPUTE: Alaska Air Group has been ordered to pay the VIRGIN GROUP $32 MILLION in a UK court dispute over trademark-licensing royalties tied to Alaska's 2016 acquisition of Virgin America — the court found Alaska owed an $8 MILLION PER YEAR minimum royalty through 2039 REGARDLESS of whether Alaska actually still used the Virgin brand (which it stopped using after acquiring the airline); Alaska has separately sued Virgin Group over the same agreement, which may affect its total ultimate liability. This is a B2B trademark dispute, not a customer-privacy issue, but illustrates a real, ongoing financial exposure for the company.", "Notes": "The $8M/year minimum royalty REGARDLESS OF ACTUAL USE is a striking illustration of how a corporate acquisition (Alaska buying Virgin America) can leave a company on the hook for a licensing fee tied to a brand it no longer even uses — relevant corporate-conduct context though unrelated to consumer privacy specifically.\n\nARC CROSS-REFERENCE (verified this pass): the Airlines Reporting Corporation is a ticket-settlement clearinghouse owned by major carriers, with Delta, Southwest, United, American, Alaska, JetBlue, Lufthansa, Air France and Air Canada all holding seats on its board. 240+ airlines use ARC for ticket settlement. Via its Travel Intelligence Program (TIP), ARC sold access to US travelers' domestic flight records - names, itineraries and financial information - to Customs and Border Protection. Per CBP documents obtained by 404 Media under FOIA, the contract barred CBP from disclosing where the data came from. CBP's stated purpose was supporting federal, state and local law enforcement in identifying persons of interest's domestic air ticketing information. Treat as ONE connected story across every carrier row with an ARC board seat, not as separate incidents.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Seattle", "HQ State": "Washington", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[DATA_SALE · FL-2] Alaska Airlines sits on the ARC board that sold US travelers' flight records to CBP under a source-concealment contract\nWHAT THE TERMS SAY: The row states Alaska is a co-owner of ARC, whose Travel Intelligence Program sold US travelers' domestic flight records - names, itineraries, financial information - to Customs and Border Protection under a contract reportedly barring CBP from disclosing the source.\nWHY IT MATTERS: Passengers have no visibility that their booking data reaches a law-enforcement agency through this channel.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-2] An active 2026 investigation is examining whether Alaska shares website visitors' data with third parties without adequate consent\nWHAT THE TERMS SAY: The row states attorneys are investigating in 2026 whether Alaska Airlines collects and shares website visitor data with third parties without adequate consent, evaluating a potential California-specific class action, and likens this to the tracking-technology exposure documented for Kaiser Permanente.\nWHY IT MATTERS: This is an active investigation, not a confirmed finding - if substantiated, it would mean website visitors' data left the airline without their knowledge, the same category of exposure the row links to Kaiser Permanente's 13.4-million-person disclosure.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The Virgin Group $32M royalty dispute is a B2B trademark/licensing matter the row itself flags as unrelated to consumer privacy and is excluded; beyond the ARC data-sale finding and the active 2026 tracking investigation, no other consumer-facing term is confirmed this pass.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=Y; jurywaiver=?; optout=N; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The ARC data-sale mechanism is clearly documented, but the 2026 tracking-consent matter is an open investigation, not a confirmed finding.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 9, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 9/30 (class_action_waiver+9) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Alaska Airlines  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Alaska Airlines you gave up your personal data sold onward, your data shared corporate-wide, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T20:00:14Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Alaska sits on the ARC board - the airline-owned clearinghouse that sold US travelers' domestic flight records, including names, itineraries and financial information, to Customs and Border Protection under a contract reportedly forbidding CBP from disclosing where it came from. There is also an active 2026 investigation into website tracking technologies on Alaska's own properties, which is the same category of exposure that produced Kaiser Permanente's 13.4-million-person disclosure documented in the Insurance tab. Two separate mechanisms, one outcome: your travel behaviour leaving the airline without you being told.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 321, "_entity_id": 493, "_entity_slug": "alaska-airlines", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "JetBlue", "Category": "Airline (North America, LCC)", "Terms & Conditions URL": "jetblue.com/legal/contract-of-carriage", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "jetblue.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "A GENUINELY VIRAL, WELL-DOCUMENTED 'SURVEILLANCE PRICING' CASE (April 2026): a JetBlue customer posted on X that a ticket price jumped $230 in one day, adding he was 'just trying to make it to a funeral' — JetBlue's official account replied suggesting he clear his cache/cookies or book in an incognito window, then QUICKLY DELETED the reply. Within days, plaintiff Andrew Phillips filed a federal class action (Brooklyn) alleging JetBlue's website secretly tracks browsing behavior and uses it to raise prices when a customer who searched, closed the browser, then returned to book — alleging violations of the federal Electronic Communications Privacy Act and New York consumer-protection law. JetBlue flatly denied using personal data/browsing history for individual pricing, calling its own deleted reply 'a mistake from an individual customer service crewmember' whose suggestion 'would not have changed the airfares available for purchase' — legal commentators noted a 'logical problem' in JetBlue simultaneously suggesting clearing cookies would help AND claiming cookies don't affect pricing. Two Democratic members of Congress separately sent JetBlue formal questions about whether it uses personal data to set prices.", "Arbitration / Class Action Waiver": "CLASS ACTION WAIVER in Contract of Carriage. NO mandatory arbitration. JetBlue was a party to the Northeast Alliance (NEA) with American Airlines — a joint venture that DOJ successfully challenged as anticompetitive (2023). In the resulting class action (Berger), a NY federal court declined to enforce the class action waiver at the pleadings stage, noting the CC was not incorporated by reference in the complaint.", "Fees / Billing Flags": "The 'surveillance pricing' allegation is specifically about individual PRICE-SETTING based on tracked behavior — a direct fee/pricing-fairness issue, not just a data-sharing concern.", "Notes": "The ARC/CBP finding is one of the most SERIOUS structural findings in this ENTIRE 400+ company audit: it implicates nearly every major US airline (JetBlue, Delta, Southwest, United, American, Alaska, plus Air Canada/Lufthansa/Air France internationally) in selling passenger data to a law-enforcement agency while instructing that agency to CONCEAL the data's origin — worth flagging as a cross-cutting finding applicable to essentially the entire US airline industry, not JetBlue alone.\n\nARC CROSS-REFERENCE (verified this pass): the Airlines Reporting Corporation is a ticket-settlement clearinghouse owned by major carriers, with Delta, Southwest, United, American, Alaska, JetBlue, Lufthansa, Air France and Air Canada all holding seats on its board. 240+ airlines use ARC for ticket settlement. Via its Travel Intelligence Program (TIP), ARC sold access to US travelers' domestic flight records - names, itineraries and financial information - to Customs and Border Protection. Per CBP documents obtained by 404 Media under FOIA, the contract barred CBP from disclosing where the data came from. CBP's stated purpose was supporting federal, state and local law enforcement in identifying persons of interest's domestic air ticketing information. Treat as ONE connected story across every carrier row with an ARC board seat, not as separate incidents.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Long Island City", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SURVEILLANCE_PRICING · FL-2] A federal class action alleges JetBlue's site secretly tracks browsing behavior to raise prices for returning shoppers\nWHAT THE TERMS SAY: The row states plaintiff Andrew Phillips filed a federal class action in Brooklyn alleging JetBlue's website secretly tracks browsing behavior and raises prices when a customer searches, closes the browser, then returns to book, citing the federal Electronic Communications Privacy Act and NY consumer-protection law; the suit followed a viral incident where a customer's fare jumped $230 in a day and JetBlue's support account suggested clearing cookies before quickly deleting that reply.\nWHY IT MATTERS: If true, the price shown to an individual traveler would be shaped by inferred willingness to pay rather than supply and demand, with no disclosure of the inputs; JetBlue denies using personal data or browsing history for individual pricing.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SALE · FL-2] JetBlue holds an ARC board seat inside the arrangement that sold passenger flight records to CBP under a source-concealment contract\nWHAT THE TERMS SAY: The row states JetBlue holds a board seat on ARC, whose Travel Intelligence Program sold US travelers' domestic flight records to Customs and Border Protection under a contract reportedly barring CBP from disclosing the data's origin; the row calls this one of the most serious structural findings across the tracker, applicable to essentially the entire US airline industry.\nWHY IT MATTERS: This is a routine, ongoing data-sharing arrangement with law enforcement that a passenger would have no way to discover from JetBlue's own terms.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CLASS_ACTION_WAIVER · FL-3] A federal court declined to enforce JetBlue's class-action waiver at the pleadings stage in the Northeast Alliance antitrust case\nWHAT THE TERMS SAY: The row states JetBlue's Contract of Carriage contains a class-action waiver with no mandatory arbitration, but in the Berger case, arising from DOJ's successful 2023 challenge to the JetBlue-American Northeast Alliance as anticompetitive, a NY federal court declined to enforce the waiver at the pleadings stage, noting the Contract of Carriage was not incorporated by reference in the complaint.\nWHY IT MATTERS: A class-action waiver's enforceability can turn on procedural details of how a complaint is drafted, so its presence in the contract does not guarantee it will bar a class action.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=Y; jurywaiver=?; optout=N; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The ARC data-sale mechanism and the class-action-waiver ruling are clearly documented, but the core surveillance-pricing allegation is an active, disputed lawsuit that JetBlue denies.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 9, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 9/30 (class_action_waiver+9) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "JetBlue  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using JetBlue you gave up your personal data sold onward, your data shared corporate-wide, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "JetBlue holds an ARC board seat, placing it inside the arrangement that sold passenger flight records to Customs and Border Protection under a source-concealment contract. Separately, the well-documented 2025 surveillance-pricing case attached to this row is the more legible harm to most travelers: the allegation that fares shown to an individual are shaped by inferences about that individual's willingness to pay rather than by supply and demand alone. If that is what is happening, the price you are quoted is not the price of the seat - it is an estimate of you, and there is no term in the conditions of carriage that discloses the inputs.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 322, "_entity_id": 494, "_entity_slug": "jetblue", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Spirit Airlines", "Category": "Airline (North America, ULCC)", "Terms & Conditions URL": "spirit.com/legal/contract-of-carriage", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "spirit.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Airline — collects passenger name records (PNRs), passport/ID data, payment information, frequent-flyer activity, seat preferences, meal selections, and increasingly, facial recognition for boarding. PNR data shared with CBP (Customs and Border Protection) under federal mandate. International flights subject to EU PNR Directive and destination-country data-sharing requirements.", "Arbitration / Class Action Waiver": "CLASS ACTION WAIVER in Contract of Carriage. NO mandatory arbitration. CAVEAT: Spirit filed for Chapter 11 bankruptcy in Nov 2024 and emerged in March 2025 after Frontier's takeover bid was blocked. Whether the pre-bankruptcy CC terms survived restructuring should be verified against the current CC.", "Fees / Billing Flags": "Spirit Airlines filed for CHAPTER 11 BANKRUPTCY (2024, emerged 2025) amid severe financial distress following the blocked JetBlue acquisition attempt (the DOJ successfully sued to block that merger, referenced in the JetBlue row) — a major operational/financial-status change worth flagging for any customer with outstanding credits, miles, or pending claims.", "Notes": "Spirit's bankruptcy status is a significant practical consideration distinct from privacy findings — customers should verify current claim/credit-honoring policies directly given the company's recent financial restructuring.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Dania Beach", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] Spirit's fee schedules are disclosed but placed where nobody reads them during a price-comparison decision\nWHAT THE TERMS SAY: The row states Spirit's advertised price covers a seat and little else; the meaningful fee schedules for carry-on sizing, seat assignment, printed boarding passes and airport check-in are disclosed but placed where they are not read during a price-comparison decision.\nWHY IT MATTERS: A Spirit fare and a legacy-carrier fare are not comparable numbers even displayed side by side, so the advertised price understates the likely total cost.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[OTHER · FL-4] Spirit's 2024 Chapter 11 bankruptcy leaves it unclear whether pre-bankruptcy contract terms, credits and claims survived restructuring\nWHAT THE TERMS SAY: The row states Spirit filed for Chapter 11 in Nov 2024 and emerged in March 2025 after a blocked Frontier takeover bid, and flags that whether pre-bankruptcy Contract of Carriage terms survived restructuring should be verified, alongside outstanding credits, miles or pending claims.\nWHY IT MATTERS: Customers with unresolved credits or claims at the time of filing may find their status changed by the restructuring without clear notice.\n(evidence: Fees / Billing Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The tracker explicitly frames this row's substantive finding as fee-disclosure design rather than privacy, and states no Spirit-specific breach or regulatory action is confirmed; padding with the generic industry PNR-collection text shared across many rows in this tab would misrepresent it as a third distinct, company-specific harm.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=Y; jurywaiver=?; optout=N; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=N; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The ancillary-fee disclosure practice is described specifically, but the tracker explicitly states no Spirit-specific breach or regulatory action is confirmed, and bankruptcy-era contract status is unverified.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 9, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 9/30 (class_action_waiver+9) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Spirit Airlines  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Spirit Airlines you gave up your biometric identifiers, your data shared corporate-wide, your right to join a class action, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "No Spirit-specific breach or regulatory action confirmed this pass. The genuine consumer finding is the ultra-low-cost fare structure itself: the advertised price covers a seat and essentially nothing else, and the meaningful terms are the ancillary fee schedules - carry-on sizing, seat assignment, printed boarding passes, airport check-in - which are disclosed but placed where nobody reads them during a price-comparison decision. This is not a privacy finding and should not be dressed as one. It is a disclosure-design finding, and it is the reason a Spirit fare and a legacy carrier fare are not comparable numbers even when they appear side by side.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 323, "_entity_id": 495, "_entity_slug": "spirit-airlines", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Frontier Airlines", "Category": "Airline (North America, ULCC)", "Terms & Conditions URL": "flyfrontier.com/legal/contract-of-carriage/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "flyfrontier.com/legal/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "VERY RECENT, ACTIVE BREACH (disclosed July 9, 2026, to the Vermont Attorney General): Frontier confirmed a cybersecurity incident exposing customer SOCIAL SECURITY NUMBERS — at least 6 Vermont residents affected per the state filing, though the full national scope remains UNDISCLOSED as of this research; multiple law firms (Edelson Lechtzin, Federman & Sherwood) opened investigations within a day of disclosure. Frontier did not provide public details about how the breach occurred.", "Arbitration / Class Action Waiver": "CLASS ACTION WAIVER in Contract of Carriage. NO mandatory arbitration. Ultra-low-cost carrier. The CC waiver covers ancillary-fee disputes (seat selection, carry-on bags, etc.) — a significant proportion of Frontier's total per-ticket revenue comes from these fees rather than the base fare.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is one of the MOST RECENT breaches in this entire tracker (disclosed just before this research was conducted) — worth a direct follow-up in the near future once the full scope becomes public, since SSN exposure is among the more serious data categories for identity-theft risk.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Denver", "HQ State": "Colorado", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Colorado SOS Business Search — sos.state.co.us/biz/BusinessEntityCriteria. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Frontier confirmed a breach exposing Social Security numbers, disclosed to Vermont's AG on July 9, 2026\nWHAT THE TERMS SAY: The row states Frontier confirmed a cybersecurity incident exposing customer Social Security numbers, disclosed July 9, 2026 to the Vermont Attorney General; at least 6 Vermont residents are confirmed affected per the state filing, full national scope remains undisclosed, and Frontier did not provide public details on how the breach occurred.\nWHY IT MATTERS: SSNs are a high-value, hard-to-remediate identifier for identity theft, and the scope is still unknown as of this pass, so the practical risk to any individual customer cannot yet be assessed.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[OTHER · FL-2] Frontier's breach became public via a mandatory Vermont AG filing, often how such incidents first surface\nWHAT THE TERMS SAY: The row states the breach became known through Vermont's mandatory AG notification requirement, which the row notes is frequently how such incidents first surface rather than through company announcement, with multiple law firms opening investigations within a day of disclosure.\nWHY IT MATTERS: Customers relying on Frontier's own communications may not learn of a breach as quickly as those who know to check state attorney general databases.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Scope and data types were still developing as of this pass per the tracker, and no arbitration or fee term beyond the standard class-action waiver is discussed for this row, so a third distinct harm is not yet supported by the text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=Y; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Frontier has not disclosed how the breach occurred or its full scope beyond the Vermont-specific minimum; most of what is known comes from the state filing rather than the company.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 9, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 9/30 (class_action_waiver+9) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Frontier Airlines  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Frontier Airlines you gave up your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T20:00:20Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Frontier disclosed a breach to the Vermont Attorney General on July 9, 2026 - very recent, and the disclosure route is the notable part. Vermont, like most US states, requires notification to the state AG, which is frequently how these incidents first become public rather than through any announcement to the affected passengers. The practical implication for a traveler is that the fastest way to learn whether a company has had a breach is often to check state attorney general notification databases, not the company's own newsroom. Scope and data types were still developing as of this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 324, "_entity_id": 496, "_entity_slug": "frontier-airlines", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "LATAM Airlines", "Category": "Airline (Latin America, legacy)", "Terms & Conditions URL": "latamairlines.com/us/en/conditions-of-carriage", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "latamairlines.com/us/en/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED HISTORICAL BREACH (2020, later resurfaced 2022): LATAM Airlines suffered a breach exposing personal data of an estimated 5.4 MILLION passengers, including some passport and financial information — the data was later found circulating on hacker forums in a 2022 resurfacing, illustrating how stolen airline data can remain in criminal circulation and resurface years after the original breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; Brazil's LGPD and Chile's data protection law apply depending on jurisdiction (LATAM is a merged Chilean/Brazilian carrier group).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The multi-year resurfacing of this stolen data (2020 breach, still circulating in 2022) is a useful reminder that breach exposure risk doesn't end when a company stops discussing an incident publicly.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Santiago", "HQ State": "Chile", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2020, 2022", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Chile) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Chile. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2020 LATAM breach exposed an estimated 5.4M passengers' data, some passport and financial; resurfaced 2022\nWHAT THE TERMS SAY: The row states LATAM suffered a 2020 breach exposing an estimated 5.4 million passengers' personal data, including some passport and financial information, and that the stolen data was later found circulating on hacker forums in a 2022 resurfacing.\nWHY IT MATTERS: Passport numbers and dates of birth cannot be reissued the way a payment card can, so the exposure functions as effectively permanent even after breach-response monitoring has lapsed.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and class-action terms are not independently confirmed and fees are not itemized this pass; the 2020 breach and its 2022 resurfacing are treated as one continuous finding rather than split into artificially separate items.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach and its 2022 resurfacing are documented with figures, but arbitration and fee terms are unconfirmed this pass.", "Exposure Score (0-100)": 11, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "LATAM Airlines  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, LATAM Airlines takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2020 LATAM breach resurfaced in 2022, which is the detail worth extracting: stolen data does not have a shelf life. It gets re-listed, re-sold and re-published years after the original incident, long after any credit monitoring the airline offered has lapsed and long after the news cycle moved on. For passport numbers and dates of birth - identifiers that cannot be reissued the way a card can - the exposure is effectively permanent, and the twelve or twenty-four months of monitoring typically offered after a breach is calibrated to the company's news cycle rather than to the durability of the harm.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 325, "_entity_id": 497, "_entity_slug": "latam-airlines", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Copa Airlines", "Category": "Airline (Latin America, legacy)", "Terms & Conditions URL": "copaair.com/en/web/us/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "copaair.com/en/web/us/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Airline — collects passenger name records (PNRs), passport/ID data, payment information, frequent-flyer activity, seat preferences, meal selections, and increasingly, facial recognition for boarding. PNR data shared with CBP (Customs and Border Protection) under federal mandate. International flights subject to EU PNR Directive and destination-country data-sharing requirements.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; Panama's data protection law applies domestically.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin English-language litigation coverage this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Panama City", "HQ State": "Panama", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Panama) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Panama. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Copa collects PNRs, passport/ID and payment data; PNR data shared with CBP under federal mandate\nWHAT THE TERMS SAY: The row states Copa collects PNRs, passport/ID data, payment information, frequent-flyer activity, seat/meal preferences and increasingly facial recognition for boarding, with PNR data shared with CBP under federal mandate and EU PNR Directive obligations on international flights.\nWHY IT MATTERS: This is a broad set of identity, financial and biometric data points moving to third parties and government agencies as routine practice.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[BIOMETRICS · FL-2] Facial recognition boarding is 'increasingly' used in Copa's passenger data collection\nWHAT THE TERMS SAY: The row states data collection is 'increasingly' including facial recognition for boarding.\nWHY IT MATTERS: Biometric identifiers cannot be reset the way a password can if compromised.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-3] Copa routes US, EU and Latin American passenger data through Panama, a jurisdiction with a thin data-protection enforcement record\nWHAT THE TERMS SAY: The row states Copa is Panama-based and hubs at Tocumen, routing a substantial share of intra-Americas traffic, so data from GDPR- or state-law-protected passengers passes through a carrier operating under Panamanian law, whose enforcement record is thin; the row records this as unverified rather than clean and recommends a follow-up on Copa's ConnectMiles data-sharing terms.\nWHY IT MATTERS: A passenger's home-jurisdiction privacy rights become harder to exercise once processing sits with a carrier outside those regimes.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Only generic industry data practices are confirmed; arbitration and breach status are explicitly unconfirmed, and Panama's enforcement record is described as thin.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "Copa Airlines  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Copa Airlines you gave up your biometric identifiers and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "No confirmed finding this pass. Copa is Panama-based and hubs at Tocumen, routing a substantial share of intra-Americas traffic, which means US, Canadian, EU and Latin American passengers' data all pass through a single carrier operating under Panamanian law - a jurisdiction whose data protection enforcement record is thin. A GDPR-protected or state-law-protected passenger's rights become considerably harder to exercise once the processing sits with a carrier outside those regimes. Recorded as unverified rather than clean; recommend a follow-up on Copa's ConnectMiles programme data-sharing terms.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Global Airlines (Top 40)", "_row_id": 326, "_entity_id": 498, "_entity_slug": "copa-airlines", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CareFirst BlueCross BlueShield", "Category": "Health Insurance (DMV)", "Terms & Conditions URL": "carefirst.com/legal/terms-of-use.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "carefirst.com/legal/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "A DECADE-LONG LITIGATION SAGA directly relevant to DMV residents: hackers gained access to CareFirst systems in June 2014, exposing data of approximately 1.1 MILLION plan members (names, birthdates, email addresses, subscriber ID numbers) — the intrusion went undetected for MONTHS. The resulting class action (Attias v. CareFirst) was dismissed in 2016 for lack of standing, REVERSED on appeal, then the Supreme Court declined review in 2018, sending it back to the district court. In March 2023 — NINE YEARS after the original breach — a federal judge finally certified a CONTRACT class covering all DC/Maryland/Virginia residents who had insurance through CareFirst, had data exposed, and were notified in May 2015; the consumer-protection-statute claims under Maryland and Virginia law were separately DISMISSED (the court found no proof of actual identity theft, and DC law doesn't treat protective/mitigation expenses as recoverable 'actual damages'), leaving only the narrower contract claim alive. SEPARATELY, CareFirst is ITSELF now a PLAINTIFF (not defendant) in a 2025 Maryland lawsuit against Change Healthcare (a UnitedHealth Group subsidiary, also documented via the Optum/OptumRx row in this tracker) over the massive 2024 Change Healthcare ransomware breach, seeking $900,000 in damages — alleging Change Healthcare's insufficient cybersecurity (no multi-factor authentication on a remote-access portal) let a Russian ransomware group in.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass for the base member Terms of Use — the 9-year Attias case's complex procedural history illustrates how long DMV-specific health-data litigation can take to resolve.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Given CareFirst's outsized role as the DOMINANT health insurer across the whole DC/MD/VA region, this 9-year case (only reaching partial class certification in 2023, with the underlying 2014 breach still generating live litigation in 2026) is one of the most directly regionally-relevant findings anywhere in this entire tracker.\n\nAUG 2026 ADDENDUM (verified this pass): breach occurred June 2014, discovered by Mandiant during a proactive review in April 2015 prompted by the Anthem/Premera/Excellus breaches; disclosed May 20 2015. Exposed: names, birthdates, email addresses, subscriber ID numbers and member-created usernames - CareFirst stated no SSNs, medical claims or financial data. ~1.1M affected of 3.4M total customers. Attias v. CareFirst (D.D.C.) dismissed 2016 for lack of standing; revived by the D.C. Circuit Aug 1 2017 on the reasoning that substantial risk of harm exists by virtue of the hack and the nature of the data; CareFirst petitioned SCOTUS (would have been the first data-breach standing case there); class cert denied 2023; contract class certified 2024. Cross-ref: the same 2014-15 Blues-sector attack wave hit Anthem (78.8M) - see Elevance Health (Anthem) row in Life-Health-Dental Insurance tab.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "NOT VERIFIED THIS PASS. CareFirst, Inc. maintains dual headquarters in Baltimore, MD and Washington, DC, but no privacy-specific mailing address was confirmed against a primary source. Because CareFirst operates through several separately chartered underwriting entities (including Group Hospitalization and Medical Services, Inc. for the DC market), identify the correct entity on your own member ID card or EOB before sending written notice.", "Legal / Privacy Contact Email": "Not verified this pass — recommend a direct follow-up", "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2014, 2015, 2024", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] CareFirst's 2014 breach exposed 1.1 million members and went undetected for months\nWHAT THE TERMS SAY: The row states hackers accessed CareFirst systems in June 2014, exposing names, birthdates, emails, subscriber IDs and usernames for approximately 1.1 million of 3.4 million total members; the intrusion was undetected for months. CareFirst states no SSNs, medical claims or financial data were exposed.\nWHY IT MATTERS: The intrusion went undetected for months, so members' data was exposed long before anyone was notified.\n(evidence: Data Sharing; Stated in tracker (firewall-edited: unverifiable figure removed) (firewall-edited: unverifiable figure removed) (firewall-edited: unverifiable figure removed) (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] It took nine years and a Supreme Court petition for a court to certify even a narrow contract class over the 2014 breach\nWHAT THE TERMS SAY: The row states Attias v. CareFirst was dismissed in 2016 for lack of standing, revived by the DC Circuit in 2017, and CareFirst petitioned the Supreme Court before a contract class covering DC/MD/VA members was finally certified in 2024 - nine years after notification; consumer-protection claims under MD and VA law were separately dismissed for lack of proof of actual identity theft, and DC law does not treat mitigation expenses as recoverable damages.\nWHY IT MATTERS: For nine years CareFirst's litigation position was that having data stolen is not itself an injury a member can sue over, and even the surviving claim is narrower than the original suit.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The row separately notes CareFirst is a plaintiff, not a defendant, in a 2025 suit against Change Healthcare over the 2024 ransomware breach; that is litigation CareFirst filed against a vendor, not a term or practice affecting CareFirst's own members, so it is not counted as a third distinct consumer-facing harm.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2014 breach and its nine-year litigation history are extensively documented with dates, but CareFirst's own arbitration terms for members are not independently confirmed this pass.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "CareFirst BlueCross BlueShield  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, CareFirst BlueCross BlueShield takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Hackers got into CareFirst in June 2014 and were not detected for eleven months - and CareFirst only found them because it went looking after Anthem, Premera and Excellus were hacked, not because anything of its own caught it. Members were notified in May 2015, a year after the intrusion. What happened next is the part that should land for anyone insured in the DMV: CareFirst spent the following decade arguing that having your data stolen is not an injury you can sue over, taking that position all the way to a Supreme Court petition, and a contract class was not certified until 2024 - nine years after the notification letters went out. For the dominant health insurer across DC, Maryland and Virginia, the practical finding is that the legal tail of a breach outlasts most people's time on the plan.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Insurance", "_row_id": 327, "_entity_id": 499, "_entity_slug": "carefirst-bluecross-blueshield", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Kaiser Permanente", "Category": "Health Insurance/Provider", "Terms & Conditions URL": "healthy.kaiserpermanente.org/legal/terms-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "healthy.kaiserpermanente.org/legal/privacy-practices", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "DIRECTLY COVERS MARYLAND, VIRGINIA, AND DC MEMBERS: a consolidated class action (filed June 2023) alleged Kaiser Foundation Health Plan embedded THIRD-PARTY TRACKING CODE on its websites and mobile apps that transmitted confidential personal and health information WITHOUT MEMBER CONSENT to Google, Microsoft, Meta, and Twitter/X, between November 2017 and May 2024 — the same Meta/Google Pixel pattern documented repeatedly elsewhere in this tracker (Kroger, Costco, Chick-fil-A, BetterHelp), here applied at healthcare scale. Kaiser's own INTERNAL investigation confirmed up to 13.4 MILLION individuals were potentially affected — the SECOND-LARGEST healthcare data breach announced in 2024. Kaiser reached a settlement of $46 MILLION (potentially up to $47.5 million) covering members specifically in California, Colorado, Georgia, Hawaii, MARYLAND, Oregon, VIRGINIA, Washington, and the DISTRICT OF COLUMBIA — meaning this settlement directly covers the exact Mid-Atlantic region this tracker focuses on. Claims deadline was March 12, 2026; final court approval hearing was held May 7, 2026 with a follow-up hearing scheduled July 2, 2026.", "Arbitration / Class Action Waiver": "Class members RELEASE any individual legal claims related to the tracking-technology conduct as part of accepting settlement payment — standard for a class settlement, but worth noting explicitly since it forecloses separate individual suits over the same underlying conduct.", "Fees / Billing Flags": "Attorneys are seeking fees up to $15,675,000 (33% of the settlement fund) plus up to $900,000 in litigation costs — meaning the amount actually reaching class members will be meaningfully less than the headline $46-47.5M figure once fees, costs, and administration expenses are deducted.", "Notes": "GIVEN THIS SETTLEMENT EXPLICITLY COVERS MARYLAND, VIRGINIA, AND DC MEMBERS, this is one of the most DIRECTLY ACTIONABLE findings in this entire tracker for Mid-Atlantic residents specifically — any current or former Kaiser Permanente member in this region who used the Kaiser website/app between Nov 2017 and May 2024 was very likely eligible to file a claim, though the March 12, 2026 filing deadline has now passed as of this research.\n\nAUG 2026 ADDENDUM (verified this pass): Kaiser Foundation Health Plan self-reported to HHS in April 2024 as an unauthorized access/disclosure HIPAA breach affecting 13.4M. Internal determination date Oct 25 2023. Kaiser's position: data involved was limited to IP address, name, signed-in status indicators, navigation behavior and health-encyclopedia search terms - no usernames, passwords, SSNs, financial or credit card data - and it denies wrongdoing. Kaiser removed the technologies and notified all potentially affected individuals. Industry context: OCR and FTC issued 130+ warning letters to healthcare organizations in 2024 on tracking-related HIPAA exposure and settled with Cerebral, Monument, BetterHelp, GoodRx and Easy Healthcare (Premom) - so this is a sector-wide pattern, not a Kaiser anomaly.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Oakland", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.hipaajournal.com/kaiser-permanente-website-tracker-breach-affects-13-4-million-individuals/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Kaiser Foundation Health Plan, Inc. (integrated nonprofit system)", "Years Referenced in Finding (heuristic)": "2017, 2023", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Kaiser Foundation Health Plan, Inc. (integrated nonprofit system)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Kaiser self-reported a HIPAA breach affecting 13.4 million people - the second-largest healthcare breach announced in 2024\nWHAT THE TERMS SAY: The row states Kaiser Foundation Health Plan self-reported to HHS in April 2024 an unauthorized access/disclosure HIPAA breach affecting up to 13.4 million individuals, with an internal determination date of October 25, 2023; this was not a hack - Kaiser had installed the tracking technologies itself and removed them after its internal review caught them, and it denies wrongdoing.\nWHY IT MATTERS: A breach this size, self-caused by the company's own tracking-technology choices rather than an external attacker, is described in the tracker as the largest confirmed healthcare breach involving website trackers to date.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Logged-in members' health-encyclopedia searches and account-linked identifiers were sent to Google, Meta, Microsoft and X\nWHAT THE TERMS SAY: The row states the trackers ran on authenticated pages, so a logged-in member's search of the health encyclopedia for a specific diagnosis, along with IP address, device and account-linked identifiers, was transmitted to advertising companies; Kaiser's position is that the data was limited to IP address, name, signed-in status, navigation behavior and health-encyclopedia search terms, with no usernames, passwords, SSNs or financial data.\nWHY IT MATTERS: Even under Kaiser's own more limited account of what was exposed, a specific health search tied to a logged-in identity reaching ad networks is a category of exposure most members would not expect or have consented to.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-1] Accepting the $46-47.5M settlement releases individual claims, and attorneys are seeking a third of the fund in fees\nWHAT THE TERMS SAY: The row states class members release any individual legal claims related to the tracking conduct as part of accepting settlement payment, and attorneys are seeking fees up to $15,675,000 (33% of the fund) plus up to $900,000 in costs, so per-member recovery will be meaningfully smaller than the headline $46-47.5 million figure; the March 12, 2026 claims deadline has passed.\nWHY IT MATTERS: Members who took the payment gave up any separate suit over the same conduct, and a substantial share of the settlement goes to legal fees before members are paid.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The tracking practice, its scale, the HIPAA self-report and the settlement terms are all documented with specific dates and figures.", "Exposure Score (0-100)": 27, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Kaiser Permanente  <-  Kaiser Foundation Health Plan, Inc. (integrated nonprofit system)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Kaiser Permanente you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T20:00:30Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "This was not a hack. Kaiser installed the tracking code itself - pixels and analytics tags from Google, Microsoft Bing, X, Adobe and Quantum Metric - and left them running on authenticated pages, meaning a logged-in member searching the health encyclopedia for a specific diagnosis had that search, their IP address, their device and account-linked identifiers transmitted to advertising companies. 13.4 million people were affected, the largest confirmed healthcare breach involving website trackers to date, and reporting indicates the trackers were in place from roughly 2017 until Kaiser's own internal review caught them in October 2023. The settlement runs up to $47.5 million, of which counsel sought about $15.7 million - a third of the fund - so the per-member recovery is small relative to what was disclosed. The uncomfortable context: studies cited alongside this case put tracker use at roughly 99% of US hospital websites.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Insurance", "_row_id": 328, "_entity_id": 501, "_entity_slug": "kaiser-permanente", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "GEICO", "Category": "Auto/Renters Insurance", "Terms & Conditions URL": "geico.com/about/corporate/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "geico.com/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Named alongside Allstate and Progressive as a major insurer using telematics (GEICO's 'DriveEasy' program) to track driving behavior — no GEICO-specific lawsuit independently confirmed this pass, though GEICO's telematics program is grouped with Allstate/Liberty Mutual/Progressive as one that CAN raise rates based on driving data rather than being purely discount-only.", "Arbitration / Class Action Waiver": "GEICO's website Terms of Use contain a dispute-resolution clause but auto insurance disputes are primarily governed by state insurance department oversight in each state where GEICO operates. The NY AG/DFS settlement ($9.75M, Nov 2024) for the 2020 quoting-tool breach was a regulatory action. GEICO HQ: Chevy Chase, Maryland (DMV) — one of the largest employers in the DMV corridor.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "GEICO is HEADQUARTERED in Chevy Chase, Maryland — directly in the DMV region this tracker focuses on — making it worth a more thorough dedicated follow-up given its outsized regional employment/customer presence beyond what this pass captured.\n\nAUG 2026 ADDENDUM - REGULATORY ACTION, verified (distinct from private litigation): NY AG Letitia James and NY DFS Superintendent Adrienne Harris, announced Nov 25 2024. GEICO $9.75M total ($4.75M OAG / $5M DFS); Travelers $1.55M ($350K OAG / $1.2M DFS) in the same action - see Travelers Insurance row in Gyms & Home-Auto Insurance tab. Combined $11.3M, 120,000+ New Yorkers across both. GEICO breach began Nov 2020; DFS had flagged a 'systemic and aggressive campaign' against quoting tools. Both companies must maintain a comprehensive information security program, build a data inventory of private information, and maintain reasonable authentication controls. Context for scale: since the DFS Cybersecurity Regulation took effect March 2017, DFS has entered consent orders with 12 entities totaling over $100M. GEICO is headquartered in Chevy Chase, MD - directly in this tracker's core region.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Chevy Chase", "HQ State": "Maryland", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "CORPORATE HEADQUARTERS (verified on GEICO's own contact-by-mail page): GEICO, 4608 Willard Avenue, Chevy Chase, MD 20815, USA. CAVEAT: GEICO's published mail page lists departmental addresses (largely HR and regional claims offices) and does NOT name a privacy-specific address; the Chevy Chase HQ is the corporate address, not a confirmed privacy-notice address. Given the $9.75M NY DFS/OAG penalty on this row, confirm the correct service address before sending anything that matters. DMV-local: GEICO is headquartered in Maryland.", "Legal / Privacy Contact Email": "Not verified this pass — recommend a direct follow-up", "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": "https://www.hunton.com/privacy-and-cybersecurity-law-blog/ny-ag-and-nydfs-announce-11-3-million-data-breach-settlement-with-geico-and-travelers", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ: Chevy Chase, Maryland (DC/MD/VA)", "Parent / Ultimate Owner": "Berkshire Hathaway Inc.", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Maryland SDAT Business Entity Search — egov.maryland.gov/businessexpress/entitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Berkshire Hathaway Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] GEICO paid $9.75M to NY regulators after driver's license numbers stolen from its quoting tool fueled fraudulent unemployment claims\nWHAT THE TERMS SAY: The row states GEICO was breached at least twice through its consumer quoting tool and again through a separate API, despite repeated DFS warnings about an active criminal campaign targeting its systems; regulators found GEICO never conducted a comprehensive security review. About 116,000 New Yorkers were exposed, and stolen license numbers were used to file fraudulent pandemic unemployment claims in other people's names. GEICO paid $9.75 million in November 2024 ($4.75M to the NY AG, $5M to DFS).\nWHY IT MATTERS: A consumer did not have to be a GEICO customer to be exposed - getting a price quote was enough - and the stolen license numbers were used to file fraudulent pandemic unemployment claims in other people's names.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[LOCATION_TRACKING · FL-2] GEICO's DriveEasy telematics program can raise rates based on tracked driving behavior, not just offer discounts\nWHAT THE TERMS SAY: The row states GEICO's DriveEasy telematics program is grouped with Allstate, Liberty Mutual and Progressive as one that can raise rates based on driving data rather than being purely discount-only; no GEICO-specific lawsuit is independently confirmed this pass.\nWHY IT MATTERS: A telematics program that can increase as well as decrease premiums changes the incentive to enroll, since it carries downside risk as well as upside.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Beyond the confirmed 2024 NY regulatory settlement and the telematics rate-increase practice, the row's remaining regulatory context - DFS's broader $100M+ enforcement history across 12 entities - is industry-wide rather than GEICO-specific.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The 2024 regulatory settlement is documented with specific figures, dates and dollar amounts split between agencies.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "GEICO  <-  Berkshire Hathaway Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, GEICO takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T20:00:33Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "New York's Department of Financial Services repeatedly warned GEICO that criminals were actively discussing how to pull driver's license numbers out of its systems - and GEICO was hit at least twice through its consumer quoting tool, then again when attackers found a separate route in through its API. Regulators concluded GEICO never conducted a comprehensive review of its systems despite all of it. About 116,000 New Yorkers were exposed, and the stolen license numbers were used to file fraudulent pandemic unemployment claims in other people's names. GEICO paid $9.75 million in November 2024 - $4.75M to the Attorney General and $5M to DFS. The detail worth sitting with: the exposure ran through the quoting tool, so you did not have to be a GEICO customer to be in it. Getting a price was enough.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Insurance", "_row_id": 329, "_entity_id": 503, "_entity_slug": "geico", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "USAA", "Category": "Insurance/Banking (military-affiliated)", "Terms & Conditions URL": "usaa.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "usaa.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "TWO SEPARATE CONFIRMED INCIDENTS: (1) A 2021 breach involving USAA's INSURANCE QUOTE TOOL — a class action alleged the tool's own design (specifically, inadequate access controls) allowed criminals to extract member data, and that USAA failed to take reasonable protective steps; USAA agreed to a $3.25 MILLION settlement fund, with an estimated per-claimant payout of approximately $143. (2) A SEPARATE, smaller 2024 'Data Incident' affected roughly 22,646 individuals whose personal information had been obtained ELSEWHERE (not from USAA directly) and was then used to fraudulently attempt to open USAA accounts in their names — notably, USAA's own settlement site clarifies that simply BEING a USAA insurance/banking customer does NOT automatically make someone an eligible class member for this specific incident, since it only affected people targeted by this particular fraud-account-opening scheme.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. USAA Federal Savings Bank Depository Agreement. 30-day opt-out via written notice. USAA serves exclusively military members and their families — the arbitration clause affects a population that is frequently relocated (making small-claims-court jurisdiction complicated) and may be deployed overseas when a dispute arises. The $140M FinCEN/OCC penalty (Jan 2016-Apr 2021 BSA/AML violations) was a regulatory action unaffected by the consumer arbitration clause.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The distinction between the two incidents is important: the 2021 quote-tool breach affected USAA's OWN system design, while the 2024 incident involved data stolen from OTHER sources being used AGAINST USAA — worth being precise about which incident a customer is asking about, since eligibility and cause differ substantially between the two. Given USAA's large military/veteran customer base in this region, this is directly relevant to that specific community.\n\nAUG 2026 ADDENDUM - REGULATORY ACTION, verified: FinCEN $80M + OCC $60M = $140M, March 2022, willful BSA/AML violations. Separate OCC $85M civil money penalty for compliance, risk and security failures. OCC cease-and-desist AA-ENF-2024-96 issued Dec 18 2024 superseding the 2019 and 2022 orders for non-compliance. These are BANKING regulatory actions, not consumer-privacy actions - keep the distinction visible; the 2021 quote-tool breach and 2024 third-party incident already recorded in the Data Sharing column are the privacy-side findings and are separate matters. Related private litigation: the Bulls class action concerns Military Lending Act / SCRA violations. Membership eligibility is restricted to military-affiliated households, which materially narrows who can be harmed but also removes the option of simply switching providers for many members.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$48.6B", "Market Cap": "Non-public", "Employees": "38,018", "HQ City": "San Antonio", "HQ State": "Texas", "CEO": "Juan Andrade", "Ticker": "Non-public", "Website (Corporate)": "usaa.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (Non-public). Service route: c/o General Counsel / Corporate Secretary, San Antonio, Texas — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.fincen.gov/news/news-releases/fincen-announces-140-million-civil-money-penalty-against-usaa-federal-savings", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "USAA (United Services Automobile Association, member-owned)", "Years Referenced in Finding (heuristic)": "2022, 2017, 2020, 2024, 2019", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: USAA (United Services Automobile Association, member-owned)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] USAA imposes mandatory binding arbitration with a class-action waiver, with only a 30-day window to opt out\nWHAT THE TERMS SAY: The row states USAA Federal Savings Bank's Depository Agreement requires mandatory binding arbitration with a class-action waiver, with a 30-day opt-out available via written notice; the row notes USAA serves military members and their families, a population that moves frequently and may be deployed overseas when a dispute arises.\nWHY IT MATTERS: A short, easy-to-miss opt-out window combined with frequent relocation or deployment makes it more likely members are locked into arbitration by default rather than by informed choice.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-1] USAA paid $140M for willful anti-money-laundering failures it knew about since 2017 and missed two deadlines to fix\nWHAT THE TERMS SAY: The row states in March 2022 USAA Federal Savings Bank paid $140 million ($80M FinCEN, $60M OCC) for willful failure to maintain an adequate AML program and file suspicious activity reports; the bank knew of the deficiencies since at least 2017, committed to fixing them by March 2020, then missed that deadline and a subsequent extension. A separate OCC cease-and-desist order issued December 18, 2024 superseded both the 2019 and 2022 orders because USAA failed to comply with elements of each, with failures spanning front-line business units, independent risk management and internal audit.\nWHY IT MATTERS: Repeated, years-long non-compliance at an institution serving military families also contributed to violations of the Military Lending Act and Servicemembers Civil Relief Act, laws specifically meant to protect that population.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CONFIRMED_BREACH · FL-2] A class action alleged USAA's 2021 quote-tool let criminals extract member data; settled for $3.25M\nWHAT THE TERMS SAY: The row states a class action alleged USAA's insurance quote tool had inadequate access controls that let criminals extract member data and that USAA failed to take reasonable protective steps; USAA agreed to a $3.25 million settlement fund with an estimated per-claimant payout of approximately $143. A separate 2024 incident affected roughly 22,646 people whose data, obtained elsewhere, was used to attempt fraudulent USAA account openings - merely being a USAA customer does not make someone eligible for that second incident's settlement.\nWHY IT MATTERS: The row puts the estimated payout at approximately $143 per claimant, and the two incidents have different causes and eligibility criteria a member must track separately - being a USAA customer does not by itself make someone eligible for the 2024 incident.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Both privacy incidents and the multi-year AML enforcement history are documented with specific dates, dollar figures and settlement mechanics.", "Exposure Score (0-100)": 44, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "USAA  <-  USAA (United Services Automobile Association, member-owned)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using USAA you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T20:02:02Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "In March 2022 USAA Federal Savings Bank paid $140 million - $80M to FinCEN and $60M to the OCC - for WILLFUL failure to maintain an adequate anti-money-laundering program and to file suspicious activity reports. The bank had known about the deficiencies since at least 2017, committed to fixing them by March 2020, then missed that deadline and the extension that followed. Its own CEO at the time acknowledged the bank had not sufficiently invested in the capabilities needed to meet regulatory requirements. Then on December 18, 2024 the OCC issued a new comprehensive cease-and-desist order that replaced BOTH the 2019 and 2022 orders - because USAA had failed to comply with elements of each. Regulators found the failures ran across all three lines of defense at once: front-line business units, independent risk management, and internal audit. For an institution whose entire proposition is serving military families, the same compliance breakdown contributed to violations of the Military Lending Act and the Servicemembers Civil Relief Act.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Insurance", "_row_id": 330, "_entity_id": 504, "_entity_slug": "usaa", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "State Farm", "Category": "Auto/Home Insurance", "Terms & Conditions URL": "statefarm.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "statefarm.com/legal/privacy-statement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "A confirmed data breach led to a class action alleging State Farm violated the Illinois Uniform Deceptive Trade Practices Act by failing to protect sensitive customer data — specific breach date/scope/settlement status not independently confirmed with full precision this pass; recommend a direct follow-up.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "State Farm's telematics program ('Drive Safe & Save') is marketed as DISCOUNT-ONLY (per independent insurance-industry research) — meaning poor driving scores REDUCE OR ELIMINATE the discount rather than actively raising the base premium, a meaningfully less risky structure than Allstate/GEICO/Liberty Mutual/Progressive's programs (see Allstate row), though the discount can still function as an effective penalty at renewal if driving data looks risky.", "Notes": "State Farm is one of the FEW insurers in this comparison whose telematics program is structured as discount-only rather than surcharge-capable — worth flagging as a genuine point of contrast for anyone comparing usage-based insurance programs across companies.\n\nAUG 2026 ADDENDUM - PRIVATE LITIGATION, ongoing (allegations, not findings): Huskey v. State Farm Fire & Casualty Co., No. 1:22-cv-07014 (N.D. Ill.), filed Dec 2022 by Illinois homeowners Jacqueline Huskey and Riian Wynn under the Fair Housing Act. Counsel includes Sanford Heisler Sharp McKnight (co-lead), Fairmark Partners, Mehri & Skalet, and NYU Law's Center on Race, Inequality and the Law. Rulings so far: FHA 3604(a) and 3605 claims dismissed without prejudice, one plaintiff's injunctive claim dismissed for lack of jurisdiction, the 3604(b) disparate-impact claim SURVIVED. Feb 2024: court limited Phase I discovery to algorithmic decision-making tools used to screen claims. Jan 15 2025: State Farm's motion for a protective order granted without prejudice; plaintiffs' motion to compel denied. Discovery ongoing as of Feb 2026. Relief sought includes a mandatory audit of the algorithmic tools. NOTE: this is the tracker's clearest example of algorithmic-decision harm in insurance and is worth cross-referencing if a severity or category column is ever added.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$123.0B", "Market Cap": "Non-public", "Employees": "67,381", "HQ City": "Bloomington", "HQ State": "Illinois", "CEO": "Jon Farney", "Ticker": "Non-public", "Website (Corporate)": "statefarm.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (Non-public). Service route: c/o General Counsel / Corporate Secretary, Bloomington, Illinois — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[DISCRIMINATORY_PRACTICE · FL-2] Algorithm allegedly routes Black homeowners into a slower, more demanding claims track using race proxies\nWHAT THE TERMS SAY: A federal FHA suit (Huskey v. State Farm) alleges State Farm's automated claims system routes Black homeowners into a 'high touch' track using algorithms that rely on proxies for race including geolocation, social media activity, biometric data, and historically biased housing data.\nWHY IT MATTERS: The named plaintiff waited two months for adjusters and four months for approval after a hailstorm, during which her unrepaired roof leaked; the disparate-impact claim survived dismissal and discovery into the algorithmic tools was ongoing as of Feb 2026.\n(evidence: SCARY | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] A confirmed data breach led to a class action over State Farm's handling of sensitive customer data\nWHAT THE TERMS SAY: The tracker states a confirmed data breach led to a class action alleging State Farm violated the Illinois Uniform Deceptive Trade Practices Act by failing to protect sensitive customer data.\nWHY IT MATTERS: Customers whose data was involved face potential exposure of sensitive information, though the tracker notes the breach's specific date, scope, and settlement status were not independently confirmed with full precision this pass.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — State Farm's telematics program is flagged as comparatively less risky (discount-only) than peers, so it is not a troubling item; only the algorithmic-discrimination litigation and the imprecisely-detailed breach class action are distinct, substantive harms this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are unconfirmed and breach specifics are imprecise, though the Huskey algorithmic-discrimination litigation is well documented.", "Exposure Score (0-100)": 23, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (biometric_collection+6, precise_location_tracking+4) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "State Farm  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using State Farm you gave up your biometric identifiers and your physical movements. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A federal class action alleges State Farm's automated claims system routes Black homeowners into a 'high touch' track - more documentation demanded, more employee interactions required, longer waits - and that the algorithms doing the routing rely on proxies for race including geolocation, social media activity, biometric data and historically biased housing data. The named plaintiff filed after a hailstorm damaged her roof: two months to get adjusters out, four months for approval, and while she waited the unrepaired roof leaked into her kitchen and two bathrooms. The complaint's framing is the sharp part - that discrimination in insurance has shifted from a person deciding to a system deciding, with the same outcome and far less to point at. State Farm got several counts dismissed, but the Fair Housing Act disparate-impact claim survived, and the court ordered the first phase of discovery aimed squarely at the algorithmic tools themselves. Discovery was still ongoing as of early 2026.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Insurance", "_row_id": 331, "_entity_id": 505, "_entity_slug": "state-farm", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Allstate", "Category": "Auto/Home Insurance", "Terms & Conditions URL": "allstate.com/legal-notices.aspx", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "allstate.com/privacy-center.aspx", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MAJOR GOVERNMENT ENFORCEMENT ACTION (Jan 2025): Texas Attorney General Ken Paxton sued Allstate AND its telematics subsidiary ARITY, alleging they unlawfully collected, used, and SOLD the driving/cellphone location data of OVER 45 MILLION AMERICANS to insurance companies (including competitors) — the data was reportedly gathered through software embedded in various third-party mobile apps, specifically including LIFE360 (see Consumer Apps tab for that company's own related FTC action). SEPARATE, ONGOING PRIVACY CLASS ACTION (2026): a federal court ordered Allstate to face a lawsuit alleging it used cellphone-tracking data to DENY COVERAGE and INCREASE RATES for drivers nationwide, without adequate consent — this is a live case where a court specifically declined to dismiss it.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Allstate's website ToS and app ToS. 30-day opt-out. The TX AG lawsuit (Jan 2025, first-ever action under TDPSA) alleges Allstate's Arity subsidiary embedded SDK trackers in Life360, GasBuddy, and other apps to collect driving data from 45M+ consumers without consent. The arbitration clause covers disputes over this data-collection practice.", "Fees / Billing Flags": "Allstate's telematics program ('Drivewise') is among those that RESERVE THE RIGHT TO RAISE RATES based on driving-behavior data (unlike 'discount-only' programs at some competitors — see Nationwide/State Farm row) — meaning enrolling in a usage-based program with Allstate carries genuine downside risk, not just upside discount potential.", "Notes": "This is the SAME Arity/Life360 driving-data-sharing pipeline already flagged in the Consumer Apps tab (Life360 row) — Allstate/Arity is the RECEIVING/monetizing side of that pipeline, while Life360 is one of the apps supplying the underlying location data. Worth treating as one connected finding across both tabs.\n\nAUG 2026 ADDENDUM - REGULATORY ACTION, verified (allegations pending): Texas v. Allstate Corp., Allstate Insurance Co., Allstate Vehicle & Property Insurance Co., Arity LLC, Arity 875 LLC, Arity Services LLC - filed Jan 13 2025, District Court of Montgomery County, TX, under the Texas Data Privacy and Security Act. First-ever state AG enforcement action under a comprehensive state privacy law. Alleged violations: failure to obtain consent, failure to provide privacy notice, failure to offer an opt-out. Mechanism: the Arity Driving Engine SDK. Paxton had issued warning letters to several companies on location-data sharing in late 2024, and separately sued General Motors (Aug 2024) over sale of driving data. CROSS-REF: Life360 row in Consumer Apps (Round 2 SCARY entry) - Life360 is the supply side of this same pipeline and Allstate/Arity is the buyer; treat as one connected story, not two incidents.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$67.7B", "Market Cap": "$64.8B", "Employees": "55,200", "HQ City": "Northbrook", "HQ State": "Illinois", "CEO": "Thomas Wilson", "Ticker": "ALL", "Website (Corporate)": "allstate.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (ALL). Service route: c/o General Counsel / Corporate Secretary, Northbrook, Illinois — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-sues-allstate-and-arity-unlawfully-collecting-using-and-selling-over-45", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "The Allstate Corporation", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: The Allstate Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[DATA_SALE · FL-2] Allstate's Arity unit allegedly sold 45M+ Americans' driving and location data without consent\nWHAT THE TERMS SAY: Texas's AG sued Allstate and its subsidiary Arity, alleging they collected, used, and sold the driving/cellphone location data of over 45 million Americans to insurance companies, including competitors, via a tracking SDK embedded in third-party apps like Life360.\nWHY IT MATTERS: This is the first-ever state AG enforcement action under a comprehensive state privacy law, alleging failure to obtain consent, provide a privacy notice, or offer an opt-out to people who never bought an Allstate product.\n(evidence: Data Sharing | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SURVEILLANCE_PRICING · FL-2] A live suit alleges Allstate used cellphone-tracking data to deny coverage and raise rates nationwide\nWHAT THE TERMS SAY: A separate, ongoing federal privacy class action alleges Allstate used cellphone-tracking data to deny coverage and increase rates for drivers nationwide without adequate consent, and a court declined to dismiss the case.\nWHY IT MATTERS: Consumers' own driving-behavior data could be used against them to deny coverage or raise their rates without their meaningful awareness or consent.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Allstate requires binding arbitration with a class-action waiver and only a 30-day opt-out window\nWHAT THE TERMS SAY: Allstate's website and app ToS mandate binding arbitration with a class action waiver, with a 30-day opt-out window; the clause covers disputes over the Arity data-collection practice.\nWHY IT MATTERS: Consumers who miss the narrow opt-out window are barred from suing or joining a class action over Allstate's data practices.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Specific case names, filing dates, and the SDK mechanism are documented, and arbitration terms are clearly stated in the ToS.", "Exposure Score (0-100)": 60, "Exposure Band": "High", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Allstate  <-  The Allstate Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Allstate you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, and your right to join a class action. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "2026-09-08T20:03:16Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Allstate's subsidiary Arity paid app developers millions of dollars to bury a tracking SDK inside apps that had nothing to do with insurance - Life360, GasBuddy, Fuel Rewards, Routely - harvesting geolocation, accelerometer, gyroscope and magnetometer readings plus derived 'events' like acceleration, speeding and distracted driving. Texas alleges this produced trillions of miles of movement data on more than 45 million Americans, assembled into what Allstate itself called the world's largest driving behavior database, and that Allstate and other insurers then used it to justify raising those same people's premiums. Nobody in that chain bought an Allstate product; they downloaded a gas-price app. Texas AG Ken Paxton filed in January 2025, and it is the first lawsuit any state attorney general has brought to enforce a comprehensive state privacy law.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Insurance", "_row_id": 332, "_entity_id": 507, "_entity_slug": "allstate", "_issuer": "The Allstate Corporation", "_issuer_slug": "the-allstate-corporation", "_ticker": "ALL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Progressive", "Category": "Auto Insurance", "Terms & Conditions URL": "progressive.com/terms-of-service/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "progressive.com/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Named alongside Allstate and GEICO as one of the major insurers using TELEMATICS technology (Progressive's 'Snapshot' program) to track driving behavior in real time — no Progressive-specific lawsuit independently confirmed this pass, but Progressive's telematics program is grouped with Allstate, GEICO, and Liberty Mutual as one that can RAISE rates based on driving data (not purely discount-only — see Allstate/State Farm rows for the broader comparison).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up on Progressive-specific litigation given the strong telematics/driving-data pattern already established for its direct competitors (Allstate, GEICO) in this same tab.\n\nAUG 2026 ADDENDUM: searched this pass for Progressive-specific regulatory action, settlements and privacy litigation - nothing independently confirmed. That is a genuine null result, not a clean bill of health; recommend a direct follow-up focused on (a) Snapshot data retention and third-party sharing terms, (b) whether Snapshot data has ever been sold or shared with data brokers, and (c) state DOI rate filings. The comparative telematics finding across this tab stands: State Farm (Drive Safe & Save) and Nationwide (SmartRide) are marketed discount-only; Allstate (Drivewise), GEICO (DriveEasy), Liberty Mutual (RightTrack) and Progressive (Snapshot) sit in the surcharge-capable group per the independent research already cited in this tab.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$87.7B", "Market Cap": "$118.9B", "Employees": "66,308", "HQ City": "Mayfield Village", "HQ State": "Ohio", "CEO": "Susan Patricia Griffith", "Ticker": "PGR", "Website (Corporate)": "progressive.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (PGR). Service route: c/o General Counsel / Corporate Secretary, Mayfield Village, Ohio — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Ohio' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SURVEILLANCE_PRICING · FL-2] Progressive's Snapshot telematics can raise, not just lower, a driver's rate based on tracked data\nWHAT THE TERMS SAY: Progressive's Snapshot program is grouped with Allstate, GEICO, and Liberty Mutual among insurers whose telematics programs can raise a driver's base rate based on tracked driving behavior, rather than only offering a discount.\nWHY IT MATTERS: Enrolling in Snapshot carries genuine rate-increase risk, not just discount potential, even though no Progressive-specific lawsuit, breach, or regulatory action was independently confirmed this pass.\n(evidence: Data Sharing | Fees | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — The tracker explicitly states no Progressive-specific lawsuit, breach, or regulatory action was confirmed this pass, calling it a genuine null result rather than a clean bill of health; only the Snapshot surcharge-capability finding is substantive enough to report.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration terms, breach history, and regulatory record are all explicitly unconfirmed this pass, leaving only industry-comparative telematics context.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Progressive  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Progressive you gave up your physical movements. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T20:03:18Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The honest finding here is a gap rather than a scandal: no confirmed regulatory action, settlement or breach specific to Progressive surfaced this pass, and manufacturing one would be worse than saying so. What IS documented is the business model - Snapshot is a telematics program that collects real-time driving behavior, and Progressive sits in the group of insurers whose programs can raise a rate rather than only lower one. That matters because the Texas Attorney General's Allstate complaint alleges the broader pattern plainly: driving data gets collected, and 'Allstate and other insurers' use it to justify premium increases at quote and renewal. Progressive is not named in that action. Treat this row as an open question with a live industry pattern behind it, and re-verify before relying on the absence of findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Insurance", "_row_id": 333, "_entity_id": 508, "_entity_slug": "progressive", "_issuer": "Progressive", "_issuer_slug": "progressive", "_ticker": "PGR", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Nationwide", "Category": "Insurance", "Terms & Conditions URL": "nationwide.com/personal/about-us/legal/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "nationwide.com/personal/about-us/legal/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Nationwide processes auto, home, life, and retirement data across its insurance and financial-services businesses. The Oct 2012 breach (1.27M people via unpatched third-party vulnerability) exposed data from people who never became Nationwide customers — their data was retained from quote requests. Nationwide's DC AG settlement specifically addresses data-retention practices.", "Arbitration / Class Action Waiver": "Nationwide's insurance policies are governed by state insurance department oversight for claims disputes. Website ToS may contain arbitration provisions for non-claims digital interactions. The 32-state + DC settlement ($5.5M, 2017) for the Oct 2012 breach was a multistate regulatory action — the DC AG's own press release is the Primary Source URL for this row.", "Fees / Billing Flags": "Nationwide's telematics program ('SmartRide') is marketed as DISCOUNT-ONLY, per the same independent research cited in the State Farm row — grouped with State Farm and USAA as insurers whose usage-based programs cannot actively surcharge a driver's base rate, only reduce/remove a discount.", "Notes": "See State Farm row for the broader discount-only vs. surcharge-capable telematics comparison across insurers in this tab.\n\nAUG 2026 ADDENDUM - REGULATORY ACTION, verified (supersedes the prior 'not independently confirmed' note): Multistate Assurance of Voluntary Compliance announced Aug 9 2017, $5.5M, Nationwide Mutual Insurance Co. and subsidiary Allied Property & Casualty Insurance Co., with 32 states plus DC (DC's OAG Office of Consumer Protection led the investigation; 168 District residents affected). Breach date Oct 3 2012; 1.27M records; exposed names, dates of birth, marital status, gender, occupation, employer, SSNs and driver's license numbers. Root cause per the AGs: failure to apply a critical security patch to third-party web application hosting software. Remedies imposed: hire a Technology Officer to own patch management, three years of policy updates and patch inventories, internal assessments, an annual third-party audit of data collection and storage practices, and - notably - affirmative disclosure to consumers that their data is retained even if they never become insureds. Nationwide provided a year of credit monitoring and up to $1M ID-fraud coverage.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$58.6B", "Market Cap": "Non-public", "Employees": "22,453", "HQ City": "Columbus", "HQ State": "Ohio", "CEO": "Kirt Walker", "Ticker": "Non-public", "Website (Corporate)": "nationwide.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation + Data breach", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (Non-public). Service route: c/o General Counsel / Corporate Secretary, Columbus, Ohio — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://oag.dc.gov/release/attorney-general-racine-announces-55-million", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Ohio' is a non-DMV US state", "Parent / Ultimate Owner": "Nationwide Mutual Insurance Company (mutual, policyholder-owned)", "Years Referenced in Finding (heuristic)": "2012, 2017", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Nationwide Mutual Insurance Company (mutual, policyholder-owned)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] A 2012 breach tied to an unpatched server exposed SSNs and driver's license numbers for 1.27M people\nWHAT THE TERMS SAY: An October 2012 breach, caused by failure to patch third-party web application hosting software, exposed names, dates of birth, marital status, gender, occupation, employer, SSNs, and driver's license numbers for 1.27 million people.\nWHY IT MATTERS: The root cause was a missed security patch rather than a sophisticated attack, exposing highly sensitive identity data used for fraud.\n(evidence: Data Sharing | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-2] Nationwide paid $5.5M to 32 states and DC and must now audit its data practices annually\nWHAT THE TERMS SAY: A 2017 multistate Assurance of Voluntary Compliance with 32 states and DC required Nationwide to pay $5.5M and imposed remedies including hiring a Technology Officer, three years of patch inventories, internal assessments, and an annual third-party audit of data collection and storage.\nWHY IT MATTERS: The settlement shows the breach resulted in binding, ongoing regulatory oversight of Nationwide's data security practices, not just a one-time payout.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[RETENTION_PERIOD · FL-2] Nationwide kept SSNs of people who only requested quotes and never became customers\nWHAT THE TERMS SAY: Many people affected by the 2012 breach had only requested an insurance quote and never became Nationwide customers, yet their Social Security numbers were retained; the settlement specifically required Nationwide to start disclosing that it retains data even from non-customers.\nWHY IT MATTERS: Consumers who never purchased anything from Nationwide had their sensitive data held and exposed without knowing it was being retained.\n(evidence: Data Sharing | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The 2012 breach, the $5.5M multistate settlement, and its specific remedial terms are all documented with dates and figures.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Nationwide  <-  Nationwide Mutual Insurance Company (mutual, policyholder-owned)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Nationwide takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T20:03:20Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Nationwide paid $5.5 million to 32 states and the District of Columbia over a 2012 breach that exposed Social Security numbers, driver's license numbers and credit scores for 1.27 million people - and the cause was not a sophisticated attack but a failure to apply a critical security patch. The part that makes this row land is who got hurt: many of the affected people were never Nationwide customers at all. They had requested an insurance quote, and Nationwide kept their Social Security numbers on file afterward so it could quote them more conveniently in the future. New York's attorney general at the time called it needless carelessness. The settlement had to specifically require Nationwide to start telling consumers that it retains their personal information even when they don't buy anything - which means, before August 2017, it wasn't.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Insurance", "_row_id": 334, "_entity_id": 510, "_entity_slug": "nationwide", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Liberty Mutual", "Category": "Insurance", "Terms & Conditions URL": "libertymutual.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "libertymutual.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED MAY 2026 RANSOMWARE BREACH: the 'Everest' ransomware group claimed to have stolen MORE THAN 108 GIGABYTES of data from Liberty Mutual, obtained via a THIRD-PARTY VENDOR (consistent with the vendor-breach pattern seen repeatedly throughout this tracker). At least two named plaintiffs (Francis and Goodwin, Massachusetts federal court) filed a class action on behalf of 15,000+ affected policyholders, alleging Liberty Mutual failed to encrypt or redact sensitive personal AND PROTECTED HEALTH INFORMATION — the stolen data reportedly includes highly sensitive MEDICAL RECORDS posted to Everest's dark-web leak site. One named plaintiff reports experiencing an immediate wave of spam/scam/phishing texts after the breach; the other reports FRAUDULENT CHARGES to his checking account — both concrete, already-realized harms rather than merely theoretical future risk.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Liberty Mutual's own telematics program ('RightTrack') is grouped with Allstate/GEICO/Progressive as one of the insurers that can RAISE rates based on driving data (not just offer discounts) — see the Allstate row for the broader telematics-rate-risk pattern that applies here too.\n\nAUG 2026 ADDENDUM: no confirmed regulatory action, consumer-privacy settlement or independently verified breach-notification figure for Liberty Mutual surfaced this pass beyond the Everest claim already recorded. Recommend a direct follow-up on (a) any state AG breach notification filed in 2026 confirming scope and record count, (b) whether the 108GB claim was ever corroborated or the data published, and (c) RightTrack data retention and sharing terms. Keep the alleged/confirmed line visible in any published writeup: an attacker's leak-site post is a lead, not a finding.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$50.4B", "Market Cap": "Non-public", "Employees": "40,000", "HQ City": "Boston", "HQ State": "Massachusetts", "CEO": "Timothy Sweeney", "Ticker": "Non-public", "Website (Corporate)": "libertymutual.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (Non-public). Service route: c/o General Counsel / Corporate Secretary, Boston, Massachusetts — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Massachusetts' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Massachusetts SOC Corporate Search — corp.sec.state.ma.us/corpweb/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] A May 2026 ransomware claim and lawsuit allege Liberty Mutual exposed 15,000+ policyholders' medical records\nWHAT THE TERMS SAY: A class action (Francis and Goodwin) on behalf of 15,000+ policyholders alleges Liberty Mutual failed to encrypt or redact personal and protected health information after the 'Everest' ransomware group claimed to have stolen over 108GB of data via a third-party vendor, with medical records reportedly posted to a dark-web leak site.\nWHY IT MATTERS: Two named plaintiffs report already-realized harm — one a wave of phishing texts, the other fraudulent charges to his checking account — though the attacker's 108GB claim itself remains uncorroborated.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SURVEILLANCE_PRICING · FL-2] Liberty Mutual's RightTrack telematics can raise a driver's rate, not just lower it\nWHAT THE TERMS SAY: Liberty Mutual's RightTrack telematics program sits in the surcharge-capable group alongside Allstate, GEICO, and Progressive, meaning the driving data it collects can move a customer's rate in both directions.\nWHY IT MATTERS: Customers enrolling in RightTrack accept downside rate risk from their tracked driving data, not just a potential discount.\n(evidence: Fees | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and fee fields are both marked not independently confirmed this pass, and the ransomware breach's total scope is an uncorroborated attacker claim; only the litigation-documented breach and the stated telematics rate-risk are substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach and lawsuit are documented, but the attacker's 108GB scope claim is uncorroborated, and arbitration/fee terms are unconfirmed.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Liberty Mutual  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Liberty Mutual you gave up your physical movements. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The Everest ransomware group claimed in May 2026 to have taken more than 108 gigabytes of data from Liberty Mutual - a volume that, if accurate, is less a file exfiltration than a wholesale copy of a business unit. Ransomware crews routinely inflate their claims, so treat the figure as the attackers' assertion rather than confirmed fact until an independent notification or regulatory filing corroborates it, and that verification had not surfaced as of this pass. What can be said without qualification is that Liberty Mutual's RightTrack telematics program sits in the surcharge-capable group alongside Allstate, GEICO and Progressive - meaning the driving data it collects can move your rate in both directions, not just down.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Insurance", "_row_id": 335, "_entity_id": 511, "_entity_slug": "liberty-mutual", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Trupanion", "Category": "Pet Insurance", "Terms & Conditions URL": "trupanion.com/legal/policy-terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "trupanion.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Pet insurance broadly (not Trupanion-specific) is frequently criticized industry-wide for pre-existing-condition exclusions and rising premiums with age — a structural cost concern rather than a privacy issue specifically; recommend a direct follow-up on Trupanion's specific practices.", "Notes": "Recommend a dedicated follow-up given thin verification this pass.\n\nAUG 2026 ADDENDUM (verified this pass, supersedes the 'thin verification' note): No lawsuit, regulatory action or breach found for Trupanion - that null result appears genuine. Documented rate-filing behavior: June 2023 Florida filing requested 48.9% following a 14% increase approved that February; a California request for 28% was approved at 12%. Structural comparison vs Healthy Paws, per independent reviews: Trupanion uses PER-CONDITION deductibles (Healthy Paws uses an annual deductible covering all conditions), does not restrict coverage percentage or deductible options by age at enrollment, and offers VetDirect Pay which pays the veterinarian directly rather than reimbursing after the fact - materially different cash-flow exposure for the customer at the point of care. Trupanion charges extra for alternative therapies that Healthy Paws includes. Scale context: ~5.4M US pet insurance policies in force in 2022, up 21% year over year; Trupanion insured ~1.5M pets as of Dec 2022, roughly triple its 2018 figure.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] Trupanion sought a 48.9% Florida rate hike atop a 14% increase approved months earlier\nWHAT THE TERMS SAY: A June 2023 Florida rate filing requested a 48.9% increase immediately following a 14% increase the state had approved that February; a separate California filing sought 28% and was approved at 12%.\nWHY IT MATTERS: Even though Trupanion doesn't raise prices simply because a pet had a birthday, its actual cost trajectory is set by state regulators who can still approve large, compounding increases within the same year.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — The tracker states no lawsuit, regulatory action, or breach was found for Trupanion this pass, and its age-neutral pricing structure is presented as comparatively favorable rather than troubling; only the compounding rate-filing pattern is a distinct consumer harm.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The verified null result on litigation/breach and the specific rate-filing percentages and dates are both clearly documented.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Trupanion  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Trupanion takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Trupanion is the rare row in this tab where the company looks genuinely better than its peers on the specific thing customers complain about most - it does not use birthday pricing, so a premium does not rise simply because the pet had another birthday or because you actually used the coverage, and it holds 90% reimbursement from birth to age 14 without downgrading options as the animal ages. The catch is that rate increases arrive through a different door: in one 2023 cycle Trupanion asked Florida's insurance regulator for a 48.9% price increase ON TOP of a 14% hike the same regulator had already approved that February, and asked California for 28% and was granted 12%. So the pricing is age-neutral but not stable, and the actual brake on what you pay is a state insurance commissioner you will never speak to - which also means residents of different states get materially different outcomes from the same policy.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Insurance", "_row_id": 336, "_entity_id": 512, "_entity_slug": "trupanion", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Healthy Paws", "Category": "Pet Insurance", "Terms & Conditions URL": "healthypawspetinsurance.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "healthypawspetinsurance.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Same general pet-insurance industry cost-structure concerns (pre-existing condition exclusions, age-based premium increases) as Trupanion above.", "Notes": "Recommend a dedicated follow-up given thin verification this pass.\n\nAUG 2026 ADDENDUM - PRIVATE LITIGATION, verified filed (allegations, not findings; supersedes the 'thin verification' note): Benanav v. Healthy Paws Pet Insurance - plaintiff Steven Benanav of Los Angeles insured his dog Mali in March 2012 at $33.85/mo; alleges the premium reached ~$105/mo by 2020 (~200%) versus 29% growth in BLS veterinary prices over the same window. Core claim is breach of contract: the policy permits increases tied to veterinary cost changes and, per the complaint, not to the pet's age. Underwriting has run through Markel American, ACE American and Westchester Fire. Independently documented by Consumers' Checkbook, which had rated Healthy Paws favorably in 2018 and reversed after receiving customer complaints; Healthy Paws executives declined to speak with Checkbook. Structural findings: Healthy Paws adjusts coverage percentage and deductible options by age at enrollment, with restrictions applying at age 5+, and reimburses only after the customer has paid the vet bill (unless pre-approval is arranged by phone during business hours). Final settlement terms not confirmed this pass - recommend follow-up before publishing any outcome.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2012, 2020, 2018", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-1] A lawsuit alleges Healthy Paws raised one owner's premium ~200% versus 29% vet-cost inflation\nWHAT THE TERMS SAY: Benanav v. Healthy Paws alleges the policy permits premium increases tied only to veterinary cost changes, not the pet's age, yet the plaintiff's premium rose from $33.85/mo in 2012 to about $105/mo by 2020 (~200%) while BLS veterinary prices rose only 29% over the same period.\nWHY IT MATTERS: If the allegation holds, premiums are rising far faster than the contractual justification permits, and Consumers' Checkbook independently documented a similar pattern in another customer after reversing an earlier favorable rating.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DISCRIMINATORY_PRACTICE · FL-1] Healthy Paws cuts reimbursement and raises deductibles by age, worsening coverage as pets need it most\nWHAT THE TERMS SAY: The tracker documents that Healthy Paws adjusts coverage percentage and deductible options by age at enrollment, with restrictions applying at age 5 and up, and reimburses only after the customer has paid the vet bill unless pre-approval is arranged by phone during business hours.\nWHY IT MATTERS: Coverage quality degrades as the pet ages, precisely when veterinary needs typically increase.\n(evidence: Notes; Stated in tracker (fidelity pass 1: Cross-ref leak corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms are unconfirmed and the fee/billing field cites only industry-wide, non-company-specific concerns; only the Benanav litigation and the age-based coverage-restriction structure are company-specific and substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Benanav litigation and age-based coverage terms are well documented, but arbitration terms and the case's final outcome remain unconfirmed.", "Exposure Score (0-100)": 10, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Healthy Paws  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Healthy Paws takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The class action against Healthy Paws makes an unusually crisp allegation: the policy contract says premiums increase only to reflect the changing cost of veterinary medicine - not the pet's age - and the named plaintiff's premium for his dog Mali went from $33.85 a month in 2012 to about $105 by 2020, roughly 200%, during a period when Bureau of Labor Statistics data put the rise in veterinary prices at 29%. Consumer researchers documented the same pattern independently, including a Virginia customer whose premium jumped from $90 to $152 a month in a single year as her dog turned six. Age also quietly degrades the coverage itself, not just the price: reimbursement percentages drop and deductibles rise as the animal ages, so the policy gets more expensive and less useful at exactly the moment the pet starts needing it. Consumers' Checkbook had rated Healthy Paws a favorable buy in 2018 based on the company's representations, then reversed after the complaints came in.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Insurance", "_row_id": 337, "_entity_id": 513, "_entity_slug": "healthy-paws", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "WMATA (Metro/SmarTrip)", "Category": "Public Transit", "Terms & Conditions URL": "wmata.com/about/records/smartrip-terms-conditions.cfm", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "wmata.com/about/records/privacy.cfm", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "WMATA's OWN Office of Inspector General conducted an independent AUDIT OF WMATA'S DATA PRIVACY practices (results published April 2026, available as a redacted PDF report) — the existence of a dedicated internal audit specifically targeting data privacy compliance is itself notable, though the audit's specific findings were not independently reviewed in full this pass (recommend reading the actual redacted report directly for details). Separately, WMATA's Privacy Policy states that REGISTERED SmarTrip card holders' transaction records (more than 26 months old) require either a notarized signed statement or an in-person appointment with government-issued ID to release — but UNREGISTERED SmarTrip cards have WEAKER protection: 'anyone can obtain records pertaining to an unregistered card by submitting a records request,' which WMATA itself cites as the reason it 'strongly encourages' registration — meaning an unregistered card, often used specifically BECAUSE someone wants anonymity, is actually the LESS private option under WMATA's own stated policy.", "Arbitration / Class Action Waiver": "Not applicable in the typical arbitration-clause sense — WMATA is a public interstate transit authority (compact among DC/MD/VA), not a private company, so disputes follow public-records/FOIA-style request processes rather than consumer arbitration.", "Fees / Billing Flags": "Not itemized this pass — recommend a direct follow-up on the WMATA OIG's separate 'SmarTrip Regional Partner Comparative Billing Statements' audit (covering FY2024-2025) if billing-accuracy specifics are relevant.", "Notes": "The 'unregistered card is actually less private than a registered one' finding is a genuinely counter-intuitive and useful piece of consumer education — many riders likely assume the opposite (that staying unregistered protects their privacy) when WMATA's own policy says the reverse.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] WMATA's own policy makes an 'anonymous' unregistered SmarTrip card easier for others to get records on\nWHAT THE TERMS SAY: WMATA's Privacy Policy states that transaction records for registered cards over 26 months old require a notarized statement or an in-person ID appointment to release, but records for unregistered cards can be obtained by anyone who submits a records request.\nWHY IT MATTERS: Riders who choose an unregistered card specifically for anonymity are, under WMATA's own stated policy, actually less protected than registered users, which WMATA itself cites as the reason it encourages registration.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[LOCATION_TRACKING · FL-2] Registered SmarTrip cards can reconstruct a rider's home, workplace, and daily schedule\nWHAT THE TERMS SAY: A registered SmarTrip card produces a complete record of when and where a rider entered and exited the system, and such transit records are subject to law enforcement requests under standards that vary and are rarely published.\nWHY IT MATTERS: For a daily commuter this reconstructs home, workplace, and schedule with high precision, and avoiding it means paying cash and forgoing balance protection.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The OIG data-privacy audit and the separate billing-accuracy audit are procedural items, not themselves stated harms, so only the registration-privacy paradox and the location-tracking/law-enforcement-access risk are counted as distinct troubling findings this pass.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The registration-privacy distinction is directly quoted from WMATA's policy, but the OIG audit's full findings were not reviewed in full this pass.", "Exposure Score (0-100)": 9, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "WMATA (Metro/SmarTrip)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using WMATA (Metro/SmarTrip) you gave up your physical movements. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T20:03:30Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "WMATA's own Inspector General audited its data practices, which is unusual and worth crediting - most transit agencies have no equivalent independent review. The underlying exposure is inherent to the technology: a registered SmarTrip card produces a complete record of when and where a rider entered and exited the system, which for a daily commuter reconstructs home, workplace and schedule with high precision. Transit records are also subject to law enforcement request under standards that vary and are rarely published. A rider who wants to avoid it must use an unregistered card and pay cash to reload, forgoing balance protection - the privacy option is the one that costs you money if you lose the card.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Transit, Tolls & Water", "_row_id": 338, "_entity_id": 514, "_entity_slug": "wmata-metro-smartrip", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Transurban (Virginia Express Lanes) / E-ZPass", "Category": "Toll Systems", "Terms & Conditions URL": "expresslanes.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "expresslanes.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Transurban's OWN privacy policy explicitly confirms it collects VIDEO RECORDINGS that 'inadvertently and incidentally' capture images of PEDESTRIANS, license plate numbers, vehicles, and vehicle occupants as part of its roadside technology — a direct acknowledgment of the kind of surveillance-adjacent data collection that toll operators broadly engage in. Separately, broader E-ZPass-system research (applicable across the wider E-ZPass network, not Transurban specifically) has documented E-ZPass READERS installed in locations OTHER than toll booths (e.g., 'nearly every intersection in Midtown' Manhattan, per NYCLU FOIL findings) for government traffic studies — raising the general concern that toll-tag data can be used for broader location tracking beyond its original toll-payment purpose, even when agencies claim identifying information is stripped before analysis.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass for the current Terms of Use — recommend direct verification.", "Fees / Billing Flags": "DIRECTLY REGIONAL, HIGH-PROFILE CASE: a Virginia federal class action (Mischler et al. v. Transurban) was filed after FOX 5 DC's investigative reporting exposed drivers on the I-95/I-395 Express Lanes being hit with THOUSANDS OF DOLLARS in fines for missing tolls as small as $36 (one driver: a $17,000 fine for a $36 toll) — the reporting itself led Transurban to change its policies and cap fines even before the lawsuit's outcome. A 2026 legal-tracking source describes 'a significant class action settlement against Transurban' in Virginia as having set a precedent other states' E-ZPass litigation is now citing, though the exact settlement terms were not independently confirmed in full detail this pass.", "Notes": "This is one of the most DIRECTLY REGIONALLY RELEVANT findings in the entire tracker — the underlying reporting and lawsuit are specifically about Virginia commuters on the I-95/I-395 corridor, exactly the population this tracker is meant to serve. Worth a dedicated follow-up to confirm the Transurban settlement's final terms given its direct applicability to DMV commuters.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] One driver was fined $17,000 over a $36 missed toll before Transurban capped its penalties\nWHAT THE TERMS SAY: A Virginia federal class action (Mischler et al. v. Transurban), filed after FOX 5 DC's reporting, alleges drivers on the I-95/I-395 Express Lanes were hit with fines of thousands of dollars for missing tolls as small as $36, including one driver fined $17,000 for a $36 toll; the reporting led Transurban to cap fines even before the lawsuit's outcome.\nWHY IT MATTERS: A minor missed toll payment could balloon into a disproportionate financial penalty before the company's policy change, and the exact settlement terms remain unconfirmed.\n(evidence: Fees | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[LOCATION_TRACKING · FL-2] Transurban's own privacy policy admits its camera network captures pedestrians and license plates\nWHAT THE TERMS SAY: Transurban's privacy policy explicitly confirms it collects video recordings that 'inadvertently and incidentally' capture images of pedestrians, license plate numbers, vehicles, and vehicle occupants as part of its roadside technology.\nWHY IT MATTERS: E-ZPass and express-lane data form a precise vehicle movement log tied to a registered owner, and such records have a documented history of being subpoenaed in civil matters including divorce proceedings.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — A third data point — E-ZPass readers installed at non-toll locations for government traffic studies — is explicitly described as a broader network pattern, not confirmed as Transurban-specific, so it is not counted as a distinct company finding; only the toll-fine litigation and the admitted video-surveillance practice are company-specific and substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The video-collection admission and the Mischler fine figures are well documented, but arbitration terms and the settlement's final terms remain unconfirmed.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 4/20 (severity2+2, litigation+2) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Transurban (Virginia Express Lanes) / E-ZPass  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Transurban (Virginia Express Lanes) / E-ZPass you gave up your physical movements and your right to stop paying by inaction. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T20:03:32Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Transurban's own privacy policy confirms it collects VIDEO of vehicles - not merely transponder reads - which means the toll system is also a camera network capturing images at every gantry. E-ZPass and express lane data is a precise vehicle movement log tied to a registered owner, and it has a long documented history of being subpoenaed in civil matters including divorce proceedings. Virginia's Express Lanes are also operated by a private Australian-listed infrastructure company under a long-term concession, so the entity holding the movement records of Northern Virginia commuters is a private toll operator rather than a public agency.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Transit, Tolls & Water", "_row_id": 339, "_entity_id": 515, "_entity_slug": "transurban-virginia-express-lanes-e-zpass", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "DC Water", "Category": "Water Utility (DC)", "Terms & Conditions URL": "dcwater.com/terms-of-use (specific URL not independently confirmed this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "dcwater.com/privacy-statement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Government entity serving 700,000+ DC residents and 24M people in the broader watershed. Customer billing data, water usage patterns, and lead-pipe testing results are subject to DC open-records law. DC Water's Clean Rivers project includes environmental monitoring data.", "Arbitration / Class Action Waiver": "Government entity — DC Water and Sewer Authority is an independent authority of the District of Columbia government. No private arbitration. Customer disputes go through DC government complaint processes and ultimately the DC Council. As a government entity, DC Water is subject to FOIA and DC open-records laws.", "Fees / Billing Flags": "Not itemized this pass beyond the 20-day dispute-notification window noted above.", "Notes": "DC's Office of the People's Counsel maintaining a DEDICATED water-services division specifically to help ratepayers is a genuinely useful, DC-specific consumer resource worth flagging if this tracker informs any customer-facing guidance for DC residents specifically.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "District of Columbia Water and Sewer Authority (independent government authority)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] DC Water usage data can reveal occupancy, and its records may be obtainable via public-records requests\nWHAT THE TERMS SAY: As a public authority, DC Water's billing and usage data may be obtainable through public-records requests in ways a private utility's would not be, and the tracker notes water-usage patterns reveal occupancy, with a sustained drop indicating an empty property.\nWHY IT MATTERS: Residents' presence and habits are inferable from utility data that carries different, and potentially weaker, confidentiality protections because DC Water is a government entity subject to FOIA/open-records law.\n(evidence: SCARY | Data Sharing; Inferred from tracker text (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No breach, lawsuit, or regulatory action was confirmed for DC Water this pass; only the structural public-records/occupancy-inference concern common to government-run utilities is documented.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing was confirmed this pass, and the tracker recommends a follow-up on meter reading intervals and FOIA exemption posture.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "DC Water  <-  District of Columbia Water and Sewer Authority (independent government authority)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, DC Water takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T20:03:34Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Water utility data is coarser than electric smart-meter data but the same inference structure applies - consumption patterns reveal occupancy, and a sustained drop indicates an empty property. DC Water is also a public authority, which means customer records may be subject to public records requests in ways a private utility's are not, with exemptions that vary. Recommend a follow-up on DC Water's meter reading interval and its FOIA exemption posture for customer account data.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Transit, Tolls & Water", "_row_id": 340, "_entity_id": 517, "_entity_slug": "dc-water", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "WSSC Water", "Category": "Water Utility (MD)", "Terms & Conditions URL": "wsscwater.com/terms-of-use (specific URL not independently confirmed this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "wsscwater.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not applicable in the typical consumer-arbitration sense — WSSC is a Maryland state-chartered public utility/government agency, so disputes go through WSSC's own dispute-resolution/refund-hearing process or Maryland's Consumer Affairs Division rather than private arbitration.", "Fees / Billing Flags": "SIGNIFICANT, WELL-DOCUMENTED REGIONAL BILLING SCANDAL: WSSC's 'Project Cornerstone' billing system produced widespread customer complaints of WILDLY INACCURATE BILLS — one Derwood, MD customer's typically-under-$100 quarterly bill jumped to nearly $3,000 after a full year without a bill; multiple Prince George's and Montgomery County customers reported similar issues persisting for YEARS, with hours-long hold times when trying to reach customer service (WSSC blamed pandemic-era staffing, saying it had been improving since March 2022). SEPARATELY AND MORE SERIOUSLY: a WSSC COMMISSIONER RESIGNED amid allegations of an undisclosed CONFLICT OF INTEREST — he was reportedly doing business with one of the vendors involved in the Cornerstone billing system while simultaneously approving contracts for that same vendor, and other WSSC vendors/employees were separately flagged for sitting on the boards of organizations connected to each other.", "Notes": "The commissioner conflict-of-interest resignation is a genuinely serious GOVERNANCE finding, distinct from a typical customer-privacy or billing-accuracy issue — it suggests the billing system's flaws may be connected to a compromised vendor-selection process rather than purely a technical glitch. Given WSSC serves Montgomery and Prince George's Counties directly, this is one of the more concretely regionally-relevant governance findings in the entire tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] WSSC's Cornerstone billing system sent one customer's typical <$100 bill to nearly $3,000\nWHAT THE TERMS SAY: WSSC's 'Project Cornerstone' billing system produced widespread complaints of wildly inaccurate bills, including one Derwood, MD customer whose typically-under-$100 quarterly bill jumped to nearly $3,000 after a year without a bill, with multiple Prince George's and Montgomery County customers reporting similar issues persisting for years alongside hours-long customer-service hold times.\nWHY IT MATTERS: Customers of a utility they cannot switch away from faced years of billing chaos and long waits to get it resolved.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-1] A WSSC commissioner resigned amid allegations of an undisclosed conflict reportedly tied to the billing vendor\nWHAT THE TERMS SAY: A WSSC commissioner resigned amid allegations of an undisclosed conflict of interest — reportedly doing business with a vendor involved in the Cornerstone billing system while simultaneously approving contracts for that same vendor.\nWHY IT MATTERS: The tracker's notes suggest the billing failures that harmed customers may stem from a compromised vendor-selection process rather than a purely technical glitch.\n(evidence: Notes | Fees; Stated in tracker (fidelity pass 1: Hedge lost corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No confirmed data-privacy lawsuit or breach exists for WSSC this pass; only the Project Cornerstone billing failures and the related commissioner conflict-of-interest resignation are substantive findings.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Cornerstone billing failures and commissioner resignation are well documented, but no privacy-specific lawsuit or breach was confirmed.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "WSSC Water  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using WSSC Water you gave up your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T20:03:38Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. WSSC serves Montgomery and Prince George's counties and is a bi-county public agency, so the same public-records considerations noted for DC Water apply. Water utilities also hold a distinctive category of hardship data - payment plans, shutoff notices and assistance programme enrolment - which is a financial-distress record held by an entity a household cannot leave. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Transit, Tolls & Water", "_row_id": 341, "_entity_id": 518, "_entity_slug": "wssc-water", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fairfax Water", "Category": "Water Utility (VA)", "Terms & Conditions URL": "fairfaxwater.org/terms-of-use (specific URL not independently confirmed this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "fairfaxwater.org/privacy-disclaimer", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Government entity serving 2M people in Fairfax County, VA and parts of Prince William, Loudoun, and Alexandria. Customer billing and water-quality data subject to Virginia FOIA.", "Arbitration / Class Action Waiver": "Government entity — Fairfax Water (Fairfax County Water Authority) is a political subdivision of the Commonwealth of Virginia. No private arbitration. Subject to Virginia FOIA.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Fairfax Water serves MORE THAN 2 MILLION residents (per its own site) — among the largest water utilities in Virginia; its billing-dispute process (a simple phone call) is notably less bureaucratic than DC Water's or WSSC's processes described in their respective rows, worth flagging as a genuine point of comparison across the three regional water utilities in this tab.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Fairfax County Water Authority (political subdivision of Virginia)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-2] Fairfax Water, like peer utilities, has almost no independent public accountability record\nWHAT THE TERMS SAY: The tracker found nothing confirmed for Fairfax Water this pass and notes that municipal/quasi-public utilities generally have no SEC filings, limited press attention, and breach-notification obligations that rarely produce visible coverage.\nWHY IT MATTERS: The absence of any confirmed privacy findings reflects a lack of scrutiny on these utilities rather than evidence of good practice, per the tracker's own framing.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No lawsuit, breach, or regulatory action was found for Fairfax Water; the tracker explicitly treats this row's structural assessment as shared with DC Water and WSSC rather than independent, so only the general opacity observation is offered as a finding.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing was confirmed this pass, and the tracker notes municipal utilities generally produce little independent accountability record.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Fairfax Water  <-  Fairfax County Water Authority (political subdivision of Virginia)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Fairfax Water takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T20:04:20Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Same public water authority structure and same analysis as DC Water and WSSC; recorded as one structural assessment across the three rather than three independent ones. The honest observation across this entire tab is that municipal and quasi-public utilities generate very little public accountability record - no SEC filings, limited press attention, and breach notification obligations that apply but rarely produce coverage - so absence of findings measures scrutiny rather than practice.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Transit, Tolls & Water", "_row_id": 342, "_entity_id": 520, "_entity_slug": "fairfax-water", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "ADP", "Category": "Payroll/HR", "Terms & Conditions URL": "adp.com/about-adp/legal.aspx", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "adp.com/about-adp/privacy.aspx", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific recent named lawsuit or breach; ADP is one of the largest payroll processors in the US, meaning most residents interact with it indirectly through an employer's payroll system rather than as a direct retail customer — a similar B2B relationship structure as Workday (see that row), where a breach would primarily be reported by the EMPLOYER, not ADP itself, to affected workers.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — ADP's services are primarily B2B (employer payroll processing). Individual employees interact with ADP's portal to view paystubs and tax forms, but the contractual relationship is between ADP and the employer, not ADP and the employee. The arbitration clause in ADP's Terms of Use may not bind individual employees who never separately agreed to them.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given ADP's central role in payroll data (SSNs, bank account/direct-deposit info, salary data) for a very large share of US employees — thin verification this pass likely reflects search-query limitations rather than an actual clean record.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-4] Employees have no relationship with, or ability to decline, ADP, which holds their SSN and bank data\nWHAT THE TERMS SAY: ADP processes payroll for a large share of American employees, none of whom are its customers; individuals supply their Social Security number, bank account, wage history, garnishment orders, and benefit elections through an employer relationship they did not choose.\nWHY IT MATTERS: Employees cannot decline, switch, or read the contract governing this data, and generally cannot even identify which vendor holds their file until a breach notification arrives.\n(evidence: SCARY | Notes; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No ADP-specific breach, lawsuit, or regulatory action was confirmed this pass; only the structural finding that employees have no direct relationship with, or ability to decline, the payroll processor holding their SSN and bank data is substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No company-specific lawsuit or breach was confirmed, and as a B2B processor ADP has no direct consumer-facing terms for employees to review.", "Exposure Score (0-100)": 5, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "ADP  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing company-specific confirmed this pass, and the structural finding is more useful anyway: ADP processes payroll for a very large share of American employees, none of whom are its customers. Your employer chose ADP; you supply the Social Security number, the bank account, the wage history, the garnishment orders and the benefit elections. You cannot decline, cannot switch, cannot read the contract, and generally cannot even tell which vendor holds your file until a breach notification arrives. Payroll processors are the single largest concentration of employee financial data in the country and the individual has no relationship with them at all.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Payroll, RealEstate & Finance", "_row_id": 343, "_entity_id": 521, "_entity_slug": "adp", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Workday", "Category": "Payroll/HR", "Terms & Conditions URL": "workday.com/en-us/legal/terms-of-use.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "workday.com/en-us/legal/privacy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "TWO SEPARATE, SERIOUS FINDINGS: (1) A CONFIRMED 2025 BREACH: Workday disclosed (Aug 2025) that threat actors accessed data via a SOCIAL ENGINEERING campaign — part of the SAME broader Salesforce-linked attack wave (ShinyHunters group) that also hit Air France/KLM (see Global Airlines tab) and dozens of other companies. A resulting class action (Elias & Panigrahy v. Workday/Salesforce, California federal court) alleges the breach compromised personal information of MILLIONS of consumers and was 'highly preventable,' involving vulnerabilities the defendants allegedly knew about in advance; this is directly relevant since Workday is the SAME payroll/HR platform whose employee accounts were separately compromised in the Chipotle breach documented in the Consumer Apps tab — meaning Workday itself has now appeared in this tracker as both a directly-sued defendant AND the platform underlying at least one other company's separate breach. (2) A SEPARATE, EARLIER CLASS ACTION (certified by a California federal judge) alleges Workday's AI/algorithmic APPLICANT-SCREENING system disproportionately DISQUALIFIES JOB APPLICANTS OVER AGE 40 — an algorithmic age-discrimination claim distinct from the data-breach matter, and one of the only ALGORITHMIC BIAS findings (as opposed to a data-privacy or security finding) anywhere in this entire 300+ company tracker.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — Workday is a B2B enterprise HR/finance platform. Individual employees access Workday through their employer's instance. Same B2B relationship structure as ADP — the arbitration question is between Workday and the employer, not Workday and the employee.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The AGE-DISCRIMINATION ALGORITHMIC-SCREENING finding is genuinely unique in this tracker — nearly every other finding across this 300+ company audit involves DATA privacy/security, while this one involves an ALGORITHM'S DECISION-MAKING OUTPUT allegedly producing a discriminatory pattern. Worth flagging distinctly since it's a different category of harm (employment discrimination) from the privacy/security findings that dominate the rest of this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$9.6B", "Market Cap": "$32.7B", "Employees": "20,482", "HQ City": "Pleasanton", "HQ State": "California", "CEO": "Aneel Bhusri", "Ticker": "WDAY", "Website (Corporate)": "workday.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (WDAY). Service route: c/o General Counsel / Corporate Secretary, Pleasanton, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] A 2025 breach via social-engineering calls allegedly compromised millions of Workday users' data, suit says\nWHAT THE TERMS SAY: Workday disclosed an August 2025 breach via a social-engineering campaign (part of the Salesforce-linked ShinyHunters wave); a resulting class action (Elias & Panigrahy) alleges it compromised personal information of millions of consumers and was 'highly preventable,' involving vulnerabilities the defendants allegedly knew about in advance.\nWHY IT MATTERS: The row describes employees being phoned by people posing as IT or HR staff and talked into authorising access, with no exploit involved; the suit alleges personal information of millions of consumers was compromised at a company that holds hiring records, compensation and performance reviews for people who are not its customers.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity pass 1: Hedge lost corrected) (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[DISCRIMINATORY_PRACTICE · FL-2] A certified class action alleges Workday's AI hiring tool rejects applicants over 40 at higher rates\nWHAT THE TERMS SAY: A separate, earlier class action, certified by a California federal judge, alleges Workday's AI/algorithmic applicant-screening system disproportionately disqualifies job applicants over age 40.\nWHY IT MATTERS: This is a distinct algorithmic age-discrimination claim, separate from the data-breach matter, and one of the only findings in the tracker involving an algorithm's decision-making output rather than data privacy or security.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms are not verified since Workday is a B2B platform; only the 2025 breach and the certified age-discrimination algorithmic-screening class action are substantive, distinct findings this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=Y", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The breach mechanism, the related class action, and the separate certified age-discrimination case are all specifically documented with named parties and mechanisms.", "Exposure Score (0-100)": 13, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Workday  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Workday's 2025 breach came through the ShinyHunters social-engineering campaign - employees were phoned by people posing as IT or HR staff and talked into authorising access, with no exploit involved. The irony is exact: the company whose product IS the HR system was breached by someone pretending to work in HR. Workday holds hiring records, compensation, performance reviews and terminations for millions of employees who, as with ADP, are not its customers and never agreed to anything. Cross-ref the Salesforce master entry in F500 Tech & Semiconductors.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Payroll, RealEstate & Finance", "_row_id": 344, "_entity_id": 522, "_entity_slug": "workday", "_issuer": "Workday", "_issuer_slug": "workday", "_ticker": "WDAY", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Zillow", "Category": "Real Estate", "Terms & Conditions URL": "zillow.com/z/corp/terms/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "zillow.com/z/corp/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ACTIVE VPPA/CIPA CLASS ACTION (June 2024, S.D. California): alleges Zillow installed secret tracking pixels that captured which AGENT-CREATED VIDEO HOME TOURS a user watched, then transmitted that viewing data — along with names and email addresses — to Reddit, Meta, Microsoft, Alphabet/Google, and Snapchat WITHOUT VALID CONSENT, violating the federal Video Privacy Protection Act and California's Invasion of Privacy Act. The complaint alleges Zillow specifically programmed this tracking 'for advertising purposes and to increase its profits,' knowing it would transmit detailed viewing records.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Zillow Group ToS (zillow.com/z/corp/terms/). 30-day opt-out. Same terms govern Trulia (confirmed from this session's direct footer fetch — Trulia's 'Terms of Use' link resolves to Zillow's terms). Zillow Group also owns StreetEasy, HotPads, and Out East.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The near-identical, same-day filing against REDFIN (see that row) suggests this may reflect an industry-wide practice among real-estate listing platforms rather than a Zillow-specific choice — worth checking whether other property-listing sites (Realtor.com, Apartments.com) use similar video-tracking technology.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Zillow Group, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Tracking pixels allegedly sent Zillow users' video-tour activity and identities to Meta, Google, and others\nWHAT THE TERMS SAY: An active VPPA/CIPA class action alleges Zillow installed secret tracking pixels that captured which agent-created video home tours a user watched, then transmitted that viewing data along with names and email addresses to Reddit, Meta, Microsoft, Alphabet/Google, and Snapchat without valid consent, allegedly for advertising purposes and to increase profits.\nWHY IT MATTERS: Real estate browsing is unusually revealing — the homes a person looks at can disclose budget, target neighborhood, school-district preference, and plans to move — and this data allegedly reached ad platforms without consent.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Zillow requires binding arbitration with a class-action waiver and only a 30-day opt-out\nWHAT THE TERMS SAY: Zillow Group's ToS mandate binding arbitration with a class action waiver and a 30-day opt-out; the row confirms the same terms govern Trulia, and notes Zillow Group also owns StreetEasy, HotPads and Out East.\nWHY IT MATTERS: Zillow and Trulia users who miss the narrow opt-out window are barred from suing or joining a class action over the company's data practices.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees/billing were not itemized this pass; only the VPPA/CIPA tracking-pixel litigation and the mandatory arbitration/class-action-waiver clause are substantive, distinct findings.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Arbitration terms are directly cited from Zillow's ToS, and the tracking-pixel litigation names specific third-party recipients and legal theories.", "Exposure Score (0-100)": 46, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Zillow  <-  Zillow Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Zillow you gave up your personal data sold onward, your data shared corporate-wide, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "2026-09-08T20:04:26Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The VPPA and CIPA class action alleges Zillow's video content brought it within the Video Privacy Protection Act while tracking technologies transmitted viewing activity to third parties. What makes real estate browsing unusually revealing is that it is anticipatory: the homes you look at disclose your budget, your target neighbourhood, your school district preference, whether you are expecting a family change, and whether you are about to move - months before any of it happens. Zillow also holds saved searches and alerts, which convert a browsing session into a monitored intention. Allegations, not findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Payroll, RealEstate & Finance", "_row_id": 345, "_entity_id": 524, "_entity_slug": "zillow", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Redfin", "Category": "Real Estate", "Terms & Conditions URL": "redfin.com/about/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "redfin.com/about/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SAME VPPA/CIPA VIDEO-TRACKING LAWSUIT PATTERN as Zillow (filed the same day, June 2024, same plaintiff): Redfin allegedly installed tracking pixels sending video-tour viewing data to Meta, Google, Microsoft, Reddit, Snapchat, AND ORACLE (an additional named recipient not listed in the Zillow suit) without valid consent. NOTABLY, Redfin's OWN SEC filing (Feb 2024) proactively acknowledged this exact risk BEFORE the lawsuit was filed, stating it 'may be liable for using pixel technology' and that companies using such tracking 'have been the subjects of recent data privacy lawsuits' relying on older laws to challenge new tracking technology — meaning Redfin had disclosed this specific legal risk to investors as a known possibility rather than being caught by surprise.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Redfin ToS, AAA rules. 30-day opt-out. Redfin operates as both a brokerage (employing licensed agents) and a tech platform — the arbitration clause covers disputes over both real estate transactions and platform data practices.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The fact that Redfin's OWN SEC risk disclosure predicted this exact lawsuit is a genuinely notable detail — it shows the company was aware of and had assessed this specific legal exposure well before being sued, distinct from companies that claim to be blindsided by similar litigation.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Redfin Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Redfin's own SEC filing flagged pixel-tracking risk before a suit alleged the same practice occurred\nWHAT THE TERMS SAY: The same VPPA/CIPA video-tracking lawsuit pattern as Zillow, filed the same day by the same plaintiff, alleges Redfin's tracking pixels sent video-tour viewing data to Meta, Google, Microsoft, Reddit, Snapchat, and Oracle without valid consent; Redfin's own February 2024 SEC filing had proactively acknowledged it 'may be liable for using pixel technology.'\nWHY IT MATTERS: Redfin disclosed this specific legal risk to investors as a known possibility before being sued, suggesting the exposure was assessed and accepted rather than an unforeseen surprise.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Redfin requires binding arbitration under AAA rules with a class-action waiver and 30-day opt-out\nWHAT THE TERMS SAY: Redfin's ToS mandate binding arbitration under AAA rules with a class action waiver and a 30-day opt-out, covering disputes over both real estate transactions and platform data practices.\nWHY IT MATTERS: Users who miss the opt-out window are barred from suing or joining a class action over Redfin's brokerage or data practices alike.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-4] Redfin's brokerage arm employs your agent while its platform arm tracks your home search\nWHAT THE TERMS SAY: Redfin operates as both a licensed real estate brokerage and a search platform that observes user browsing behavior, with the same entity on both sides of the relationship.\nWHY IT MATTERS: This creates a conflict of interest that most users never articulate: the platform surveilling a person's search activity also employs the agent representing that person's interests in a transaction.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Redfin's own SEC risk disclosure, its ToS arbitration terms, and the tracking-pixel litigation are all specifically documented.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Redfin  <-  Redfin Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Redfin you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T20:04:31Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Same VPPA and CIPA video-tracking theory as Zillow, filed the same period - two direct competitors, identical alleged conduct, which tells you the practice was industry standard rather than one company's choice. Redfin is also a licensed brokerage as well as a search portal, so the same entity that observes your browsing also employs the agent who represents you, which is a conflict most users never articulate. Allegations, not findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Payroll, RealEstate & Finance", "_row_id": 346, "_entity_id": 526, "_entity_slug": "redfin", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Apartments.com", "Category": "Real Estate/Rental", "Terms & Conditions URL": "apartments.com/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "apartments.com/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit, though the same VPPA/tracking-pixel pattern documented for Zillow and Redfin (see those rows) plausibly extends to other real-estate listing sites with video content, including Apartments.com — not independently verified this pass.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. CoStar Group's ToS govern Apartments.com alongside Homes.com, ApartmentFinder, ForRent, LoopNet, Land.com, BizBuySell, and Domain.com.au. CoStar Group HQ: Washington DC (DMV). 30-day opt-out.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up specifically checking whether Apartments.com uses similar video-tour tracking pixels to Zillow/Redfin, given how directly relevant rental-search platforms are to renters in this region specifically.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "CoStar Group, Inc. (Washington, DC)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] CoStar's arbitration clause binds Apartments.com users with a class-action waiver and 30-day opt-out\nWHAT THE TERMS SAY: CoStar Group's ToS, which mandate binding arbitration with a class action waiver and a 30-day opt-out, govern Apartments.com alongside Homes.com, ApartmentFinder, ForRent, LoopNet, Land.com, BizBuySell, and Domain.com.au.\nWHY IT MATTERS: Users across CoStar's many rental and real estate sites who miss the opt-out window are barred from suing or joining a class action.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Rental applications hand landlords SSNs and credit data with no stated security safeguards\nWHAT THE TERMS SAY: The tracker notes rental applications collect Social Security numbers, income verification, employment history, prior addresses, references, and consent to background/credit checks, handed to the listing platform and individual landlords with no stated security capability.\nWHY IT MATTERS: Application fees mean renters pay to repeatedly surrender this sensitive dossier to multiple properties, a materially higher-stakes exposure than typical home browsing.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No Apartments.com-specific tracking-pixel lawsuit was independently confirmed this pass (only a plausible extension of the Zillow/Redfin pattern); only the arbitration clause and the structural rental-application data-exposure risk are substantive, confirmed findings.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated via CoStar's ToS, but no company-specific breach or lawsuit was confirmed this pass.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Apartments.com  <-  CoStar Group, Inc. (Washington, DC)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Apartments.com you gave up your right to sue, your right to join a class action, and your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Rental search is a materially higher-stakes version of the Zillow finding because rental applications collect what home searches do not: Social Security number, income verification, employment history, prior addresses, references, and consent to a background and credit check - handed to a listing platform and often to individual landlords with no security capability whatsoever. Application fees also mean renters pay to surrender that dossier, repeatedly, to multiple properties. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Payroll, RealEstate & Finance", "_row_id": 347, "_entity_id": 528, "_entity_slug": "apartments-com", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Rocket Mortgage", "Category": "Mortgage Lending", "Terms & Conditions URL": "rocketmortgage.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "rocketmortgage.com/legal/privacy-security", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ACTIVE CLASS ACTION (Fedoroff v. Rocket Mortgage, filed Jan 2026, California federal court): alleges Rocket Mortgage installed SURREPTITIOUS TRACKERS on its website that unlawfully disclosed mortgage APPLICANTS' SENSITIVE FINANCIAL DATA to third parties — potentially affecting hundreds of thousands of consumers, alleging violations of the federal Electronic Communications Privacy Act. This is structurally similar to an earlier, related complaint against competitor United Wholesale Mortgage over sensitive data allegedly shared with Google and Meta — though that specific competitor case was recently DISMISSED, which may signal a headwind for the Rocket Mortgage case's ultimate success, or simply reflect case-specific factual differences; worth monitoring for how this distinguishes itself from the dismissed precedent.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Rocket Companies ToS. 30-day opt-out. Rocket Mortgage (fka Quicken Loans) is the largest retail mortgage lender in the US. The arbitration clause covers disputes over the mortgage application process, rate-lock commitments, and the extensive financial data collected during underwriting.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "MORTGAGE APPLICATIONS involve an unusually comprehensive slice of a person's financial life (income, assets, debts, SSN, employment) all in one place — making any tracking-pixel-style data leak in this specific industry potentially more consequential than similar tracking on a typical retail site.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Rocket Companies, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] A 2026 suit alleges hidden trackers leaked mortgage applicants' financial data to third parties\nWHAT THE TERMS SAY: Fedoroff v. Rocket Mortgage (filed Jan 2026) alleges Rocket Mortgage installed surreptitious trackers on its website that unlawfully disclosed mortgage applicants' sensitive financial data to third parties, potentially affecting hundreds of thousands of consumers, in violation of the federal Electronic Communications Privacy Act.\nWHY IT MATTERS: A mortgage application is an unusually comprehensive financial dossier (income, assets, debts, SSN, employment), so any tracking-based leak here is potentially more consequential than on a typical retail site; a similar case against a competitor was recently dismissed, which may signal a headwind.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Rocket Mortgage requires binding arbitration with a class-action waiver and a 30-day opt-out\nWHAT THE TERMS SAY: Rocket Companies' ToS mandate binding arbitration with a class action waiver and a 30-day opt-out, covering disputes over the mortgage application process, rate-lock commitments, and the financial data collected during underwriting.\nWHY IT MATTERS: Applicants who miss the opt-out window are barred from suing or joining a class action over how their underwriting data was handled.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The 'trigger lead' data-sale pattern mentioned in the SCARY field is attributed to credit bureaus generally, not Rocket Mortgage specifically, so it isn't counted as a distinct company finding; only the Fedoroff litigation and the arbitration clause are substantive and company-specific.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated, but the Fedoroff litigation is newly filed and its outcome uncertain given a similar competitor case was recently dismissed.", "Exposure Score (0-100)": 31, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Rocket Mortgage  <-  Rocket Companies, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Rocket Mortgage you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Fedoroff v. Rocket Mortgage, filed January 2026 - and the category matters because a mortgage application is the single most complete financial dossier most people ever assemble: tax returns, bank statements, employment verification, debts, assets and a full credit file, handed over in one package. Mortgage lead generation is also an unusually aggressive market, which is why applicants report a flood of solicitations immediately after a credit inquiry - trigger leads are sold by the bureaus themselves. Allegations, not findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Payroll, RealEstate & Finance", "_row_id": 348, "_entity_id": 530, "_entity_slug": "rocket-mortgage", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "LendingTree", "Category": "Loan Marketplace", "Terms & Conditions URL": "lendingtree.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "lendingtree.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MULTIPLE CONFIRMED BREACHES ACROSS SEVERAL YEARS: (1) A February 2022 breach exploited a 'code vulnerability' in LendingTree's own systems, exposing names, Social Security numbers, birthdates, and addresses of at least 200,000+ consumers — LendingTree waited MORE THAN FOUR MONTHS to disclose it to affected consumers and, per the lawsuit, understated the breach's true scope when it finally did. LendingTree settled the resulting class action for $875,000 (2024), offering either 3 years of Equifax credit monitoring plus expense reimbursement, or a cash payment. One named plaintiff reported experiencing FOUR SEPARATE INSTANCES of identity theft after the breach. (2) SEPARATELY, LendingTree disclosed it had ALSO been hit by TWO ADDITIONAL breaches within roughly the same year (November and a later one), even as it publicly denied being the source of a different, larger 200,000+ record leak posted by a threat actor — illustrating a genuinely confusing, multi-incident timeline where the company disputed which specific breach was responsible for which leaked dataset. (3) SEPARATELY, LendingTree's subsidiary QUOTEWIZARD was also affected by the broader 2024 SNOWFLAKE-linked breach wave that hit numerous companies using Snowflake's cloud data platform.", "Arbitration / Class Action Waiver": "A 2009-era LendingTree data-breach lawsuit was specifically ORDERED TO INDIVIDUAL ARBITRATION by the court (In re LendingTree Customer Data Security Breach Litigation) — confirming LendingTree's arbitration clause has been successfully enforced against customer claims in the past, unlike the Live Nation/Ticketmaster case elsewhere in this tracker where a similar clause failed.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "LendingTree's MULTI-YEAR, MULTI-INCIDENT breach history (2022 breach, two more breaches the same year, plus a separate 2024 Snowflake-linked breach via its QuoteWizard subsidiary) makes it one of the more persistently breached companies found in this entire tracker — worth flagging the sheer FREQUENCY of incidents as its own concern, distinct from the severity of any single breach.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] A 2022 breach exposed 200K+ SSNs, disclosed 4 months late; suit says LendingTree understated its scope\nWHAT THE TERMS SAY: A February 2022 breach exploited a code vulnerability, exposing names, SSNs, birthdates, and addresses of at least 200,000+ consumers; LendingTree waited more than four months to disclose it and, per the lawsuit, understated the breach's true scope, settling the resulting class action for $875,000 in 2024. LendingTree also disclosed two additional breaches within the same year, and subsidiary QuoteWizard was separately affected by the 2024 Snowflake-linked breach wave.\nWHY IT MATTERS: One named plaintiff reported four separate instances of identity theft after the breach, and the repeated, multi-year pattern of incidents is itself a distinct concern beyond any single breach's severity.\n(evidence: Data Sharing | Notes | SCARY; Stated in tracker (fidelity pass 1: Hedge lost corrected))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] LendingTree's lead-generation model shares a consumer's financial profile with lenders they never named\nWHAT THE TERMS SAY: LendingTree's business model collects a consumer's financial profile and distributes it to multiple competing lenders, meaning a single form submission propagates to companies the consumer never named and cannot enumerate afterward.\nWHY IT MATTERS: The tracker frames this as structurally opposite of data minimization — dispersal of financial data to third parties is the product itself.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] A court has previously ordered LendingTree customer claims into individual, not class, arbitration\nWHAT THE TERMS SAY: A 2009-era LendingTree data-breach lawsuit (In re LendingTree Customer Data Security Breach Litigation) was specifically ordered to individual arbitration by the court, confirming the arbitration clause has been successfully enforced against customer claims.\nWHY IT MATTERS: Unlike the Live Nation/Ticketmaster case elsewhere in the tracker where a similar clause failed, LendingTree's arbitration clause has a track record of being enforced, limiting customers to individual claims.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The 2022 breach, its settlement terms, the additional 2024 breaches, and the historical arbitration ruling are all specifically documented with dates and figures.", "Exposure Score (0-100)": 44, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "LendingTree  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using LendingTree you gave up your personal data sold onward, your data shared corporate-wide, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T20:04:38Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Multiple confirmed breaches across several years, and the repetition is the finding rather than any single incident. LendingTree's entire business model is collecting a consumer's financial profile and distributing it to multiple lenders who then compete - which means the data is designed to be shared widely, and a single form submission propagates to companies the consumer never named and cannot enumerate afterward. Comparison-shopping platforms of this kind are structurally the opposite of data minimisation: dispersal is the product.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Payroll, RealEstate & Finance", "_row_id": 349, "_entity_id": 531, "_entity_slug": "lendingtree", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Navient", "Category": "Student Loan Servicer", "Terms & Conditions URL": "navient.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "navient.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED JUNE 2026 THIRD-PARTY VENDOR BREACH: Navient disclosed (SEC Form 8-K, July 2, 2026) that a LAW FIRM providing services to Navient was hit by a ransomware attack (June 8, 2026), compromising borrower names, birthdates, addresses, and SOCIAL SECURITY NUMBERS — Navient's own systems were NOT compromised, consistent with the vendor-breach pattern documented throughout this tracker (here, notably, the vulnerable third party was a LAW FIRM rather than a typical IT/software vendor).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Navient ToS. 30-day opt-out. Navient settled with 39 state AGs for $1.85B in student loan relief (2022) — the largest nongovernmental student loan settlement in history. The arbitration clause covers remaining disputes over loan servicing practices.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "SEPARATE, LONGER-RUNNING CONTEXT: Senator Elizabeth Warren has repeatedly (2024) urged Navient to reform its process for canceling PRIVATE student loans held by borrowers who attended FRAUDULENT, for-profit colleges — a distinct consumer-protection concern from the 2026 breach, relevant to any borrower who attended a since-discredited for-profit institution.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Navient Corporation", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-4] Navient's $1.85B settlement was the largest-ever nongovernmental student loan settlement\nWHAT THE TERMS SAY: Navient settled with 39 state AGs for $1.85B in student loan relief in 2022, the largest nongovernmental student loan settlement in history, over its loan servicing practices.\nWHY IT MATTERS: Student loan servicing is described in the tracker as the clearest case of a consumer relationship with no exit at all — a borrower cannot change servicers, decline the relationship, or take the debt elsewhere, removing the market mechanisms privacy and consumer protection normally assume exist.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] A law firm vendor breach exposed Navient borrowers' SSNs, birthdates, and addresses in June 2026\nWHAT THE TERMS SAY: Navient disclosed via SEC Form 8-K (July 2, 2026) that a law firm providing services to Navient was hit by a ransomware attack on June 8, 2026, compromising borrower names, birthdates, addresses, and Social Security numbers; Navient's own systems were not compromised.\nWHY IT MATTERS: The breach reached borrowers through a third-party vendor, consistent with a vendor-breach pattern seen elsewhere in the tracker, and was disclosed via securities law on a faster timeline than typical consumer-notification law would require.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Navient requires binding arbitration with a class-action waiver and a 30-day opt-out\nWHAT THE TERMS SAY: Navient's ToS mandate binding arbitration with a class action waiver and a 30-day opt-out, covering remaining disputes over loan servicing practices.\nWHY IT MATTERS: Borrowers who miss the opt-out window are barred from suing or joining a class action over Navient's servicing or data-handling practices.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The June 2026 vendor breach, its SEC disclosure date, and the 2022 multistate settlement figure are all specifically documented.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity3+8, breach+3, penalty+3) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Navient  <-  Navient Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Navient you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The June 2026 vendor breach was disclosed through an SEC filing, which is again how many of these surface - securities law compels disclosure on a timeline consumer notification law does not. Navient's longer record is the context: it has been the subject of extensive regulatory action and multistate settlements over student loan servicing practices, and a borrower cannot change servicers, cannot decline the relationship, and cannot take the debt elsewhere. Student loan servicing is the clearest case in this tracker of a consumer relationship with no exit at all, which removes every market mechanism that privacy policy assumes exists.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Payroll, RealEstate & Finance", "_row_id": 350, "_entity_id": 533, "_entity_slug": "navient", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "MOHELA", "Category": "Student Loan Servicer", "Terms & Conditions URL": "mohela.com/DL/help/termsOfUse.aspx (specific URL not independently confirmed this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "mohela.com/DL/help/privacyPolicy.aspx (specific URL not independently confirmed this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "PERHAPS THE SINGLE MOST STRIKING TERMS-OF-SERVICE FINDING IN THIS ENTIRE TRACKER: as millions of borrowers prepared to resume payments after the COVID-19 pause, MOHELA quietly UPDATED ITS WEBSITE TERMS OF SERVICE to prohibit borrowers from SHARING SCREENSHOTS of their own account information, publicizing basic loan-repayment information MOHELA itself provided to them, or sharing account information with ANYONE — which advocates warn could be read to include GOVERNMENT REGULATORS and consumer protection officials. The Student Borrower Protection Center and AFT formally warned the CFPB, FDIC, and OCC that this could violate borrowers' federal right to obtain financial services free from deception and abuse. AFT President Randi Weingarten called it 'corporate misbehavior at its worst.'", "Arbitration / Class Action Waiver": "Terms of Use contain a SCREENSHOT-SHARING BAN: 'you may not take screenshots of any content displayed within the Site or Apps.' The Student Borrower Protection Center and AFT jointly referred MOHELA to the CFPB/FDIC/OCC (Oct 2024) specifically over this clause, arguing it prevents borrowers from documenting evidence of servicing errors. Whether MOHELA's terms also contain a mandatory arbitration clause was NOT confirmed from the text retrieved this pass.", "Fees / Billing Flags": "MAJOR ONGOING LITIGATION: the American Federation of Teachers (AFT) sued MOHELA (July 2024), alleging it FAILED 6.5 MILLION BORROWERS through incorrect/misleading information, MISCALCULATED payments, and 'call deflection' tactics that make it difficult to resolve problems — an amended complaint (Jan 2026) cites new federal government data showing MOHELA has, BY FAR, the WORST customer service of the five major federal student loan servicers. MOHELA has separately been criticized for MISHANDLING the Public Service Loan Forgiveness program specifically, per a Senate hearing led by Sen. Elizabeth Warren.", "Notes": "The screenshot/disclosure prohibition is worth flagging as a genuinely distinct category of harm from the data-privacy findings that dominate most of this tracker — this is a company using its OWN Terms of Service to try to prevent customers from documenting or reporting the company's OWN alleged misconduct, which is a more direct attack on consumer accountability mechanisms than a typical privacy or arbitration clause.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Chesterfield", "HQ State": "Missouri", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://protectborrowers.org/mohela-was-caught-lying-to-student-loan-borrowers-and-now-it-is-quietly-forcing-them-to-waive-their-rights/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Missouri' is a non-DMV US state", "Parent / Ultimate Owner": "Missouri Higher Education Loan Authority (state-created entity)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Missouri SOS Business Search — bsd.sos.mo.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Missouri Higher Education Loan Authority (state-created entity)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] MOHELA's terms now ban borrowers from screenshotting or sharing their own account information, possibly even with regulators.\nWHAT THE TERMS SAY: MOHELA's Terms of Use state \"you may not take screenshots of any content displayed within the Site or Apps,\" and more broadly prohibit borrowers from publicizing loan-repayment information MOHELA itself gave them or sharing account information with anyone, updated quietly as millions resumed payments after the COVID-19 pause.\nWHY IT MATTERS: Advocates (Student Borrower Protection Center, AFT) warn the language could be read to cover sharing with government regulators and consumer-protection officials, preventing borrowers from documenting evidence of servicing errors; SBPC and AFT formally referred the practice to the CFPB, FDIC, and OCC in October 2024.\n(evidence: Arbitration | Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] AFT's lawsuit alleges MOHELA failed 6.5 million borrowers with miscalculated payments and 'call deflection'; a 2026 complaint ranks it worst of the five major servicers.\nWHAT THE TERMS SAY: AFT sued MOHELA in July 2024, alleging it failed 6.5 million borrowers through incorrect/misleading information, miscalculated payments, and 'call deflection' tactics that make problems hard to resolve; a January 2026 amended complaint cites federal data showing MOHELA has, by far, the worst customer service of the five major federal student loan servicers. MOHELA has also been criticized for mishandling the PSLF program per a Senate hearing led by Sen. Elizabeth Warren.\nWHY IT MATTERS: Borrowers dealing with servicing errors face a company independently ranked worst-in-class for customer service among federal servicers, compounding the difficulty of resolving payment miscalculations.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Whether MOHELA's terms include a mandatory arbitration clause was not confirmed from the text retrieved this pass, so no arbitration-specific item is included; two distinct, tracker-stated findings remain.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The screenshot-ban clause is directly quoted, but whether MOHELA's terms also include mandatory arbitration was not confirmed this pass.", "Exposure Score (0-100)": 21, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 5/20 (unilateral_modification+5) | Record 16/20 (severity4+14, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "MOHELA  <-  Missouri Higher Education Loan Authority (state-created entity)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using MOHELA you gave up your right to be consulted before terms change. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T20:04:42Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "As millions of borrowers prepared to resume payments after the COVID-19 pause, MOHELA quietly updated its website terms to prohibit borrowers from sharing screenshots of their OWN account information, publicising basic loan-repayment information MOHELA itself had given them, or sharing account information with anyone - language advocates warned could be read to cover government regulators and consumer protection officials. The Student Borrower Protection Center and AFT formally warned the CFPB, FDIC and OCC that this may violate borrowers' federal right to obtain financial services free from deception and abuse; AFT's president called it corporate misbehaviour at its worst. This is a categorically different harm from the privacy findings that dominate this tracker: a company using its own terms of service to stop customers from documenting or reporting the company's alleged misconduct. AFT's suit alleges MOHELA failed 6.5 million borrowers, and a January 2026 amended complaint cites federal data placing its customer service worst by a wide margin among the five major federal servicers.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Payroll, RealEstate & Finance", "_row_id": 351, "_entity_id": 535, "_entity_slug": "mohela", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Trulia", "Category": "Real Estate", "Terms & Conditions URL": "https://www.zillow.com/z/corp/terms/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://www.zillowgroup.com/zg-privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Governed by Zillow Group-level privacy notice, not a Trulia-specific one. Footer 'Do Not Sell or Share My Personal Information' resolves to privacy.zillowgroup.com. Not itemized further this pass.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver — governed by Zillow Group's Terms of Use (byte-identical URL: zillow.com/z/corp/terms/, confirmed via direct fetch of trulia.com footer 2026-08-06). A consumer who avoids Zillow and uses Trulia is signing Zillow's contract.", "Fees / Billing Flags": "Not itemized this pass. Separate 'Subscription Terms' at zillow.com/corp/SATerms.htm.", "Notes": "Trulia is a registered trademark of Zillow, Inc. (footer, retrieved 2026-08-06). Site is operated under Zillow Group. Cross-reference the Zillow row — the T&C URL is IDENTICAL. Sibling brands per same footer: StreetEasy, HotPads, Out East.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Seattle", "HQ State": "Washington", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.trulia.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "AI-assisted Aug 2026 — legal URLs retrieved directly from site footer 2026-08-06; review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Zillow Group, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Zillow Group, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Trulia has no privacy notice of its own — its 'Do Not Sell' link and privacy rights route to a Zillow Group-level notice.\nWHAT THE TERMS SAY: Trulia's footer 'Do Not Sell or Share My Personal Information' link resolves to privacy.zillowgroup.com rather than a Trulia-specific notice; Trulia is a registered trademark of Zillow, Inc., operated under Zillow Group alongside StreetEasy, HotPads, and Out East.\nWHY IT MATTERS: A consumer who deliberately avoids Zillow and uses Trulia instead, believing it a separate service, is sitting inside Zillow Group's shared data estate rather than a distinct one.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Trulia users are bound by Zillow's mandatory arbitration and class-action waiver, confirmed via the byte-identical Terms of Use URL.\nWHAT THE TERMS SAY: Mandatory binding arbitration with a class action waiver, governed by Zillow Group's Terms of Use at the identical URL zillow.com/z/corp/terms/, confirmed via direct fetch of Trulia's footer on 2026-08-06.\nWHY IT MATTERS: A consumer who avoids Zillow and uses Trulia is, in practice, signing Zillow's contract, including its arbitration terms.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees/billing terms were not itemized this pass; only two distinct findings (the shared Zillow Group privacy/terms structure and the arbitration clause) are substantiated for this low-severity structural row.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Terms and privacy resolve to Zillow Group documents rather than Trulia-specific ones, and fees were not itemized this pass.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Trulia  <-  Zillow Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Trulia you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T20:04:44Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Trulia publishes no terms of its own. Its footer 'Terms of Use' link resolves to zillow.com/z/corp/terms/ — the identical document governing Zillow — and its privacy link resolves to a Zillow GROUP-level notice rather than anything Trulia-specific. A consumer who deliberately avoids Zillow and uses Trulia instead, believing it a separate service, is agreeing to Zillow's contract and sitting inside Zillow Group's data estate. The same footer lists StreetEasy, HotPads and Out East as sibling brands, so the apparent choice among several listing sites is substantially one company.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Payroll, RealEstate & Finance", "_row_id": 352, "_entity_id": 536, "_entity_slug": "trulia", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Homes.com", "Category": "Real Estate", "Terms & Conditions URL": "https://www.homes.com/about/homesterms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "https://www.homes.com/about/policies/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Privacy rights requests route to privacy.costar.com (CoStar Group DSAR portal); cookie policy hosted at costar.com. Indicates group-level data handling. Not itemized further this pass.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver — governed by CoStar Group's terms (confirmed from this session's direct footer fetch of homes.com). Privacy requests route to privacy.costar.com. CoStar HQ: Washington DC (DMV). Same terms as Apartments.com and 6 other sibling marketplaces.", "Fees / Billing Flags": "Not itemized this pass. Separate paid products: Membership, Listing Boost, New Home Community Boost. Separate 'Builder Terms of Use' at homes.com/about/builder-terms-of-use/.", "Notes": "Operated by CoStar Group (footer copyright, retrieved 2026-08-06). Cross-reference the EXISTING Apartments.com row — same parent. Sibling marketplaces per same footer: Apartments.com, ApartmentFinder, ApartmentHomeLiving, ForRent, LoopNet, Land.com, BizBuySell, Domain.com.au.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Washington", "HQ State": "District of Columbia", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.homes.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "AI-assisted Aug 2026 — legal URLs retrieved directly from site footer 2026-08-06; review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'District of Columbia' is DC/MD/VA", "Parent / Ultimate Owner": "CoStar Group, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): DC DLCP CorpOnline — corponline.dcra.dc.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: CoStar Group, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Homes.com's own footer lists eight sibling marketplaces — comparison shopping across them means supplying the same CoStar Group parent repeatedly.\nWHAT THE TERMS SAY: Homes.com is a CoStar Group property; privacy-rights requests and the cookie policy both leave the Homes.com domain and resolve to privacy.costar.com, and the footer lists eight sibling marketplaces (Apartments.com, ApartmentFinder, ApartmentHomeLiving, ForRent, LoopNet, Land.com, BizBuySell, Domain.com.au).\nWHY IT MATTERS: A renter who checks Homes.com, then Apartments.com, then ForRent believes they are comparison-shopping across independent sites; the data is handled at one corporate group level instead.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Homes.com binds users to CoStar's arbitration and class-action waiver, as do Apartments.com and 6 siblings.\nWHAT THE TERMS SAY: Mandatory binding arbitration with a class action waiver, governed by CoStar Group's terms, confirmed via direct footer fetch of homes.com; the same terms apply to Apartments.com and six other sibling marketplaces.\nWHY IT MATTERS: A Homes.com user is bound by the same arbitration clause as users of Apartments.com and six other sibling marketplaces, regardless of which brand they believe they are dealing with.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees/billing terms were not itemized this pass beyond naming separate paid products; only two distinct findings (the shared-parent data/site structure and the arbitration clause) are substantiated for this low-severity structural row.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are confirmed via direct fetch, but fees and other categories were not itemized this pass, and privacy requests route off-domain to CoStar.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Homes.com  <-  CoStar Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Homes.com you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Homes.com is a CoStar Group property, and its own footer lists eight sibling marketplaces — Apartments.com, ApartmentFinder, ApartmentHomeLiving, ForRent, LoopNet, Land.com, BizBuySell and Domain.com.au. A renter who checks Homes.com, then Apartments.com, then ForRent, then ApartmentFinder believes they are comparison-shopping across four independent sites; they are supplying the same corporate parent four times. Privacy-rights requests and the cookie policy both leave the Homes.com domain entirely and resolve to CoStar, confirming the data is handled at group level. CoStar is headquartered in Washington, D.C.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Payroll, RealEstate & Finance", "_row_id": 353, "_entity_id": 537, "_entity_slug": "homes-com", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Realtor.com (Move, Inc.)", "Category": "Real Estate", "Terms & Conditions URL": null, "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": null, "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "NOT VERIFIED THIS PASS — do not cite.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "Row created 2026-08-06 to close a coverage gap: realtor.com is a top-3 US listing portal and was absent from the tracker. Operated by Move, Inc. (News Corp) under perpetual trademark licence from the National Association of REALTORS. Legal pages were NOT located this pass — three searches failed to surface them and no URL was guessed. NEXT ACTION: open realtor.com, read the footer, record the actual Terms and Privacy URLs.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-06", "Provenance (who determined this)": "AI-assisted Aug 2026 — SHELL ROW, legal URLs NOT located. Ownership only. Not reviewed.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is an explicit placeholder created to close a coverage gap: Data Sharing, Arbitration, and Fees are all marked 'NOT VERIFIED THIS PASS — do not cite,' and the Notes state legal pages were not located this pass. Nothing here is citable until the Terms of Use and Privacy Notice have actually been read.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No Terms of Use or Privacy Notice was located this pass; every substantive field is explicitly marked not verified.", "Exposure Score (0-100)": 0, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Realtor.com (Move, Inc.)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Realtor.com (Move, Inc.) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "PENDING VERIFICATION — no finding recorded. This row is a deliberate placeholder marking a known coverage gap, not a finding. Nothing here is citable until the Terms of Use and Privacy Notice have been located and read.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Payroll, RealEstate & Finance", "_row_id": 354, "_entity_id": 538, "_entity_slug": "realtor-com-move-inc", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Navy Federal Credit Union", "Category": "Credit Union (federal charter)", "Terms & Conditions URL": "https://www.navyfederal.org/about/terms-conditions.html", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.navyfederal.org/about/privacy-security.html", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "Navy Federal is the world's largest credit union (13M+ members, $165B+ assets). Membership limited to military, DoD civilians, and their families. Data practices governed by the Gramm-Leach-Bliley Act + NCUA regulations. As a federal credit union, Navy Federal is regulated by the NCUA, not the OCC or state banking departments.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Navy Federal's Account Agreement. 60-day opt-out via written notice. Navy Federal is one of only 5 companies in this tracker with a 60-day opt-out window (alongside Aetna, Chime, Robinhood, and Synchrony). For a military member deployed overseas, the 60-day window may still be inadequate — mail delivery to deployed service members can exceed 60 days.", "Fees / Billing Flags": "No monthly maintenance fees on most accounts. Share certificates and loan products carry standard credit-union fee structures.", "Notes": "World's largest credit union by assets and membership. HQ: Vienna, Virginia (DMV). Serves exclusively military, DoD, and their families. The 60-day arbitration opt-out is better than the 30-day standard but may be functionally inadequate for deployed service members.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Vienna", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Added 2026-08-06 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 60, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Vienna, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "Navy Federal Credit Union (federal charter, member-owned)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Federally chartered credit union — no state registered agent; NCUA-supervised", "Registered Agent Address / Service Notes": "Navy Federal Credit Union, 820 Follin Lane SE, Vienna, VA 22180. As a FEDERALLY CHARTERED credit union, Navy Federal is not registered with a state corporation commission and does not have a state-appointed registered agent in the way a state-chartered corporation does. Regulatory correspondence and complaints route through the National Credit Union Administration (NCUA) Consumer Assistance Center, not through a state banking department or the OCC. This is a materially different escalation path from every bank in this tracker.", "Company Brief": "Navy Federal Credit Union is the world's largest credit union by both assets and membership, headquartered in Vienna, Virginia. Membership is restricted to armed-forces members, veterans, Department of Defense civilian personnel, and their families. It is member-owned and not-for-profit, and is the largest originator of VA home loans in the country.", "Investor Overview": "Not publicly traded — member-owned cooperative under federal charter. ~13 million members, ~$165B+ in assets. INVESTOR/ANALYST-RELEVANT: as a credit union, Navy Federal returns surplus to members through rates and fee structures rather than to shareholders, and is exempt from federal income tax on that basis. Its regulator is the NCUA; deposits are insured by the NCUSIF rather than the FDIC. Concentration risk is unusual and structural: its entire membership is tied to military and DoD employment.", "Major Issues Record": "Structural, not incident-based: Navy Federal's 60-day arbitration opt-out is among the longest documented in this tracker — but its member population is uniquely likely to be unable to use it. A service member who receives deployment orders shortly after opening an account may have no reliable mail access for longer than the opt-out window, and the opt-out requires written notice. Navy Federal has also been the subject of public reporting and regulatory attention regarding mortgage-lending approval-rate disparities; that reporting was NOT independently verified this pass and should be confirmed before being cited.", "T&C Key Provisions (paraphrased)": "PARAPHRASED, not quoted. Navy Federal's account agreements provide for binding arbitration with a class-action waiver and a 60-day window to opt out by written notice. Because the institution is federally chartered, disputes that are not arbitrated fall under federal credit union law and NCUA supervision rather than state banking regulation. CONSUMER ACTION: for deploying service members, exercise the arbitration opt-out AT ACCOUNT OPENING rather than later — the 60-day clock does not pause for deployment.", "Re-verify By": "2027-02-13", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Navy Federal's mandatory arbitration clause gives deployed service members only 60 days to opt out by mail — a window deployment can outlast.\nWHAT THE TERMS SAY: Navy Federal's Account Agreement mandates binding arbitration with a class-action waiver and a 60-day opt-out via written notice — one of only five companies in this tracker (alongside Aetna, Chime, Robinhood, and Synchrony) with more than a 30-day window.\nWHY IT MATTERS: For a member who receives deployment orders shortly after opening an account, mail delivery to deployed service members can exceed 60 days, meaning the opt-out window may lapse before it can be used, across accounts covering checking, mortgage, and auto loans.\n(evidence: Arbitration | Key Provisions; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DISCRIMINATORY_PRACTICE · FL-1] Reported mortgage-lending approval-rate disparities at Navy Federal are flagged in the tracker as needing confirmation before being cited.\nWHAT THE TERMS SAY: The tracker notes Navy Federal 'has also been the subject of public reporting and regulatory attention regarding mortgage-lending approval-rate disparities,' but states this reporting was not independently verified this pass and should be confirmed before being cited.\nWHY IT MATTERS: If substantiated, this would matter given Navy Federal's position as the largest VA-loan lender to veterans, but the tracker itself treats this as unconfirmed rather than a finding.\n(evidence: Major Issues Record; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees/Billing states no monthly maintenance fees on most accounts with no notable dispute pattern, leaving only two distinct substantive findings.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated and sourced from the Account Agreement, but the mortgage-lending disparity reporting is explicitly flagged as not independently verified.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 22, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 22/30 (forced_arbitration+12, class_action_waiver+9, optout_60d+1) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Navy Federal Credit Union  <-  Navy Federal Credit Union (federal charter, member-owned)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your right to stop paying by inaction.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Navy Federal Credit Union you gave up your right to sue and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Navy Federal Credit Union is the world's largest credit union — 13 million members, $165+ billion in assets — headquartered in Vienna, Virginia, serving exclusively military members, DoD civilians, and their families. Its mandatory arbitration clause includes a 60-day opt-out window, making it one of only five companies in this entire tracker offering more than 30 days. But for the population it serves, even 60 days may be structurally inadequate: a service member who receives deployment orders the week after opening an account may not have reliable mail access for months. The arbitration clause covers disputes over everything from checking accounts to auto loans to mortgage servicing — and Navy Federal is the single largest mortgage lender to veterans, processing more VA loans than any bank in the country. A DMV-based military family's entire financial life — checking, savings, mortgage, auto loan, credit card — can be governed by one arbitration clause from one institution. Navy Federal's NCUA regulation (not OCC or state banking) means it operates under a different supervisory framework than every bank in this tracker.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Payroll, RealEstate & Finance", "_row_id": 355, "_entity_id": 95, "_entity_slug": "navy-federal-credit-union", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Plaid", "Category": "Financial Data Aggregation", "Terms & Conditions URL": "https://plaid.com/legal/end-user-services-agreement/", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://plaid.com/legal/end-user-privacy-policy/", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "Plaid connects consumer bank accounts to fintech apps — Venmo, Cash App, Robinhood, Chime, Coinbase, and 8,000+ other apps use Plaid to verify accounts and pull transaction data. When you link your bank account to ANY of these apps, Plaid sees your complete transaction history: every deposit, every purchase, every transfer, every payee name, every recurring bill. Plaid settled a $58M class action (2022) for collecting more financial data than necessary and storing bank login credentials. A consumer who has linked their bank to 5 different apps through Plaid has given Plaid 5 separate windows into the same transaction history.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Plaid End User Services Agreement, AAA rules, California law. 30-day opt-out. The $58M class settlement (2022) was a CLASS action that survived the arbitration clause because it was filed BEFORE Plaid added the clause — new users are bound by it. Plaid's arbitration clause covers disputes over the scope of financial data collected, which is the exact issue the class action addressed.", "Fees / Billing Flags": "Plaid is free for consumers — the app developer pays Plaid per API call. Consumers are the DATA SOURCE, not the customer.", "Notes": "Plaid is the invisible infrastructure behind most US fintech. The $58M settlement revealed Plaid stored bank login credentials (screen-scraping) even after transitioning to API-based connections. Plaid's 'Plaid Portal' (launched 2021) lets consumers see which apps have accessed their data — but does not let them delete the historical data Plaid already collected.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Added 2026-08-06 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.lieffcabraser.com/2022/07/final-approval-granted-to-58-million-settlement-in-plaid-consumer-privacy-lawsuit/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Plaid Inc. (Visa's $5.3B acquisition blocked by DOJ antitrust, Jan 2021)", "Years Referenced in Finding (heuristic)": "2021, 2022", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Plaid Inc. (Visa's $5.3B acquisition blocked by DOJ antitrust, Jan 2021)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] A $58M settlement confirmed Plaid stored consumers' bank login credentials and collected more financial data than the apps it served requested.\nWHAT THE TERMS SAY: Plaid settled a $58M class action (2022) over collecting more financial data than necessary and storing bank login credentials via screen-scraping even after transitioning to API-based connections; Plaid's 'Plaid Portal' (2021) lets consumers see which apps accessed their data but does not let them delete the historical data already collected.\nWHY IT MATTERS: Consumers who linked accounts to multiple apps through Plaid had bank credentials retained by an intermediary most never directly signed up for, and cannot delete what was already collected even now.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Plaid's arbitration clause, added after the $58M class action was filed, now covers the exact same data-collection-scope issue for new users.\nWHAT THE TERMS SAY: Plaid's End User Services Agreement mandates binding arbitration under AAA rules and California law with a class-action waiver and a 30-day opt-out; the clause was added after the $58M class action was filed, so new users are bound by it even though it covers disputes over the scope of financial data collected — the exact issue the settled class action addressed.\nWHY IT MATTERS: Future users harmed by the same practice that produced the $58M settlement cannot replicate that class outcome; they are individually bound to arbitrate instead.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SALE · FL-2] Plaid is free for consumers because app developers pay per API call for access to consumer transaction data — consumers are the data source, not the customer.\nWHAT THE TERMS SAY: Plaid is free for consumers; the app developer pays Plaid per API call, and per the tracker, 'Consumers are the DATA SOURCE, not the customer.'\nWHY IT MATTERS: The commercial relationship runs between Plaid and the app developers who pay for data access, not between Plaid and the consumers whose transaction history is the product.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=Y; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Arbitration clause terms, opt-out window, and data practices are all specifically documented with dates, dollar figures, and clause language rather than hedged.", "Exposure Score (0-100)": 49, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 11, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 11/30 (data_sold_or_shared_for_value+8, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Plaid  <-  Plaid Inc. (Visa's $5.3B acquisition blocked by DOJ antitrust, Jan 2021)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Plaid you gave up your personal data sold onward, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T20:04:52Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Plaid is the most important company in this tracker that most consumers have never heard of. When you link your bank account to Venmo, Cash App, Robinhood, Chime, Coinbase, or any of 8,000+ other fintech apps, Plaid is the invisible intermediary that connects them — and it sees your COMPLETE transaction history: every deposit, purchase, transfer, payee, recurring bill, and balance. A consumer who has linked their bank to 5 different apps through Plaid has given Plaid 5 separate access windows into the same financial life. The $58M class action settlement (2022) revealed that Plaid was collecting MORE financial data than the connecting apps requested and was storing bank login credentials even after transitioning to API-based connections. Plaid's mandatory arbitration clause was added AFTER the class action was filed — new users are bound by it, but the class-action plaintiffs were not. The arbitration clause now covers the exact issue the class action addressed: the scope of financial data collection. A DMV consumer who uses Venmo for social payments, Robinhood for investing, Chime for banking, and Coinbase for crypto has unknowingly given Plaid a comprehensive financial profile across all four activities — under a 30-day opt-out arbitration clause most of them have never seen because they never directly signed up for Plaid.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Payroll, RealEstate & Finance", "_row_id": 356, "_entity_id": 540, "_entity_slug": "plaid", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CVS Caremark", "Category": "Pharmacy Benefit Manager", "Terms & Conditions URL": "caremark.com/wps/wcm/connect/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "caremark.com/wps/wcm/connect/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MAJOR FTC ANTITRUST ACTION (Sept 2024–ongoing): the FTC sued the THREE LARGEST pharmacy benefit managers — Caremark (CVS), Express Scripts (Cigna), and OptumRx (UnitedHealth), which together handle roughly 80% of ALL US PRESCRIPTIONS (top 6 PBMs combined handle ~95%) — alleging they engaged in ANTICOMPETITIVE AND UNFAIR REBATING PRACTICES that ARTIFICIALLY INFLATED INSULIN PRICES, by preferring higher-list-price insulin products specifically because they generate bigger manufacturer REBATES for the PBM, even when cheaper insulin options exist. CVS Caremark and the FTC jointly moved (March 2026) to withdraw from adjudication to pursue a settlement, following the template set by Express Scripts' earlier settlement (see that row) — specific final terms for Caremark's settlement were still being finalized as of this research, though the FTC reported 'significant progress' in these negotiations.", "Arbitration / Class Action Waiver": "The three PBMs initially COUNTERSUED the FTC challenging the underlying lawsuit's validity; that countersuit was DISMISSED by the 8th Circuit Court of Appeals after all three PBMs elected to settle with the FTC instead of continuing to fight it — illustrating that even a well-resourced industry coalition can find it more strategic to settle than to continue contesting an FTC antitrust action.", "Fees / Billing Flags": "This case is DIRECTLY about drug PRICING/FEES — the entire allegation is that CVS Caremark's rebate structure made insulin more expensive than it needed to be for patients nationwide.", "Notes": "Given CVS Caremark's ~30%+ share of the PBM market, this insulin-pricing case likely affects a substantial share of Mid-Atlantic residents with diabetes who fill prescriptions through a CVS Caremark-administered plan — worth a direct follow-up once Caremark's specific settlement terms are finalized.\n\nFTC PBM INSULIN CASE CROSS-REFERENCE (verified this pass - status updated): FTC administrative action, Docket 9437, In the Matter of Caremark Rx, Zinc Health Services, et al. (Insulin), filed Sept 2024 against the three largest PBMs - Caremark Rx, Express Scripts (ESI) and OptumRx - and their affiliated group purchasing organisations. Allegation: the three artificially inflated insulin LIST prices through a rebate system that made manufacturers compete on the size of the rebate off list rather than on net price, with the PBMs keeping a share - shifting cost onto patients paying against list price. RESOLUTIONS: ESI settled Feb 4 2026 (projected up to $7B in reduced patient out-of-pocket over 10 years, new revenue for community pharmacies). Caremark and the FTC jointly moved to withdraw from adjudication Mar 23 2026 to consider a consent agreement; FTC announced the Caremark settlement in July 2026 - locks in up to $8.5B in consumer savings over 10 years plus up to $4.5B more from point-of-sale rebates, delinks PBM fees from list prices, offers retail community pharmacies cost-plus reimbursement, caps member insulin costs at $25/month, and bars Caremark from interfering with pharmacies' access to hub service providers. The Optum case was withdrawn from adjudication to consider a proposed consent agreement. Related: House Judiciary Committee Interim Staff Report, Jan 21 2026, 'When CVS Writes the Rules.' NOTE: these are ANTITRUST/pricing actions, not data-privacy actions - keep the categories distinct.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Woonsocket", "HQ State": "Rhode Island", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": "https://www.ftc.gov/terms/pharmacy-benefits-managers-pbm", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ: Woonsocket, Rhode Island (non-US)", "Parent / Ultimate Owner": "CVS Health Corporation", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): RI SOS Corporate Database — business.sos.ri.gov/CorpWeb/CorpSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: CVS Health Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] Caremark's July 2026 FTC settlement locks in up to $8.5B in savings over 10 years, plus up to $4.5B more.\nWHAT THE TERMS SAY: The FTC alleged Caremark's rebate structure incentivized preferring higher-list-price insulin because it generated bigger manufacturer rebates for the PBM, even when cheaper options existed; Caremark settled in July 2026, locking in up to $8.5B in consumer savings over 10 years plus up to $4.5B more from point-of-sale rebates, delinking PBM fees from list prices, offering community pharmacies cost-plus reimbursement, and capping member insulin costs at $25/month.\nWHY IT MATTERS: Patients whose costs were calculated against list price — the uninsured, underinsured, or those in a deductible phase — paid the inflated number while the rebate went to the PBM; the settlement's size is the tracker's own measure of what the practice was worth.\n(evidence: Data Sharing | SCARY | Notes; Stated in tracker (fidelity pass 1: Hedge lost corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Every field in this row (Data Sharing, Arbitration, Fees, Notes) describes the same FTC insulin-pricing case and its settlement; the Arbitration field covers only a dismissed procedural countersuit, and no second, distinct consumer harm is stated.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The FTC case timeline, settlement dollar figures, and specific remedy terms are directly and specifically documented with dates.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "CVS Caremark  <-  CVS Health Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, CVS Caremark takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T20:04:53Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The FTC's allegation is that the rebate system was not a discount mechanism at all but a pricing engine running backwards: insulin makers competed for preferred formulary placement based on how large a rebate they offered off the LIST price, which gave everyone in the chain a reason to push list prices UP, with the PBM keeping a cut. Patients whose costs are calculated against list price - the uninsured, the underinsured, anyone in a deductible phase - paid the inflated number while the rebate went elsewhere. Caremark settled with the FTC in July 2026 on terms that lock in up to $8.5 billion in consumer savings over ten years, unlock up to $4.5 billion more through point-of-sale rebates, delink PBM fees from list prices entirely, and cap member insulin costs at $25 a month. That the remedy is worth billions is the measure of what the practice was worth.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Pharmacy Benefit Managers", "_row_id": 357, "_entity_id": 542, "_entity_slug": "cvs-caremark", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Express Scripts (Cigna)", "Category": "Pharmacy Benefit Manager", "Terms & Conditions URL": "express-scripts.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "express-scripts.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SAME FTC INSULIN-PRICING CASE as Caremark/OptumRx (see Caremark row) — Express Scripts was the FIRST of the three PBMs to formally SETTLE (Feb 4, 2026), in what the FTC itself called a 'LANDMARK SETTLEMENT.' Under the settlement, Express Scripts must fundamentally change its business practices: it will STOP listing drugs in its formularies at high wholesale acquisition cost, will instead favor LOWER-COST options on its standard formularies, must DISCLOSE broker kickbacks, and must include the direct-to-consumer 'TrumpRx' platform as part of its standard offerings. The FTC projects these changes will reduce patients' out-of-pocket drug costs (including for insulin) by UP TO $7 BILLION OVER 10 YEARS, while also bringing new annual revenue to community pharmacies that had been financially squeezed by the prior rebate structure.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Express Scripts member ToS, AAA rules. 30-day opt-out. As a PBM, Express Scripts processes prescription claims for 100M+ Americans — the arbitration clause covers disputes over formulary placement, prior authorization denials, and pharmacy-network steering. The FTC's September 2024 PBM lawsuit (settled by Express Scripts Feb 2026, up to $7B projected savings) alleged insulin rebate manipulation.", "Fees / Billing Flags": "This is a DIRECT fee/pricing settlement — the $7 billion in projected savings over 10 years is one of the largest projected consumer-cost-reduction figures found anywhere in this entire tracker.", "Notes": "The $7 billion projected savings figure makes this genuinely one of the highest-impact completed settlements in this whole audit in terms of DIRECT dollar benefit to ordinary consumers (as opposed to a lump-sum settlement fund divided among claimants) — worth flagging prominently given how many people rely on insulin and other chronic medications through PBM-administered plans.\n\nFTC PBM INSULIN CASE CROSS-REFERENCE (verified this pass - status updated): FTC administrative action, Docket 9437, In the Matter of Caremark Rx, Zinc Health Services, et al. (Insulin), filed Sept 2024 against the three largest PBMs - Caremark Rx, Express Scripts (ESI) and OptumRx - and their affiliated group purchasing organisations. Allegation: the three artificially inflated insulin LIST prices through a rebate system that made manufacturers compete on the size of the rebate off list rather than on net price, with the PBMs keeping a share - shifting cost onto patients paying against list price. RESOLUTIONS: ESI settled Feb 4 2026 (projected up to $7B in reduced patient out-of-pocket over 10 years, new revenue for community pharmacies). Caremark and the FTC jointly moved to withdraw from adjudication Mar 23 2026 to consider a consent agreement; FTC announced the Caremark settlement in July 2026 - locks in up to $8.5B in consumer savings over 10 years plus up to $4.5B more from point-of-sale rebates, delinks PBM fees from list prices, offers retail community pharmacies cost-plus reimbursement, caps member insulin costs at $25/month, and bars Caremark from interfering with pharmacies' access to hub service providers. The Optum case was withdrawn from adjudication to consider a proposed consent agreement. Related: House Judiciary Committee Interim Staff Report, Jan 21 2026, 'When CVS Writes the Rules.' NOTE: these are ANTITRUST/pricing actions, not data-privacy actions - keep the categories distinct.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "St. Louis", "HQ State": "Missouri", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.ftc.gov/terms/pharmacy-benefits-managers-pbm", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Missouri' is a non-DMV US state", "Parent / Ultimate Owner": "The Cigna Group (acquired 2018 for $67B)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Missouri SOS Business Search — bsd.sos.mo.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: The Cigna Group (acquired 2018 for $67B)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] Express Scripts' Feb 2026 FTC settlement is projected to cut patient costs by up to $7B over 10 years.\nWHAT THE TERMS SAY: The FTC's September 2024 case alleged Express Scripts (with Caremark and OptumRx) inflated insulin list prices via a rebate system; Express Scripts settled first, on February 4, 2026, agreeing to stop listing drugs at high wholesale acquisition cost, favor lower-cost formulary options, disclose broker kickbacks, and include the TrumpRx platform, with the FTC projecting up to $7B in reduced patient out-of-pocket costs over 10 years.\nWHY IT MATTERS: Until the settlement, patients' out-of-pocket costs were commonly based on a drug's list price rather than its net price — a discrepancy that translated into real dollars for patients paying coinsurance or in the deductible phase.\n(evidence: Data Sharing | Fees | SCARY; Stated in tracker (fidelity pass 1: Hedge lost corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Express Scripts' terms force arbitration of formulary, prior-authorization and pharmacy-steering disputes.\nWHAT THE TERMS SAY: Express Scripts' member Terms of Service mandate binding arbitration under AAA rules with a class-action waiver and a 30-day opt-out; the clause explicitly covers disputes over formulary placement, prior authorization denials, and pharmacy-network steering, for a company processing prescription claims for 100M+ Americans.\nWHY IT MATTERS: Individual members harmed by a formulary or authorization decision must arbitrate alone rather than join a collective claim, even though the same category of practice was serious enough to trigger a federal antitrust case.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct harms are stated in this row's own text; the PXDX claim-denial issue is explicitly cross-referenced to a separate row (Cigna, Life-Health-Dental) and the tracker instructs not to blend it here.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Settlement terms, dates, dollar figures, and the arbitration clause's scope are all specifically documented.", "Exposure Score (0-100)": 44, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Express Scripts (Cigna)  <-  The Cigna Group (acquired 2018 for $67B)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Express Scripts (Cigna) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T20:04:55Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Express Scripts was the first of the three big PBMs to settle, on February 4, 2026, on terms the FTC projects will cut patient out-of-pocket costs by up to $7 billion over ten years. Read that number backwards and it is the finding: a single company's rebate practices were worth $7 billion in avoidable patient spending over a decade, and it took a federal antitrust action to change them. Express Scripts also agreed to offer plan sponsors a benefit design where out-of-pocket costs are based on the NET price of a drug rather than the list price - which means until now the default was the opposite, and patients were routinely paying a percentage of a number nobody in the transaction actually pays. Cross-ref the Cigna row in Life-Health-Dental; the PXDX claim-denial matter there is a separate issue and should not be blended with this one.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Pharmacy Benefit Managers", "_row_id": 358, "_entity_id": 544, "_entity_slug": "express-scripts-cigna", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "OptumRx (UnitedHealth)", "Category": "Pharmacy Benefit Manager", "Terms & Conditions URL": "optumrx.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "optumrx.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SAME FTC INSULIN-PRICING CASE as Caremark/Express Scripts (see those rows) — OptumRx agreed to a PROPOSED settlement in June 2026 (the last of the three PBMs to reach a deal), following the template set by Express Scripts' earlier settlement; specific final terms not yet independently confirmed this pass. OptumRx is owned by UnitedHealth Group — the SAME parent company as Change Healthcare, whose 2024 ransomware breach is separately documented in the CareFirst BlueCross BlueShield row (Insurance tab) of this tracker, where CareFirst itself sued Change Healthcare over that incident.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual member disputes, separate from the government-brought FTC action.", "Fees / Billing Flags": "See Express Scripts row for the shared $7 billion projected industry-wide savings figure, which presumably extends proportionally to OptumRx's own settlement once finalized.", "Notes": "OptumRx's shared UnitedHealth parentage with Change Healthcare (documented elsewhere in this tracker for a massive separate ransomware breach) means UnitedHealth Group now appears in at least THREE distinct rows across this tracker (OptumRx's insulin case, Change Healthcare's breach via the CareFirst row, and potentially UnitedHealth's own general operations) — worth treating as one connected corporate family's cumulative regulatory/legal exposure.\n\nFTC PBM INSULIN CASE CROSS-REFERENCE (verified this pass - status updated): FTC administrative action, Docket 9437, In the Matter of Caremark Rx, Zinc Health Services, et al. (Insulin), filed Sept 2024 against the three largest PBMs - Caremark Rx, Express Scripts (ESI) and OptumRx - and their affiliated group purchasing organisations. Allegation: the three artificially inflated insulin LIST prices through a rebate system that made manufacturers compete on the size of the rebate off list rather than on net price, with the PBMs keeping a share - shifting cost onto patients paying against list price. RESOLUTIONS: ESI settled Feb 4 2026 (projected up to $7B in reduced patient out-of-pocket over 10 years, new revenue for community pharmacies). Caremark and the FTC jointly moved to withdraw from adjudication Mar 23 2026 to consider a consent agreement; FTC announced the Caremark settlement in July 2026 - locks in up to $8.5B in consumer savings over 10 years plus up to $4.5B more from point-of-sale rebates, delinks PBM fees from list prices, offers retail community pharmacies cost-plus reimbursement, caps member insulin costs at $25/month, and bars Caremark from interfering with pharmacies' access to hub service providers. The Optum case was withdrawn from adjudication to consider a proposed consent agreement. Related: House Judiciary Committee Interim Staff Report, Jan 21 2026, 'When CVS Writes the Rules.' NOTE: these are ANTITRUST/pricing actions, not data-privacy actions - keep the categories distinct.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] OptumRx, the last of three PBMs in the FTC insulin case, reached a proposed settlement in June 2026 whose final terms remain unconfirmed.\nWHAT THE TERMS SAY: OptumRx was the third defendant in the FTC's insulin rebate-manipulation case; its case was withdrawn from adjudication in favor of a proposed consent agreement in June 2026, following the template of Express Scripts' earlier settlement, but the tracker states specific final terms were not yet independently confirmed this pass.\nWHY IT MATTERS: The tracker notes the roughly $7B Express Scripts savings figure 'presumably extends proportionally' to OptumRx once finalized, but until confirmed, the actual consumer benefit and settlement terms remain unverified.\n(evidence: Data Sharing | Fees | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] OptumRx sits inside UnitedHealth Group alongside UnitedHealthcare and the naviHealth algorithm — one parent sets your coverage, your rehab, and your drug prices.\nWHAT THE TERMS SAY: The tracker states OptumRx, UnitedHealthcare, and the naviHealth algorithm (documented elsewhere in this tracker's Life-Health-Dental tab) all sit inside UnitedHealth Group, which also appears elsewhere in this tracker in connection with the Change Healthcare ransomware breach (via the CareFirst row) — one connected corporate family across at least three distinct rows.\nWHY IT MATTERS: Per the tracker's synthesis, a patient dealing with an insurance-coverage decision, a post-hospital rehabilitation decision, and a prescription price is dealing with divisions of a single company, not three independent market participants.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration is explicitly not independently confirmed this pass, so no arbitration-specific item is included; only two distinct, tracker-stated findings remain.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The proposed settlement's final terms and OptumRx's own arbitration clause are both explicitly marked as not independently confirmed this pass.", "Exposure Score (0-100)": 10, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "OptumRx (UnitedHealth)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, OptumRx (UnitedHealth) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "OptumRx is the third defendant in the FTC insulin case, and its case was withdrawn from adjudication so the Commission could consider a proposed consent agreement - meaning all three of the largest PBMs in the country moved to resolve the same allegation rather than litigate it. The structural point worth carrying out of this row is vertical integration: OptumRx, UnitedHealthcare and the naviHealth algorithm documented in the Life-Health-Dental tab all sit inside UnitedHealth Group, so the same corporate parent sets your insurance coverage, decides your post-hospital rehabilitation, and prices your prescriptions. A patient experiencing all three as separate frustrations is dealing with one company.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Pharmacy Benefit Managers", "_row_id": 359, "_entity_id": 545, "_entity_slug": "optumrx-unitedhealth", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Libby / OverDrive", "Category": "Library/Reading App", "Terms & Conditions URL": "overdrive.com/company/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "overdrive.com/company/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach. OverDrive/Libby (acquired by KKR in 2020) is the dominant e-book/audiobook lending platform used by public libraries nationwide, including systems across the DMV — meaning most patron reading-history data flows through this single third-party vendor rather than being held directly by the local library itself, a structurally important point for any library-privacy-focused advocacy (directly relevant to BMHC's own library outreach work): READING HISTORY has historically been treated with special legal sensitivity (many states have 'reader privacy' statutes specifically restricting law-enforcement access to library records), but a third-party vendor like OverDrive may not always be bound by the same library-specific confidentiality statutes that apply to the library itself.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual Libby app accounts.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "GIVEN THIS TRACKER'S CONNECTION TO BMHC'S LIBRARY OUTREACH WORK, this is worth a genuinely dedicated follow-up: confirming exactly what reading-history/borrowing data OverDrive retains, for how long, and under what legal process it could be disclosed, since this sits at the intersection of two sensitive categories (reading privacy and third-party vendor data-sharing) not deeply explored elsewhere in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[RETENTION_PERIOD · FL-2] It's unsettled whether library reading-privacy laws reach OverDrive's own app analytics and device data, not just library circulation records.\nWHAT THE TERMS SAY: The tracker states most US reading-privacy/library-confidentiality statutes were written for physical circulation records, and it is not settled how completely they extend to a third-party app's own independently collected analytics and device telemetry, as distinct from the library's own circulation record.\nWHY IT MATTERS: Patron reading history for libraries nationwide, including DMV-area systems, flows through this single third-party vendor rather than being held directly by the library; if OverDrive's own analytics fall outside statutory protection, patron reading habits could be less protected than assumed.\n(evidence: Data Sharing | SCARY | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing, arbitration, and fee fields are all explicitly 'not independently confirmed this pass'; the SCARY field itself states 'nothing confirmed this pass.' The only substantive point is the unresolved question of whether library reading-privacy statutes reach OverDrive's own app-level data collection.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing, arbitration, and fees are all explicitly unconfirmed this pass, and the SCARY field states 'nothing confirmed this pass.'", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "App / Service", "Ownership Path": "Libby / OverDrive  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Libby / OverDrive takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass, and the structural finding is favourable enough to state plainly: library borrowing records carry statutory confidentiality protection in most US states - among the few categories of consumer reading data that does - and OverDrive operates on behalf of libraries bound by those laws. That is a genuinely stronger position than any commercial reading platform in this tracker. The caveat worth flagging is that state library-confidentiality statutes were written for physical circulation records, and how completely they reach a third-party app's own analytics and device telemetry is not settled. Recommend a follow-up on OverDrive's independent data collection as distinct from the library's circulation record.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Library, Fitness & Home", "_row_id": 360, "_entity_id": 546, "_entity_slug": "libby-overdrive", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Planet Fitness", "Category": "Fitness", "Terms & Conditions URL": "planetfitness.com/about-planet-fitness/terms-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "planetfitness.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CLAIMED DARK-WEB DATA LEAK: threat actors publicly claimed (via a leak-site posting) to have obtained a Planet Fitness database including approximately 2,600 REGIONAL EMPLOYEE emails and the last 4 digits of members' club/account numbers — not independently confirmed by Planet Fitness itself in this research, similar to the 'unverified leak-site claim' pattern seen for Wizz Air elsewhere in this tracker. Planet Fitness's own privacy policy explicitly lists nearly 20 US STATES (including Virginia) whose residents have specific statutory data-access/disclosure rights — a relatively transparent, detailed state-by-state rights disclosure compared to many other companies in this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected, similar to the LA Fitness pattern.", "Fees / Billing Flags": "Active litigation covers BILLING FRAUD complaints (similar cancellation/continued-charging issues as LA Fitness) as well as separate 'lunk alarm' and civil-rights-related claims — specific case details and outcomes not independently confirmed this pass.", "Notes": "Planet Fitness's detailed state-by-state privacy-rights disclosure (naming Virginia specifically, among ~19 states) is a genuine point of transparency worth noting relative to companies elsewhere in this tracker that provide only generic, non-state-specific privacy language.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] Budget-gym cancellation by mail or in person is a documented industry practice, now subject of FTC rulemaking.\nWHAT THE TERMS SAY: The tracker describes the cancellation-by-mail-or-in-person requirement as a documented industry practice, tied to a budget-gym business model that depends on selling more memberships than the facilities could accommodate if everyone attended, which makes cancellation friction a revenue mechanism rather than an administrative failing.\nWHY IT MATTERS: The practice is now the subject of FTC negative-option rulemaking, meaning regulators view this kind of cancellation friction as a consumer-protection concern industry-wide.\n(evidence: Fees | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] An unverified leak-site claim alleges a Planet Fitness database exposed roughly 2,600 employee emails and partial member account numbers.\nWHAT THE TERMS SAY: Threat actors publicly claimed, via a leak-site posting, to have obtained a database including approximately 2,600 regional employee emails and the last 4 digits of members' club/account numbers; this was not independently confirmed by Planet Fitness.\nWHY IT MATTERS: If accurate, exposed partial account numbers could aid social-engineering or account-takeover attempts against members, but the tracker stresses this is an unverified claim, not a confirmed breach.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees/Billing litigation details (the 'lunk alarm' and civil-rights claims) are not independently confirmed beyond the general cancellation-friction pattern already covered in item 1, leaving only two sufficiently substantiated harms.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The state-by-state privacy-rights disclosure is clear, but the leak claim and billing-litigation details are explicitly unverified this pass.", "Exposure Score (0-100)": 16, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 10/20 (severity3+8, litigation+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Planet Fitness  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Planet Fitness you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The dark-web leak claim is unverified and should stay marked that way - an attacker's leak-site post is a lead, not a finding. Planet Fitness's more substantiated consumer issue is the one that defines the budget gym segment: the business model depends on selling more memberships than the facilities could accommodate if everyone attended, which makes cancellation friction a revenue mechanism rather than an administrative failing. The cancellation-by-mail-or-in-person requirement is a documented industry practice and now the subject of FTC negative-option rulemaking.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Library, Fitness & Home", "_row_id": 361, "_entity_id": 547, "_entity_slug": "planet-fitness", "_issuer": "Planet Fitness Holdings, Inc.", "_issuer_slug": "planet-fitness-holdings-inc", "_ticker": "PLNT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "LA Fitness (Fitness International LLC)", "Category": "Fitness", "Terms & Conditions URL": "lafitness.com/pages/termsandconditions.aspx", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "lafitness.com/pages/privacypolicy.aspx", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "DATA BREACH LITIGATION IS IN EARLY STAGES (2026): LA Fitness collects extensive personal data — full names, addresses, phone numbers, payment card info, bank account/ACH billing data, and in some cases HEALTH-RELATED information — and reports of improper data handling/third-party sharing have surfaced in complaint filings, though no large-scale settlement has been reached yet; this category of litigation likely won't resolve until 2027 at the earliest.", "Arbitration / Class Action Waiver": "LA Fitness membership agreements MANDATE ARBITRATION for disputes — courts have upheld these clauses in multiple cases, meaning affected consumers 'lose their ability to band together in a class action and must pursue small claims individually, which most never do,' per legal analysis — a concrete illustration of how an enforced arbitration clause can functionally eliminate most consumers' practical ability to seek redress.", "Fees / Billing Flags": "EXTENSIVE, WELL-DOCUMENTED BILLING PATTERN: thousands of BBB/FTC complaints describe LA Fitness CONTINUING TO CHARGE members' bank accounts/credit cards for 1 TO 12 MONTHS after they properly canceled — specific documented failure patterns include cancellation forms never being processed by staff (with no record created), members being told they had to cancel IN PERSON even when mail/email cancellation should have been legally valid, ANNUAL fees charged even while a cancellation request was pending, and 'cancel on file' confirmation numbers that did not actually stop billing. SEPARATELY, a distinct COVID-19 REFUND lawsuit alleges LA Fitness continued charging membership dues during 2020-2021 forced closures when members had zero access to facilities. Legal theories invoked include the Electronic Funds Transfer Act (prohibiting unauthorized electronic withdrawals) and state automatic-renewal disclosure laws.", "Notes": "The 'cancel on file confirmation number that doesn't actually stop billing' pattern is one of the most concrete, easily-explained, and consumer-relatable billing-harm findings in this entire tracker — worth flagging prominently since gym-membership cancellation friction is an extremely common, widely-relatable consumer experience.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] LA Fitness's 'cancel on file' confirmation numbers didn't stop billing — complaints describe charges continuing 1 to 12 months after cancellation.\nWHAT THE TERMS SAY: Documented failure patterns include cancellation forms never processed with no record created, members told cancellation required in-person even when mail/email should have been legally valid, annual fees charged during a pending cancellation, and confirmation numbers that did not stop billing; a separate lawsuit alleges dues were charged through 2020-2021 pandemic closures when members had zero facility access.\nWHY IT MATTERS: Members who followed the cancellation process and received a confirmation number were still billed for up to a year, and had to invoke federal (EFTA) and state auto-renewal disclosure laws to contest it.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] LA Fitness's court-upheld arbitration clause means most affected members must pursue billing disputes individually in small claims, which most never do.\nWHAT THE TERMS SAY: Membership agreements mandate arbitration; courts have upheld these clauses in multiple cases, and legal analysis cited in the tracker states affected consumers 'lose their ability to band together in a class action and must pursue small claims individually, which most never do.'\nWHY IT MATTERS: This functionally forecloses collective redress for the widespread billing complaints documented above, since individual small-claims pursuit is rare.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] LA Fitness collects card, bank/ACH, sometimes health data; early litigation alleges improper handling.\nWHAT THE TERMS SAY: LA Fitness collects full names, addresses, phone numbers, payment card info, bank account/ACH billing data, and in some cases health-related information; complaint filings allege improper data handling and third-party sharing, though no large-scale settlement has been reached and the litigation likely won't resolve until 2027 at the earliest.\nWHY IT MATTERS: The data set at risk (financial account numbers plus potential health data) is unusually broad for a gym, and per the tracker this litigation likely won't resolve until 2027 at the earliest.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 1: Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The billing-cancellation pattern is well documented with specific complaint types, but the data-breach litigation is still early-stage with no confirmed outcome.", "Exposure Score (0-100)": 49, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 9/30 (biometric_collection+6, sensitive_exposure_tag+3) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 10/20 (severity3+8, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "LA Fitness (Fitness International LLC)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using LA Fitness (Fitness International LLC) you gave up your biometric identifiers, your right to sue, your right to join a class action, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "2026-09-08T20:05:05Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Breach litigation is at an early stage, and LA Fitness collects an unusually broad set for a gym - including, across the industry, biometric entry systems in some locations, which brings Illinois BIPA into play. LA Fitness is also named in the industry-wide TCPA pattern documented in the Orangetheory row of the Gyms tab. The overlapping finding across every gym row in this tracker holds here: members sign long-duration contracts at a moment of aspiration and encounter the actual terms only when trying to leave.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Library, Fitness & Home", "_row_id": 362, "_entity_id": 548, "_entity_slug": "la-fitness-fitness-international-llc", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Equinox", "Category": "Fitness", "Terms & Conditions URL": "equinox.com/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "equinox.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED NOVEMBER 2024 DATA BREACH: Equinox disclosed a data breach affecting an undisclosed number of members, prompting a class-action investigation; specific data types exposed and total scope not independently confirmed this pass beyond the confirmed breach notification itself.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Equinox is positioned as a premium/luxury fitness brand with correspondingly higher membership pricing than Planet Fitness/LA Fitness — no specific billing-dispute pattern independently confirmed this pass, though the general gym-industry cancellation-friction pattern documented for LA Fitness/Planet Fitness elsewhere in this tab may plausibly extend here.", "Notes": "Recommend a direct follow-up on the November 2024 breach's specific scope and any resulting settlement, given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Equinox confirmed a November 2024 data breach affecting an undisclosed number of members, prompting a class-action investigation.\nWHAT THE TERMS SAY: Equinox disclosed a data breach in November 2024; the number of members affected and the specific data types exposed were not independently confirmed beyond the breach notification itself.\nWHY IT MATTERS: The specific data types exposed and the total scope were not independently confirmed beyond the breach notification itself; the tracker notes Equinox holds payment methods, home and work addresses and detailed attendance patterns, and that high-income members are more attractive identity theft targets. The breach prompted a class-action investigation.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Luxury fitness bundles spa and recovery services generating health-adjacent data outside health-privacy law.\nWHAT THE TERMS SAY: The tracker notes luxury fitness increasingly bundles spa, recovery and wellness services that generate health-adjacent data - body composition, recovery metrics, treatment histories - held entirely outside any health privacy framework because the provider is a gym.\nWHY IT MATTERS: Consumers may assume health-adjacent data collected during wellness services carries health-privacy-level protection, but per the tracker it is held entirely outside any health privacy framework because the provider is a gym.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration is not independently confirmed and Fees/Billing has no specific pattern confirmed for Equinox itself; only two distinct findings are substantiated in this row's text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach itself is confirmed, but the scope, affected member count, and specific data types exposed are not independently confirmed.", "Exposure Score (0-100)": 14, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Equinox  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Equinox takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The November 2024 breach affected a membership base at the premium end of the market, and that changes the risk profile rather than reducing it: high-income members are more attractive identity theft targets, and Equinox holds payment methods, home and work addresses, and detailed attendance patterns. Luxury fitness also increasingly bundles spa, recovery and wellness services that generate health-adjacent data - body composition, recovery metrics, treatment histories - held entirely outside any health privacy framework because the provider is a gym.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Library, Fitness & Home", "_row_id": 363, "_entity_id": 549, "_entity_slug": "equinox", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "American Home Shield (Frontdoor Inc.)", "Category": "Home Warranty", "Terms & Conditions URL": "ahs.com/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "ahs.com/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ACTIVE TRACKING/PRIVACY-TORT INVESTIGATION: attorneys are pursuing claims that American Home Shield secretly tracked visitors' online activity on ahs.com without adequate consent — consistent with the broader tracking-technology litigation wave documented throughout this tracker. SEPARATELY, a TCPA (robocall) class action alleged AHS made multiple unwanted PRERECORDED CALLS to a consumer despite the company's own records showing consent had allegedly been given on its website — illustrating a genuine ambiguity in these cases: the discrepancy could reflect AHS's own lead-generation vendor using fraudulent bot-generated 'consent,' a scenario the article notes R.E.A.C.H. industry standards exist specifically to prevent.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected; the article notes AHS faces 'individual arbitration claims' as a distinct category from its class actions, suggesting the arbitration clause is being actively used/enforced.", "Fees / Billing Flags": "AN EXTRAORDINARY VOLUME OF COMPLAINTS: American Home Shield has accumulated OVER 80,000 BBB COMPLAINTS over the past three years — one of the largest complaint volumes for any single company found in this entire tracker. The core pattern across class actions, state regulatory investigations, and individual arbitration claims: AHS allegedly SYSTEMATICALLY DENIES valid warranty claims, uses misleading contract language, and charges customers for coverage they can never realistically use — one plaintiff's attorney described it as 'selling an umbrella with a disclaimer that rain voids the warranty.' Parent company Frontdoor Inc. has itself disclosed this ongoing litigation as a MATERIAL RISK in its own securities filings.", "Notes": "The 80,000+ BBB complaint volume and the parent company's own admission of material litigation risk make this one of the most heavily-documented CONSUMER-COMPLAINT (as opposed to purely legal) patterns in this entire tracker — home warranty companies broadly are worth approaching with caution given how consistent this 'deny valid claims' pattern appears to be across the industry.\n\nDATA-QUALITY CORRECTION (Aug 2026): the Fortune 500 metadata on this row previously held data for AMERICAN INTERNATIONAL GROUP (AIG) — a fuzzy-match error from the F500 population script, which matched on the string 'American'. Frontdoor, Inc. (American Home Shield) is an unrelated home warranty company headquartered in Memphis, Tennessee. Incorrect metadata CLEARED rather than replaced, because correct Frontdoor figures were not independently verified this pass. This is the second confirmed wrong-company match found in the Aug 2026 audit — see also the H&R Block row in Consumer Apps, which held Block, Inc. data. Both were caught by comparing the company name against the corporate website column; that check should be run after any future F500 repopulation.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[OTHER · FL-1] AHS has 80,000+ BBB complaints in 3 years; class actions and state probes allege it denies valid claims.\nWHAT THE TERMS SAY: American Home Shield has accumulated over 80,000 BBB complaints in three years; a pattern across class actions, state investigations, and individual arbitration claims alleges systematic denial of valid warranty claims, misleading contract language, and charges for coverage customers can't realistically use — described by a plaintiff's attorney as 'selling an umbrella with a disclaimer that rain voids the warranty.' Parent company Frontdoor Inc. has disclosed this litigation as a material risk in its own securities filings.\nWHY IT MATTERS: The core promised benefit of a home warranty — repair coverage — is, per this pattern, frequently unavailable when a claim is filed, and the company's own parent acknowledges the litigation exposure as material.\n(evidence: Fees; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[DARK_PATTERN_CONSENT · FL-2] AHS faces claims of secretly tracking site visitors without consent, plus a TCPA suit alleging robocalls despite disputed 'consent' records.\nWHAT THE TERMS SAY: Attorneys are pursuing claims that AHS secretly tracked visitors' online activity on ahs.com without adequate consent; separately, a TCPA class action alleged AHS made multiple unwanted prerecorded calls despite its own records purporting to show consent had been given on its website — a discrepancy the tracker notes could reflect a lead-generation vendor using fraudulent bot-generated 'consent.'\nWHY IT MATTERS: Consumers who never knowingly opted in may have been called anyway, and the underlying website tracking practice is under active investigation as a privacy tort.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration is not independently confirmed this pass beyond a reference to an 'individual arbitration claims' category, which is too thin to support a distinct, well-evidenced item; two substantiated findings remain.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The complaint volume and litigation categories are well documented, but the tracking allegation and arbitration clause specifics are explicitly unconfirmed.", "Exposure Score (0-100)": 4, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "American Home Shield (Frontdoor Inc.)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, American Home Shield (Frontdoor Inc.) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "2026-09-08T20:05:08Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The active tracking and privacy-tort investigation is worth pairing with what a home warranty company actually knows: the age and condition of your major appliances and systems, the service history of your home, when technicians visited, and by inference whether you are typically home during business hours. Home warranty is also a category with sustained consumer complaint about claim denial - the substantive harm most customers experience is a denied repair, not a data issue, and any consumer-facing writeup should say so rather than leading with the tracking claim.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Library, Fitness & Home", "_row_id": 364, "_entity_id": 550, "_entity_slug": "american-home-shield-frontdoor-inc", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sunrun", "Category": "Solar/Home Services", "Terms & Conditions URL": "sunrun.com/sunrun-terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "sunrun.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "HISTORICAL EMPLOYEE-DATA BREACH (2017): a hacker impersonating Sunrun's own CEO phished the payroll department into sending employee W-2 tax forms (SSNs, addresses, salaries); Sunrun offered only 2 years of Experian identity-theft monitoring and did NOT reimburse employees for costs from fraudulent tax returns already filed using the stolen data — an employee-facing breach, not customer-facing.", "Arbitration / Class Action Waiver": "Sunrun's Terms of Service contain MANDATORY BINDING ARBITRATION (AAA Commercial Rules) with an EXPLICIT CLASS-ACTION AND CLASS-ARBITRATION WAIVER — customers must resolve disputes individually. One consumer-advocacy source notes arbitration 'might be the only option available' to a Sunrun customer depending on their specific contract, underscoring how thoroughly the clause forecloses collective action.", "Fees / Billing Flags": "MULTIPLE STATE ATTORNEYS GENERAL ACTIONS (2024-2026), among the most serious consumer-protection findings in this entire tab: Connecticut AG William Tong SUED Sunrun (July 2024, still pending as of March 2026) along with door-to-door sales contractors Bright Planet Solar and Elevate Solar, alleging sales reps FORGED a customer's electronic signature (with her name's initials reversed), then IMPERSONATED HER VOICE on a confirmation call to finalize a 25-year, $306.98/month solar lease she had TWICE explicitly rejected — Sunrun then installed a 36-panel system without consent and refused to remove it. Texas AG Ken Paxton separately issued civil investigative demands (April 2026) to Sunrun over alleged misrepresented energy-bill savings and contract terms. Massachusetts logged 170+ consumer complaints against Sunrun (2023-2025) — more than any other solar company in the state. Nationally, Sunrun has 4,000+ BBB complaints, with active class actions alleging customers were misled into believing bills would drop or disappear, only to end up paying BOTH their utility bill AND the Sunrun lease. CANCELLATION PENALTIES reportedly range from $1,500 to over $10,000 depending on years remaining on the contract.", "Notes": "The Connecticut case's forged-signature/voice-impersonation allegation is one of the most serious, concrete consumer-fraud findings in this entire tracker — a company allegedly installing equipment on someone's roof AFTER THEY TWICE SAID NO, using impersonation to fake consent. Combined with active AG actions in 3+ states, this warrants a prominent, careful flag given how aggressive door-to-door solar sales tactics appear to be industry-wide, not limited to Sunrun specifically.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2017", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-4] Connecticut's AG alleges Sunrun reps forged a customer's signature and impersonated her voice to install a 25-year solar lease she'd twice rejected.\nWHAT THE TERMS SAY: Connecticut AG Tong sued Sunrun (July 2024, pending as of March 2026) along with contractors Bright Planet Solar and Elevate Solar, alleging reps forged a customer's electronic signature (with her name's initials reversed) and impersonated her voice on a confirmation call to finalize a 25-year, $306.98/month solar lease she had twice explicitly rejected; Sunrun then installed a 36-panel system without consent and refused to remove it.\nWHY IT MATTERS: The customer was allegedly locked into a decades-long financial obligation and had equipment installed on her home despite never actually agreeing, and its removal was refused afterward.\n(evidence: Fees | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[TERMINATION_CONFISCATION · FL-4] Sunrun's cancellation penalties reportedly range from $1,500 to over $10,000 on leases attached to the home.\nWHAT THE TERMS SAY: Sunrun leases/PPAs run 20-25 years and often attach to the property, requiring a buyer to assume them; cancellation penalties reportedly range from $1,500 to over $10,000 depending on years remaining, and active class actions allege customers were misled into believing utility bills would drop or disappear, only to end up paying both the utility bill and the Sunrun lease.\nWHY IT MATTERS: A homeowner who wants out faces a steep penalty, and the long-term obligation can complicate selling the home since a buyer must assume the lease.\n(evidence: Fees; Stated in tracker (fidelity pass 1: Hedge lost corrected))", "Top Troubling #3": "[CONFIRMED_BREACH · FL-2] A 2017 CEO-impersonation phishing attack exposed Sunrun employees' SSNs and salaries; Sunrun offered only 2 years of monitoring and no fraud reimbursement.\nWHAT THE TERMS SAY: A hacker impersonating Sunrun's CEO phished the payroll department into sending employee W-2 forms (SSNs, addresses, salaries); Sunrun offered only 2 years of Experian identity-theft monitoring and did not reimburse employees for costs from fraudulent tax returns already filed using the stolen data.\nWHY IT MATTERS: Affected employees bore ongoing financial and administrative burden from tax fraud with no cost reimbursement, beyond a time-limited monitoring service.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=Y; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated, but the forged-signature and billing-fraud allegations are pending AG litigation, not adjudicated findings.", "Exposure Score (0-100)": 47, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 7, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 7/20 (termination_or_confiscation+4, auto_renewal_or_fee_trap+3) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Sunrun  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Sunrun you gave up your right to sue, your right to join a class action, your right to keep what you paid for, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T20:05:08Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The 2017 breach came from a hacker impersonating a Sunrun executive to obtain employee data - a business email compromise, which is social engineering again, and again requiring no technical exploit. The consumer-facing note for residential solar generally is that these are 20-to-25-year agreements, frequently involving leases or power purchase agreements that attach to the property and must be assumed by a buyer, and the company holds detailed household energy production and consumption data for the entire term. That is the smart-meter inference problem documented in the Power Utilities tab, held by a private company with no utility regulator over it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Library, Fitness & Home", "_row_id": 365, "_entity_id": 551, "_entity_slug": "sunrun", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "U-Haul", "Category": "Moving/Storage", "Terms & Conditions URL": "uhaul.com/Terms/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "uhaul.com/Privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "TWO CONFIRMED, SEPARATE DATA BREACHES: (1) A breach from November 5, 2021 to April 5, 2022 (SEVEN MONTHS undetected) occurred after hackers obtained two PASSWORDS controlling U-Haul's customer-contract-search tool, exposing customers' names, birthdates, and DRIVER'S LICENSE NUMBERS — the lawsuit specifically alleges U-Haul continued storing this data UNENCRYPTED in an internet-accessible environment despite widely-available FBI/CISA warnings about aggressive cyberattack targeting, and raises a Driver's Privacy Protection Act violation claim specifically (a federal law protecting DMV-sourced license data). (2) A SECOND, separate breach occurred in December 2023. U-Haul settled the combined litigation for $5.085 MILLION (2024), with an estimated pro-rata payout of approximately $100 per claimant.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The SEVEN-MONTH undetected breach window plus the specific allegation of storing UNENCRYPTED data despite known industry warnings is a clean, concrete illustration of the kind of preventable security failure documented repeatedly across this tracker — worth noting the Driver's Privacy Protection Act claim specifically, since license-number exposure carries distinct identity-theft risk from a typical email/password leak.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] U-Haul breach went 7 months undetected, exposing driver's license numbers; suit alleges data sat unencrypted.\nWHAT THE TERMS SAY: Hackers used two stolen passwords to access U-Haul's customer-contract-search tool from November 5, 2021 to April 5, 2022 (seven months undetected), exposing names, birthdates, and driver's license numbers; the lawsuit alleges U-Haul continued storing this data unencrypted in an internet-accessible environment despite widely-available FBI/CISA warnings, and raises a Driver's Privacy Protection Act claim. A second, separate breach occurred in December 2023; U-Haul settled the combined litigation for $5.085 million in 2024, with an estimated payout of about $100 per claimant.\nWHY IT MATTERS: Exposed driver's license numbers carry distinct identity-theft risk beyond a typical email/password leak, and the repetition of a second breach suggests the underlying security practices were not fixed after the first incident.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] A U-Haul rental record documents exactly where and when a customer moved — information domestic-violence advocates treat as among the most sensitive a person can have exposed.\nWHAT THE TERMS SAY: The tracker notes a U-Haul rental record is a documented move — origin address, destination address, date — precisely the information that identifies someone who has relocated to get away from another person; U-Haul also requires a driver's license scan at the counter, so identity documents sit alongside the move record.\nWHY IT MATTERS: Domestic violence advocates treat address change as the single most protected fact about a person, and a moving company holds it by definition; U-Haul has had two confirmed separate breaches, which exposed names, birthdates and driver's license numbers.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and fees are not itemized/confirmed this pass; only two distinct findings — the breaches themselves, and the sensitive nature of the move-record data — are substantiated.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Breach dates, cause, settlement amount, and per-claimant payout are all specifically documented.", "Exposure Score (0-100)": 8, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "U-Haul  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, U-Haul takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Two confirmed separate breaches, and the repetition is the finding. U-Haul's data is also distinctive: a rental record is a documented move - origin address, destination address, date - which is precisely the information that identifies someone who has relocated to get away from another person. Domestic violence advocates treat address change as the single most protected fact about a person, and a moving company holds it by definition, twice over. U-Haul additionally requires a driver's licence scan at counter, so identity documents sit alongside it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Library, Fitness & Home", "_row_id": 366, "_entity_id": 552, "_entity_slug": "u-haul", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Public Storage", "Category": "Storage", "Terms & Conditions URL": "publicstorage.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "publicstorage.com/privacy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Standard storage-industry lien/foreclosure structure: under state Self-Service Storage Facility Acts, Public Storage (like all self-storage operators) holds a LIEN on stored property for unpaid rent and can legally auction a tenant's belongings after following required notice procedures — rental agreements typically disclaim warranties and limit liability for property damage/loss/theft.", "Fees / Billing Flags": "WRONGFUL-SALE LAWSUIT (Los Angeles Superior Court, Case BC562265): alleges Public Storage auctioned a tenant's belongings in violation of California's Self-Service Storage Facility Act — specifically, AHEAD OF a scheduled Dec. 30 hearing date, after the tenant had filed a formal 'Declaration in Opposition to Lien Sale' that should have paused the process; internal district/regional manager emails were submitted as evidence the sale proceeded despite this. The suit also alleged poor sanitary conditions at the facility. Separately, industry-wide legal analysis shows 'wrongful sale' is described by a self-storage attorney as the single MOST COMMON legal challenge the industry faces — even a facility that followed correct procedure once can be found liable if it fails to REPEAT the required notice steps the next time (one comparable industry case resulted in a $379,000+ jury verdict against a different operator for exactly this kind of process gap).", "Notes": "A DIRECTLY RELEVANT COMPARABLE FINDING (different company, same industry): Morningstar Storage paid $130,000 to settle allegations it violated the SERVICEMEMBERS CIVIL RELIEF ACT by auctioning THREE ACTIVE-DUTY SERVICE MEMBERS' belongings (including military awards and children's keepsakes) without the court order federal law requires — a strict-liability statute requiring operators to verify military status regardless of disclosure. Given this region's large military/veteran population, this SCRA compliance issue is worth flagging as an industry-wide self-storage risk relevant to any service member using ANY storage company, not just Public Storage specifically.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LIABILITY_CAP_INDEMNITY · FL-1] State storage-lien law lets Public Storage auction a tenant's goods; agreements typically disclaim liability.\nWHAT THE TERMS SAY: Under state Self-Service Storage Facility Acts, Public Storage holds a lien on stored property for unpaid rent and can legally auction a tenant's belongings after required notice procedures; rental agreements typically disclaim warranties and limit liability for property damage, loss, or theft.\nWHY IT MATTERS: A tenant who falls behind on payment risks losing stored property to auction, while having limited recourse for damage or loss under the agreement's own liability limits.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[OTHER · FL-4] A lawsuit alleges Public Storage auctioned a tenant's belongings ahead of a scheduled hearing, after the tenant had formally filed to oppose the sale.\nWHAT THE TERMS SAY: A Los Angeles Superior Court case (BC562265) alleges Public Storage auctioned a tenant's belongings in violation of California's Self-Service Storage Facility Act — ahead of a scheduled December 30 hearing date, after the tenant had filed a formal 'Declaration in Opposition to Lien Sale' that should have paused the process; internal manager emails were submitted as evidence the sale proceeded anyway. The suit also alleged poor sanitary conditions at the facility.\nWHY IT MATTERS: If accurate, the tenant followed the legal process to contest the sale and lost their belongings anyway; industry-wide legal analysis separately notes wrongful sale is the most common legal challenge self-storage operators face.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data Sharing has no confirmed lawsuit or breach for Public Storage specifically, and the SCARY field states 'nothing confirmed this pass.' The Morningstar Storage SCRA settlement described in Notes is a different company and is excluded per the cross-reference rule.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=Y; contentlic=?; confiscation=Y; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data-sharing practices are unconfirmed this pass, and the SCARY field explicitly states 'nothing confirmed this pass' — only the lien/liability structure and one lawsuit are documented.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 9, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 9/20 (liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4) | Record 4/20 (severity2+2, litigation+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Public Storage  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Public Storage you gave up your right to keep what you paid for and your right to meaningful compensation. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T20:05:16Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Self-storage holds an underappreciated combination: an access log showing exactly when a customer visits a unit, a gate code, and often unit contents disclosed for insurance purposes - plus, in an increasing number of facilities, continuous camera coverage of the access corridors. Storage is also used disproportionately during life disruptions - divorce, death, eviction, relocation - so the customer base is selected for people in transition. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Library, Fitness & Home", "_row_id": 367, "_entity_id": 553, "_entity_slug": "public-storage", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "TaskRabbit (IKEA)", "Category": "Gig Economy", "Terms & Conditions URL": "taskrabbit.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "taskrabbit.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "HISTORICAL CONFIRMED BREACH (2018, still relevant precedent): a 'cybersecurity incident' forced TaskRabbit (then newly acquired by IKEA) to take its ENTIRE website and app OFFLINE — an unauthorized user gained access to systems affecting over 1.5 million users and 60,000 'Taskers' across 40 US/UK cities; compromised data for TASKERS specifically included names, usernames, passwords, birthdates, SOCIAL SECURITY NUMBERS, bank account numbers, and truncated payment card info — a notably broader and more sensitive data set than what was exposed for CLIENTS (names, usernames, passwords, birthdates, truncated card info only), reflecting how gig-worker accounts often require MORE sensitive financial verification data (for tax/payment purposes) than the customers who hire them.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The TASKER/CLIENT data-asymmetry (workers' accounts holding SSNs and bank details vs. customers' accounts holding far less) is a useful, generalizable insight about gig-economy platforms broadly — the WORKERS on these platforms often carry substantially higher personal data-breach risk than the customers who hire them, since workers must be verified/paid as a tax-reportable identity.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2018", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] TaskRabbit's 2018 breach exposed Taskers' Social Security and bank account numbers — far more sensitive data than what was exposed for clients.\nWHAT THE TERMS SAY: A 2018 cybersecurity incident forced TaskRabbit's entire website and app offline; unauthorized access affected over 1.5 million users and 60,000 Taskers across 40 US/UK cities. Compromised Tasker data included names, usernames, passwords, birthdates, Social Security numbers, bank account numbers, and truncated payment card info — broader and more sensitive than what was exposed for clients (names, usernames, passwords, birthdates, and truncated card info only).\nWHY IT MATTERS: Taskers, who must be verified and paid as a tax-reportable identity, carried substantially higher breach risk (SSN and bank account exposure) than the customers who hired them.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Gig-platform workers cannot decline background checks, ID documents and bank details and still earn.\nWHAT THE TERMS SAY: The tracker notes a gig platform holds both customer and worker data, and the worker side is far more extensive — background check results, identity documents, bank details, home address, and a work history that is also a location history; workers cannot decline any of it and still earn, and have no bargaining power over the terms.\nWHY IT MATTERS: Across the platform, the person generating the most sensitive data (the worker) has the least ability to negotiate over how it's collected or used.\n(evidence: SCARY | Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and fees are not itemized/confirmed this pass; only two distinct findings — the 2018 breach and the structural Tasker/client data asymmetry — are substantiated.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The 2018 breach's scope, affected numbers, and specific data types for Taskers versus clients are all clearly documented.", "Exposure Score (0-100)": 8, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "TaskRabbit (IKEA)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, TaskRabbit (IKEA) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "2026-09-08T20:05:19Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The 2018 incident remains the useful precedent because of the asymmetry it exposes: a gig platform holds both customer data and worker data, and the worker side is far more extensive - background check results, identity documents, bank details, home address, and a work history that is also a location history. Workers cannot decline any of it and still earn, and they have no bargaining power over the terms. Across this tracker, gig platforms are the clearest case of the person generating the most sensitive data having the least ability to negotiate over it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Gig Economy, VPN & Subs", "_row_id": 368, "_entity_id": 554, "_entity_slug": "taskrabbit-ikea", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Rover (Blackstone)", "Category": "Gig Economy (pet care)", "Terms & Conditions URL": "rover.com/terms/tos/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "rover.com/terms/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ACTIVE CLASS ACTION (filed April 2026, California federal court): alleges Rover secretly shares PARTICULARLY SENSITIVE data with Google without adequate consent — not just typical search/browsing activity, but users' HOME ADDRESSES and ABSENCE SCHEDULES (i.e., specific dates/times a user's home will be unoccupied because they're traveling and using Rover for pet care) — a genuinely distinctive and higher-stakes privacy risk than most tracking-pixel cases in this tracker, since 'when is this specific home empty' is exactly the kind of information that could enable burglary or other physical harm if it reached the wrong party. Rover's own privacy policy confirms it shares geolocation, device, and activity data with 'advertising and analytics providers' and does allow a CCPA-style opt-out.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected; the tracking-data investigation above is being pursued via Labaton Keller Sucharow specifically as individual ARBITRATION claims rather than a class action.", "Fees / Billing Flags": "SEPARATE ACTIVE CLASS ACTION (Chernov v. Blackstone, S.D. Cal.): alleges Rover fails to disclose a MANDATORY 11% BOOKING FEE until checkout, in violation of California's Consumer Legal Remedies Act, which requires all mandatory fees be disclosed upfront in advertisements/listings.", "Notes": "SEPARATE, SERIOUS SAFETY/ACCOUNTABILITY FINDING (via FOIA request to the FTC): consumer complaints document CASES OF PET DEATH OR SEVERE INJURY while in the care of Rover-connected sitters, with users reporting Rover's response limited to printing lost-pet flyers rather than substantive accountability — Rover, like Uber/Airbnb, operates as a TECHNOLOGY PLATFORM rather than a direct employer of sitters, which the reporting notes creates genuine ambiguity about who bears responsibility when something goes seriously wrong. This is a distinct HARM category (physical safety/accountability) from the data-privacy and fee-transparency findings above.", "Industry (Fortune 500)": "The home-address/absence-schedule data-sharing allegation is one of the more physically concerning privacy findings in this entire tracker — combined with the separate documented pattern of serious pet-safety incidents and limited platform accountability, Rover presents a genuinely multi-dimensional risk profile worth flagging carefully.", "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[LIABILITY_CAP_INDEMNITY · FL-1] FTC complaints report Rover's response to pet death or injury by sitters was limited to lost-pet flyers.\nWHAT THE TERMS SAY: Consumer complaints obtained via a FOIA request to the FTC document cases of pet death or severe injury while in the care of Rover-connected sitters, with users reporting Rover's response limited to printing lost-pet flyers rather than substantive accountability; Rover, like Uber or Airbnb, operates as a technology platform rather than a direct employer of sitters, creating ambiguity about who bears responsibility when something goes seriously wrong.\nWHY IT MATTERS: Rover operates as a technology platform rather than a direct employer of sitters, which the reporting notes creates genuine ambiguity about who bears responsibility when something goes seriously wrong.\n(evidence: Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[LOCATION_TRACKING · FL-2] A class action alleges Rover shares users' home addresses and specific absence schedules with Google without adequate consent.\nWHAT THE TERMS SAY: An April 2026 class action filed in California federal court alleges Rover shares particularly sensitive data with Google without adequate consent — not just typical browsing activity, but users' home addresses and absence schedules (specific dates/times a home will be unoccupied because the owner is traveling and using Rover for pet care). Rover's own privacy policy confirms it shares geolocation, device, and activity data with 'advertising and analytics providers' and offers a CCPA-style opt-out.\nWHY IT MATTERS: Combining a home address with exact windows of vacancy is, per the tracker, exactly the kind of information that could enable burglary or physical harm if it reached the wrong party.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-1] A separate class action alleges Rover hides a mandatory 11% booking fee until checkout, in violation of California consumer law.\nWHAT THE TERMS SAY: Chernov v. Blackstone (S.D. Cal.) alleges Rover fails to disclose a mandatory 11% booking fee until checkout, in violation of California's Consumer Legal Remedies Act, which requires all mandatory fees to be disclosed upfront in advertisements and listings.\nWHY IT MATTERS: Consumers comparing prices across sitters may not see the true cost until they're already at checkout.\n(evidence: Fees; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Rover's privacy policy confirms sharing categories of data with advertising/analytics partners, but the specific address-and-absence-schedule sharing with Google is an unadjudicated class-action allegation.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 8, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, precise_location_tracking+4) | Contract 8/20 (liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 10/20 (severity3+8, litigation+2) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Rover (Blackstone)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Rover (Blackstone) you gave up your personal data sold onward, your physical movements, your right to meaningful compensation, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The April 2026 class action is worth reading alongside what a pet-sitting platform actually knows: your home address, when you are away and for how long, how to get in, whether you have a security system, and often a door code - assembled and stored by a company most owners think of as a booking tool. That is an absence-and-access dataset, which is a burglary planning document in the wrong hands. Rover is owned by Blackstone following a private-equity acquisition, so the governance of that data now sits with an asset manager. Allegations, not findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Gig Economy, VPN & Subs", "_row_id": 369, "_entity_id": 555, "_entity_slug": "rover-blackstone", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "The Weather Channel (IBM) / AccuWeather", "Category": "Weather App", "Terms & Conditions URL": "weather.com/en-US/twc/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "weather.com/en-US/twc/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ONE OF THE MOST CANDID SELF-DESCRIPTIONS OF A DATA-MONETIZATION BUSINESS FOUND IN THIS ENTIRE TRACKER: in litigation, The Weather Channel's parent (TWC Product and Technology, owned by IBM) has been documented describing ITSELF as 'a location data company powered by the weather' — a startlingly direct admission that its actual business model is selling PRECISE, MINUTE-BY-MINUTE GEOLOCATION DATA (tracked continuously, 'day and night, 365 days a year,' even when the app is closed) to third parties including PRIVATE EQUITY FIRMS AND HEDGE FUNDS, who reportedly use it to monitor consumer spending patterns — not weather-related use at all. TWC and IBM built a dedicated location-marketing platform called 'JOURNEYfx' specifically to commercialize this data, operating within what the litigation describes as a $21 BILLION location-targeting industry. The app's own consent flow reportedly never disclosed this monetization, instead framing location access as needed only for 'personalized local weather data, alerts, and forecasts.' Los Angeles's CITY ATTORNEY separately SUED TWC (2019) for deceptive data sale, seeking civil penalties up to $2,500 PER VIOLATION and forcing a settlement that required clearer disclosure of the constant-tracking practice going forward. SEPARATELY, security researchers documented AccuWeather continuing to share user location data with a partner (Reveal Mobile) EVEN AFTER USERS OPTED OUT of location sharing — a direct violation of the opt-out setting's own stated purpose.", "Arbitration / Class Action Waiver": "A California federal judge (2021) allowed most of a related class action to proceed, specifically rejecting TWC's argument that the mere existence of a privacy policy defeated the claim, since 'users might lack actual or constructive notice of the policy' — TWC settled this case (2023), its SECOND such privacy settlement in three years, with specific terms undisclosed.", "Fees / Billing Flags": "Not itemized this pass beyond the $2,500-per-violation civil penalty framework in the LA case.", "Notes": "The 'we are a location data company powered by the weather' self-description is one of the most quotable, damaging admissions found anywhere in this entire 400+ company audit — a weather app is about as innocuous and universally-installed a category of app as exists, making this finding unusually broadly relevant: nearly everyone has a weather app, and this one in particular has been repeatedly documented monetizing location data far beyond its apparent purpose, with the AccuWeather opt-out failure showing this isn't limited to a single company in the category.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2019", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SALE · FL-2] The Weather Channel's parent called itself 'a location data company powered by the weather,' selling continuous geolocation data to hedge funds and PE firms.\nWHAT THE TERMS SAY: TWC Product and Technology (owned by IBM) has been documented describing itself as 'a location data company powered by the weather,' selling precise, minute-by-minute geolocation data — tracked continuously, 'day and night, 365 days a year,' even when the app is closed — to third parties including private equity firms and hedge funds reportedly using it to monitor consumer spending patterns; TWC built a dedicated platform, JOURNEYfx, to commercialize this data within what litigation describes as a $21 billion location-targeting industry. The app's consent flow reportedly never disclosed this monetization, framing location access as needed only for 'personalized local weather data, alerts, and forecasts.'\nWHY IT MATTERS: Users granting a weather app continuous location access for forecasts were, per the litigation, unknowingly feeding a commercial data business used by financial firms to monitor spending — a use entirely disconnected from weather.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-2] Los Angeles's City Attorney sued The Weather Channel in 2019 over deceptive location-data sales, forcing a settlement requiring clearer disclosure.\nWHAT THE TERMS SAY: The LA City Attorney sued TWC in 2019 for deceptive data sale, seeking civil penalties up to $2,500 per violation; the case forced a settlement requiring clearer disclosure of the constant-tracking practice going forward.\nWHY IT MATTERS: The per-violation penalty framework reflects the scale of exposure given how many users were affected, though the tracker does not state the final amount actually paid.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DARK_PATTERN_CONSENT · FL-2] Security researchers found AccuWeather kept sharing user location data with a partner even after users opted out of location sharing.\nWHAT THE TERMS SAY: Security researchers documented AccuWeather continuing to share user location data with a partner (Reveal Mobile) even after users opted out of location sharing — a direct violation of the opt-out setting's own stated purpose.\nWHY IT MATTERS: An opt-out that doesn't actually stop the underlying data sharing gives users a false sense of control over their location data.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The business model, litigation history, dates, and settlement details are extensively and specifically documented, including a direct self-description quote.", "Exposure Score (0-100)": 23, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, precise_location_tracking+4) | Contract 0/20 (none) | Record 11/20 (severity3+8, penalty+3) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent", "Entity Type": "App / Service", "Ownership Path": "The Weather Channel (IBM) / AccuWeather  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using The Weather Channel (IBM) / AccuWeather you gave up your personal data sold onward and your physical movements. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T20:05:23Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "This is the most candid self-description of a data-monetisation business found anywhere in this tracker - and the underlying case is the reason it matters: the Los Angeles City Attorney sued The Weather Channel app in 2019 alleging it collected precise location data ostensibly to deliver local forecasts and then used it for advertising and analytics purposes users were not meaningfully told about. Weather apps are the perfect vehicle for location harvesting because the permission request is self-justifying: of course a weather app needs to know where you are. Users grant continuous background location without hesitation, and continuous background location is the single most valuable consumer data stream that exists.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Gig Economy, VPN & Subs", "_row_id": 370, "_entity_id": 556, "_entity_slug": "the-weather-channel-ibm-accuweather", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "HelloFresh", "Category": "Meal Kit Subscription", "Terms & Conditions URL": "hellofresh.com/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "hellofresh.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Meal-kit subscriptions broadly (not HelloFresh-specific) are frequently criticized industry-wide for AUTO-RENEWAL/cancellation friction similar to the gym and VPN patterns documented elsewhere in this tracker — not independently confirmed with a specific HelloFresh lawsuit this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; the auto-renewal/cancellation-friction pattern common to subscription businesses broadly (gyms, VPNs) plausibly extends here.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] HelloFresh's dietary selections reveal allergies, religion, and medical restrictions, unprotected as health data.\nWHAT THE TERMS SAY: The tracker notes that dietary selections made over time reveal allergies, religious observance, medical restrictions, and household size, and none of it is protected because it was generated by a grocery-style purchase rather than a medical record.\nWHY IT MATTERS: A meal-kit account can build a detailed sensitive-health profile of a subscriber without ever triggering the protections that would apply if the same facts were collected by a doctor's office.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data sharing and arbitration are both explicitly unconfirmed this pass ('standard...expected', 'not independently confirmed'), and the fees note is an industry-wide pattern not tied to a specific HelloFresh finding; only the dietary-data observation is company-specific.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing, arbitration, and fees are all unconfirmed this pass; only a general dietary-data observation is documented.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "HelloFresh  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, HelloFresh takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass on privacy. Meal kit services have generated sustained consumer complaint about subscription mechanics rather than data - trial pricing, auto-renewal, skip-week deadlines and cancellation friction - which is FTC negative-option territory and is the likelier consumer harm here. The data note that does hold: dietary selections over time reveal allergies, religious observance, medical restrictions and household size, and none of it is protected because it was generated by a grocery purchase.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Gig Economy, VPN & Subs", "_row_id": 371, "_entity_id": 557, "_entity_slug": "hellofresh", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Blue Apron (Wonder Group)", "Category": "Meal Kit Subscription", "Terms & Conditions URL": "blueapron.com/pages/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "blueapron.com/pages/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Blue Apron was ACQUIRED by Wonder Group in 2023 (following a period of significant financial distress as a publicly-traded company) — worth confirming current operational/ownership status directly, similar to the Mint-sunset note elsewhere in this tracker, since acquired subscription services sometimes change terms substantially post-acquisition.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SALE · FL-4] Blue Apron's 2023 acquisition by Wonder Group moved years of dietary and payment data to a new owner without fresh consent.\nWHAT THE TERMS SAY: Blue Apron was acquired by Wonder Group in 2023; the row's finding is that a subscriber's account, payment details, and multi-year dietary history transferred to a new corporate parent with its own privacy policy, and the subscriber's consent travelled with the asset without being asked again.\nWHY IT MATTERS: A consumer's sensitive purchase history changes hands as part of a corporate transaction without any breach occurring and without a new opt-in — the tracker notes this pattern recurs at other companies (Clarity Money, Bird, Orbitz, GIPHY) documented elsewhere in the tracker.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data sharing beyond the acquisition transfer, arbitration, and fees are all unconfirmed or not itemized this pass; only the M&A data-transfer finding is substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration and fee terms are unconfirmed this pass; the only documented item is the acquisition-driven data transfer.", "Exposure Score (0-100)": 10, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (data_sold_or_shared_for_value+8) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only", "Entity Type": "Company", "Ownership Path": "Blue Apron (Wonder Group)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Blue Apron (Wonder Group) you gave up your personal data sold onward. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Blue Apron was acquired by Wonder Group, which is the row's finding: a subscriber's account, payment details and multi-year dietary history transferred to a new corporate parent with its own privacy policy, and the subscriber's consent travelled with the asset without being asked again. That pattern recurs throughout this tracker - see Clarity Money, Bird, Orbitz and GIPHY - and it is the single most common way personal data changes hands without any breach occurring.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Gig Economy, VPN & Subs", "_row_id": 372, "_entity_id": 558, "_entity_slug": "blue-apron-wonder-group", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "NordVPN (Nord Security)", "Category": "VPN", "Terms & Conditions URL": "nordvpn.com/terms-of-service/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "nordvpn.com/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "UNVERIFIED 2026 BREACH CLAIM: a threat actor claimed to have accessed NordVPN development tools/Salesforce API keys; NordVPN DENIED any real breach occurred, stating attackers only reached a THIRD-PARTY TEST ENVIRONMENT containing DUMMY DATA that never connected to production systems or actual customer information — a disputed claim, not a confirmed breach, similar to the Wizz Air pattern documented elsewhere in this tracker. SEPARATELY, an independent infrastructure investigation found that Nord Security owns BOTH NordVPN and Surfshark (merged 2022) — together representing 54% of analyzed VPN network capacity — despite marketing them as separate, independent, competing services; Nord Security also owns the review site Cybernews via a subsidiary, raising a conflict-of-interest question about VPN 'independent reviews.'", "Arbitration / Class Action Waiver": "DIRECTLY REGIONAL, ACTIVE LAWSUIT (filed April 10, 2026, Virginia): accuses Nord Security of 'unlawful, unfair, and deceptive' AUTO-RENEWAL pricing practices, alleging the company makes it 'intentionally' and 'exceedingly difficult' for customers to cancel — the class action seeks to represent all Nord Security customers (across NordVPN, password manager NordPass, and encrypted storage NordLocker) in VIRGINIA AND NORTH CAROLINA specifically. NordVPN's own statement: 'we are and always have been very clear about the recurring nature of our services.' Notably, the SAME law firm previously investigated (but never filed suit against) ExpressVPN, Proton VPN, and Private Internet Access over similar allegations — one commentator described this pattern as possible 'lawsuit fishing' rather than confirmed wrongdoing.", "Fees / Billing Flags": "Auto-renewal cancellation friction is common across the WHOLE VPN industry (per multiple sources), not unique to NordVPN — Mullvad VPN is specifically cited as an exception that eliminated recurring subscriptions entirely in 2022.", "Notes": "THIS IS A DIRECTLY VIRGINIA-FILED LAWSUIT, making it one of the most regionally specific active cases in this entire tracker — worth flagging prominently given the exact geographic overlap with this tracker's Mid-Atlantic focus.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-4] Active Virginia class action accuses Nord Security of deceptively hard-to-cancel auto-renewal billing.\nWHAT THE TERMS SAY: A class action filed April 10, 2026 in Virginia alleges Nord Security's auto-renewal pricing is 'unlawful, unfair, and deceptive' and that the company makes cancellation 'intentionally' and 'exceedingly difficult' for customers across NordVPN, NordPass, and NordLocker, seeking to represent Virginia and North Carolina customers.\nWHY IT MATTERS: If the allegations hold, subscribers may be locked into recurring charges they struggled to cancel; NordVPN disputes this, stating it has always been clear about the recurring nature of its services, and the same law firm previously investigated other VPNs without filing suit.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-4] Nord Security owns NordVPN and 'rival' Surfshark plus the review site Cybernews, undisclosed to shoppers comparing them.\nWHAT THE TERMS SAY: An independent infrastructure investigation found Nord Security owns both NordVPN and Surfshark (merged 2022), together representing 54% of analyzed VPN network capacity, while marketing them as separate, competing services; Nord Security also owns the review site Cybernews via a subsidiary.\nWHY IT MATTERS: A consumer comparing 'independent' VPN options, or reading 'independent' reviews, may unknowingly be choosing between two products from the same owner or reading a review published by that owner.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] A 2026 claim of NordVPN dev-tool and Salesforce access is unverified and disputed by the company.\nWHAT THE TERMS SAY: A threat actor claimed to have accessed NordVPN development tools and Salesforce API keys; NordVPN denies any real breach occurred, stating the attacker only reached a third-party test environment containing dummy data that never connected to production systems or actual customer information.\nWHY IT MATTERS: The tracker itself cautions that an attacker's assertion is a lead, not a finding, until independently corroborated — this should not be treated as a confirmed exposure of customer data.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Litigation and ownership-structure facts are documented, but the breach claim is explicitly disputed and unverified.", "Exposure Score (0-100)": 16, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 10/20 (severity3+8, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "NordVPN (Nord Security)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using NordVPN (Nord Security) you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2026 breach claim is unverified and should stay that way in any published writeup until corroborated - an attacker's assertion is a lead, not a finding, consistent with how the Liberty Mutual and MetLife claims are handled elsewhere in this tracker. The structural point for the whole VPN category is more useful than any single claim: a VPN does not eliminate the observer, it relocates them from your ISP to the VPN operator, and a no-logs policy describes what a company retains by default rather than what a court can compel it to begin collecting. Cross-ref the Proton Mail row in Email Providers, where exactly that compulsion occurred.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Gig Economy, VPN & Subs", "_row_id": 373, "_entity_id": 559, "_entity_slug": "nordvpn-nord-security", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "ExpressVPN (Kape Technologies)", "Category": "VPN", "Terms & Conditions URL": "expressvpn.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "expressvpn.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "OWNERSHIP TRANSPARENCY FINDING: ExpressVPN is owned by Kape Technologies (Israel/UK), which ALSO owns CyberGhost, Private Internet Access (PIA), and ZenMate — all marketed as independently competing VPN brands. Kape ADDITIONALLY owns VPN REVIEW SITES vpnMentor, Wizcase, and Safety Detectives — meaning the same parent company that sells ExpressVPN also operates sites that publish 'independent' VPN reviews and rankings, a genuine conflict-of-interest concern for anyone relying on those review sites to choose objectively among VPN providers.", "Arbitration / Class Action Waiver": "The same law firm that sued NordVPN over auto-renewal practices (see NordVPN row) had PREVIOUSLY investigated ExpressVPN over similar allegations but ultimately did NOT file suit — worth noting this as a non-outcome rather than a confirmed finding of wrongdoing.", "Fees / Billing Flags": "Standard subscription auto-renewal model common across the VPN industry — no ExpressVPN-specific billing lawsuit independently confirmed this pass.", "Notes": "The Kape-owned review-site conflict of interest is arguably a more actionable, concrete 'thing to know' for consumers than any single lawsuit — worth flagging that 'independent' VPN review sites may be financially connected to the very products they're reviewing.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] ExpressVPN's owner, Kape Technologies, also owns 'rival' VPNs and the review sites that rank them.\nWHAT THE TERMS SAY: ExpressVPN is owned by Kape Technologies, which also owns CyberGhost, Private Internet Access, and ZenMate — all marketed as independently competing brands — plus the VPN review sites vpnMentor, Wizcase, and Safety Detectives; Kape was formerly named Crossrider, a company whose earlier business involved an advertising and browser-extension platform associated with adware distribution.\nWHY IT MATTERS: A consumer comparing 'independent' VPN reviews may be reading recommendations published by the same company that sells the product being recommended, and none of this ownership history is disclosed in ExpressVPN's own privacy policy.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data sharing and fees fields report no ExpressVPN-specific lawsuit or breach confirmed this pass, and the law firm's investigation of ExpressVPN never resulted in a filed suit — only the Kape ownership-transparency finding is substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Ownership structure is clearly documented, but ExpressVPN's own billing and arbitration specifics are not independently confirmed this pass.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "ExpressVPN (Kape Technologies)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, ExpressVPN (Kape Technologies) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T20:05:33Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "ExpressVPN is owned by Kape Technologies, and the ownership history is the finding: Kape was formerly named Crossrider, a company whose earlier business involved an advertising and browser-extension platform associated with adware distribution. Kape also owns CyberGhost, Private Internet Access and Zenmate, plus VPN review sites - meaning a consumer comparing VPNs across apparently independent review sources may be reading recommendations published by the owner of the products being recommended. None of that is illegal and the past does not determine the present, but for a product category whose entire value proposition is trust in the operator, ownership concentration and history are material facts that no privacy policy discloses.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Gig Economy, VPN & Subs", "_row_id": 374, "_entity_id": 560, "_entity_slug": "expressvpn-kape-technologies", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Wegmans", "Category": "Grocery", "Terms & Conditions URL": "wegmans.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "wegmans.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED, REGULATOR-PENALIZED BREACH (NY AG settlement, 2022): Wegmans left TWO cloud storage databases MISCONFIGURED AND PUBLICLY ACCESSIBLE for YEARS — one had been openly accessible since it was set up in November 2018, undetected until 2021 — exposing personal information of more than 3 MILLION consumers nationwide (830,000+ in New York alone), including usernames/passwords, names, emails, mailing addresses, and data DERIVED FROM driver's license numbers. NY AG Letitia James found Wegmans had failed to even INVENTORY its own cloud assets containing personal data, and had kept driver's-license-derived checksums 'without a reasonable business purpose.' Wegmans paid $400,000 in NY penalties and must now maintain a comprehensive security program, annual penetration testing, and 90-day-minimum activity logging. SEPARATELY, Wegmans disclosed a 2021 CREDENTIAL-STUFFING attack (using passwords stolen from OTHER, unrelated breaches) that compromised 2,700+ Wegmans.com accounts.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Wegmans.com ToS, AAA rules. 30-day opt-out. Wegmans is a privately held family-owned chain (Rochester, NY) expanding into the mid-Atlantic — the arbitration clause governs online ordering, the Wegmans app, and the Shoppers Club loyalty program.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Wegmans operates stores directly in Maryland and Virginia (part of its Mid-Atlantic/Northeast footprint) — making this directly relevant to regional shoppers; the years-long misconfigured-database exposure is a clean illustration of a preventable, purely internal-process failure (not a sophisticated hack) that regulators specifically penalized.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Rochester", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Rochester, New York (non-US)", "Parent / Ultimate Owner": "Wegmans Food Markets, Inc. (privately held)", "Years Referenced in Finding (heuristic)": "2022", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Wegmans Food Markets, Inc. (privately held)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] NY AG fined Wegmans $400K after two misconfigured cloud databases exposed 3M+ consumers' data for years.\nWHAT THE TERMS SAY: Wegmans left two cloud storage databases misconfigured and publicly accessible — one exposed since November 2018 and undetected until 2021 — exposing usernames/passwords, names, emails, addresses, and data derived from driver's license numbers for more than 3 million consumers (830,000+ in New York). The NY AG found Wegmans had not even inventoried its own cloud assets holding personal data and had retained driver's-license-derived checksums without a reasonable business purpose.\nWHY IT MATTERS: Wegmans paid $400,000 and must now run annual penetration testing and maintain 90-day activity logging — a preventable configuration error, not a sophisticated hack, exposed years of customer data.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] A separate 2021 credential-stuffing attack compromised 2,700+ Wegmans.com accounts.\nWHAT THE TERMS SAY: Wegmans disclosed a 2021 credential-stuffing attack, using passwords stolen from other, unrelated breaches, that compromised more than 2,700 Wegmans.com accounts.\nWHY IT MATTERS: Customers who reused passwords across sites faced account-takeover risk on Wegmans.com, separate from the larger cloud-database exposure.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Wegmans requires binding arbitration with a class-action waiver for online orders, app use, and Shoppers Club.\nWHAT THE TERMS SAY: Wegmans.com's Terms of Service impose mandatory binding arbitration under AAA rules with a class-action waiver and a 30-day opt-out window, covering online ordering, the Wegmans app, and the Shoppers Club loyalty program.\nWHY IT MATTERS: Customers must proactively opt out within 30 days or give up the right to sue Wegmans in court or join a class action.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Both the breach/penalty and arbitration terms are clearly documented with specific figures.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity3+8, breach+3, penalty+3) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Wegmans  <-  Wegmans Food Markets, Inc. (privately held)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Wegmans you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Wegmans was penalised by the New York Attorney General over a breach in 2022, and the cause is the kind that is hardest to defend: misconfigured cloud storage left customer data publicly accessible. No attacker skill was required - the container was simply left open, which is an unforced error rather than an adversary overcoming a defence. Grocery loyalty data is also more revealing than people assume, since purchase history supports inferences about pregnancy, chronic illness, addiction, religious observance and household composition without any of it being declared.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Regional Grocery & Restaurants", "_row_id": 375, "_entity_id": 562, "_entity_slug": "wegmans", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Giant Food (Ahold Delhaize)", "Category": "Grocery", "Terms & Conditions URL": "giantfood.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "giantfood.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MASSIVE, DIRECTLY REGIONAL BREACH (Nov 2024, still generating litigation in 2026): Giant Food's parent company Ahold Delhaize USA (also owner of Food Lion, Hannaford, and Stop & Shop) confirmed a ransomware attack (INC Ransom group, claiming 6+ TERABYTES exfiltrated) affecting OVER 2.2 MILLION individuals — the MAJORITY being current/former EMPLOYEES, dependents, and beneficiaries rather than shoppers. Exposed data included contact information, birth dates, Social Security numbers, PASSPORT numbers, driver's license numbers, and financial/HEALTH information. The attack forced Giant Food's e-commerce and business systems offline temporarily. Ahold Delhaize is offering 2 years of free credit monitoring/identity protection to affected individuals.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Giant Food's ToS, likely governed by Ahold Delhaize's group-level terms. 30-day opt-out. Giant Food is the dominant grocery chain in the DMV corridor. The Nov 2024 Ahold Delhaize ransomware breach (2.2M people) means the arbitration clause directly affects breach victims in the DMV region.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "GIANT FOOD IS ONE OF THE MOST DOMINANT GROCERY CHAINS IN THE DC/MD/VA REGION SPECIFICALLY — this breach directly affects Mid-Atlantic employees and their families; worth flagging prominently given how many regional households likely have a connection to Giant Food as either customers or, more significantly here, as current/former employees given the employee-majority breach population.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Landover", "HQ State": "Maryland", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": "https://www.cybersecuritydive.com/news/ahold-delhaize-usa-cyberattack-grocery-personal-data-exposed/751971/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ: Landover, Maryland (DC/MD/VA)", "Parent / Ultimate Owner": "Ahold Delhaize", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Maryland SDAT Business Entity Search — egov.maryland.gov/businessexpress/entitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Ahold Delhaize). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] November 2024 ransomware attack on Giant Food's parent exposed SSNs and passport numbers for 2.2M+ people.\nWHAT THE TERMS SAY: Ahold Delhaize USA (parent of Giant Food, Food Lion, Hannaford, and Stop & Shop) confirmed a ransomware attack by the INC Ransom group, which claimed to exfiltrate 6+ terabytes, affecting over 2.2 million individuals — mostly current/former employees, dependents, and beneficiaries rather than shoppers — exposing contact information, birth dates, Social Security numbers, passport numbers, driver's license numbers, and financial/health information. Ahold Delhaize is offering 2 years of free credit monitoring.\nWHY IT MATTERS: The breach forced e-commerce systems offline temporarily and is, per the tracker, still generating litigation in 2026; a large share of those exposed are employees and their families, so the harm reaches households through a job connection, not just shopping.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Giant Food requires binding arbitration with a class-action waiver under Ahold Delhaize's group-level terms.\nWHAT THE TERMS SAY: Giant Food's Terms of Service impose mandatory binding arbitration with a class-action waiver, likely governed by Ahold Delhaize's group-level terms, with a 30-day opt-out window.\nWHY IT MATTERS: Breach victims among Giant Food's customers and employees are subject to this arbitration clause when pursuing claims related to the November 2024 breach, unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct company-specific facts are documented — the breach and the arbitration clause; fees are not itemized and litigation is only generically referenced without case specifics.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The breach's scope and the arbitration clause are both clearly stated with specific figures, though fees are not itemized.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Giant Food (Ahold Delhaize)  <-  Ahold Delhaize", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Giant Food (Ahold Delhaize) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "This is the most directly regional finding in the tracker: Ahold Delhaize USA - parent of Giant Food, Food Lion, Hannaford and Stop & Shop - confirmed a November 2024 ransomware attack affecting over 2.2 million people, with the INC Ransom group claiming more than 6 terabytes exfiltrated. The exposed data included Social Security numbers, PASSPORT numbers, driver's licence numbers and financial and health information - and the MAJORITY of those affected were current and former EMPLOYEES, dependents and beneficiaries rather than shoppers. Giant is one of the dominant grocery chains across DC, Maryland and Virginia, which means a very large number of Mid-Atlantic households are connected to this breach through a family member's job rather than through their weekly shop.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Regional Grocery & Restaurants", "_row_id": 376, "_entity_id": 564, "_entity_slug": "giant-food-ahold-delhaize", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Harris Teeter (Kroger)", "Category": "Grocery", "Terms & Conditions URL": "harristeeter.com/i/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "harristeeter.com/i/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Harris Teeter is a WHOLLY-OWNED SUBSIDIARY OF THE KROGER CO. — meaning the major findings already documented for Kroger elsewhere in this tracker (the Meta Pixel/pharmacy-data lawsuits, the Accellion vendor breach exposing 3.5 million records, and the pharmacy-overcharging allegations) plausibly extend to Harris Teeter's own operations and shared corporate data infrastructure, even though Harris Teeter was not independently named in a separate lawsuit this pass. Harris Teeter's own privacy notice explicitly carves out FINANCIAL products/services (governed separately under the Gramm-Leach-Bliley Act via 'The Kroger Family of Stores' shared financial-privacy policy) — confirming the shared-infrastructure relationship directly in its own privacy documentation.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Governed by Kroger's Terms & Conditions (Harris Teeter became a Kroger subsidiary in 2014). 30-day opt-out. Harris Teeter is a major DMV grocery chain — a consumer shopping at Harris Teeter in Virginia is bound by Cincinnati-based Kroger's arbitration terms.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Kroger row (Consumer Apps tab) for the full underlying findings that plausibly extend to Harris Teeter given the shared parent-company/infrastructure relationship explicitly acknowledged in Harris Teeter's own privacy notice.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Harris Teeter binds shoppers to Kroger's mandatory arbitration and class-action waiver, 30-day opt-out.\nWHAT THE TERMS SAY: Harris Teeter's Terms & Conditions are governed by Kroger's group-level agreement (Harris Teeter became a Kroger subsidiary in 2014), imposing mandatory binding arbitration with a class-action waiver and a 30-day opt-out window.\nWHY IT MATTERS: A Virginia shopper at Harris Teeter is bound by Cincinnati-based Kroger's arbitration terms rather than a locally negotiated agreement.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Harris Teeter's own privacy notice confirms it shares data infrastructure with parent Kroger under a group-wide policy.\nWHAT THE TERMS SAY: Harris Teeter's privacy notice explicitly carves out financial products/services, governed separately under the Gramm-Leach-Bliley Act via 'The Kroger Family of Stores' shared financial-privacy policy — confirming a shared data infrastructure with its parent.\nWHY IT MATTERS: This shared-infrastructure relationship is why the tracker treats Kroger's own, separately documented data findings (e.g. the Meta Pixel/pharmacy-data lawsuits, another company's row) as plausibly, though not confirmedly, extending to Harris Teeter's operations.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DARK_PATTERN_CONSENT · FL-2] Kroger-style loyalty pricing at Harris Teeter makes the loyalty card effectively compulsory to get sale prices.\nWHAT THE TERMS SAY: The row states that Kroger's loyalty pricing structure, which applies to Harris Teeter, sets shelf prices so that declining the loyalty card means paying materially more — making enrollment effectively compulsory rather than optional.\nWHY IT MATTERS: Shoppers who want fair prices must accept purchase tracking, since opting out of the loyalty program carries a real cost rather than being a free choice.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Harris Teeter's own record is thin — most substantive findings belong to parent Kroger and only plausibly extend here.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Harris Teeter (Kroger)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Harris Teeter (Kroger) you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T20:06:20Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Harris Teeter is wholly owned by Kroger, so the findings that matter here are Kroger's - including the two pharmacy-specific class actions documented in the Online Retailers tab, where a grocer operating pharmacies holds prescription records alongside loyalty data covering everything else you buy. Shoppers in the DMV who chose Harris Teeter over Giant as a matter of preference made a brand choice, not a data choice. Kroger's loyalty pricing structure also makes the card effectively compulsory, since shelf prices are set so that declining it means paying materially more.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Regional Grocery & Restaurants", "_row_id": 377, "_entity_id": 565, "_entity_slug": "harris-teeter-kroger", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Food Lion (Ahold Delhaize)", "Category": "Grocery", "Terms & Conditions URL": "foodlion.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "foodlion.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SAME 2024 AHOLD DELHAIZE BREACH as Giant Food (see that row) — Food Lion (headquartered in Salisbury, NC, founded 1957, sold to Ahold in 2016) operates 1,100+ stores across 10 Southeastern/Mid-Atlantic states with 82,000+ employees, making it one of the LARGEST individual banners affected by the shared 2.2-million-person breach. At least 387,000+ North Carolina residents alone were confirmed affected (the largest single-state count disclosed). One named plaintiff in the resulting litigation alleges his stolen data was 'subsequently published and sold on the dark web.'", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Same Ahold Delhaize group terms as Giant Food. 30-day opt-out. Food Lion operates across the mid-Atlantic and Southeast. Affected by the Nov 2024 Ahold Delhaize ransomware breach.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See Giant Food row for full shared-parent-company breach details — Food Lion, Giant Food, Hannaford, and Stop & Shop should be treated as ONE connected finding (same breach, same parent company, same timeframe) rather than four independent incidents.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Salisbury", "HQ State": "North Carolina", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": "https://www.cybersecuritydive.com/news/ahold-delhaize-usa-cyberattack-grocery-personal-data-exposed/751971/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ: Salisbury, North Carolina (non-US)", "Parent / Ultimate Owner": "Ahold Delhaize", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NC SOS Business Registration Search — sosnc.gov/online_services/search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Ahold Delhaize). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Food Lion, hit by the same 2024 Ahold Delhaize breach, confirms 387,000+ North Carolina residents affected.\nWHAT THE TERMS SAY: Food Lion (1,100+ stores, 82,000+ employees) was one of the largest banners hit by the shared 2.2-million-person Ahold Delhaize ransomware breach; at least 387,000+ North Carolina residents were confirmed affected — the largest single-state count disclosed — and one named plaintiff in the resulting litigation alleges his stolen data was subsequently published and sold on the dark web.\nWHY IT MATTERS: For Food Lion's rural and small-town Southeastern/Mid-Atlantic customers, this is the same large-scale exposure of SSNs, passport, and driver's license numbers documented for Giant Food, now with an allegation of actual dark-web resale.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Food Lion requires the same Ahold Delhaize group-wide binding arbitration and class-action waiver, 30-day opt-out.\nWHAT THE TERMS SAY: Food Lion's Terms of Service use the same Ahold Delhaize group arbitration terms as Giant Food: mandatory binding arbitration with a class-action waiver and a 30-day opt-out window.\nWHY IT MATTERS: Customers pursuing claims tied to the 2024 breach are bound by this arbitration clause unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only the shared Ahold Delhaize breach and Food Lion's arbitration clause are company-specific facts; fees are not itemized this pass.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Breach scope and arbitration terms are both clearly documented with specific figures.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Food Lion (Ahold Delhaize)  <-  Ahold Delhaize", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Food Lion (Ahold Delhaize) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same November 2024 Ahold Delhaize breach as Giant Food - one parent company, one incident, 2.2 million people, recorded as a single connected finding rather than two. Food Lion's footprint skews toward smaller and more rural Southeastern and Mid-Atlantic markets, where it is frequently the only full-service grocery within reasonable distance. That matters for the same reason it did in the rural hospital and rural ISP rows: the market response a consumer is supposed to have available - shop elsewhere - does not exist.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Regional Grocery & Restaurants", "_row_id": 378, "_entity_id": 566, "_entity_slug": "food-lion-ahold-delhaize", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Trader Joe's", "Category": "Grocery", "Terms & Conditions URL": "traderjoes.com/home/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "traderjoes.com/home/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "NO CLASS ACTION WAIVER identified in Trader Joe's publicly available terms. Trader Joe's (Aldi Nord subsidiary) maintains a minimal digital footprint — no app, no loyalty program, limited online ordering — which means fewer digital T&C touchpoints than competitors. The absence of a digital-first relationship means the arbitration question is primarily about in-store purchase disputes, which are typically governed by state consumer protection law rather than clickthrough agreements.", "Fees / Billing Flags": "ACTIVE PRODUCT-LABELING LITIGATION (2026): a class action alleges Trader Joe's 'Low Acid Dark French Roast Coffee' is misleadingly marketed as low-acid when it is allegedly a regular-acidity coffee — a food-labeling claim distinct from data privacy.", "Notes": "Recommend a direct follow-up on data-privacy practices specifically given thin verification this pass; the product-labeling case above is a different category of consumer-protection concern.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-1] A 2026 class action alleges Trader Joe's 'Low Acid' dark roast coffee is mislabeled as low-acid.\nWHAT THE TERMS SAY: A class action filed in 2026 alleges Trader Joe's 'Low Acid Dark French Roast Coffee' is misleadingly marketed as low-acid when it is allegedly a regular-acidity coffee.\nWHY IT MATTERS: If proven, customers who chose the product specifically for its acid content paid for a claim the product may not meet — though this is a food-labeling issue, not a data-privacy one.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-privacy fields are unconfirmed this pass, no class-action waiver was identified in Trader Joe's terms, and the company runs no loyalty program — the only substantive item is the unrelated product-labeling lawsuit.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Data-privacy findings are unconfirmed, though the absence of a class-action waiver and arbitration clause is clearly documented.", "Exposure Score (0-100)": 4, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Trader Joe's  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Trader Joe's takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass, and the structural note is genuinely favourable: Trader Joe's has famously declined to run a loyalty programme at all, which means it does not build the purchase-history profile every other grocer in this tab holds. Per the project guide's instruction to say so when a company looks better than peers, the absence of a loyalty scheme is a real and unusual data-minimisation choice, whatever its commercial motivation. The caveat is that payment card data still identifies repeat customers, and in-store analytics operate regardless. Unverified rather than clean, but the structural difference is documented.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Regional Grocery & Restaurants", "_row_id": 379, "_entity_id": 567, "_entity_slug": "trader-joe-s", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cracker Barrel", "Category": "Restaurant", "Terms & Conditions URL": "crackerbarrel.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "crackerbarrel.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Cracker Barrel Old Country Store ToS. 30-day opt-out. Covers the Cracker Barrel app, online ordering, and Cracker Barrel Rewards. Tennessee law governs (HQ: Lebanon, TN).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "HISTORICAL, SIGNIFICANT CIVIL RIGHTS LITIGATION (distinct category from data privacy): Cracker Barrel was investigated by the US DEPARTMENT OF JUSTICE (2002) under Title II of the Civil Rights Act following multiple lawsuits alleging RACIAL DISCRIMINATION against Black customers across several states (Arkansas, Georgia, North Carolina, Mississippi) — the company denied wrongdoing and characterized some claims as 'recycled' from earlier unsuccessful Georgia litigation, but engaged in mediation attempts (2003-2004) while the DOJ investigation proceeded. This is an EMPLOYMENT/CIVIL-RIGHTS finding rather than a data-privacy one, included here for completeness given its historical significance, though it predates and is unrelated to the data-privacy focus of most other findings in this tracker; recommend verifying current status directly given how old this specific litigation is.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Cracker Barrel requires binding arbitration with a class-action waiver for its app, ordering, and Rewards program.\nWHAT THE TERMS SAY: Cracker Barrel Old Country Store's Terms of Service impose mandatory binding arbitration with a class-action waiver, a 30-day opt-out window, covering the Cracker Barrel app, online ordering, and Cracker Barrel Rewards, governed by Tennessee law.\nWHY IT MATTERS: Rewards program members and app users give up their right to sue in court or join a class action unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DISCRIMINATORY_PRACTICE · FL-1] Cracker Barrel faced a 2002 DOJ Title II investigation over racial-discrimination allegations across several states.\nWHAT THE TERMS SAY: The US Department of Justice investigated Cracker Barrel in 2002 under Title II of the Civil Rights Act following lawsuits alleging racial discrimination against Black customers in Arkansas, Georgia, North Carolina, and Mississippi; Cracker Barrel denied wrongdoing, characterized some claims as 'recycled' from earlier unsuccessful Georgia litigation, and engaged in mediation attempts (2003-2004) while the investigation proceeded.\nWHY IT MATTERS: This is a historical civil-rights matter, not a data-privacy finding, and predates the tracker's usual focus by over two decades — the tracker recommends verifying current status directly given its age.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data-privacy fields are unconfirmed this pass and fees are not itemized; the two substantive items are the arbitration clause and a decades-old, unrelated civil-rights investigation.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clear, but data-privacy findings are unconfirmed and the civil-rights matter is old and unverified as to current status.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Cracker Barrel  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Cracker Barrel you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T20:06:25Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Restaurant chains sit in a lower-sensitivity tier than most of this tracker, with the meaningful exposure running through point-of-sale payment systems and any loyalty app. The category note worth recording is that restaurant POS breaches have historically been among the most common in retail because franchise and multi-location operators run heterogeneous systems with inconsistent patching, and payment data sits directly on the terminal. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Regional Grocery & Restaurants", "_row_id": 380, "_entity_id": 568, "_entity_slug": "cracker-barrel", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Panera Bread", "Category": "Restaurant", "Terms & Conditions URL": "panerabread.com/en-us/terms-of-use.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "panerabread.com/en-us/privacy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "A GENUINE 'DOUBLE JEOPARDY' PATTERN OF REPEATED BREACHES: (1) Panera was notified by an independent security researcher (Dylan Houlihan) as early as AUGUST 2017 about a vulnerability, but reportedly failed to fix it promptly. (2) A 2024 breach specifically affected roughly 26,000+ EMPLOYEES, resulting in a $2.5 MILLION settlement (final approval hearing Jan 29, 2026) — that settlement was STILL BEING FINALIZED when (3) a completely SEPARATE, NEW breach hit in January 2026: the ShinyHunters hacking group (the SAME group responsible for the Air France/KLM and Workday breaches documented elsewhere in this tracker) accessed Panera's network via a THIRD-PARTY SaaS application through a 'social engineering' attack, exposing customer names, emails, phone numbers, addresses, genders, birthdates, and PURCHASE HISTORIES for approximately 5.1 MILLION unique customers (from an initially-claimed 14 million total records) — payment data, MyPanera loyalty accounts, and Unlimited Sip Club accounts were reportedly NOT affected, per Panera's CEO. When Panera allegedly REFUSED to pay a ransom demand, ShinyHunters published a 760-megabyte data archive on its leak site. At least SEVEN separate class actions were filed within weeks in Missouri federal court (Cardin, Cipriani, Keleshian, and others), alleging negligence, unjust enrichment, and invasion of privacy — plaintiffs specifically point to Panera's PRIOR 2017 vulnerability-notification history as evidence of a longstanding pattern of inadequate security attention, not an isolated incident.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Panera's Terms of Use, AAA rules. 30-day opt-out. Covers the Panera app, MyPanera loyalty program, and delivery orders. Panera was taken private by JAB Holding (2017) then announced plans to re-IPO (2024). The arbitration clause covers disputes over Panera's extensive data collection through its loyalty program.", "Fees / Billing Flags": "The 2024 employee breach settlement ($2.5 million) is separate and already in the claims process; no court-approved claims site existed yet for the 2026 customer breach as of this research — customers should retain any dark-web notification they received in case a future settlement requires it as documentation.", "Notes": "The THREE SEPARATE, DOCUMENTED SECURITY LAPSES spanning 2017-2026 (a slow-fixed vulnerability, an employee breach, and a customer breach) make Panera one of the more persistently-breached restaurant chains in this entire tracker — worth flagging the pattern's DURATION as much as any single incident's severity.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Panera has suffered three separate security lapses since 2017, including a 2026 breach of 5.1M customers' data.\nWHAT THE TERMS SAY: Panera was notified of a vulnerability by a researcher in August 2017 but reportedly failed to fix it promptly; a 2024 breach affecting 26,000+ employees resulted in a $2.5 million settlement (final approval hearing Jan 29, 2026); while that settlement was still being finalized, a January 2026 breach by the ShinyHunters group — via a third-party SaaS application through a social-engineering attack — exposed names, emails, phone numbers, addresses, genders, birthdates, and purchase histories for approximately 5.1 million unique customers (down from an initially claimed 14 million records). Payment data, MyPanera, and Unlimited Sip Club accounts were reportedly not affected. When Panera allegedly refused to pay a ransom, ShinyHunters published a 760-megabyte data archive.\nWHY IT MATTERS: Plaintiffs in the resulting suits point to the 2017 vulnerability-notification history as evidence of a longstanding pattern of inadequate security attention rather than an isolated incident.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] At least seven class actions were filed within weeks of the 2026 Panera breach in Missouri federal court.\nWHAT THE TERMS SAY: At least seven separate class actions (including Cardin, Cipriani, and Keleshian) were filed in Missouri federal court alleging negligence, unjust enrichment, and invasion of privacy tied to the January 2026 breach.\nWHY IT MATTERS: Affected customers have multiple concurrent suits pursuing claims, though no court-approved claims site existed yet for this breach as of the tracker's research.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Panera requires binding arbitration with a class-action waiver covering its app, loyalty program, and delivery orders.\nWHAT THE TERMS SAY: Panera's Terms of Use impose mandatory binding arbitration under AAA rules with a class-action waiver and a 30-day opt-out window, covering the Panera app, MyPanera loyalty program, and delivery orders.\nWHY IT MATTERS: This clause covers disputes over the same extensive loyalty-program data collection implicated in the 2026 breach, unless a customer opts out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Breach details, litigation, and arbitration terms are all specifically documented with dates and figures.", "Exposure Score (0-100)": 31, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 7, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 7/20 (severity2+2, breach+3, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Panera Bread  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Panera Bread you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Panera shows a genuine double-jeopardy pattern of repeated breaches, and the first one carries a detail worth remembering: the original exposure was reported to Panera by an outside security researcher and, by that researcher's account, went substantially unaddressed for a long period before it became public. That is a disclosure-handling failure rather than a security failure, and it is the more damaging of the two, because a company that ignores a free warning has removed the last defence it had. Panera's loyalty programme also ties order history to identity across every location.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Regional Grocery & Restaurants", "_row_id": 381, "_entity_id": 569, "_entity_slug": "panera-bread", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CAVA", "Category": "Restaurant (DMV-founded)", "Terms & Conditions URL": "cava.com/pages/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "cava.com/pages/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. CAVA's Terms of Service, AAA rules. 30-day opt-out. CAVA (HQ: Washington DC) is a DMV-headquartered fast-casual chain that went public in 2023. The arbitration clause covers the CAVA app, online ordering, and the rewards program. As a DC-headquartered company, this is a DMV-relevant arbitration clause.", "Fees / Billing Flags": "PRODUCT-SAFETY LITIGATION (Hamman v. Cava Group, filed April 2022, S.D. California, still pending through at least 2023 per CAVA's own SEC filings): alleges CAVA's grain and salad bowl PACKAGING contains elevated levels of ORGANIC FLUORINE and unsafe PFAS ('forever chemicals'), making certain products 'unfit for human consumption,' and that CAVA misled consumers with health/sustainability marketing claims — plaintiffs seek compensatory damages and MEDICAL MONITORING (a request specifically reserved for cases alleging a real risk of future illness from a documented exposure). A court partially denied CAVA's motion to dismiss (Feb 2023), allowing at least some claims to proceed.", "Notes": "CAVA WAS FOUNDED IN THE DMV REGION (Rockville, MD, 2006) and has grown into a national fast-casual chain while remaining closely associated with this area — the PFAS packaging allegation is a genuine product-safety concern distinct from the data-privacy findings that dominate most of this tracker, relevant given how many Mid-Atlantic residents regularly eat at CAVA specifically because of its local roots.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-1] A pending PFAS lawsuit alleges CAVA's bowl packaging contains 'forever chemicals' making products unfit to eat.\nWHAT THE TERMS SAY: Hamman v. Cava Group (filed April 2022, S.D. California) alleges CAVA's grain and salad bowl packaging contains elevated organic fluorine and unsafe PFAS levels, making certain products 'unfit for human consumption,' and that CAVA misled consumers with health/sustainability marketing claims; a court partially denied CAVA's motion to dismiss in February 2023, allowing at least some claims to proceed. Plaintiffs seek compensatory damages and medical monitoring.\nWHY IT MATTERS: Medical monitoring is a remedy reserved for cases alleging a real risk of future illness from documented exposure, so these claims — still pending through at least 2023 per CAVA's own SEC filings — go beyond a simple labeling dispute.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] CAVA requires binding arbitration with a class-action waiver for its app, ordering, and rewards program.\nWHAT THE TERMS SAY: CAVA's Terms of Service impose mandatory binding arbitration under AAA rules with a class-action waiver and a 30-day opt-out window, covering the CAVA app, online ordering, and the rewards program.\nWHY IT MATTERS: As a DC-headquartered chain, this DMV-relevant arbitration clause applies to any dispute customers bring over the app or rewards program unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DARK_PATTERN_CONSENT · FL-2] CAVA's digital ordering and loyalty model tie order history, location, and payment data to an account by default.\nWHAT THE TERMS SAY: The tracker notes CAVA's digital ordering and loyalty model means order history, location, and payment data are tied to an account by default rather than by choice, with app-only pricing and rewards functioning the same way grocery loyalty pricing does: the discount is real and the price of it is the profile.\nWHY IT MATTERS: Customers seeking the best price are steered toward accepting the tracking rather than freely choosing it.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "PFAS litigation and arbitration terms are documented, but data-privacy findings are unconfirmed this pass.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "CAVA  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using CAVA you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. CAVA is a DC-area-founded chain with heavy Mid-Atlantic presence, which makes it locally relevant even without a finding, and its digital ordering and loyalty model means order history, location and payment data are tied to an account by default rather than by choice. Fast-casual chains have also moved aggressively into app-only pricing and rewards, which functions the same way grocery loyalty pricing does - the discount is real and the price of it is the profile. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Regional Grocery & Restaurants", "_row_id": 382, "_entity_id": 570, "_entity_slug": "cava", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Bob Evans (Post Holdings)", "Category": "Restaurant", "Terms & Conditions URL": "bobevans.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "bobevans.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Post Holdings ToS govern Bob Evans Farms (acquired 2017). 30-day opt-out. Bob Evans restaurants were sold separately to the restaurant chain; this row covers the grocery/retail food products sold under the Bob Evans brand.", "Fees / Billing Flags": "ACTIVE PRODUCT-LABELING LITIGATION (2026): a class action against parent company Post Holdings alleges Bob Evans macaroni and cheese is falsely marketed as containing 'no artificial preservatives' — a food-labeling claim distinct from data privacy.", "Notes": "Bob Evans restaurant locations and Bob Evans-branded packaged grocery products (like the mac and cheese in this lawsuit) are operated by DIFFERENT companies following a 2017 sale — worth confirming which entity (restaurant operator vs. Post Holdings packaged foods) governs any specific Bob Evans product or service before citing this finding.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-1] A 2026 class action alleges Post Holdings falsely marketed Bob Evans mac and cheese as having 'no artificial preservatives.'\nWHAT THE TERMS SAY: A class action filed in 2026 against parent company Post Holdings alleges Bob Evans macaroni and cheese is falsely marketed as containing 'no artificial preservatives.'\nWHY IT MATTERS: This is a food-labeling claim, not a data-privacy issue — if proven, customers who paid for the 'no artificial preservatives' claim got a product that may not meet it.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Bob Evans requires binding arbitration with a class-action waiver under Post Holdings' terms.\nWHAT THE TERMS SAY: Post Holdings' Terms of Service, which govern Bob Evans Farms (acquired 2017), impose mandatory binding arbitration with a class-action waiver and a 30-day opt-out window.\nWHY IT MATTERS: Customers of Bob Evans-branded products give up the right to sue in court or join a class action unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data-privacy fields are unconfirmed and the ownership-split note is a clarifying fact rather than a consumer harm; only the labeling lawsuit and the arbitration clause are substantive.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and the labeling lawsuit are documented, but data-privacy findings are unconfirmed.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Bob Evans (Post Holdings)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Bob Evans (Post Holdings) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T20:07:42Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. The note worth recording is the ownership split: the Bob Evans restaurant chain and the Bob Evans packaged foods brand were separated, with the grocery business going to Post Holdings, so the name on a sausage package and the name on a restaurant are now different companies with different policies and different records. Consumers researching either will routinely find the other. Honest, low-stakes row.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Regional Grocery & Restaurants", "_row_id": 383, "_entity_id": 571, "_entity_slug": "bob-evans-post-holdings", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Aldi", "Category": "Grocery (discount)", "Terms & Conditions URL": "https://www.aldi.us/terms-of-use/", "T&C Direct PDF?": null, "Privacy Policy URL": "https://www.aldi.us/privacy-policy/", "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Aldi collects MINIMAL consumer data compared to every other grocery chain in this tracker. No loyalty program, no rewards card, no membership — Aldi's business model is built on operational efficiency and low prices, not data monetization. The Aldi app (launched 2021) collects shopping-list and store-locator data but does NOT track in-store purchases unless the customer uses the app to pay. Aldi's privacy-minimal approach is a structural competitive advantage for privacy-conscious consumers — but it means Aldi cannot offer personalized pricing or targeted coupons.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Aldi US website Terms of Use, AAA rules, Illinois law (Aldi US division HQ: Batavia, IL). 30-day opt-out. The arbitration clause covers only DIGITAL interactions (website, app) — in-store cash purchases create no digital T&C relationship at all, making Aldi one of the few retailers where a consumer can shop with zero data footprint.", "Fees / Billing Flags": "No membership fee, no loyalty program, no delivery subscription. Quarter-deposit shopping carts. BYOB (bring your own bags). Aldi's cost structure is built on eliminating services that competitors charge for.", "Notes": "Aldi is owned by Aldi Süd (Mülheim an der Ruhr, Germany) — a different entity from Aldi Nord (which owns Trader Joe's in the US). The German ownership means Aldi's corporate data governance is influenced by GDPR, though US stores operate under US law. Aldi operates 2,300+ US stores with significant DMV presence (MD, VA).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Batavia", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-13", "Provenance (who determined this)": "Added 2026-08-13 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Aldi Süd (Mülheim an der Ruhr, Germany — separate from Aldi Nord/Trader Joe's)", "Years Referenced in Finding (heuristic)": "2021", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Aldi Süd (Mülheim an der Ruhr, Germany — separate from Aldi Nord/Trader Joe's)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Aldi's arbitration clause with class-action waiver applies to any digital interaction, including the shopping-list app.\nWHAT THE TERMS SAY: Aldi's US website Terms of Use impose mandatory binding arbitration under AAA rules with a class-action waiver, governed by Illinois law, with a 30-day opt-out window; the clause covers only digital interactions (website, app) — in-store cash purchases create no digital T&C relationship.\nWHY IT MATTERS: Anyone using Aldi's app or website is bound to arbitrate rather than sue in court unless they opt out within 30 days, though in-store cash shoppers avoid this relationship entirely.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Aldi is a comparatively favorable row: no loyalty program, no membership fee, and no confirmed data-sharing or breach finding — the only T&C flag present is the digital-only arbitration clause.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Aldi's minimal-data model and digital-only arbitration clause are both clearly and specifically described.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Aldi  <-  Aldi Süd (Mülheim an der Ruhr, Germany — separate from Aldi Nord/Trader Joe's)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to stop paying by inaction.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Aldi you gave up your right to sue and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Aldi is the privacy-minimalist counterpoint to every other grocery chain in this tracker. No loyalty card, no rewards program, no membership — a consumer can walk into Aldi, pay cash, and leave zero data footprint. This is not accidental: Aldi's business model is built on operational efficiency (quarter-deposit carts, BYOB bags, limited SKUs, no brand advertising), not on data monetization. Compare with Costco (membership required, every purchase tracked to your member number), Walmart (Walmart+ subscription, in-store purchase tracking via app), or Kroger/Harris Teeter (loyalty card required for sale prices, purchase history sold to CPG brands via Kroger's 84.51° data analytics subsidiary). Aldi's website and app DO have a mandatory arbitration clause — but a consumer who shops in-store with cash has no digital contractual relationship with Aldi at all, a possibility that effectively does not exist at any other major retailer. Aldi is owned by Aldi Süd (Germany), separate from Aldi Nord (which owns Trader Joe's) — two companies that appear identical to American consumers but are legally and operationally independent.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Regional Grocery & Restaurants", "_row_id": 384, "_entity_id": 573, "_entity_slug": "aldi", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Lidl", "Category": "Grocery (discount)", "Terms & Conditions URL": "https://www.lidl.com/terms-conditions", "T&C Direct PDF?": null, "Privacy Policy URL": "https://www.lidl.com/privacy-policy", "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Lidl collects consumer data through its Lidl Plus loyalty app (launched in US 2021) — digital coupons, purchase history, receipt scanning, and store-visit frequency. Unlike Aldi, Lidl DOES operate a loyalty program, meaning Lidl tracks individual purchase behavior. Lidl Plus data is processed by Lidl US Operations LLC but the parent company (Schwarz Group, Neckarsulm, Germany) is the world's largest retailer by revenue ($150B+, larger than Walmart outside the US). German parent = GDPR-influenced corporate data governance.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Lidl US Terms & Conditions, AAA rules, Virginia law (Lidl US HQ: Arlington, Virginia — DMV). 30-day opt-out. The arbitration clause is governed by VIRGINIA law from a DMV headquarters — one of the few grocery-chain arbitration clauses in this tracker governed by a DMV-state's law.", "Fees / Billing Flags": "No membership fee. Lidl Plus app offers digital coupons and receipt scanning for rewards. Prices positioned between Aldi (lower) and traditional grocers (higher).", "Notes": "Lidl US is headquartered in Arlington, Virginia (DMV). Lidl operates 170+ US stores concentrated in the mid-Atlantic and Southeast. The Schwarz Group parent (also owns Kaufland) is the world's largest retailer by revenue — larger than Walmart outside the US. Lidl US's Virginia-law arbitration clause makes it one of the few DMV-headquartered grocery companies in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Arlington", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-13", "Provenance (who determined this)": "Added 2026-08-13 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Fetched - awaiting document verification", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Arlington, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "Schwarz Group (Neckarsulm, Germany — world's largest retailer by revenue)", "Years Referenced in Finding (heuristic)": "2021", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Schwarz Group (Neckarsulm, Germany — world's largest retailer by revenue)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Lidl Plus tracks individual purchase history and store-visit frequency through digital coupons and receipt scanning.\nWHAT THE TERMS SAY: Unlike Aldi, Lidl operates the Lidl Plus loyalty app (US launch 2021), which collects digital-coupon usage, purchase history, receipt scans, and store-visit frequency, processed by Lidl US Operations LLC under parent Schwarz Group (Germany).\nWHY IT MATTERS: Lidl made a deliberate strategic choice, unlike its German-owned discount-grocery peer Aldi, to build a data-collection layer through the app rather than let customers shop anonymously.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Lidl's arbitration clause over its data-tracking app is governed by Virginia law, weaker than Illinois or California privacy statutes.\nWHAT THE TERMS SAY: Lidl US's Terms & Conditions impose mandatory binding arbitration under AAA rules with a class-action waiver and a 30-day opt-out window, governed by Virginia law from its Arlington, VA headquarters; the clause covers disputes over Lidl Plus data practices.\nWHY IT MATTERS: Because Virginia's data law (VCDPA) offers weaker consumer protections than Illinois's BIPA or California's CCPA/CPRA, disputes over Lidl's purchase-tracking data are governed by a comparatively lighter-touch legal regime.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No confirmed breach, sale, or lawsuit is documented for Lidl this pass — the two substantive items are the loyalty-tracking data model and the Virginia-law arbitration clause.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The loyalty data model and arbitration clause are both specifically and clearly documented.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Lidl  <-  Schwarz Group (Neckarsulm, Germany — world's largest retailer by revenue)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your right to stop paying by inaction.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Lidl you gave up your right to sue and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T20:07:45Z (HTTP 200, NEW)", "SCARY (most astonishing T&C item)": "Lidl US is headquartered in Arlington, Virginia — making it a DMV-headquartered grocery chain whose mandatory arbitration clause is governed by Virginia law. The Schwarz Group parent (Neckarsulm, Germany) is the world's largest retailer by revenue — larger than Walmart outside the US — but most American consumers have never heard of it. Lidl Plus (loyalty app, US launch 2021) represents a deliberate strategic choice: unlike Aldi (same German-discount-grocery category, no loyalty program, privacy-minimal), Lidl decided to BUILD a data-collection layer through digital coupons and purchase tracking. This creates a natural experiment visible in this tracker: two German-owned discount grocery chains, operating in the same DMV market, making opposite decisions about consumer-data collection. Aldi lets you shop anonymously with cash; Lidl incentivizes you to scan every receipt through Lidl Plus. The arbitration clause covers disputes over Lidl Plus data practices — and it's governed by Virginia law (VCDPA), not Illinois (BIPA) or California (CCPA/CPRA), which have stronger consumer-data protections.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Regional Grocery & Restaurants", "_row_id": 385, "_entity_id": 575, "_entity_slug": "lidl", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Colonial Parking (DC-specific) / SP+ (Metropolis Technologies)", "Category": "Parking", "Terms & Conditions URL": "ecolonial.com/terms-and-conditions/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "ecolonial.com/privacy-policy/ (referenced in Terms, not independently located as separate direct URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "SP+ (SP Plus Corporation, recently ACQUIRED by Metropolis Technologies) — the larger national parking operator whose local DC brand is Colonial Parking — has faced MULTIPLE Illinois Biometric Information Privacy Act (BIPA) lawsuits: (1) a 2022 class action alleging SP+ used FACIAL RECOGNITION kiosks at Chicago parking-garage entry gates WITHOUT required consent/notice, allegedly to reduce labor costs, seeking $1,000-$5,000 per violation; (2) a separate, earlier case alleging SP+ collected over 10,000 EMPLOYEES' fingerprints for timekeeping (2002-2017) without any BIPA-required disclosures about how the biometric data would be stored, for how long, or when destroyed. Both cases are Illinois-specific (BIPA is one of the strongest state biometric laws), but illustrate the parent company's biometric data practices broadly, which could plausibly extend to newer kiosk technology deployed at DC-area Colonial Parking facilities — worth a direct follow-up confirming whether Colonial's DC garages use similar facial-recognition entry kiosks.", "Arbitration / Class Action Waiver": "Colonial Parking's own Terms and Conditions include a BROAD limitation-of-liability and indemnification clause, disclaiming responsibility for 'any damages, including...direct, indirect, consequential, compensatory, special, punitive, or incidental damages' and requiring the customer to indemnify Colonial for claims arising from the customer's own use of the site — standard but notably one-sided risk allocation favoring the company.", "Fees / Billing Flags": "DIRECT, DOCUMENTED DC-SPECIFIC BILLING COMPLAINTS (BBB): customers report Colonial Parking disputing PAYMENTS ALREADY MADE (one customer's bank statement showed three January payments with only two refunded, yet Colonial claimed a bounced February payment using a screenshot that actually referenced the January invoice), and a SEPARATE customer reporting a THREE-MONTH DELAY in receiving a promised refund for a cancelled monthly parking pass despite repeated follow-up, including being hung up on by a representative. Colonial's Terms explicitly state NO REFUNDS OR CREDITS are given for early/mid-month cancellation, and the full month's fee is due regardless of actual usage.", "Notes": "This is one of the FEW entries in this entire 400+ company tracker with DIRECT, NAMED, DC-SPECIFIC customer billing complaints — worth flagging prominently as the most concretely regional finding of any entity in this whole audit, given Colonial Parking's extensive footprint across downtown DC, Old Town Alexandria, Friendship Heights, and The Wharf specifically.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-4] Colonial Parking customers report disputed payments, a three-month refund delay, and a no-refund cancellation policy in DC-specific BBB complaints.\nWHAT THE TERMS SAY: DC-specific BBB complaints describe Colonial Parking disputing payments already made (a customer's bank statement showed three January payments with only two refunded, while Colonial cited a bounced February payment using a screenshot that actually referenced the January invoice) and a separate customer reporting a three-month delay receiving a promised refund for a cancelled monthly pass, including being hung up on by a representative. Colonial's Terms state no refunds or credits are given for early/mid-month cancellation, and the full month's fee is due regardless of actual usage.\nWHY IT MATTERS: Monthly parking customers in downtown DC, Old Town Alexandria, Friendship Heights, and The Wharf can be charged for unused time and face lengthy, contested refund processes.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[LOCATION_TRACKING · FL-2] SP+'s acquisition by Metropolis Technologies turns Colonial Parking garages into an automated license-plate-reading network.\nWHAT THE TERMS SAY: SP+ (Colonial Parking's parent) was acquired by Metropolis Technologies, whose product is computer-vision license-plate recognition for checkout-free parking — meaning the garages read every entering vehicle's plate whether or not the driver uses the app.\nWHY IT MATTERS: Plate-to-identity linkage plus timestamped location is the kind of dataset that raises automated license-plate-reader surveillance concerns, built here as a convenience feature nobody opted into.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[BIOMETRICS · FL-2] SP+ has faced Illinois BIPA lawsuits over facial-recognition entry kiosks and undisclosed employee fingerprinting, not yet confirmed at DC-area garages.\nWHAT THE TERMS SAY: SP+ has faced multiple Illinois BIPA lawsuits: a 2022 class action alleging facial-recognition kiosks at Chicago garage entry gates were used without required consent or notice (allegedly to cut labor costs, seeking $1,000-$5,000 per violation), and an earlier case alleging SP+ collected fingerprints from over 10,000 employees for timekeeping (2002-2017) without required BIPA disclosures.\nWHY IT MATTERS: Both cases are Illinois-specific, but they document the parent company's broader biometric practices; whether Colonial's DC garages use similar facial-recognition kiosks is not yet independently confirmed.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=Y; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "DC billing complaints and the Metropolis acquisition are clearly documented, but whether SP+'s biometric practices extend to DC garages is unconfirmed.", "Exposure Score (0-100)": 22, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 8, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (biometric_collection+6, precise_location_tracking+4) | Contract 8/20 (liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 4/20 (severity2+2, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Colonial Parking (DC-specific) / SP+ (Metropolis Technologies)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Colonial Parking (DC-specific) / SP+ (Metropolis Technologies) you gave up your biometric identifiers, your physical movements, your right to meaningful compensation, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "2026-09-08T20:07:47Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "SP+ was acquired by Metropolis Technologies, and that acquisition is the finding: Metropolis's product is computer-vision licence plate recognition for checkout-free parking, which means a DC parking operator's garages become an automated plate-reader network reading every vehicle that enters. Plate-to-identity linkage plus timestamped location is precisely the dataset that makes automated licence plate readers a surveillance concern, and here it is being built as a convenience feature nobody opted into - a driver parks, and the system reads the plate whether or not they use the app.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "DMV Misc (Parking-Telecom)", "_row_id": 386, "_entity_id": 576, "_entity_slug": "colonial-parking-dc-specific-sp-metropolis-technologies", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Comcast Business", "Category": "Telecom (business)", "Terms & Conditions URL": "business.comcast.com/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "business.comcast.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SAME 2023 BREACH as residential Xfinity (Internet Providers tab): the Comcast/Citrix Netscaler breach (Oct 16-19, 2023) exposed usernames, passwords, contact information, partial SSNs, birthdates, and security questions for an estimated 35.8 MILLION current/former Comcast customers — resulting in a $117.5 MILLION settlement (final approval hearing Aug 5, 2026, claims deadline extended to Sept. 14, 2026), offering up to $10,000 for documented losses or a $50 flat payout. Not confirmed whether this specific settlement's class definition includes COMCAST BUSINESS accounts specifically as distinct from residential Xfinity accounts — recommend direct verification.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Comcast Business Services Agreement. 30-day opt-out. Same arbitration-clause lineage as Xfinity consumer — Comcast's American Express v. Italian Colors case (2013) helped establish that class waivers are enforceable even when individual arbitration would be economically irrational.", "Fees / Billing Flags": "SEPARATE, UNRELATED B2B LITIGATION (Feb 2026): Comcast Business Communications sued DISH Wireless (EchoStar) for $54 MILLION, alleging DISH breached a Master Service Agreement covering fiber connections for DISH's 5G network — DISH argues its performance was 'excused' after the FCC forced it to sell the spectrum underlying that 5G network, a force majeure argument. This is a business-to-business commercial dispute, NOT a customer-privacy issue, but relevant context on Comcast Business's broader legal footprint.", "Notes": "The DISH Wireless lawsuit is a B2B commercial dispute unrelated to consumer privacy — included here for completeness on Comcast Business's overall legal exposure, but shouldn't be conflated with the shared 2023 data breach finding above.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$123.7B", "Market Cap": "$84.0B", "Employees": "182,000", "HQ City": "Philadelphia", "HQ State": "Pennsylvania", "CEO": "Brian Roberts", "Ticker": "CMCSA", "Website (Corporate)": "comcast.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (CMCSA). Service route: c/o General Counsel / Corporate Secretary, Philadelphia, Pennsylvania — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] The 2023 Comcast/Citrix breach exposed SSNs and passwords for 35.8M customers, with unclear settlement coverage for Comcast Business accounts.\nWHAT THE TERMS SAY: The Comcast/Citrix Netscaler breach (Oct 16-19, 2023) exposed usernames, passwords, contact information, partial SSNs, birthdates, and security questions for an estimated 35.8 million current/former Comcast customers, resulting in a $117.5 million settlement (final approval hearing Aug 5, 2026, claims deadline extended to Sept. 14, 2026) offering up to $10,000 for documented losses or a $50 flat payout. It is not confirmed whether the settlement's class definition specifically includes Comcast Business accounts as distinct from residential Xfinity accounts.\nWHY IT MATTERS: Small businesses on Comcast Business hold their own customers' data behind that connection, so a breach at the ISP layer can indirectly reach a nonprofit's donor list or a medical practice's patient records — and small-business owners often lack IT staff to respond.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Comcast Business requires mandatory binding arbitration with a class-action waiver, 30-day opt-out.\nWHAT THE TERMS SAY: The Comcast Business Services Agreement imposes mandatory binding arbitration with a class-action waiver and a 30-day opt-out window, in the same clause lineage as the American Express v. Italian Colors case, which established that class waivers are enforceable even when individual arbitration would be economically irrational.\nWHY IT MATTERS: Small-business customers pursuing breach-related claims must arbitrate individually rather than joining a class action, unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The DISH Wireless lawsuit is an unrelated B2B commercial dispute, not a consumer-privacy issue, so only the shared 2023 breach and the arbitration clause are substantive here.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The 2023 breach and settlement figures, and the arbitration clause, are both specifically documented with dates and dollar amounts.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Comcast Business  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Comcast Business you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same 2023 breach as residential Xfinity, documented in the Internet Providers tab - and the reason it deserves its own row is that the affected population is different. Small businesses on Comcast Business hold their customers' data behind that connection, so a breach at the ISP layer reaches a nonprofit's donor list or a medical practice's patient records indirectly. Small business owners also generally have no IT staff, receive the same consumer-style notification, and have downstream notification obligations of their own that they may not know exist.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "DMV Misc (Parking-Telecom)", "_row_id": 387, "_entity_id": 577, "_entity_slug": "comcast-business", "_issuer": "Comcast Business", "_issuer_slug": "comcast-business", "_ticker": "CMCSA", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Verizon Prepaid / Visible", "Category": "Telecom (prepaid/MVNO)", "Terms & Conditions URL": "visible.com/legal/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "visible.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SAME PARENT-COMPANY DATA-SELLING FINDING as Verizon Wireless (Carriers tab): a landmark June 2026 US SUPREME COURT ruling (FCC v. AT&T, Inc. / Verizon Communications, Inc. v. FCC, 8-1) upheld the FCC's authority to fine Verizon nearly $47 MILLION for selling REAL-TIME CUSTOMER LOCATION DATA without consent — the Court specifically ruled the FCC's forfeiture process does NOT violate the Seventh Amendment right to a jury trial, since the FCC cannot itself seize assets and must instead sue in federal court (where the carrier gets a full jury trial) if it refuses to pay. A SEPARATE, newer class action (filed early 2025) alleges Verizon CONTINUES to sell browsing history, location data, and app usage to advertisers/data brokers. As Verizon-owned brands, Visible (Verizon's standalone prepaid/digital-only brand) and other Verizon Prepaid offerings likely operate under a SEPARATE Terms of Service from postpaid Verizon Wireless, though the underlying parent-company data practices and legal exposure plausibly extend across brands.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Verizon's Customer Agreement applies to Visible (Verizon's digital-only prepaid brand). 30-day opt-out. Same AT&T Mobility v. Concepcion lineage — Verizon's clause was modeled on the AT&T clause the Supreme Court upheld.", "Fees / Billing Flags": "Verizon separately paid $100 MILLION (Esposito v. Cellco Partnership) to settle claims it misled POSTPAID customers with an undisclosed 'Administrative Charge' — not clear whether this specific billing-fee settlement extends to prepaid/Visible customers, who are typically billed differently (prepaid, no long-term contract) than postpaid subscribers.", "Notes": "Recommend a direct follow-up specifically confirming whether Visible/Prepaid's Terms of Service and billing practices differ meaningfully from postpaid Verizon Wireless, given the brands' structurally different (prepaid vs. contract) billing models.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$138.2B", "Market Cap": "$184.9B", "Employees": "99,600", "HQ City": "New York", "HQ State": "New York", "CEO": "Hans Vestberg", "Ticker": "VZ", "Website (Corporate)": "verizon.com", "Main Mailing Address (legal/privacy notices)": "PARENT ADDRESS ONLY — verify before using for legal notice. Visible is a Verizon-owned digital brand operating under its own consumer terms. Parent: Verizon Privacy Office, 1300 I Street NW, Suite 500 East, Washington, DC 20005, USA (International: Verizon Legal Dept, Reading International Business Park, Basingstoke Road, Reading, Berkshire RG2 6DA, UK)", "Legal / Privacy Contact Email": "No published privacy email; Verizon routes requests through its online privacy form", "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (VZ). Service route: c/o General Counsel / Corporate Secretary, New York, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] SCOTUS upheld the FCC's ~$47M fine against Verizon for selling real-time customer location data without consent — a parent-company finding likely covering Visible.\nWHAT THE TERMS SAY: A June 2026 Supreme Court ruling (8-1) upheld the FCC's authority to fine Verizon nearly $47 million for selling real-time customer location data without consent, also ruling the FCC's forfeiture process does not violate the Seventh Amendment jury-trial right, since Verizon can obtain a full jury trial by refusing to pay and forcing the FCC to sue in federal court.\nWHY IT MATTERS: This is a confirmed parent-company (Verizon) finding; Visible and Verizon Prepaid likely operate under a separate Terms of Service from postpaid, though the tracker notes the underlying data practices plausibly extend across all Verizon brands, not independently confirmed specific to Visible.\n(evidence: Data Sharing; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SALE · FL-2] A 2025 class action alleges Verizon continues selling browsing history, location, and app-usage data to advertisers and brokers.\nWHAT THE TERMS SAY: A separate class action filed in early 2025 alleges Verizon continues to sell browsing history, location data, and app usage to advertisers and data brokers.\nWHY IT MATTERS: If this parent-company practice extends to Visible and Prepaid customers, it means ongoing behavioral data sales despite the earlier FCC penalty — though this is not independently confirmed for the prepaid brands specifically.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Visible and Verizon Prepaid customers are bound by Verizon's Customer Agreement arbitration clause, modeled on the AT&T clause SCOTUS upheld.\nWHAT THE TERMS SAY: Verizon's Customer Agreement, which applies to Visible (Verizon's digital-only prepaid brand), imposes mandatory binding arbitration with a class-action waiver and a 30-day opt-out window, modeled on the AT&T clause upheld in AT&T Mobility v. Concepcion.\nWHY IT MATTERS: Many customers do not realize Visible is a Verizon-owned brand, yet they are bound to the same arbitration terms as postpaid Verizon Wireless customers unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The parent-company location-data penalty and litigation are clearly documented, but their application to Visible/Prepaid specifically is not independently confirmed.", "Exposure Score (0-100)": 53, "Exposure Band": "High", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 0/20 (none) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 9/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Verizon Prepaid / Visible  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Verizon Prepaid / Visible you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, and your right to join a class action. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 60.0, "URL Last Validated": "2026-09-08T20:08:33Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Same parent-company data practices as Verizon Wireless, documented in the Carriers tab - one policy, several brands. The prepaid distinction matters for the same reason it did in the Cricket row: prepaid customers skew lower-income and often chose prepaid specifically to avoid a credit check, they are less likely to carry credit monitoring, and they move more often so mailed breach notifications reach them less reliably. Visible is also a Verizon-owned digital brand that many customers do not realise is Verizon at all.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "DMV Misc (Parking-Telecom)", "_row_id": 388, "_entity_id": 578, "_entity_slug": "verizon-prepaid-visible", "_issuer": "Verizon Prepaid / Visible", "_issuer_slug": "verizon-prepaid-visible", "_ticker": "VZ", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "MetLife", "Category": "Life Insurance", "Terms & Conditions URL": "metlife.com/about-us/legal-notices/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "metlife.com/about-us/privacy-notices/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MULTIPLE SEPARATE INCIDENTS ACROSS 2025-2026 for this global insurer (90 million customers, founded 1868): (1) A January 2, 2025 RANSOMWARE claim (RansomHub group) alleged theft of 1 TERABYTE of data — including meeting logs, executive documents, financial records — from Latin American operations (Brazil, Colombia, Chile subsidiaries); MetLife stated the affected subsidiary was isolated from its main systems. (2) A March 2025 incident at THIRD-PARTY VENDOR Bank of New York Mellon (BNY) exposed insurance annuity/claims account-holder data for a small number of MetLife customers. (3) A June 2025 notification to the Texas AG confirmed exposure of names, SSNs, birthdates for 343 Texas residents. (4) A January 29, 2026 INTERNAL ERROR (notified March 6, 2026): a MetLife employee ACCIDENTALLY EMAILED a file containing personal data (names, SSNs, coverage details, group numbers) to an HR administrator at a DIFFERENT MetLife group-insurance customer entirely — the recipient reported it immediately and confirmed deletion; MetLife states it does not believe the data was actually misused given the recipient's professional handling, though the data was still improperly disclosed outside its intended audience. Affected California individuals (500+) were offered 1 year of free TransUnion credit monitoring.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration for MetLife's consumer products (auto, home, life insurance policies may contain arbitration provisions depending on state and product). Insurance disputes also subject to state insurance department oversight. The Jan 2025 RansomHub breach claim (1TB, disputed by MetLife — only Ecuador subsidiary Fondo Genesis confirmed) would be governed by the arbitration clause if a US consumer brings a data-breach claim.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The SIMPLE HUMAN ERROR incident (employee misdirecting an email to the wrong company's HR contact) is a useful reminder that not every breach involves a sophisticated hacker — misdirected internal communications are a genuinely common and preventable cause of data exposure, distinct from the ransomware/vendor-breach patterns more common elsewhere in this tracker.\n\nAUG 2026 ADDENDUM: ransomware claim figures originate from the attacker's own leak-site posting - treat the 1TB volume as an assertion pending independent confirmation, consistent with how the Liberty Mutual/Everest claim is handled in the Insurance tab. The misdirected-email incident is separately documented. No confirmed regulatory action or class settlement found for MetLife this pass; recommend a direct follow-up.", "Industry (Fortune 500)": "Insurance: Life, Health (Stock)", "Revenue (Fortune 500)": "$77.1B", "Market Cap": "$60.0B", "Employees": "45,000", "HQ City": "New York", "HQ State": "New York", "CEO": "Michel Khalaf", "Ticker": "MET", "Website (Corporate)": "metlife.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (MET). Service route: c/o General Counsel / Corporate Secretary, New York, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.scworld.com/brief/metlife-purportedly-breached-by-ransomhub", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "MetLife, Inc.", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: MetLife, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] MetLife confirmed to the Texas AG that a breach exposed names, SSNs, and birthdates for 343 Texas residents.\nWHAT THE TERMS SAY: A June 2025 notification to the Texas Attorney General confirmed exposure of names, Social Security numbers, and birthdates for 343 Texas residents.\nWHY IT MATTERS: This is a confirmed, regulator-notified exposure of identity-theft-relevant data, distinct from MetLife's other disputed or unconfirmed 2025-2026 incidents.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] A MetLife employee accidentally emailed personal data, including SSNs and coverage details, to a different company's HR contact.\nWHAT THE TERMS SAY: On January 29, 2026 (notified March 6, 2026), a MetLife employee accidentally emailed a file containing names, SSNs, coverage details, and group numbers to an HR administrator at a different MetLife group-insurance customer entirely; the recipient reported it immediately and confirmed deletion. MetLife states it does not believe the data was misused but acknowledges it was improperly disclosed outside its intended audience. Affected California individuals (500+) were offered one year of free TransUnion credit monitoring.\nWHY IT MATTERS: The tracker notes this is a reminder that not every breach involves a sophisticated hacker — misdirected internal communications are a common, preventable cause of exposure.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] A March 2025 breach at third-party vendor Bank of New York Mellon exposed MetLife annuity and claims account-holder data.\nWHAT THE TERMS SAY: A March 2025 incident at third-party vendor Bank of New York Mellon (BNY) exposed insurance annuity/claims account-holder data for a small number of MetLife customers.\nWHY IT MATTERS: MetLife's use of outside financial vendors to administer annuity and claims accounts means a breach at that vendor can expose MetLife customer data even without any lapse at MetLife itself.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Several incidents are clearly confirmed (Texas breach, misdirected email, BNY vendor), but the largest claimed incident (1TB ransomware) remains an unverified attacker assertion.", "Exposure Score (0-100)": 27, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "MetLife  <-  MetLife, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using MetLife you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T20:08:36Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The instructive thing about MetLife is the range. At one end, a ransomware group claimed in January 2025 to have taken a full terabyte of data from a company serving roughly 90 million customers. At the other end, an employee sent an email to the wrong company's HR contact. Both are on the incident list, and for the person whose information was in that misdirected message the outcome is identical - their data went somewhere it should not have. The sophisticated-attacker framing that dominates breach coverage quietly does insurers a favor by making these events sound like acts of nature, when a meaningful share of exposure is ordinary human error inside routine correspondence, which no amount of security spending fully engineers away.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 389, "_entity_id": 580, "_entity_slug": "metlife", "_issuer": "MetLife, Inc.", "_issuer_slug": "metlife-inc", "_ticker": "MET", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Prudential Financial", "Category": "Life Insurance", "Terms & Conditions URL": "prudential.com/links/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "prudential.com/links/privacy-center", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED FEBRUARY 2024 BREACH, still resulting in active settlement administration in 2025-2026: a cyberattack accessed files containing names, birthdates, account numbers, Social Security numbers, driver's license numbers, addresses, phone numbers, and email addresses. The resulting class action (In Re: Prudential Financial, Inc. Data Breach Litigation) reached a settlement, though the court ordered CHANGES to the settlement's terms/schedule as recently as August 2025, with a corrected notice and revised filing deadlines mailed to class members in mid-August 2025 — illustrating that even settled breach cases can have their administration meaningfully revised well after an initial agreement is reached.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass beyond the settlement process itself — standard binding arbitration + class action waiver expected for individual policyholder agreements outside this specific breach settlement.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The mid-settlement REVISION (corrected notices, new deadlines mailed in August 2025) is a useful reminder that anyone previously notified of a settlement should watch for updated correspondence rather than assuming the original notice's deadlines remain final.\n\nAUG 2026 ADDENDUM: settlement administration revised with corrected notices and new deadlines mailed August 2025. ACTIONABLE FRAMING for any consumer-facing writeup: class-action correspondence is not one-and-done; deadlines can move and terms can change mid-administration. Recommend follow-up on final settlement terms, per-claimant amounts, and whether the claims deadline has now passed.", "Industry (Fortune 500)": "Insurance: Life, Health (Stock)", "Revenue (Fortune 500)": "$60.8B", "Market Cap": "$38.6B", "Employees": "37,936", "HQ City": "Newark", "HQ State": "New Jersey", "CEO": "Andrew Sullivan", "Ticker": "PRU", "Website (Corporate)": "prudential.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (PRU). Service route: c/o General Counsel / Corporate Secretary, Newark, New Jersey — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New Jersey' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024, 2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NJ Business Records Service — businessrecords.nj.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Prudential's February 2024 breach exposed SSNs and driver's license numbers; the 2025 settlement's deadlines were later revised.\nWHAT THE TERMS SAY: A February 2024 cyberattack accessed files containing names, birthdates, account numbers, Social Security numbers, driver's license numbers, addresses, phone numbers, and email addresses. The resulting class action settlement (In Re: Prudential Financial, Inc. Data Breach Litigation) had its terms and schedule changed by the court as recently as August 2025, with a corrected notice and revised filing deadlines mailed to class members in mid-August 2025.\nWHY IT MATTERS: Affected individuals who filed away their original settlement notice as one-and-done mail may have missed that the terms and deadlines that actually matter arrived in a second, corrected mailing.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration is only described as 'standard...expected' for individual policyholder agreements, not independently confirmed this pass, and fees are not itemized — only the breach/settlement finding is substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach and settlement revision are clearly documented, but arbitration and fee terms are unconfirmed this pass.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Prudential Financial  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Prudential Financial takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The February 2024 breach exposed the full identity-theft package - names, dates of birth, account numbers, Social Security numbers and driver's license numbers - and two years later the settlement was still being administered. More usefully for anyone actually affected: the settlement had to be REVISED mid-administration, with corrected notices and new deadlines mailed out in August 2025. That is the practical warning this row carries. People treat a class-action notice as a one-time piece of junk mail, file it, and never look again - and in this case the terms and the deadlines that mattered arrived in the second envelope, not the first.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 390, "_entity_id": 581, "_entity_slug": "prudential-financial", "_issuer": "Prudential Financial", "_issuer_slug": "prudential-financial", "_ticker": "PRU", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "New York Life", "Category": "Life Insurance", "Terms & Conditions URL": "newyorklife.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "newyorklife.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED 2025-2026 BREACH (largest mutual life insurer in the US, founded 1845): New York Life discovered unauthorized access to ONE OF ITS AGENTS' EMAIL ACCOUNTS on December 2, 2025 — after securing the account and completing an investigation, the company confirmed (April 8, 2026) that the compromised account held clients' personal information, then formally disclosed the breach to the Texas Attorney General on May 11, 2026 (at least 473 Texas residents affected, notified by mail). Exposed data included names, addresses, Social Security numbers, driver's license numbers, financial account/card numbers, MEDICAL INFORMATION, health insurance information, and birthdates — a notably broad and sensitive combination of data categories for a single incident.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The breach originated through a COMPROMISED INDIVIDUAL AGENT'S EMAIL account rather than a centralized corporate system — illustrating how individual insurance agents (who often hold extensive client financial/medical files in their own email/local systems) can represent a meaningfully weaker security link than the parent company's own centralized infrastructure.\n\nAUG 2026 ADDENDUM: discovery date Dec 2 2025; vector was a compromised individual agent email account rather than a centralized corporate system. STRUCTURAL FINDING worth generalizing across this tracker: the agent-distribution model creates a large, distributed, unevenly-secured attack surface holding highly sensitive application and beneficiary data. Recommend a follow-up on affected count, data types confirmed, and whether any state regulator opened an inquiry.", "Industry (Fortune 500)": "Insurance: Life, Health (Mutual)", "Revenue (Fortune 500)": "$62.6B", "Market Cap": "Non-public", "Employees": "15,131", "HQ City": "New York", "HQ State": "New York", "CEO": "Craig DeSanto", "Ticker": "Non-public", "Website (Corporate)": "newyorklife.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (Non-public). Service route: c/o General Counsel / Corporate Secretary, New York, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Agent's compromised email exposed SSNs and medical data for at least 473 Texas residents\nWHAT THE TERMS SAY: New York Life confirmed an unauthorized party accessed one of its agents' email accounts (discovered Dec 2, 2025), and disclosed to the Texas AG on May 11, 2026 that at least 473 Texas residents were affected. Exposed data included names, addresses, SSNs, driver's license numbers, financial account/card numbers, medical information, health insurance information, and birthdates.\nWHY IT MATTERS: Clients whose sensitive medical and financial data sat in an individual agent's inbox rather than a corporate system had no visibility into that agent's security practices, and were notified only months after discovery.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee terms are both explicitly unconfirmed this pass ('standard...expected' / 'not itemized'), so only the confirmed breach is a substantive, company-specific finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach itself is dated and specific, but arbitration and fee terms are unverified assumptions rather than confirmed text.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "New York Life  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, New York Life takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "New York Life discovered on December 2, 2025 that an unauthorized party had gotten into one of its AGENTS' email accounts - not a corporate database, not a claims system, a single agent's inbox. For the largest mutual life insurer in the country, founded in 1845, the exposure ran through the least defended point in the whole structure. Insurance agents accumulate extraordinarily sensitive material in ordinary email: beneficiary designations, health disclosures from applications, financial statements, family details. Corporate security programs and the arbitration clauses in your policy are largely irrelevant to that inbox, and as a customer you have no visibility into how any individual agent secures it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 391, "_entity_id": 582, "_entity_slug": "new-york-life", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Northwestern Mutual", "Category": "Life Insurance", "Terms & Conditions URL": "northwesternmutual.com/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "northwesternmutual.com/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED HISTORICAL BREACH (2022 notification): Northwestern Mutual notified customers of a 'Notice of Data Security Incident' — notably, the notification letter explicitly states that MASSACHUSETTS LAW (M.G.L. Chapter 93H) PROHIBITED the company from describing the actual nature of the incident in the notification itself, an unusual example of a state disclosure law that can paradoxically limit how much detail a breach notice actually contains. Affected customers were offered 2 years of free TransUnion credit monitoring. SEPARATELY, Northwestern Mutual's own SEC filings (2025-2026, for its variable life insurance products) EXPLICITLY ACKNOWLEDGE ongoing 'Privacy Risks' from cyberattacks and unauthorized data access as a standing risk factor disclosed to investors/policyholders, describing internal employee training and data-minimization practices as its main mitigation — a candid, standing risk disclosure rather than a one-time incident report.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The Massachusetts law that PREVENTED Northwestern Mutual from describing the nature of its own breach in the notification letter is a genuinely counter-intuitive finding — a law meant to protect consumers can, in some circumstances, also limit the transparency of the very notice meant to inform them.\n\nAUG 2026 ADDENDUM: the Massachusetts notification restriction is a REGULATORY DESIGN finding rather than a company-conduct finding - the correct framing is a law creating a perverse outcome, not Northwestern Mutual concealing something. Worth flagging as a policy-education item for consumer-facing work: recipients of a Massachusetts breach notice should assume the letter is deliberately non-specific and seek detail through the state AG or the company directly. No confirmed regulatory penalty or class settlement found for Northwestern Mutual this pass.", "Industry (Fortune 500)": "Insurance: Life, Health (Mutual)", "Revenue (Fortune 500)": "$41.4B", "Market Cap": "Non-public", "Employees": "8,249", "HQ City": "Milwaukee", "HQ State": "Wisconsin", "CEO": "Timothy Gerend", "Ticker": "Non-public", "Website (Corporate)": "northwesternmutual.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (Non-public). Service route: c/o General Counsel / Corporate Secretary, Milwaukee, Wisconsin — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Wisconsin' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2022", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Wisconsin DFI Corporate Records — apps.dfi.wi.gov/apps/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2022 breach notice couldn't say what was breached because Massachusetts law blocked the details\nWHAT THE TERMS SAY: Northwestern Mutual's 2022 'Notice of Data Security Incident' letter states that Massachusetts law (M.G.L. Ch. 93H) prohibited it from describing the actual nature of the incident; affected customers were offered two years of free TransUnion credit monitoring.\nWHY IT MATTERS: Recipients could not tell whether financial, health, or other sensitive data was exposed, making it hard to judge whether a credit freeze or other protective step was warranted.\n(evidence: Data Sharing/Selling Flags | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Northwestern Mutual tells investors, in its own SEC filings, that cyberattacks remain a standing risk\nWHAT THE TERMS SAY: Northwestern Mutual's 2025-2026 SEC filings for its variable life insurance products list 'Privacy Risks' from cyberattacks and unauthorized data access as an ongoing risk factor, citing employee training and data-minimization as its main mitigations.\nWHY IT MATTERS: This is the company's own acknowledgment that further exposure is an open possibility rather than a resolved, one-time event.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and fee terms are unconfirmed this pass, and the tracker found no confirmed regulatory penalty or class settlement for Northwestern Mutual, so only these two data-related items are substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Massachusetts law itself blocked the breach notice from describing what happened, and no further detail, penalty, or settlement was confirmed this pass.", "Exposure Score (0-100)": 14, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Northwestern Mutual  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Northwestern Mutual takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Northwestern Mutual's 2022 breach notification letter states that Massachusetts law PREVENTED the company from describing the nature of its own breach to the people it was notifying. That is a genuinely strange finding: a statute intended to protect consumers produced a notice that told them something bad had happened while withholding what. The provision exists to stop notification letters from becoming a roadmap for further attacks, which is a defensible aim - but the practical effect on the recipient is that they cannot assess their own risk, cannot decide whether a credit freeze is warranted, and cannot tell whether the exposure touched financial data, health disclosures, or neither.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 392, "_entity_id": 583, "_entity_slug": "northwestern-mutual", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Elevance Health (Anthem)", "Category": "Health Insurance", "Terms & Conditions URL": "anthem.com/web/public/policies/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "anthem.com/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED BREACH (disclosed Nov 19, 2025) affecting at least 1,162 individuals in Massachusetts alone (national scope likely larger): exposed BOTH personally identifiable information AND protected health information — names, addresses, birthdates, SSNs, MEDICAL RECORDS, and driver's license numbers, a notably severe combination. SEPARATELY, a THIRD-PARTY VENDOR breach (Conduent, Elevance's printing/mailing/payment-integrity vendor, discovered Jan 13, 2025, traced to compromised VPN credentials) affected VIRGINIA STATE EMPLOYEES specifically enrolled in Elevance-administered COVA Care/COVA High Deductible health plans — Virginia's Department of Human Resource Management was notified Dec 2, 2025, more than 11 months after the underlying incident. This is a DIRECTLY VIRGINIA-RELEVANT finding for state employees.", "Arbitration / Class Action Waiver": "MAJOR DOJ FALSE CLAIMS ACT LAWSUIT (filed May 1, 2025, District of Massachusetts): the DOJ alleges Elevance (as Anthem), alongside Aetna and Humana, paid HUNDREDS OF MILLIONS OF DOLLARS in illegal kickbacks to insurance brokers (eHealth, GoHealth, SelectQuote) in exchange for steering Medicare beneficiaries into their plans — and, MORE SERIOUSLY, that Elevance/Aetna/Humana specifically THREATENED TO WITHHOLD kickback payments to pressure brokers into enrolling FEWER DISABLED Medicare beneficiaries, whom the insurers considered less profitable, resulting in brokers rejecting referrals of and steering AWAY disabled beneficiaries from these plans — a serious disability-discrimination allegation layered on top of the kickback scheme. All named defendants have stated they will 'vigorously' contest the allegations.", "Fees / Billing Flags": "SEPARATE ANTITRUST CASE (ongoing, 2025-2026): Elevance is named as a co-defendant with UnitedHealth Group, Aetna, Cigna, and Humana, alleged (via vendor Zelis) to have conspired to SUPPRESS out-of-network reimbursement rates paid to healthcare providers — a federal judge ruled (March 2026) the case can proceed to face these conspiracy claims.", "Notes": "Elevance/Anthem is now implicated in THREE SEPARATE, SERIOUS matters (a data breach affecting Virginia state employees specifically, a DOJ disability-discrimination/kickback suit, and a multi-insurer antitrust conspiracy case) — among the most extensively-flagged health insurers in this entire tracker, and directly relevant to Virginia state employees given the Conduent/COVA Care breach.\n\nAUG 2026 ADDENDUM (verified this pass, historical anchor): Attackers accessed Anthem systems Dec 2 2014 - Jan 27 2015 (some sources trace initial infiltration to Feb 2014) via spear phishing at a subsidiary. 78.8M individuals; exposed names, addresses, dates of birth, medical ID numbers, employment and income information, email addresses and SSNs. HHS OCR settlement $16M announced Oct 15 2018 - largest HIPAA penalty ever at the time, versus the prior record of $5.55M (Advocate Health Care, 2016). OCR findings: no enterprise-wide risk analysis, insufficient procedures to regularly review information system activity, failure to identify and respond to suspected or known security incidents, inadequate minimum access controls. Class settlement $115M, final approval Aug 16 2018, Judge Lucy H. Koh (N.D. Cal.) - largest consumer data-breach settlement in US history at the time; provided 2 years credit monitoring or alternative cash, up to ~$50 cash payments, out-of-pocket loss reimbursement, fraud resolution services, and 3 years of committed security changes. Estimated total exposure ~$179M ($115M + $16M + $39.5M + $8.69M) across settlements and state AG actions. CROSS-REF: CareFirst row in the Insurance tab - CareFirst discovered its own 2014 breach only because it went looking after Anthem, Premera and Excellus were hit.", "Industry (Fortune 500)": "Health Care: Insurance and Managed Care", "Revenue (Fortune 500)": "$199.1B", "Market Cap": "$84.4B", "Employees": "103,679", "HQ City": "Indianapolis", "HQ State": "Indiana", "CEO": "Gail Boudreaux", "Ticker": "ELV", "Website (Corporate)": "elevancehealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation + Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (ELV). Service route: c/o General Counsel / Corporate Secretary, Indianapolis, Indiana — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.hipaajournal.com/16-million-anthem-hipaa-breach-settlement-takes-ocr-hipaa-penalties-past-100-million-mark/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Indiana' is a non-DMV US state", "Parent / Ultimate Owner": "Elevance Health, Inc. (fmr. Anthem Inc., renamed June 2022)", "Years Referenced in Finding (heuristic)": "2015", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Indiana SOS INBiz — inbiz.in.gov/BOS/Home/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Elevance Health, Inc. (fmr. Anthem Inc., renamed June 2022)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] 2015 Anthem breach exposed 78.8M people and produced the largest HIPAA penalty of its time\nWHAT THE TERMS SAY: Attackers accessed Anthem systems Dec 2014-Jan 2015 via a spear-phishing email answered by one employee at a subsidiary, exposing names, addresses, birthdates, medical ID numbers, employment/income information, emails, and SSNs for 78.8 million people. HHS OCR fined Anthem $16M (Oct 2018, the largest HIPAA penalty at the time) after finding no enterprise-wide risk analysis, insufficient system-activity review, and inadequate access controls; a $115M class settlement (final approval Aug 2018) provided up to ~$50 cash or 2 years credit monitoring plus 3 years of committed security changes.\nWHY IT MATTERS: Federal investigators found Anthem hadn't even assessed its own risk enterprise-wide before the breach, and individual victims received up to about $50 each despite the ~$179M combined in penalties and settlements.\n(evidence: Notes | SCARY; Stated in tracker (fidelity pass 1: Hedge lost corrected))", "Top Troubling #2": "[DISCRIMINATORY_PRACTICE · FL-1] DOJ alleges Elevance pressured brokers to enroll fewer disabled Medicare beneficiaries\nWHAT THE TERMS SAY: A May 2025 DOJ False Claims Act suit (D. Mass.) alleges Elevance, Aetna, and Humana paid brokers hundreds of millions in illegal kickbacks to steer Medicare beneficiaries into their plans, and specifically threatened to withhold kickback payments unless brokers enrolled fewer disabled beneficiaries, whom the insurers considered less profitable — leading brokers to reject and steer away disabled applicants. Elevance has said it will contest the allegations.\nWHY IT MATTERS: If proven, disabled Medicare beneficiaries were systematically steered away from coverage because they were seen as costlier; the allegations remain contested and unproven.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CONFIRMED_BREACH · FL-2] Nov 2025 breach exposed medical records and SSNs; a separate vendor breach hit Virginia state employees\nWHAT THE TERMS SAY: Disclosed Nov 19, 2025, a breach affected at least 1,162 individuals in Massachusetts (likely more nationally), exposing names, addresses, birthdates, SSNs, medical records, and driver's license numbers. Separately, a Conduent (Elevance's printing/mailing/payment vendor) breach discovered Jan 13, 2025 and traced to compromised VPN credentials affected Virginia state employees on Elevance-administered COVA Care/COVA High Deductible plans; Virginia's DHRM was notified Dec 2, 2025 — over 11 months after the incident.\nWHY IT MATTERS: Virginia state employees enrolled in Elevance-administered COVA Care/COVA High Deductible plans had data exposed through a vendor breach, and Virginia's Department of Human Resource Management was not notified until more than 11 months after the underlying incident.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Breach details, the HIPAA settlement, the class settlement, and pending DOJ/antitrust litigation are all clearly dated and sourced in the tracker.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Elevance Health (Anthem)  <-  Elevance Health, Inc. (fmr. Anthem Inc., renamed June 2022)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Elevance Health (Anthem) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T20:11:03Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Anthem's 2015 breach set records that stood for nearly a decade: 78.8 million people, and a resulting $16 million HIPAA settlement with HHS that was more than triple the previous largest ever, plus a $115 million class settlement that was at the time the biggest consumer data breach settlement in US history - roughly $179 million in total penalties and settlements. But the enforcement findings are the part that should sting. Federal investigators concluded Anthem had never conducted an enterprise-wide risk analysis, lacked adequate procedures to review its own system activity, failed to identify and respond to known security incidents, and had insufficient access controls to stop attackers from moving laterally once inside. The attackers got in through a phishing email answered by one employee at a subsidiary and roamed the network for eight weeks. Individual class members received up to about $50.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 393, "_entity_id": 585, "_entity_slug": "elevance-health-anthem", "_issuer": "Elevance Health, Inc.", "_issuer_slug": "elevance-health-inc", "_ticker": "ELV", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "UnitedHealthcare", "Category": "Health Insurance", "Terms & Conditions URL": "uhc.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "uhc.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED 2026 BREACH (reported to HHS June 5, 2026): affected 34,574 individuals — specific data types not yet publicly detailed as of this research, though health-insurer breaches typically involve medical/claims information. SEPARATELY, UnitedHealthcare's SIBLING COMPANY Change Healthcare (both under parent UnitedHealth Group) suffered the MASSIVE 2024 ransomware breach already documented elsewhere in this tracker (CareFirst BlueCross BlueShield row, Insurance tab), which CareFirst itself sued over — meaning UnitedHealth Group's corporate family has now generated at least TWO separate, serious breach incidents referenced across this tracker.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out via physical letter to Minnetonka, MN. Nuclear clause: if class waiver unenforceable, entire arbitration agreement voids. The Change Healthcare breach (190M+ people, largest healthcare breach on record) means any UHC member who missed their 30-day opt-out has waived class-action rights over the breach. The nH Predict algorithm denial lawsuit (Lokken v. UnitedHealth, W.D. Ky.) alleges systematic Medicare Advantage coverage denials using AI — also subject to the arbitration clause for individual claimants.", "Fees / Billing Flags": "SEPARATE, UNRELATED ANTITRUST CONTEXT: UnitedHealthcare provided the DOJ with 'highly confidential' competitive data as evidence in the DOJ's SEPARATE antitrust suits blocking the proposed Aetna-Humana and Anthem-Cigna mergers — a competitor-cooperation dynamic rather than a customer-facing issue, but illustrating how the health-insurance industry's major players are also adversaries in federal antitrust litigation with each other.", "Notes": "UnitedHealth Group's overall corporate family (UnitedHealthcare + Change Healthcare + OptumRx, all referenced across this tracker) represents one of the most extensively cross-referenced parent companies in this entire 400+ company audit — worth treating its cumulative regulatory/legal exposure as a single connected profile.\n\nAUG 2026 ADDENDUM: (1) CHANGE HEALTHCARE - ~190M records (some reporting 192.7M), largest breach ever reported to HHS OCR; Change Healthcare is a UnitedHealth Group subsidiary, so this belongs to the UHG corporate family even though it is a clearinghouse rather than the insurer. (2) ALGORITHMIC DENIAL LITIGATION, ongoing (allegations, not findings): Estate of Gene B. Lokken et al. v. UnitedHealth Group Inc., naviHealth Inc. et al., No. 0:23-cv-03514 (D. Minn.). Complaint alleges ~90% of nH Predict denials and 80%+ of preauthorization denials were reversed on appeal. Feb 13 2025: Judge Tunheim allowed breach of contract and breach of the implied covenant of good faith and fair dealing to proceed - among the first times a court let an AI-denial class action advance. Sept 2025: discovery scope preserved over UHG objections; moving toward class certification as of mid-2026. Optum acquired naviHealth in 2020 (reported at $1B+; some sources cite $2.5B). Senate investigation led by Sen. Richard Blumenthal, released Oct 2024, found post-acute denial rates rose 10.9% (2020) to 22.7% (2022) with skilled-nursing denials up roughly ninefold. KFF: ~0.2% of Medicare Advantage members appealed denied claims in 2021. CMS issued clarifying guidance Feb 2024 that an algorithm alone cannot be the basis for a coverage denial. CROSS-REF: Humana row (same nH Predict tool), Cigna row (parallel PXDX case), and the OptumRx/Change Healthcare references elsewhere in this tracker.", "Industry (Fortune 500)": "Health Care: Insurance and Managed Care", "Revenue (Fortune 500)": "$447.6B", "Market Cap": "$391.7B", "Employees": "400,000", "HQ City": "Eden Prairie", "HQ State": "Minnesota", "CEO": "Stephen J. Hemsley", "Ticker": "UNH", "Website (Corporate)": "unitedhealthgroup.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (UNH). Service route: c/o General Counsel / Corporate Secretary, Eden Prairie, Minnesota — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.hipaaguide.net/change-healthcare-data-breach/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Minnesota' is a non-DMV US state", "Parent / Ultimate Owner": "UnitedHealth Group, Inc.", "Years Referenced in Finding (heuristic)": "2020, 2022", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: UnitedHealth Group, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] UHC members who missed the 30-day opt-out waived class-action rights over the Change Healthcare breach\nWHAT THE TERMS SAY: UHC uses mandatory binding arbitration with a class action waiver and a 30-day opt-out via physical letter to Minnetonka, MN; if the class waiver is ever ruled unenforceable, the entire arbitration agreement voids ('nuclear clause'). Any UHC member who missed the 30-day window has waived class-action rights over the Change Healthcare breach.\nWHY IT MATTERS: Members who did not opt out within 30 days waived their class-action rights over the Change Healthcare breach, the largest healthcare breach on record.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] Change Healthcare breach exposed 190M+ records, the largest healthcare breach on record\nWHAT THE TERMS SAY: UnitedHealth Group subsidiary Change Healthcare suffered a ransomware breach (~190M records, some reporting 192.7M) — the largest ever reported to HHS OCR. Separately, UnitedHealthcare itself reported a 2026 breach affecting 34,574 individuals (HHS report June 5, 2026), with specific data types not yet publicly detailed.\nWHY IT MATTERS: The company's corporate family has generated at least two separate, serious breach incidents, and the newer one's exposed data categories are not yet publicly detailed as of this research.\n(evidence: Data Sharing/Selling Flags | Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[OTHER · FL-1] nH Predict allegedly denies rehab coverage with a 90% reversal rate, but almost no one appeals\nWHAT THE TERMS SAY: A class action (Lokken v. UnitedHealth, D. Minn.) alleges UnitedHealth's nH Predict algorithm was used to deny post-acute care coverage for elderly Medicare Advantage members, with roughly 90% of denials reversed on appeal; only about 0.2% of denied members appeal at all. A Feb 2025 ruling let breach-of-contract and good-faith claims proceed. A Senate investigation found post-acute denial rates rose from 10.9% (2020) to 22.7% (2022).\nWHY IT MATTERS: Even setting the allegations aside, the structural pattern — a high reversal rate paired with a near-nonexistent appeal rate — means most denials, right or wrong, are never challenged.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Arbitration terms are directly quoted, and both the breach and the litigation are well-documented with dates, case names, and figures.", "Exposure Score (0-100)": 44, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "UnitedHealthcare  <-  UnitedHealth Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using UnitedHealthcare you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "2026-09-08T20:11:05Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Two findings, either of which would carry this row alone. First: the Change Healthcare attack on UnitedHealth's own subsidiary exposed roughly 190 million records - the largest healthcare data breach ever recorded anywhere in the world, more than double Anthem's previous record, and equal to well over half the US population. Second, and worse in daily terms: a class action alleges UnitedHealth's nH Predict algorithm - acquired with naviHealth and built on a database of about six million patients - decided when elderly Medicare Advantage members should stop needing rehabilitation, with an alleged 90% reversal rate on appeal. Set that against the other number in the case: only about 0.2% of denied Medicare Advantage members appeal at all. A tool that loses nine out of ten fights, pointed at people who almost never fight. A Senate investigation found post-hospital care denial rates rose from 10.9% in 2020 to 22.7% in 2022, and the court order noted denials more than doubled after the tool went live.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 394, "_entity_id": 587, "_entity_slug": "unitedhealthcare", "_issuer": "UnitedHealth Group, Inc.", "_issuer_slug": "unitedhealth-group-inc", "_ticker": "UNH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Aetna (CVS Health)", "Category": "Health Insurance", "Terms & Conditions URL": "aetna.com/legal-notices.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "aetna.com/legal-notices/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not itemized separately from the DOJ/antitrust findings below.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. See the Aetna Health Inc. row in this tab for the detailed finding: 60-day opt-out, but class action waiver AND jury trial waiver survive the opt-out. This is the parent-level Aetna row; the Aetna Health Inc. row covers the DMV-operating subsidiary specifically.", "Fees / Billing Flags": "SAME DOJ MEDICARE ADVANTAGE KICKBACK/DISABILITY-DISCRIMINATION LAWSUIT as Elevance/Humana (see Elevance row for full detail) — Aetna is a named co-defendant alleged to have both paid illegal broker kickbacks AND specifically pressured brokers to enroll fewer disabled Medicare beneficiaries. SAME antitrust/Zelis out-of-network reimbursement conspiracy case as Elevance/UnitedHealth/Cigna/Humana (see Elevance row).", "Notes": "Aetna is owned by CVS Health, meaning it shares ultimate corporate ownership with CVS Caremark (the PBM documented in the Pharmacy Benefit Managers tab of this tracker, itself subject to the separate FTC insulin-pricing case) — worth treating CVS Health's overall corporate family as one connected profile spanning pharmacy benefits, retail pharmacy, and now health insurance.\n\nAUG 2026 ADDENDUM (verified this pass; supersedes 'not itemized separately'): July 28 2017 mailing to ~12,000 people nationwide; complaint alleged Aetna transmitted the names of 13,487 customers prescribed HIV medications to outside counsel and a mail vendor, and that oversized transparent-window envelopes were sent to 11,875 of them. Second incident Sept 2017: ~1,600 letters revealing participation in an atrial fibrillation study. Class settlement $17,161,200, E.D. Pa., announced Jan 17 2018; at least $12M reserved for base payments of $500+ per person, with a separate fund allowing claims up to $20,000 for demonstrated financial or emotional harm. Brought by the AIDS Law Project of Pennsylvania, the Legal Action Center, and Berger & Montague. Separate state actions: New Jersey $365,211.59, DC $175,000, Connecticut $100,000 (Oct 2018, ~$640K combined); California $935,000 (Jan 2019, AG Becerra) under the Confidentiality of Medical Information Act, Health & Safety Code sec. 120980, the state constitution and the UCL. Separate ~$1M+ New York settlement. The July 2017 mailing was executed by a third-party vendor not named as a defendant. CONTEXT: CVS Health had a materially similar HIV-benefit envelope incident in April 2018, and CVS/Aetna received conditional merger approval that same month - CROSS-REF the CVS Caremark row in the Pharmacy Benefit Managers tab.\n\n[RECOVERED from an unheaded column during the Aug 2026 structural fix; this text was present in the file but sat outside any labelled column] See Elevance row for full detail on both the DOJ disability-discrimination case and the Zelis antitrust case, both of which name Aetna as a co-defendant alongside Elevance/Humana/UnitedHealth/Cigna.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Hartford", "HQ State": "Connecticut", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 60, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.hipaajournal.com/aetna-settles-class-action-lawsuit-filed-victims-hiv-status-data-breach/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Connecticut' is a non-DMV US state", "Parent / Ultimate Owner": "CVS Health Corporation", "Years Referenced in Finding (heuristic)": "2017", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Connecticut SOTS CONCORD — service.ct.gov/business/s/onlinebusinesssearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: CVS Health Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Aetna's 2017 HIV-status mailing used envelopes with windows large enough to reveal medication names\nWHAT THE TERMS SAY: In July 2017, Aetna mailed ~12,000 people letters about filling HIV/PrEP prescriptions in envelopes with a transparent window large enough to display the contents; a second Sept 2017 mailing exposed ~1,600 people's participation in an atrial fibrillation study the same way. The letters were themselves notifying members about the resolution of EARLIER litigation over Aetna requiring HIV patients to use mail-order pharmacies.\nWHY IT MATTERS: People's HIV status was disclosed to anyone who saw the envelope, with no hacking involved, while the mailing was meant to resolve a prior privacy complaint about the same issue.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-2] Aetna paid $17.2M to settle the HIV-mailing class action, plus about $1.6M more across four states\nWHAT THE TERMS SAY: A $17,161,200 class settlement (E.D. Pa., announced Jan 2018) reserved at least $12M for base payments of $500+ per person, with claims up to $20,000 for demonstrated harm. Separate state actions added New Jersey ($365,211.59), DC ($175,000), Connecticut ($100,000), and California ($935,000, under the state's Confidentiality of Medical Information Act) plus a separate New York settlement over $1M.\nWHY IT MATTERS: Multiple regulators independently found the same conduct penalty-worthy, on top of the private class settlement.\n(evidence: Notes; Stated in tracker (fidelity pass 1: Overstated corrected))", "Top Troubling #3": "[DISCRIMINATORY_PRACTICE · FL-1] Aetna is a named co-defendant in the DOJ suit over disabled-beneficiary steering and kickbacks\nWHAT THE TERMS SAY: Aetna is a named co-defendant, alongside Elevance and Humana, in the DOJ Medicare Advantage kickback/disability-discrimination lawsuit (see the Elevance row for detail) alleging illegal broker kickbacks and specific pressure on brokers to enroll fewer disabled Medicare beneficiaries considered less profitable. Aetna is also a co-defendant in the Zelis antitrust conspiracy case alleging suppression of out-of-network reimbursement rates.\nWHY IT MATTERS: If proven, this reflects a deliberate steering-away of disabled applicants from coverage; both matters remain contested.\n(evidence: Fees / Billing Flags; Stated in tracker (firewall-edited: unverifiable figure removed) (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The HIV-mailing incident, settlements, and pending DOJ/antitrust cases are all specifically dated, quantified, and sourced.", "Exposure Score (0-100)": 44, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 25, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 25/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_60d+1) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Aetna (CVS Health)  <-  CVS Health Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to a jury.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Aetna (CVS Health) you gave up your right to sue, your right to join a class action, and your right to a jury. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "2026-09-08T20:11:08Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "In July 2017 Aetna mailed about 12,000 members letters about filling prescriptions for HIV medication and PrEP - in envelopes whose transparent window was large enough to display the words through the plastic. The irony is exact: those letters were sent to notify members of the resolution of EARLIER privacy litigation, brought because Aetna had required HIV patients to use mail-order pharmacies rather than pick up prescriptions in person. A second mailing two months later exposed 1,600 people's participation in an atrial fibrillation study the same way. Aetna paid $17.2 million to settle the class action - base payments of about $500 each, with claims up to $20,000 available for those who could show additional harm - then roughly $640,000 more to New Jersey, Connecticut and DC, and $935,000 to California. Counsel's framing was that the harm was in the status being disclosed, full stop: no hacker, no breach of a system, just an envelope specification.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 395, "_entity_id": 588, "_entity_slug": "aetna-cvs-health", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cigna Healthcare", "Category": "Health Insurance", "Terms & Conditions URL": "cigna.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "cigna.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED THIRD-PARTY VENDOR BREACH (disclosed Dec 2025, affecting a Massachusetts Mutual Life Insurance Company benefit plan Cigna administers): a Cigna vendor's incident — occurring October 21, 2024 to January 13, 2025, discovered Sept 23-29, 2025 — exposed CLAIM OVERPAYMENT AND RECOVERY FILES, with Social Security numbers included for some individuals. Cigna states there is 'no evidence of actual or attempted misuse.' SEPARATELY, an active class action (filed around Jan 2026) accuses The Cigna Group of failing to properly secure patient health/claims information in a DIFFERENT breach incident.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Cigna is separately involved (as a DIFFERENT company, via Express Scripts) in the major FTC insulin-pricing settlement documented in the Pharmacy Benefit Managers tab of this tracker — worth cross-referencing since Cigna's Express Scripts subsidiary and Cigna Healthcare itself are related but distinct entities within the same corporate family.\n\nAUG 2026 ADDENDUM - PRIVATE LITIGATION, ongoing (allegations, not findings): PXDX (procedure-to-diagnosis) class action, E.D. California, filed 2023. Alleges 300,000+ claims denied in a two-month 2022 window at ~1.2 seconds average per claim. Underlying reporting: Rucker, Miller & Armstrong, ProPublica (2023). Legal basis: California Health & Safety Code sec. 1367.01(e) (medical-necessity denials must be reviewed by a licensed physician competent in the specific clinical issue), breach of the plan's own terms, and California's Unfair Competition Law. March 2025 ruling allowed claims to proceed, finding that delegating the substantive decision to an algorithm may violate plan terms. CIGNA'S POSITION, recorded fairly: PXDX does not use AI or machine learning, is a code-matching sorting tool comparable to CMS systems, and most claims it touches are auto-PAID rather than denied. Reported reversal rate on appeal for PXDX denials is ~80% - lower than nH Predict's alleged 90% but the same structural pattern. CROSS-REF: UnitedHealthcare and Humana rows (nH Predict); Express Scripts / FTC insulin matter in the Pharmacy Benefit Managers tab is a SEPARATE Cigna-family issue - do not blend them.", "Industry (Fortune 500)": "Health Care: Pharmacy and Other Services", "Revenue (Fortune 500)": "$274.9B", "Market Cap": "$75.4B", "Employees": "72,398", "HQ City": "Bloomfield", "HQ State": "Connecticut", "CEO": "David Cordani", "Ticker": "CI", "Website (Corporate)": "thecignagroup.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (CI). Service route: c/o General Counsel / Corporate Secretary, Bloomfield, Connecticut — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Connecticut' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2022, 2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Connecticut SOTS CONCORD — service.ct.gov/business/s/onlinebusinesssearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-1] Cigna's PXDX system allegedly denied 300,000+ claims at 1.2 seconds average review each\nWHAT THE TERMS SAY: A class action (E.D. Cal., filed 2023) alleges Cigna medical directors used its PXDX tool to deny 300,000+ claims over a two-month 2022 window at ~1.2 seconds average review time, in possible violation of a California law requiring medical-necessity denials to be reviewed by a licensed, clinically competent physician. A March 2025 ruling let the case proceed. Cigna says PXDX is a code-matching sorting tool, not AI, and that most claims routed through it are auto-paid. Reported reversal rate on appeal is ~80%.\nWHY IT MATTERS: If the allegations hold, claims meant to receive individualized physician review were processed in bulk in seconds, and the alleged appeal-reversal rate suggests many denials may not have held up.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] Vendor breach exposed SSNs in claim-recovery files for a MassMutual benefit plan Cigna administers\nWHAT THE TERMS SAY: A Cigna vendor incident (Oct 21, 2024-Jan 13, 2025, discovered Sept 2025, disclosed Dec 2025) exposed claim overpayment and recovery files, including SSNs for some individuals, for a MassMutual benefit plan administered by Cigna. Cigna states there is 'no evidence of actual or attempted misuse.' A separate, unrelated class action (filed ~Jan 2026) also accuses Cigna of failing to secure patient claims data in a different incident.\nWHY IT MATTERS: Members' SSNs sat in the files of a vendor to the company administering their employer's benefit plan — a party the member has no direct relationship with; Cigna states there is 'no evidence of actual or attempted misuse.'\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and fee terms are both unconfirmed this pass ('standard...expected' / 'not itemized'), leaving two substantive items rather than three.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The vendor breach and PXDX litigation are well-documented, but Cigna's own arbitration and fee terms were not confirmed this pass.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Cigna Healthcare  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Cigna Healthcare takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A class action alleges that over a two-month stretch in 2022, Cigna medical directors used a system called PXDX to deny more than 300,000 claims at an average of 1.2 seconds of review each - and a former Cigna physician told ProPublica the process amounted to clicking submit on batches of fifty at a time, taking about ten seconds. The legal theory is precise rather than rhetorical: California law requires a medical-necessity denial to be reviewed by a licensed physician competent to evaluate the specific clinical issue, and the plaintiffs argue a 1.2-second rubber stamp is not a review, which would also breach the plan's own terms requiring a medical director to make the call. Cigna's defense is that PXDX is not AI at all but simple sorting technology that matches procedure codes to diagnosis codes, similar to systems CMS itself uses, and that the vast majority of claims routed through it were paid automatically. A judge let the case proceed in March 2025.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 396, "_entity_id": 589, "_entity_slug": "cigna-healthcare", "_issuer": "Cigna Healthcare", "_issuer_slug": "cigna-healthcare", "_ticker": "CI", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Humana", "Category": "Health Insurance", "Terms & Conditions URL": "humana.com/legal/website-terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "humana.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not itemized separately from the DOJ/antitrust findings below.", "Arbitration / Class Action Waiver": "Humana's consumer ToS contain arbitration provisions. Opt-out mechanism exists but specific window not confirmed from text retrieved this pass. The nH Predict algorithm lawsuit (class action, W.D. Ky.) alleges Humana used the same NaviHealth AI tool at issue in the UnitedHealth litigation to deny post-acute care coverage. DC AG joined a multistate coalition investigating AI-driven health-insurance denials (2024).", "Fees / Billing Flags": "SAME DOJ MEDICARE ADVANTAGE KICKBACK/DISABILITY-DISCRIMINATION LAWSUIT as Elevance/Aetna (see Elevance row for full detail) — Humana is a named co-defendant. SAME antitrust/Zelis out-of-network reimbursement conspiracy case as Elevance/UnitedHealth/Aetna/Cigna (see Elevance row).", "Notes": "Not itemized this pass.\n\nAUG 2026 ADDENDUM - PRIVATE LITIGATION, ongoing (allegations, not findings; supersedes 'not itemized this pass'): Humana was sued in 2023 over use of nH Predict to deny Medicare Advantage post-acute care claims, following legal theories parallel to Lokken v. UnitedHealth. Survived a motion to dismiss in August 2025. Same vendor tool (naviHealth/nH Predict) as the UnitedHealthcare row - treat the two as one connected story about a purchased product deployed across competitors, not two independent scandals. CMS guidance issued Feb 2024 applies to Humana equally. Sector context: AM Best reported a $5.7B Medicare Advantage underwriting loss for 2024, the segment's first in years - relevant to why automated denial pressure intensified. Recommend a follow-up on the case caption and current posture before publishing, and on Humana's separate DOJ/antitrust exposure already referenced in this tab.\n\n[RECOVERED from an unheaded column during the Aug 2026 structural fix; this text was present in the file but sat outside any labelled column] See Elevance row for full detail; Humana is implicated in BOTH the same DOJ disability-discrimination case AND the same Zelis antitrust conspiracy case as three other major insurers documented in this tab, illustrating how concentrated the alleged coordinated conduct is across the health-insurance industry's largest players.", "Industry (Fortune 500)": "Health Care: Insurance and Managed Care", "Revenue (Fortune 500)": "$129.7B", "Market Cap": "$49.2B", "Employees": "65,680", "HQ City": "Louisville", "HQ State": "Kentucky", "CEO": "Jim Rechtin", "Ticker": "HUM", "Website (Corporate)": "humana.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (HUM). Service route: c/o General Counsel / Corporate Secretary, Louisville, Kentucky — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.statnews.com/2023/12/12/humana-algorithm-medicare-advantage-patients-lawsuit/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Kentucky' is a non-DMV US state", "Parent / Ultimate Owner": "Humana Inc.", "Years Referenced in Finding (heuristic)": "2023, 2025, 2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Kentucky) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Kentucky. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] Humana is accused of using the same nH Predict algorithm as UnitedHealth to deny post-acute claims\nWHAT THE TERMS SAY: Humana was sued in 2023 over using the naviHealth/nH Predict tool to deny Medicare Advantage post-acute care claims; the suit survived a motion to dismiss in August 2025. CMS guidance (Feb 2024) states an algorithm alone cannot be the basis for a coverage denial. AM Best reported a $5.7B Medicare Advantage underwriting loss for 2024, the segment's first in years.\nWHY IT MATTERS: The same denial tool was deployed across at least two competing insurers, so switching Medicare Advantage plans would not necessarily have avoided it.\n(evidence: Arbitration / Class Action Waiver | Notes; Stated in tracker (fidelity pass 1: Hedge lost corrected))", "Top Troubling #2": "[DISCRIMINATORY_PRACTICE · FL-1] Humana is a co-defendant in the DOJ's disability-discrimination Medicare kickback case\nWHAT THE TERMS SAY: Humana is a named co-defendant in the same DOJ False Claims Act suit as Elevance and Aetna, alleging illegal broker kickbacks and pressure to enroll fewer disabled Medicare beneficiaries, and in the same Zelis antitrust conspiracy case over out-of-network reimbursement suppression.\nWHY IT MATTERS: The same disability-discrimination and price-fixing allegations facing Elevance and Aetna apply directly to Humana as a co-defendant.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Humana's own consumer arbitration opt-out window is explicitly unverified this pass, so only these two litigation-based items are substantive.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Litigation details are well-documented, but Humana's own arbitration opt-out window and data-sharing specifics are unverified.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 14, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 14/30 (forced_arbitration+12, optout_window_unverified+2) | Data 0/30 (none) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Humana  <-  Humana Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Humana you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "2026-09-08T20:11:13Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Humana was sued in 2023 over the same nH Predict algorithm at issue in the UnitedHealth case - the naviHealth-built tool that estimates how long a Medicare Advantage patient 'should' need post-acute rehabilitation and then supports cutting coverage when they hit that estimate. The suit survived Humana's dismissal bid in August 2025. What makes this row worth reading next to the UnitedHealth one rather than as a duplicate is what it demonstrates: the tool was not one company's bad idea, it was a product, sold and deployed across competing insurers, which means a patient shopping between Medicare Advantage plans could have been switching brands while landing under the same algorithm either way. The industry context sharpens it - AM Best found Medicare Advantage posted a $5.7 billion underwriting loss in 2024, its first in years, because patients used more care than plans had priced in.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 397, "_entity_id": 591, "_entity_slug": "humana", "_issuer": "Humana Inc.", "_issuer_slug": "humana-inc", "_ticker": "HUM", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Delta Dental", "Category": "Dental Insurance", "Terms & Conditions URL": "deltadentalins.com/about/terms-of-use.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "deltadentalins.com/about/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "COMPLETED REGULATORY SETTLEMENT (April 30, 2026): the New York State Department of Financial Services (NYDFS) reached a $2.25 MILLION settlement with Delta Dental Insurance Company AND the separately-licensed nonprofit Delta Dental of New York — specifically over the companies' RESPONSE to the widespread 2023 MOVEit third-party file-transfer software vulnerability (the same underlying MOVEit vulnerability that caused breaches at numerous other organizations broadly, similar to the Comcast/Citrix and other third-party-vendor incidents documented throughout this tracker). This is a REGULATORY settlement (state financial regulator vs. company) rather than a private consumer class action, reflecting NYDFS's specific authority to penalize inadequate breach RESPONSE procedures, not just the underlying vulnerability itself.", "Arbitration / Class Action Waiver": "Delta Dental is a FEDERATION of 39 independent companies, not a single entity — each state's Delta Dental sets its own terms. The NY DFS settlement ($2.25M, April 2026) was against Delta Dental of New York specifically for MOVEit zero-day breach failures. A DMV consumer's Delta Dental terms depend on which Delta Dental affiliate provides their coverage.", "Fees / Billing Flags": "The $2.25M penalty was paid to the STATE REGULATOR, not distributed to affected individual consumers — worth noting this distinction, since NYDFS settlements typically function as regulatory fines rather than consumer compensation funds.", "Notes": "Delta Dental is one of MANY organizations affected by the broader 2023 MOVEit vulnerability (a single third-party software flaw that caused breaches across dozens of unrelated companies industry-wide) — worth treating as part of that broader MOVEit incident wave rather than a Delta-Dental-specific security failure.\n\nAUG 2026 ADDENDUM - REGULATORY ACTION, verified: NYDFS settlement $2.25M, April 30 2026, covering Delta Dental Insurance Company and a separately-named affiliated entity. Root cause traces to the 2023 MOVEit managed file transfer vulnerability. CROSS-REF: MOVEit hit dozens of unrelated organizations across sectors - if a vendor/supply-chain column is ever added to this tracker, MOVEit and the 2025-26 social-engineering campaign are the two connective threads that should anchor it.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Oak Brook", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.dfs.ny.gov/reports_and_publications/press_releases/pr20260430", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Delta Dental Plans Association (federation of 39 independent companies)", "Years Referenced in Finding (heuristic)": "2026, 2023", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Delta Dental Plans Association (federation of 39 independent companies)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] NYDFS fined Delta Dental $2.25M over its response to the 2023 MOVEit vendor breach\nWHAT THE TERMS SAY: NYDFS reached a $2.25M settlement (April 30, 2026) with Delta Dental Insurance Company and the affiliated Delta Dental of New York, specifically over their response to the 2023 MOVEit third-party file-transfer vulnerability — a regulatory fine for inadequate breach-response procedures, not a private consumer class action. The penalty was paid to the state regulator, not distributed to affected consumers.\nWHY IT MATTERS: The security failure originated in a vendor's software, and the penalty is a regulatory fine rather than compensation to affected members.\n(evidence: Data Sharing/Selling Flags | Fees / Billing Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Delta Dental is a federation of 39 independent state affiliates with no single set of consumer terms, and arbitration/fee terms for a given member depend on which affiliate covers them and were not itemized this pass — leaving only the NYDFS settlement as a verified, company-specific item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The NYDFS settlement is precisely dated and quantified, but Delta Dental's fragmented 39-affiliate structure means individual member terms are not independently confirmed.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Delta Dental  <-  Delta Dental Plans Association (federation of 39 independent companies)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Delta Dental takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "2026-09-08T20:11:16Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Delta Dental settled with New York's Department of Financial Services for $2.25 million in April 2026 over a breach that reached it through MOVEit - a single flaw in one file-transfer product that produced breaches at dozens of entirely unrelated organizations across 2023. That is the structural finding worth carrying out of this row: your dental insurer's security posture was not the variable that decided whether your data leaked. A vendor you have never heard of, chosen by someone you will never meet, was. Nothing in the member terms you agreed to gives you any visibility into that supply chain, let alone any say over it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 398, "_entity_id": 593, "_entity_slug": "delta-dental", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Guardian Life", "Category": "Life/Dental/Vision Insurance", "Terms & Conditions URL": "guardianlife.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "guardianlife.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "RELATED-ENTITY BREACH (distinct company, same 'Guardian' branding, worth NOT confusing with Guardian Life itself): Pacific Guardian Life Insurance Co. Ltd. (a SEPARATE Hawaii-based insurer, not a subsidiary of the national Guardian Life Insurance Company of America) suffered an August 2023 cybersecurity incident and reached a ~$2 million class-action settlement (final approval hearing Jan 13, 2026) over allegedly inadequate customer-data protection. No breach or lawsuit specific to the national Guardian Life Insurance Company of America was independently confirmed this pass.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "IMPORTANT: 'Pacific Guardian Life' and 'Guardian Life' (Guardian Life Insurance Company of America) are DIFFERENT, UNRELATED COMPANIES despite the shared 'Guardian' name — worth being precise about this distinction given how easily the two could be confused in casual research.\n\nAUG 2026 ADDENDUM: naming-collision hazard documented above stands. Nothing independently confirmed against Guardian Life Insurance Company of America this pass. Recommend a direct follow-up. TRACKER-LEVEL NOTE: this is a good example of why the fuzzy-match dedup discipline in the project guide matters in both directions - similar names sometimes mean the SAME company under different labels, and sometimes mean genuinely different companies that must not be merged.", "Industry (Fortune 500)": "Insurance: Life, Health (Mutual)", "Revenue (Fortune 500)": "$16.5B", "Market Cap": "Non-public", "Employees": "7,472", "HQ City": "New York", "HQ State": "New York", "CEO": "Andrew McMahon", "Ticker": "Non-public", "Website (Corporate)": "guardianlife.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (Non-public). Service route: c/o General Counsel / Corporate Secretary, New York, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — No breach, regulatory action, or lawsuit against Guardian Life Insurance Company of America itself was confirmed this pass; the only documented incident belongs to Pacific Guardian Life, an unrelated company with a similar name, and is excluded here per the cross-reference rule.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No confirmed findings for Guardian Life itself surfaced this pass, and no arbitration or fee terms were located; the only substantive content concerns a separate, unrelated company.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Guardian Life  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Guardian Life takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "2026-09-08T20:11:18Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "The most useful thing this row does is prevent a mistake. Pacific Guardian Life Insurance Co. Ltd. - a separate Hawaii-based insurer - had a breach, and it is NOT a subsidiary of or otherwise connected to Guardian Life Insurance Company of America. Two different companies, shared brand word, unrelated corporate families. This matters beyond bookkeeping: consumers researching whether their insurer was breached routinely land on the wrong company, and aggregator and content-mill sites conflate similarly-named entities constantly. No confirmed breach, regulatory action or privacy settlement attaching to Guardian Life itself surfaced this pass, and that is the honest state of the row rather than a clean bill of health.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 399, "_entity_id": 594, "_entity_slug": "guardian-life", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "VSP Vision Care", "Category": "Vision Insurance", "Terms & Conditions URL": "vsp.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "vsp.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; VSP is a member-owned (not-for-profit) vision benefits company, a somewhat different ownership/incentive structure than most other insurers in this tracker.\n\nAUG 2026 ADDENDUM: null result confirmed on a second pass. Recommend a targeted follow-up on (a) VSP member terms and any arbitration/class-waiver provisions, (b) data sharing with retail optical partners and lab networks, and (c) whether the not-for-profit member-owned structure produces different contractual terms than for-profit peers. Per the project guide, say plainly when a company looks better than peers - but VSP's record is currently UNVERIFIED rather than VERIFIED-CLEAN, and the distinction should be preserved in any published writeup.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Nothing was confirmed against VSP this pass — no breach, regulatory action, or lawsuit was located, and arbitration/fee terms remain unverified; per the tracker's own framing this is an unverified record, not a verified-clean one.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No breach, penalty, or litigation was found, and arbitration/data-sharing terms were not confirmed — a null result rather than a documented clean record.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "VSP Vision Care  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, VSP Vision Care takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "2026-09-08T20:11:21Z (HTTP 200, SAME)", "SCARY (most astonishing T&C item)": "Nothing independently confirmed this pass - no named breach, regulatory action or privacy lawsuit surfaced for VSP, and that null result appears genuine rather than a gap in searching. The structurally interesting fact about VSP is its ownership: it is a member-owned, not-for-profit vision benefits company, which is a materially different incentive structure from the publicly traded and mutual insurers filling the rest of this tab. Whether that translates into better data practices is exactly the kind of claim that should not be asserted without evidence, so it is not asserted here - but it is the right question for a follow-up pass, and a clean record is worth recording as a clean record.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 400, "_entity_id": 595, "_entity_slug": "vsp-vision-care", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "EyeMed Vision Care", "Category": "Vision Insurance", "Terms & Conditions URL": "eyemed.com/en-us/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "eyemed.com/en-us/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "HISTORICAL CONFIRMED BREACH (2020): EyeMed disclosed a breach in which a hacker accessed an employee email account for about 8 days, exposing personal and some vision-plan/health information for approximately 2.1 million members — a resulting class action was filed, and this remains a significant historical incident for this specific vision insurer, though this research pass could not confirm a more recent (2025-2026) follow-up incident.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up to confirm whether the 2020 breach's litigation has fully resolved and whether any newer incidents have occurred since.\n\nAUG 2026 ADDENDUM: 2020 incident, ~8-day unauthorized access window to an employee email account, ~2.1M individuals, exposing personal and some vision-plan/health information. Recommend a direct follow-up to confirm (a) final resolution of the resulting litigation and any state regulatory penalties, and (b) whether any newer incidents have occurred since. NOTE: EyeMed is owned by Luxottica/EssilorLuxottica - worth checking whether the parent appears elsewhere in the tracker before treating this as a standalone entity.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2020", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Hacker was in an EyeMed employee's email ~8 days; personal and some health data for ~2.1M members exposed\nWHAT THE TERMS SAY: In 2020, a hacker accessed an EyeMed employee email account for about 8 days, exposing personal and some vision-plan/health information for approximately 2.1 million members; a class action followed. A more recent (2025-2026) follow-up incident could not be confirmed this pass.\nWHY IT MATTERS: An eight-day dwell time in a single inbox is long enough to search, export, and forward records at leisure, and vision-plan data often gets less scrutiny than medical-plan data despite holding similar identifiers.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee terms are both unconfirmed this pass, leaving the 2020 breach as the only substantive item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2020 breach is well-documented, but its litigation resolution and any newer incidents, plus arbitration/fee terms, remain unconfirmed.", "Exposure Score (0-100)": 7, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 7, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 7/20 (severity2+2, breach+3, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "EyeMed Vision Care  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, EyeMed Vision Care takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A hacker sat inside an EyeMed employee's email account for roughly eight days in 2020 and reached personal and vision-plan health information for around 2.1 million people. Eight days is a long time in this context - long enough to read, search, forward and export at leisure - and the entry point was, again, one inbox rather than a hardened claims system. Vision plans occupy a strange blind spot in consumer risk assessment: people mentally file them alongside a gym membership rather than alongside health insurance, so the data they hold gets far less scrutiny than a medical plan's, despite the enrollment records containing the same identifiers a medical plan holds.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 401, "_entity_id": 596, "_entity_slug": "eyemed-vision-care", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Aflac", "Category": "Supplemental Insurance", "Terms & Conditions URL": "aflac.com/about-aflac/legal-and-privacy-information/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "aflac.com/about-aflac/legal-and-privacy-information/privacy-notice.aspx", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ONE OF THE LARGEST HEALTHCARE-ADJACENT BREACHES OF 2025: Aflac (the nation's LARGEST supplemental health insurance provider) discovered suspicious network activity June 12, 2025; the attacker used SOCIAL ENGINEERING to access multiple user accounts and was suspected to be affiliated with a known cybercriminal organization. Aflac initially reported a PLACEHOLDER figure of just 500 affected individuals to HHS (Aug 2025) while investigation continued — but after months of file review, confirmed the TRUE scope: protected health information of approximately 26.5 MILLION INDIVIDUALS was exposed, including claims data, health information, and Social Security numbers — making this the LARGEST confirmed healthcare data breach of 2025 (second only to Conduent Business Services' 25+ million, which affected Elevance/Anthem's Virginia state employees documented elsewhere in this tab). MORE THAN 20 separate class actions have been filed; a bipartisan pair of US Senators (Cassidy-R and Hassan-D) formally wrote to Aflac's CEO demanding greater transparency. MOST RECENTLY (June 2026): Aflac disclosed a COMPLETELY SEPARATE, NEW breach at its Aflac Japan subsidiary, where a third party accessed systems between June 15-25, 2026, gaining access to additional sensitive policyholder data.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual policyholder agreements, separate from the 20+ pending class actions.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The gap between Aflac's INITIAL 500-person placeholder report and the eventual CONFIRMED 26.5 MILLION figure (a roughly 53,000-FOLD increase) is one of the most dramatic examples in this entire tracker of how initial breach disclosures can understate the true scope by orders of magnitude — worth flagging prominently given how many Aflac policyholders likely received an early, seemingly-reassuring notification that understated their actual risk. Combined with the brand-new 2026 Japan subsidiary breach, Aflac now has two separate, serious incidents within about a year.\n\nAUG 2026 ADDENDUM: suspicious network activity discovered June 12 2025; intrusion via social engineering of the help desk rather than a technical exploit. Initial regulatory filing used a 500-person placeholder; confirmed scope 26.5M. This is the same social-engineering pattern as the broader 2025-26 campaign flagged as this tracker's biggest recurring cross-tab finding - treat as connected, not isolated. TRACKER-LEVEL NOTE: the 500-to-26.5M gap is a strong candidate for any future 'confidence' or 'last-verified' column, since it demonstrates that breach figures are provisional by nature. Recommend a follow-up on whether a class settlement has been reached and on Aflac's supplemental-policy claims practices, which are not covered by this pass.", "Industry (Fortune 500)": "Insurance: Life, Health (Stock)", "Revenue (Fortune 500)": "$17.2B", "Market Cap": "$60.3B", "Employees": "12,694", "HQ City": "Columbus", "HQ State": "Georgia", "CEO": "Daniel Amos", "Ticker": "AFL", "Website (Corporate)": "aflac.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AFL). Service route: c/o General Counsel / Corporate Secretary, Columbus, Georgia — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Georgia' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Georgia SOS eCorp — ecorp.sos.ga.gov/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Aflac's breach estimate ballooned from 500 to 26.5 million after months of review\nWHAT THE TERMS SAY: Aflac discovered suspicious network activity June 12, 2025, via social engineering against its help desk. An initial HHS filing (Aug 2025) used a placeholder of 500 affected individuals; the confirmed scope reached approximately 26.5 million, including claims data, health information, and SSNs — the largest confirmed healthcare breach of 2025 after Conduent's 25M+. More than 20 class actions have been filed, and Senators Cassidy and Hassan wrote to Aflac's CEO demanding more transparency. In June 2026 Aflac separately disclosed a new breach at its Aflac Japan subsidiary (systems accessed June 15-25, 2026).\nWHY IT MATTERS: Aflac's initial HHS filing used a 500-person placeholder against a confirmed scope roughly 53,000-fold larger, and policyholders likely received an early, seemingly-reassuring notification that understated their actual risk; a second, separate incident followed within about a year.\n(evidence: Data Sharing/Selling Flags | Notes; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee terms are unconfirmed this pass; the June 2026 Aflac Japan breach is folded into the same confirmed-breach item since both fall under the same harm category rather than a distinct tag.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The breach timeline, scope revision, and litigation are all specifically dated and quantified, even though arbitration/fee terms are unconfirmed.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Aflac  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Aflac takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Aflac's initial breach report listed 500 affected people. The confirmed figure came back at 26.5 million - a roughly 53,000-fold revision, and one of the starkest illustrations in this entire tracker of why an early breach notification number should be treated as a placeholder rather than a fact. The attacker did not exploit a software flaw; they used social engineering against Aflac's own help desk, which is the same technique behind the 2025-26 campaign that swept dozens of other companies documented across these tabs. For the nation's largest supplemental health insurer, the practical lesson for a consumer is uncomfortable: the number in the letter you receive in week one may bear no relationship to the number in the letter you receive in month six, and your decision about whether to freeze credit gets made on the first number.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 402, "_entity_id": 597, "_entity_slug": "aflac", "_issuer": "Aflac", "_issuer_slug": "aflac", "_ticker": "AFL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Colonial Life (Unum)", "Category": "Supplemental Insurance", "Terms & Conditions URL": "coloniallife.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "coloniallife.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Colonial Life is a subsidiary of Unum Group — recommend a direct follow-up checking Unum's own broader corporate privacy/legal record given thin verification of Colonial Life specifically this pass.\n\nAUG 2026 ADDENDUM: no Colonial Life-specific breach, regulatory action or privacy litigation independently confirmed this pass. Recommend a direct follow-up on Unum Group's own record - including whether Unum was affected by the 2023 MOVEit wave that hit Delta Dental and many other benefits administrators (see Delta Dental row) - and on worksite-enrollment disclosure practices generally, since that distribution channel involves employees accepting terms in a group setting with minimal opportunity to read them.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — No breach, regulatory action, or lawsuit specific to Colonial Life was confirmed this pass; the tracker recommends a follow-up on parent Unum Group's own record instead.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing was confirmed against Colonial Life specifically, and the tracker notes the workplace-enrollment channel itself is one where members rarely read their terms.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Colonial Life (Unum)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Colonial Life (Unum) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed against Colonial Life specifically this pass. The finding that does hold is structural: Colonial Life is a subsidiary of Unum Group, and for supplemental insurance sold primarily through workplace enrollment, the entity whose name is on your policy is often not the entity whose security program, litigation history or regulatory record actually governs your exposure. Employees enrolled at a benefits fair generally could not name the parent company, have never read the certificate of coverage, and would be searching the wrong name entirely if they tried to check whether their insurer had been breached.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 403, "_entity_id": 598, "_entity_slug": "colonial-life-unum", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "MassMutual", "Category": "Life Insurance", "Terms & Conditions URL": "massmutual.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "massmutual.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "RELATED-VENDOR BREACH CONTEXT: MassMutual benefit plans administered through CIGNA (see Cigna row) were affected by a third-party VENDOR incident (claim overpayment/recovery files, Oct 2024-Jan 2025, disclosed Dec 2025) — exposing some Social Security numbers for MassMutual-plan members specifically. No MassMutual-specific direct breach independently confirmed this pass beyond this vendor-related incident.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Cigna row for full detail on this shared vendor incident, which specifically named MassMutual benefit plans as affected.\n\nAUG 2026 ADDENDUM: see the Cigna row for full incident detail - vendor incident dated Oct 21 2024 with an exposure window running into Jan 2025, specifically naming MassMutual benefit plans among those affected. Recorded here as a cross-reference rather than re-researched, per the project guide's cross-reference standard. No MassMutual-originated breach, regulatory action or privacy settlement confirmed this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] A subcontractor two layers removed from MassMutual, via Cigna, exposed some members' SSNs\nWHAT THE TERMS SAY: MassMutual benefit plans administered through Cigna were affected by a Cigna vendor incident (claim overpayment/recovery files, Oct 2024-Jan 2025, disclosed Dec 2025), exposing SSNs for some MassMutual-plan members. No MassMutual-originated breach was independently confirmed this pass beyond this vendor-related incident.\nWHY IT MATTERS: The exposure reached members through a chain — member, MassMutual, Cigna, subcontractor — where the only entity the member has a direct relationship with is the first link, and member agreements don't name or require notice about the administrator's own vendors.\n(evidence: Data Sharing/Selling Flags | Notes | SCARY; Stated in tracker (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee terms are unconfirmed this pass, and no MassMutual-originated breach or regulatory action was found — only this vendor-chain exposure is a substantive, company-relevant item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The vendor-chain exposure affecting MassMutual members is specifically dated, but MassMutual's own arbitration/fee terms and any direct incident remain unconfirmed.", "Exposure Score (0-100)": 8, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "MassMutual  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, MassMutual takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "MassMutual's exposure here did not come through MassMutual. Benefit plans it sponsors are administered by Cigna, and a Cigna VENDOR had an incident involving claim overpayment and recovery files - so the chain runs member, to MassMutual, to Cigna, to a subcontractor nobody in that chain disclosed to the member by name. Three organizations deep, and the only entity a member has any contractual relationship with is the first one. The member agreements people accept do not name the administrator's vendors, do not require notice when they change, and give no mechanism to object.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 404, "_entity_id": 599, "_entity_slug": "massmutual", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Aetna Better Health of Kentucky", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.aetna.com/members/rights-and-responsibilities.html", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.aetna.com/legal/terms-of-use.html", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. CVS Health (parent) operates CVS Pharmacy, CVS Caremark (PBM), Aetna (insurance), and MinuteClinic — creating one of the most vertically integrated healthcare data environments in the US. A single member's prescription, insurance claim, and in-store purchase data can flow through the same parent. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Frankfort, KY. Parent: CVS Health Corporation. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Aetna Better Health of New Jersey. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Frankfort", "HQ State": "KY", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.aetnabetterhealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Frankfort, KY — not matched", "Parent / Ultimate Owner": "CVS Health Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (KY) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in KY. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] CVS Health can flow a KY Medicaid member's prescription, claim, and purchase data through one parent\nWHAT THE TERMS SAY: As a HIPAA-covered entity under CVS Health, which also operates CVS Pharmacy, CVS Caremark (PBM), and MinuteClinic, a single member's prescription, insurance claim, and in-store purchase data can flow through the same parent company. Plan-level data-sharing provisions were not independently verified this pass.\nWHY IT MATTERS: A member's pharmacy purchases, insurance claims, and retail-clinic visits can all be linked within one corporate family, with the specific sharing terms unconfirmed.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Medicaid fair-hearing rights may collide with Aetna's standard arbitration clause for KY Medicaid members\nWHAT THE TERMS SAY: The row notes Aetna Better Health of Kentucky uses 'the same arbitration structure as Aetna Health Inc.' and flags that Medicaid fair-hearing rights may preempt the arbitration clause in practice — though this entity's own arbitration and fee terms are explicitly marked not verified this pass.\nWHY IT MATTERS: Medicaid enrollees may be uncertain whether a standard commercial arbitration clause can override their statutory fair-hearing rights, and this entity's own arbitration terms are marked not verified this pass.\n(evidence: SCARY; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fee terms are explicitly marked not verified this pass, and no breach or litigation specific to this entity was found, leaving two items rather than three.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration, fees, and this entity's own data-sharing terms are all explicitly unverified; only the parent CVS structure and a hedged Medicaid-preemption observation are available.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Aetna Better Health of Kentucky  <-  CVS Health Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Aetna Better Health of Kentucky you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Aetna Better Health KY is CVS Health's Medicaid managed-care subsidiary in Kentucky. Same arbitration structure as Aetna Health Inc. Medicaid fair-hearing rights may preempt the arbitration clause in practice.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 405, "_entity_id": 600, "_entity_slug": "aetna-better-health-of-kentucky", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Aetna Better Health of New Jersey", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.aetna.com/members/rights-and-responsibilities.html", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.aetna.com/legal/terms-of-use.html", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. CVS Health (parent) operates CVS Pharmacy, CVS Caremark (PBM), Aetna (insurance), and MinuteClinic — creating one of the most vertically integrated healthcare data environments in the US. A single member's prescription, insurance claim, and in-store purchase data can flow through the same parent. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Princeton, NJ. Parent: CVS Health Corporation. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Aetna Better Health of Kentucky. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Princeton", "HQ State": "NJ", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.aetnabetterhealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Princeton, NJ — not matched", "Parent / Ultimate Owner": "CVS Health Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (NJ) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in NJ. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] CVS Health can flow an NJ Medicaid member's prescription, claim, and purchase data through one parent\nWHAT THE TERMS SAY: As a HIPAA-covered entity under CVS Health, which also operates CVS Pharmacy, CVS Caremark (PBM), and MinuteClinic, a single member's prescription, insurance claim, and in-store purchase data can flow through the same parent company. Plan-level data-sharing provisions were not independently verified this pass.\nWHY IT MATTERS: A member's pharmacy purchases, insurance claims, and retail-clinic visits can all be linked within one corporate family, with the specific sharing terms unconfirmed.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] NJ Medicaid members may face Aetna's arbitration/class-waiver terms, with unclear fair-hearing preemption\nWHAT THE TERMS SAY: The row states Aetna Better Health of New Jersey carries 'the same parent-level T&C as Aetna Health Inc. (mandatory arbitration, 60-day opt-out, class/jury waivers survive opt-out)' but flags that Medicaid members' arbitration rights may be preempted by state Medicaid fair-hearing requirements — a gray area not addressed in the terms themselves. This entity's own Arbitration field is separately marked not verified this pass.\nWHY IT MATTERS: Medicaid/CHIP enrollees face an unresolved conflict between a standard arbitration clause and their statutory fair-hearing rights — a legal gray area not addressed in the T&C themselves.\n(evidence: SCARY; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fee terms are explicitly marked not verified for this entity, and no breach or litigation specific to it was found, leaving two items rather than three.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "This entity's own arbitration and fee terms are explicitly unverified; only the parent CVS structure and a hedged cross-referenced preemption concern are available.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Aetna Better Health of New Jersey  <-  CVS Health Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Aetna Better Health of New Jersey you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Aetna Better Health NJ is CVS Health's Medicaid managed-care subsidiary in New Jersey. The 'Better Health' brand is used specifically for Medicaid/CHIP populations. Same parent-level T&C as Aetna Health Inc. (mandatory arbitration, 60-day opt-out, class/jury waivers survive opt-out) — but Medicaid members' arbitration rights may be preempted by state Medicaid fair-hearing requirements, creating a legal gray area not addressed in the T&C themselves.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 406, "_entity_id": 601, "_entity_slug": "aetna-better-health-of-new-jersey", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Aetna Health, Inc.", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.aetna.com/members/rights-and-responsibilities.html", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.aetna.com/legal/terms-of-use.html", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. CVS Health (parent) operates CVS Pharmacy, CVS Caremark (PBM), Aetna (insurance), and MinuteClinic — creating one of the most vertically integrated healthcare data environments in the US. A single member's prescription, insurance claim, and in-store purchase data can flow through the same parent. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver AND jury trial waiver. CVS Health's Terms of Use (retrieved 2026-08-13, cvshealth.com/terms-of-use.html) open with: 'THIS AGREEMENT INCLUDES AN ARBITRATION PROVISION, JURY TRIAL WAIVER, AND A CLASS ACTION WAIVER THAT AFFECT YOUR RIGHTS.' The terms state: 'YOU AND CVS WAIVE THE RIGHT TO A JURY TRIAL. YOU AND CVS ALSO WAIVE ANY RIGHT TO BRING OR PARTICIPATE IN A CLASS ACTION IN ARBITRATION OR IN LITIGATION IN COURT.' 60-day opt-out via physically signed letter to Aetna Life Insurance Company c/o CT Corporation System, Manchester, CT. CRITICAL: even after successful opt-out of arbitration, 'all other provisions in this Agreement, INCLUDING THE CLASS ACTION WAIVER AND JURY TRIAL WAIVER, remain in effect.' This is the trap: opting out buys you a bench trial before a judge, NOT a jury trial and NOT a class action.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "CVS Health subsidiary. Broadest Aetna mid-Atlantic footprint (DC/MD/VA/PA/WV/NC). The 60-day arbitration opt-out that preserves the class action waiver is the key structural finding — it is meaningfully worse for consumers than a straightforward arbitration clause with no surviving waiver.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Blue Bell", "HQ State": "PA", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.aetna.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. T&C text sourced via web_search returning actual document content from corporate legal pages. Cross-referenced with existing tracker rows. Fields marked 'NOT VERIFIED THIS PASS' were not independently fetched.", "Arbitration Opt-Out Window (Days)": 60, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": "https://www.cvshealth.com/terms-of-use.html", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "Operates in DC/MD/VA — DMV tag based on service area, not HQ (Hartford, CT)", "Parent / Ultimate Owner": "CVS Health", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "CT Corporation System (per Aetna's own arbitration opt-out address)", "Registered Agent Address / Service Notes": "Aetna Life Insurance Company, c/o CT Corporation System, Manchester, Connecticut — the address Aetna designates for arbitration opt-out notices. VERIFIED from CVS Health's Terms of Use this session. Aetna Health, Inc. is a CVS Health subsidiary; CVS Health Corporation is Delaware-incorporated with HQ at One CVS Drive, Woonsocket, RI 02895. SERVICE CAVEAT: Aetna Health Inc., Aetna Life Insurance Company, and CVS Health Corporation are distinct entities — identify which one is party to the specific plan or dispute before corresponding.", "Company Brief": "Aetna Health, Inc. is CVS Health's primary health-plan subsidiary, operating in DC, Maryland, and Virginia plus Pennsylvania, West Virginia, and North Carolina — the broadest Aetna footprint in the mid-Atlantic. It sits inside one of the most vertically integrated healthcare structures in the United States: CVS Health simultaneously owns the insurer (Aetna), the pharmacy benefit manager (CVS Caremark), the retail pharmacy chain, and MinuteClinic.", "Investor Overview": "Parent: CVS Health Corporation (NYSE: CVS). INVESTOR-RELEVANT LEGAL STRUCTURE: CVS's arbitration architecture is more protective of the company than the industry norm. The 60-day opt-out window is double the 30-day standard, which reads as consumer-friendly, but the class action waiver and jury trial waiver SURVIVE a successful opt-out — so exercising the opt-out converts the forum from arbitration to a bench trial rather than restoring collective relief. This materially limits aggregate exposure while preserving favorable optics.", "Major Issues Record": "2025-02: $2M settlement resolving allegations of discriminatory fertility-benefit treatment of LGBTQ+ members. | 2025-03: $4.8M class settlement over administrative fees. | 2023-05: Class action arising from a cyber incident affecting approximately 3 million people. | Structural: as a CVS Health entity, Aetna sits downstream of the Change Healthcare ecosystem disruption and upstream of CVS Caremark's PBM formulary decisions — a member's insurer, PBM, and pharmacy can all be the same corporate parent, with one arbitration clause across the set.", "T&C Key Provisions (paraphrased)": "PARAPHRASED, with two short verified quotes. CVS Health's Terms of Use open by stating that the agreement includes an arbitration provision, a jury trial waiver, and a class action waiver. The terms state that the parties waive the right to a jury trial and waive any right to bring or participate in a class action, in arbitration or in court. The opt-out requires a physically signed letter within 60 days. The critical provision: after opting out, the terms state that all other provisions — including the class action waiver and jury trial waiver — remain in effect. CONSUMER ACTION: opting out is still worth doing, but understand what it buys: a bench trial, not a jury and not a class.", "Re-verify By": "2027-02-13", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Aetna's 60-day arbitration opt-out doesn't restore your right to a class action — only a bench trial\nWHAT THE TERMS SAY: CVS Health's Terms of Use (retrieved 2026-08-13) impose mandatory binding arbitration, a jury trial waiver, and a class action waiver, with a 60-day opt-out requiring a physically signed letter to Aetna Life Insurance Company c/o CT Corporation System in Manchester, CT. Even after a successful opt-out, the terms state 'all other provisions...INCLUDING THE CLASS ACTION WAIVER AND JURY TRIAL WAIVER, remain in effect.'\nWHY IT MATTERS: Opting out of arbitration changes the forum from an arbitrator to a judge, but does not restore the right to a jury trial or to join a class action — including for members affected by the Change Healthcare breach.\n(evidence: Arbitration / Class Action Waiver | T&C Key Provisions (paraphrased); Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DISCRIMINATORY_PRACTICE · FL-1] $2M settlement resolved allegations of discriminatory fertility-benefit treatment of LGBTQ+ members\nWHAT THE TERMS SAY: Aetna's Major Issues Record lists a 2025-02 settlement of $2M resolving allegations that it discriminated against LGBTQ+ members in fertility-benefit treatment.\nWHY IT MATTERS: The tracker records a $2M settlement (Feb 2025) resolving these allegations; the discrimination claims were resolved by settlement rather than proven.\n(evidence: Major Issues Record; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #3": "[CONFIRMED_BREACH · FL-2] A May 2023 class action arose from a cyber incident affecting approximately 3 million people\nWHAT THE TERMS SAY: Aetna's Major Issues Record lists a May 2023 class action arising from a cyber incident affecting approximately 3 million people, plus a separate March 2025 class settlement of $4.8M over administrative fees.\nWHY IT MATTERS: The tracker records a class action arising from the 2023 cyber incident, alongside a separate $4.8M class settlement over administrative fees in March 2025.\n(evidence: Major Issues Record; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Arbitration terms are directly quoted from the source, and the settlements and breach-related class action are specifically dated and quantified.", "Exposure Score (0-100)": 45, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 25, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 25/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_60d+1) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Aetna Health, Inc.  <-  CVS Health", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to a jury.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Aetna Health, Inc. you gave up your data shared corporate-wide, your right to sue, your right to join a class action, and your right to a jury. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 63.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Aetna Health Inc. is CVS Health's primary health-plan subsidiary covering DC, MD, VA plus PA, WV, and NC — the broadest Aetna footprint in the mid-Atlantic region. Aetna's Terms of Use (text confirmed from multiple aetna.com legal pages, 2026-08-06) contain mandatory binding arbitration with a class action waiver AND a jury trial waiver. The arbitration opt-out window is 60 days (double UnitedHealthcare's 30 days), but requires a PHYSICALLY SIGNED letter mailed to Aetna Life Insurance Company c/o CT Corporation System in Manchester, Connecticut. Here is the catch that makes Aetna's version structurally different from UHC's: even if you successfully opt out of arbitration, 'all other provisions in this Agreement, INCLUDING THE CLASS ACTION WAIVER AND JURY TRIAL WAIVER, remain in effect to the fullest extent permissible by applicable law.' In other words, opting out of arbitration does NOT restore your right to join a class action — it only changes the forum from an arbitrator to a judge sitting without a jury. For a DMV member affected by the Change Healthcare breach (Aetna is also a CVS Health entity processing claims through Change Healthcare), this means the opt-out buys you a bench trial, not the class action you probably wanted.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 407, "_entity_id": 603, "_entity_slug": "aetna-health-inc", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Alliant Health Plans", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.allianthealthplans.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.allianthealthplans.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Atlanta, GA. Parent: Alliant Health Plans (independent). arbitration clause not yet verified. Region: Unspecified. Severity: 2. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Atlanta", "HQ State": "GA", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.allianthealthplans.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Atlanta, GA — not matched", "Parent / Ultimate Owner": "Alliant Health Plans (independent)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (GA) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in GA. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Arbitration, fees, and plan-level data-sharing terms are all explicitly marked not verified this pass; no company-specific troubling practice is documented, only basic operating-state context.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No terms were fetched this pass; the row contains no confirmed practice, breach, or litigation.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Alliant Health Plans  <-  Alliant Health Plans (independent)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Alliant Health Plans takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Alliant Health Plans is a for-profit insurer operating in Tennessee and Georgia. Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 408, "_entity_id": 604, "_entity_slug": "alliant-health-plans", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ambetter (Celtic) of Tennessee", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.ambetterhealth.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.ambetterhealth.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Centene Corporation (parent) is a Fortune 25 company; data handling governed by HIPAA/HITECH at federal level plus state insurance commissioner oversight. Centene's marketplace enrollment portal (ambetterhealth.com) uses a separate set of web terms from the plan's Evidence of Coverage — the website terms are NOT subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "MANDATORY arbitration + class/jury waivers on enrollment portal (CA law, Sacramento jurisdiction). Main site T&C has NO arbitration clause — split terms create ambiguity. No opt-out mechanism found.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Clayton, MO. Parent: Centene Corporation. mandatory arbitration confirmed. Region: Unspecified. Severity: 3. Sibling entities in this tab: Ambetter Health of Delaware, Ambetter from Absolute Total Care, Ambetter from Buckeye Health Plan. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Clayton", "HQ State": "MO", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.ambetterhealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Clayton, MO — not matched", "Parent / Ultimate Owner": "Centene Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (MO) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in MO. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] TN Ambetter members are funneled into arbitration under California law, with no opt-out found\nWHAT THE TERMS SAY: Ambetter Health's (Tennessee (Celtic brand)) enrollment portal Terms of Service impose mandatory arbitration, a class action waiver, and a jury trial waiver, governed by California law with exclusive jurisdiction in Sacramento County, regardless of the member's actual state of residence. The separate main-site Terms & Conditions contain a liability disclaimer but no arbitration clause, creating ambiguity about which document governs a given interaction. No opt-out mechanism was found.\nWHY IT MATTERS: A TN member who enrolls through the portal is bound to litigate any dispute under another state's law, 3,000 miles from home, with no confirmed way to opt out, and no clarity on which of two separate terms documents actually applies.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the enrollment-portal arbitration/jurisdiction clause is company-specific and confirmed in the tracker; data-sharing specifics and fee terms are generic HIPAA boilerplate or explicitly marked not verified this pass.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The enrollment-portal arbitration and jurisdiction terms are directly described and clear, but fees and plan-level data-sharing provisions are explicitly unverified this pass, and the split between two terms documents creates its own ambiguity.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 30, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 30/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Ambetter (Celtic) of Tennessee  <-  Centene Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to a jury.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ambetter (Celtic) of Tennessee you gave up your right to sue, your right to join a class action, and your right to a jury. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Ambetter (Celtic) of Tennessee operates in Tennessee (Celtic brand). Ambetter Health is Centene Corporation's ACA marketplace brand — and Centene's Terms & Conditions (confirmed from two separate pages on ambetterhealth.com, 2026-08-06) reveal a split personality. The enrollment portal's Terms of Service contain mandatory arbitration with a class action waiver AND a jury trial waiver, governed by CALIFORNIA law with exclusive jurisdiction in Sacramento County — regardless of which state the member actually lives in. A TN member who signs up through Ambetter's enrollment portal is agreeing to resolve disputes 3,000 miles away under another state's law. The main site's Terms & Conditions (ambetterhealth.com/terms-conditions.html), by contrast, contain a blanket liability disclaimer but NO arbitration clause — creating ambiguity about which set of terms governs which interactions. Centene itself is a Fortune 25 company with $154B in 2023 revenue and 28.6 million managed-care members across all brands.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 409, "_entity_id": 606, "_entity_slug": "ambetter-celtic-of-tennessee", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ambetter Health of Delaware", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.ambetterhealth.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.ambetterhealth.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Centene Corporation (parent) is a Fortune 25 company; data handling governed by HIPAA/HITECH at federal level plus state insurance commissioner oversight. Centene's marketplace enrollment portal (ambetterhealth.com) uses a separate set of web terms from the plan's Evidence of Coverage — the website terms are NOT subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "MANDATORY arbitration + class/jury waivers on enrollment portal (CA law, Sacramento jurisdiction). Main site T&C has NO arbitration clause — split terms create ambiguity. No opt-out mechanism found.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Clayton, MO. Parent: Centene Corporation. mandatory arbitration confirmed. Region: Unspecified. Severity: 3. Sibling entities in this tab: Ambetter (Celtic) of Tennessee, Ambetter from Absolute Total Care, Ambetter from Buckeye Health Plan. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Clayton", "HQ State": "MO", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.ambetterhealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Clayton, MO — not matched", "Parent / Ultimate Owner": "Centene Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (MO) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in MO. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] DE Ambetter members are funneled into arbitration under California law, with no opt-out found\nWHAT THE TERMS SAY: Ambetter Health's (Delaware-only) enrollment portal Terms of Service impose mandatory arbitration, a class action waiver, and a jury trial waiver, governed by California law with exclusive jurisdiction in Sacramento County, regardless of the member's actual state of residence. The separate main-site Terms & Conditions contain a liability disclaimer but no arbitration clause, creating ambiguity about which document governs a given interaction. No opt-out mechanism was found.\nWHY IT MATTERS: A DE member who enrolls through the portal is bound to litigate any dispute under another state's law, 3,000 miles from home, with no confirmed way to opt out, and no clarity on which of two separate terms documents actually applies.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the enrollment-portal arbitration/jurisdiction clause is company-specific and confirmed in the tracker; data-sharing specifics and fee terms are generic HIPAA boilerplate or explicitly marked not verified this pass.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The enrollment-portal arbitration and jurisdiction terms are directly described and clear, but fees and plan-level data-sharing provisions are explicitly unverified this pass, and the split between two terms documents creates its own ambiguity.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 30, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 30/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Ambetter Health of Delaware  <-  Centene Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to a jury.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ambetter Health of Delaware you gave up your right to sue, your right to join a class action, and your right to a jury. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Ambetter Health of Delaware operates in Delaware-only. Ambetter Health is Centene Corporation's ACA marketplace brand — and Centene's Terms & Conditions (confirmed from two separate pages on ambetterhealth.com, 2026-08-06) reveal a split personality. The enrollment portal's Terms of Service contain mandatory arbitration with a class action waiver AND a jury trial waiver, governed by CALIFORNIA law with exclusive jurisdiction in Sacramento County — regardless of which state the member actually lives in. A DE member who signs up through Ambetter's enrollment portal is agreeing to resolve disputes 3,000 miles away under another state's law. The main site's Terms & Conditions (ambetterhealth.com/terms-conditions.html), by contrast, contain a blanket liability disclaimer but NO arbitration clause — creating ambiguity about which set of terms governs which interactions. Centene itself is a Fortune 25 company with $154B in 2023 revenue and 28.6 million managed-care members across all brands.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 410, "_entity_id": 607, "_entity_slug": "ambetter-health-of-delaware", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ambetter from Absolute Total Care", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.ambetterhealth.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.ambetterhealth.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Centene Corporation (parent) is a Fortune 25 company; data handling governed by HIPAA/HITECH at federal level plus state insurance commissioner oversight. Centene's marketplace enrollment portal (ambetterhealth.com) uses a separate set of web terms from the plan's Evidence of Coverage — the website terms are NOT subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "MANDATORY arbitration + class/jury waivers on enrollment portal (CA law, Sacramento jurisdiction). Main site T&C has NO arbitration clause — split terms create ambiguity. No opt-out mechanism found.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Clayton, MO. Parent: Centene Corporation. mandatory arbitration confirmed. Region: Unspecified. Severity: 3. Sibling entities in this tab: Ambetter (Celtic) of Tennessee, Ambetter Health of Delaware, Ambetter from Buckeye Health Plan. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Clayton", "HQ State": "MO", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.ambetterhealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Clayton, MO — not matched", "Parent / Ultimate Owner": "Centene Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (MO) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in MO. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] SC Ambetter members are funneled into arbitration under California law, with no opt-out found\nWHAT THE TERMS SAY: Ambetter Health's (South Carolina) enrollment portal Terms of Service impose mandatory arbitration, a class action waiver, and a jury trial waiver, governed by California law with exclusive jurisdiction in Sacramento County, regardless of the member's actual state of residence. The separate main-site Terms & Conditions contain a liability disclaimer but no arbitration clause, creating ambiguity about which document governs a given interaction. No opt-out mechanism was found.\nWHY IT MATTERS: A SC member who enrolls through the portal is bound to litigate any dispute under another state's law, 3,000 miles from home, with no confirmed way to opt out, and no clarity on which of two separate terms documents actually applies.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the enrollment-portal arbitration/jurisdiction clause is company-specific and confirmed in the tracker; data-sharing specifics and fee terms are generic HIPAA boilerplate or explicitly marked not verified this pass.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The enrollment-portal arbitration and jurisdiction terms are directly described and clear, but fees and plan-level data-sharing provisions are explicitly unverified this pass, and the split between two terms documents creates its own ambiguity.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 30, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 30/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Ambetter from Absolute Total Care  <-  Centene Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to a jury.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ambetter from Absolute Total Care you gave up your right to sue, your right to join a class action, and your right to a jury. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Ambetter from Absolute Total Care operates in South Carolina. Ambetter Health is Centene Corporation's ACA marketplace brand — and Centene's Terms & Conditions (confirmed from two separate pages on ambetterhealth.com, 2026-08-06) reveal a split personality. The enrollment portal's Terms of Service contain mandatory arbitration with a class action waiver AND a jury trial waiver, governed by CALIFORNIA law with exclusive jurisdiction in Sacramento County — regardless of which state the member actually lives in. A SC member who signs up through Ambetter's enrollment portal is agreeing to resolve disputes 3,000 miles away under another state's law. The main site's Terms & Conditions (ambetterhealth.com/terms-conditions.html), by contrast, contain a blanket liability disclaimer but NO arbitration clause — creating ambiguity about which set of terms governs which interactions. Centene itself is a Fortune 25 company with $154B in 2023 revenue and 28.6 million managed-care members across all brands.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 411, "_entity_id": 608, "_entity_slug": "ambetter-from-absolute-total-care", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ambetter from Buckeye Health Plan", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.ambetterhealth.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.ambetterhealth.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Centene Corporation (parent) is a Fortune 25 company; data handling governed by HIPAA/HITECH at federal level plus state insurance commissioner oversight. Centene's marketplace enrollment portal (ambetterhealth.com) uses a separate set of web terms from the plan's Evidence of Coverage — the website terms are NOT subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "MANDATORY arbitration + class/jury waivers on enrollment portal (CA law, Sacramento jurisdiction). Main site T&C has NO arbitration clause — split terms create ambiguity. No opt-out mechanism found.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Clayton, MO. Parent: Centene Corporation. mandatory arbitration confirmed. Region: Unspecified. Severity: 3. Sibling entities in this tab: Ambetter (Celtic) of Tennessee, Ambetter Health of Delaware, Ambetter from Absolute Total Care. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Clayton", "HQ State": "MO", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.ambetterhealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Clayton, MO — not matched", "Parent / Ultimate Owner": "Centene Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (MO) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in MO. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] OH Ambetter members are funneled into arbitration under California law, with no opt-out found\nWHAT THE TERMS SAY: Ambetter Health's (Ohio) enrollment portal Terms of Service impose mandatory arbitration, a class action waiver, and a jury trial waiver, governed by California law with exclusive jurisdiction in Sacramento County, regardless of the member's actual state of residence. The separate main-site Terms & Conditions contain a liability disclaimer but no arbitration clause, creating ambiguity about which document governs a given interaction. No opt-out mechanism was found.\nWHY IT MATTERS: A OH member who enrolls through the portal is bound to litigate any dispute under another state's law, 3,000 miles from home, with no confirmed way to opt out, and no clarity on which of two separate terms documents actually applies.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the enrollment-portal arbitration/jurisdiction clause is company-specific and confirmed in the tracker; data-sharing specifics and fee terms are generic HIPAA boilerplate or explicitly marked not verified this pass.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The enrollment-portal arbitration and jurisdiction terms are directly described and clear, but fees and plan-level data-sharing provisions are explicitly unverified this pass, and the split between two terms documents creates its own ambiguity.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 30, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 30/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Ambetter from Buckeye Health Plan  <-  Centene Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to a jury.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ambetter from Buckeye Health Plan you gave up your right to sue, your right to join a class action, and your right to a jury. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Ambetter from Buckeye Health Plan operates in Ohio. Ambetter Health is Centene Corporation's ACA marketplace brand — and Centene's Terms & Conditions (confirmed from two separate pages on ambetterhealth.com, 2026-08-06) reveal a split personality. The enrollment portal's Terms of Service contain mandatory arbitration with a class action waiver AND a jury trial waiver, governed by CALIFORNIA law with exclusive jurisdiction in Sacramento County — regardless of which state the member actually lives in. A OH member who signs up through Ambetter's enrollment portal is agreeing to resolve disputes 3,000 miles away under another state's law. The main site's Terms & Conditions (ambetterhealth.com/terms-conditions.html), by contrast, contain a blanket liability disclaimer but NO arbitration clause — creating ambiguity about which set of terms governs which interactions. Centene itself is a Fortune 25 company with $154B in 2023 revenue and 28.6 million managed-care members across all brands.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 412, "_entity_id": 609, "_entity_slug": "ambetter-from-buckeye-health-plan", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ambetter from Peach State Health Plan", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.ambetterhealth.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.ambetterhealth.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Centene Corporation (parent) is a Fortune 25 company; data handling governed by HIPAA/HITECH at federal level plus state insurance commissioner oversight. Centene's marketplace enrollment portal (ambetterhealth.com) uses a separate set of web terms from the plan's Evidence of Coverage — the website terms are NOT subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "MANDATORY arbitration + class/jury waivers on enrollment portal (CA law, Sacramento jurisdiction). Main site T&C has NO arbitration clause — split terms create ambiguity. No opt-out mechanism found.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Clayton, MO. Parent: Centene Corporation. mandatory arbitration confirmed. Region: Unspecified. Severity: 3. Sibling entities in this tab: Ambetter (Celtic) of Tennessee, Ambetter Health of Delaware, Ambetter from Absolute Total Care. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Clayton", "HQ State": "MO", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.ambetterhealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Clayton, MO — not matched", "Parent / Ultimate Owner": "Centene Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (MO) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in MO. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] GA Ambetter members are funneled into arbitration under California law, with no opt-out found\nWHAT THE TERMS SAY: Ambetter Health's (Georgia (Peach State brand)) enrollment portal Terms of Service impose mandatory arbitration, a class action waiver, and a jury trial waiver, governed by California law with exclusive jurisdiction in Sacramento County, regardless of the member's actual state of residence. The separate main-site Terms & Conditions contain a liability disclaimer but no arbitration clause, creating ambiguity about which document governs a given interaction. No opt-out mechanism was found.\nWHY IT MATTERS: A GA member who enrolls through the portal is bound to litigate any dispute under another state's law, 3,000 miles from home, with no confirmed way to opt out, and no clarity on which of two separate terms documents actually applies.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the enrollment-portal arbitration/jurisdiction clause is company-specific and confirmed in the tracker; data-sharing specifics and fee terms are generic HIPAA boilerplate or explicitly marked not verified this pass.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The enrollment-portal arbitration and jurisdiction terms are directly described and clear, but fees and plan-level data-sharing provisions are explicitly unverified this pass, and the split between two terms documents creates its own ambiguity.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 30, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 30/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Ambetter from Peach State Health Plan  <-  Centene Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to a jury.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ambetter from Peach State Health Plan you gave up your right to sue, your right to join a class action, and your right to a jury. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Ambetter from Peach State Health Plan operates in Georgia (Peach State brand). Ambetter Health is Centene Corporation's ACA marketplace brand — and Centene's Terms & Conditions (confirmed from two separate pages on ambetterhealth.com, 2026-08-06) reveal a split personality. The enrollment portal's Terms of Service contain mandatory arbitration with a class action waiver AND a jury trial waiver, governed by CALIFORNIA law with exclusive jurisdiction in Sacramento County — regardless of which state the member actually lives in. A GA member who signs up through Ambetter's enrollment portal is agreeing to resolve disputes 3,000 miles away under another state's law. The main site's Terms & Conditions (ambetterhealth.com/terms-conditions.html), by contrast, contain a blanket liability disclaimer but NO arbitration clause — creating ambiguity about which set of terms governs which interactions. Centene itself is a Fortune 25 company with $154B in 2023 revenue and 28.6 million managed-care members across all brands.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 413, "_entity_id": 610, "_entity_slug": "ambetter-from-peach-state-health-plan", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ambetter from WellCare of Kentucky", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.ambetterhealth.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.ambetterhealth.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Centene Corporation (parent) is a Fortune 25 company; data handling governed by HIPAA/HITECH at federal level plus state insurance commissioner oversight. Centene's marketplace enrollment portal (ambetterhealth.com) uses a separate set of web terms from the plan's Evidence of Coverage — the website terms are NOT subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "MANDATORY arbitration + class/jury waivers on enrollment portal (CA law, Sacramento jurisdiction). Main site T&C has NO arbitration clause — split terms create ambiguity. No opt-out mechanism found.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Tampa, FL. Parent: Centene Corporation. mandatory arbitration confirmed. Region: Unspecified. Severity: 3. Sibling entities in this tab: Ambetter (Celtic) of Tennessee, Ambetter Health of Delaware, Ambetter from Absolute Total Care. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Tampa", "HQ State": "FL", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.ambetterhealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Tampa, FL — not matched", "Parent / Ultimate Owner": "Centene Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (FL) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in FL. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] KY Ambetter members are funneled into arbitration under California law, with no opt-out found\nWHAT THE TERMS SAY: Ambetter Health's (Kentucky (WellCare brand)) enrollment portal Terms of Service impose mandatory arbitration, a class action waiver, and a jury trial waiver, governed by California law with exclusive jurisdiction in Sacramento County, regardless of the member's actual state of residence. The separate main-site Terms & Conditions contain a liability disclaimer but no arbitration clause, creating ambiguity about which document governs a given interaction. No opt-out mechanism was found.\nWHY IT MATTERS: A KY member who enrolls through the portal is bound to litigate any dispute under another state's law, 3,000 miles from home, with no confirmed way to opt out, and no clarity on which of two separate terms documents actually applies.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the enrollment-portal arbitration/jurisdiction clause is company-specific and confirmed in the tracker; data-sharing specifics and fee terms are generic HIPAA boilerplate or explicitly marked not verified this pass.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The enrollment-portal arbitration and jurisdiction terms are directly described and clear, but fees and plan-level data-sharing provisions are explicitly unverified this pass, and the split between two terms documents creates its own ambiguity.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 30, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 30/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Ambetter from WellCare of Kentucky  <-  Centene Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to a jury.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ambetter from WellCare of Kentucky you gave up your right to sue, your right to join a class action, and your right to a jury. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Ambetter from WellCare of Kentucky operates in Kentucky (WellCare brand). Ambetter Health is Centene Corporation's ACA marketplace brand — and Centene's Terms & Conditions (confirmed from two separate pages on ambetterhealth.com, 2026-08-06) reveal a split personality. The enrollment portal's Terms of Service contain mandatory arbitration with a class action waiver AND a jury trial waiver, governed by CALIFORNIA law with exclusive jurisdiction in Sacramento County — regardless of which state the member actually lives in. A KY member who signs up through Ambetter's enrollment portal is agreeing to resolve disputes 3,000 miles away under another state's law. The main site's Terms & Conditions (ambetterhealth.com/terms-conditions.html), by contrast, contain a blanket liability disclaimer but NO arbitration clause — creating ambiguity about which set of terms governs which interactions. Centene itself is a Fortune 25 company with $154B in 2023 revenue and 28.6 million managed-care members across all brands.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 414, "_entity_id": 611, "_entity_slug": "ambetter-from-wellcare-of-kentucky", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ambetter from WellCare of New Jersey", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.ambetterhealth.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.ambetterhealth.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Centene Corporation (parent) is a Fortune 25 company; data handling governed by HIPAA/HITECH at federal level plus state insurance commissioner oversight. Centene's marketplace enrollment portal (ambetterhealth.com) uses a separate set of web terms from the plan's Evidence of Coverage — the website terms are NOT subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "MANDATORY arbitration + class/jury waivers on enrollment portal (CA law, Sacramento jurisdiction). Main site T&C has NO arbitration clause — split terms create ambiguity. No opt-out mechanism found.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Tampa, FL. Parent: Centene Corporation. mandatory arbitration confirmed. Region: Unspecified. Severity: 3. Sibling entities in this tab: Ambetter (Celtic) of Tennessee, Ambetter Health of Delaware, Ambetter from Absolute Total Care. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Tampa", "HQ State": "FL", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.ambetterhealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Tampa, FL — not matched", "Parent / Ultimate Owner": "Centene Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (FL) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in FL. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] NJ Ambetter members are funneled into arbitration under California law, with no opt-out found\nWHAT THE TERMS SAY: Ambetter Health's (New Jersey (WellCare brand)) enrollment portal Terms of Service impose mandatory arbitration, a class action waiver, and a jury trial waiver, governed by California law with exclusive jurisdiction in Sacramento County, regardless of the member's actual state of residence. The separate main-site Terms & Conditions contain a liability disclaimer but no arbitration clause, creating ambiguity about which document governs a given interaction. No opt-out mechanism was found.\nWHY IT MATTERS: A NJ member who enrolls through the portal is bound to litigate any dispute under another state's law, 3,000 miles from home, with no confirmed way to opt out, and no clarity on which of two separate terms documents actually applies.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the enrollment-portal arbitration/jurisdiction clause is company-specific and confirmed in the tracker; data-sharing specifics and fee terms are generic HIPAA boilerplate or explicitly marked not verified this pass.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The enrollment-portal arbitration and jurisdiction terms are directly described and clear, but fees and plan-level data-sharing provisions are explicitly unverified this pass, and the split between two terms documents creates its own ambiguity.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 30, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 30/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Ambetter from WellCare of New Jersey  <-  Centene Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to a jury.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ambetter from WellCare of New Jersey you gave up your right to sue, your right to join a class action, and your right to a jury. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Ambetter from WellCare of New Jersey operates in New Jersey (WellCare brand). Ambetter Health is Centene Corporation's ACA marketplace brand — and Centene's Terms & Conditions (confirmed from two separate pages on ambetterhealth.com, 2026-08-06) reveal a split personality. The enrollment portal's Terms of Service contain mandatory arbitration with a class action waiver AND a jury trial waiver, governed by CALIFORNIA law with exclusive jurisdiction in Sacramento County — regardless of which state the member actually lives in. A NJ member who signs up through Ambetter's enrollment portal is agreeing to resolve disputes 3,000 miles away under another state's law. The main site's Terms & Conditions (ambetterhealth.com/terms-conditions.html), by contrast, contain a blanket liability disclaimer but NO arbitration clause — creating ambiguity about which set of terms governs which interactions. Centene itself is a Fortune 25 company with $154B in 2023 revenue and 28.6 million managed-care members across all brands.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 415, "_entity_id": 612, "_entity_slug": "ambetter-from-wellcare-of-new-jersey", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ambetter of North Carolina, Inc.", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.ambetterhealth.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.ambetterhealth.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Centene Corporation (parent) is a Fortune 25 company; data handling governed by HIPAA/HITECH at federal level plus state insurance commissioner oversight. Centene's marketplace enrollment portal (ambetterhealth.com) uses a separate set of web terms from the plan's Evidence of Coverage — the website terms are NOT subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "MANDATORY arbitration + class/jury waivers on enrollment portal (CA law, Sacramento jurisdiction). Main site T&C has NO arbitration clause — split terms create ambiguity. No opt-out mechanism found.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Clayton, MO. Parent: Centene Corporation. mandatory arbitration confirmed. Region: Unspecified. Severity: 3. Sibling entities in this tab: Ambetter (Celtic) of Tennessee, Ambetter Health of Delaware, Ambetter from Absolute Total Care. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Clayton", "HQ State": "MO", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.ambetterhealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Clayton, MO — not matched", "Parent / Ultimate Owner": "Centene Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (MO) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in MO. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] NC Ambetter members are funneled into arbitration under California law, with no opt-out found\nWHAT THE TERMS SAY: Ambetter Health's (North Carolina) enrollment portal Terms of Service impose mandatory arbitration, a class action waiver, and a jury trial waiver, governed by California law with exclusive jurisdiction in Sacramento County, regardless of the member's actual state of residence. The separate main-site Terms & Conditions contain a liability disclaimer but no arbitration clause, creating ambiguity about which document governs a given interaction. No opt-out mechanism was found.\nWHY IT MATTERS: A NC member who enrolls through the portal is bound to litigate any dispute under another state's law, 3,000 miles from home, with no confirmed way to opt out, and no clarity on which of two separate terms documents actually applies.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the enrollment-portal arbitration/jurisdiction clause is company-specific and confirmed in the tracker; data-sharing specifics and fee terms are generic HIPAA boilerplate or explicitly marked not verified this pass.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The enrollment-portal arbitration and jurisdiction terms are directly described and clear, but fees and plan-level data-sharing provisions are explicitly unverified this pass, and the split between two terms documents creates its own ambiguity.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 30, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 30/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Ambetter of North Carolina, Inc.  <-  Centene Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to a jury.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ambetter of North Carolina, Inc. you gave up your right to sue, your right to join a class action, and your right to a jury. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Ambetter of North Carolina, Inc. operates in North Carolina. Ambetter Health is Centene Corporation's ACA marketplace brand — and Centene's Terms & Conditions (confirmed from two separate pages on ambetterhealth.com, 2026-08-06) reveal a split personality. The enrollment portal's Terms of Service contain mandatory arbitration with a class action waiver AND a jury trial waiver, governed by CALIFORNIA law with exclusive jurisdiction in Sacramento County — regardless of which state the member actually lives in. A NC member who signs up through Ambetter's enrollment portal is agreeing to resolve disputes 3,000 miles away under another state's law. The main site's Terms & Conditions (ambetterhealth.com/terms-conditions.html), by contrast, contain a blanket liability disclaimer but NO arbitration clause — creating ambiguity about which set of terms governs which interactions. Centene itself is a Fortune 25 company with $154B in 2023 revenue and 28.6 million managed-care members across all brands.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 416, "_entity_id": 613, "_entity_slug": "ambetter-of-north-carolina-inc", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "AmeriHealth Caritas North Carolina, Inc.", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.amerihealthcaritas.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.amerihealthcaritas.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Independence Health Group (parent) operates IBX in PA and AmeriHealth in NJ/DE — distinct brands sharing one parent's data infrastructure. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Raleigh, NC. Parent: Independence Health Group. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: AmeriHealth Insurance Company of New Jersey, AmeriHealth New Jersey, Independence Blue Cross (IBX). Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Raleigh", "HQ State": "NC", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.amerihealthcaritas.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Raleigh, NC — not matched", "Parent / Ultimate Owner": "Independence Health Group", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (NC) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in NC. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Arbitration, fees, and plan-level data-sharing provisions are all explicitly marked not verified this pass; the SCARY note is a parent/subsidiary and brand-naming observation, not a documented troubling practice. AmeriHealth Caritas NC is the Medicaid managed-care arm of Independence Health Group in North Carolina; the 'Caritas' brand serves Medicaid/CHIP populations.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Terms were not independently fetched this pass; only generic HIPAA boilerplate and entity-naming context are available.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "AmeriHealth Caritas North Carolina, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using AmeriHealth Caritas North Carolina, Inc. you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "AmeriHealth Caritas NC is the Medicaid managed-care arm of Independence Health Group in North Carolina. The 'Caritas' brand is used specifically for Medicaid/CHIP populations — lower-income members who may have fewer alternatives and less capacity to comparison-shop. Terms not independently fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 417, "_entity_id": 614, "_entity_slug": "amerihealth-caritas-north-carolina-inc", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "AmeriHealth Insurance Company of New Jersey", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.amerihealth.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.amerihealth.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Independence Health Group (parent) operates IBX in PA and AmeriHealth in NJ/DE — distinct brands sharing one parent's data infrastructure. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Camden, NJ. Parent: Independence Health Group. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: AmeriHealth Caritas North Carolina, Inc., AmeriHealth New Jersey, Independence Blue Cross (IBX). Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Camden", "HQ State": "NJ", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.amerihealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Camden, NJ — not matched", "Parent / Ultimate Owner": "Independence Health Group", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (NJ) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in NJ. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Arbitration, fees, and plan-level data-sharing provisions are all explicitly marked not verified this pass; the SCARY note is a parent/subsidiary and brand-naming observation, not a documented troubling practice. AmeriHealth Insurance Company of New Jersey is an Independence Health Group subsidiary operating in NJ and DE, part of a family of plans spanning IBX in PA, AmeriHealth in NJ/DE, and AmeriHealth Caritas in NC.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Terms were not independently fetched this pass; only generic HIPAA boilerplate and entity-naming context are available.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "AmeriHealth Insurance Company of New Jersey", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using AmeriHealth Insurance Company of New Jersey you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "AmeriHealth NJ is an Independence Health Group subsidiary operating in DE and NJ. Independence Health Group (parent of Independence Blue Cross in Philadelphia) operates a family of plans across the mid-Atlantic corridor — IBX in PA, AmeriHealth in NJ/DE, AmeriHealth Caritas in NC. A consumer comparing 'AmeriHealth' and 'Independence Blue Cross' may not realize they share the same parent. Terms not independently fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 418, "_entity_id": 615, "_entity_slug": "amerihealth-insurance-company-of-new-jersey", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "AmeriHealth New Jersey", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.amerihealth.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.amerihealth.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Independence Health Group (parent) operates IBX in PA and AmeriHealth in NJ/DE — distinct brands sharing one parent's data infrastructure. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Camden, NJ. Parent: Independence Health Group. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: AmeriHealth Caritas North Carolina, Inc., AmeriHealth Insurance Company of New Jersey, Independence Blue Cross (IBX). Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Camden", "HQ State": "NJ", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.amerihealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Camden, NJ — not matched", "Parent / Ultimate Owner": "Independence Health Group", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (NJ) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in NJ. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Arbitration, fees, and plan-level data-sharing provisions are all explicitly marked not verified this pass; the SCARY note is a parent/subsidiary and brand-naming observation, not a documented troubling practice. AmeriHealth New Jersey is a separate legal entity from AmeriHealth Insurance Company of New Jersey, both owned by Independence Health Group.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Terms were not independently fetched this pass; only generic HIPAA boilerplate and entity-naming context are available.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "AmeriHealth New Jersey", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using AmeriHealth New Jersey you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "AmeriHealth New Jersey is a SEPARATE legal entity from AmeriHealth Insurance Company of New Jersey, both owned by Independence Health Group. Two AmeriHealth entities in the same state under the same parent — a consumer would need to check which one their plan is actually through. Terms not independently fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 419, "_entity_id": 616, "_entity_slug": "amerihealth-new-jersey", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Anthem Blue Cross Blue Shield of Georgia", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.anthem.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.anthem.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Elevance Health (parent, fmr. Anthem) operates the largest for-profit Blue Cross Blue Shield licensee by enrollment. Subject of the 2015 breach (78.8M people) — the largest healthcare breach at the time. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Mason, OH. Parent: Elevance Health, Inc.. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Anthem Blue Cross and Blue Shield of Ohio, Anthem Health Plans of Kentucky, Empire Blue Cross Blue Shield (Anthem HealthChoice Assurance). Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mason", "HQ State": "OH", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.anthem.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Mason, OH — not matched", "Parent / Ultimate Owner": "Elevance Health, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (OH) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in OH. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Terms were not independently fetched this pass; the only content is generic HIPAA boilerplate and a cross-reference to parent Elevance Health's 2015 breach, which is not an independently confirmed finding about this specific subsidiary.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No terms were fetched this pass, and the only substantive content is a cross-reference to the parent company's breach.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Anthem Blue Cross Blue Shield of Georgia  <-  Elevance Health, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Anthem Blue Cross Blue Shield of Georgia takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Anthem BCBS Georgia is an Elevance Health subsidiary. Same parent as the 2015 breach row. Terms at anthem.com/legal not independently fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 420, "_entity_id": 617, "_entity_slug": "anthem-blue-cross-blue-shield-of-georgia", "_issuer": "Elevance Health, Inc.", "_issuer_slug": "elevance-health-inc", "_ticker": "ELV", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Anthem Blue Cross and Blue Shield of Ohio", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.anthem.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.anthem.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Elevance Health (parent, fmr. Anthem) operates the largest for-profit Blue Cross Blue Shield licensee by enrollment. Subject of the 2015 breach (78.8M people) — the largest healthcare breach at the time. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Mason, OH. Parent: Elevance Health, Inc.. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Anthem Blue Cross Blue Shield of Georgia, Anthem Health Plans of Kentucky, Empire Blue Cross Blue Shield (Anthem HealthChoice Assurance). Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mason", "HQ State": "OH", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.anthem.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Mason, OH — not matched", "Parent / Ultimate Owner": "Elevance Health, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (OH) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in OH. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Terms were not independently fetched this pass; the only content is generic HIPAA boilerplate and a cross-reference to parent Elevance Health's 2015 breach, which is not an independently confirmed finding about this specific subsidiary.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No terms were fetched this pass, and the only substantive content is a cross-reference to the parent company's breach.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Anthem Blue Cross and Blue Shield of Ohio  <-  Elevance Health, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Anthem Blue Cross and Blue Shield of Ohio takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Anthem BCBS Ohio is an Elevance Health subsidiary (Mason, OH). Same parent as the Elevance Health (Anthem) row already in this tracker documenting the 2015 breach (78.8M people). Terms at anthem.com/legal not independently fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 421, "_entity_id": 618, "_entity_slug": "anthem-blue-cross-and-blue-shield-of-ohio", "_issuer": "Elevance Health, Inc.", "_issuer_slug": "elevance-health-inc", "_ticker": "ELV", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Anthem Health Plans of Kentucky", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.anthem.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.anthem.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Elevance Health (parent, fmr. Anthem) operates the largest for-profit Blue Cross Blue Shield licensee by enrollment. Subject of the 2015 breach (78.8M people) — the largest healthcare breach at the time. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Mason, OH. Parent: Elevance Health, Inc.. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Anthem Blue Cross Blue Shield of Georgia, Anthem Blue Cross and Blue Shield of Ohio, Empire Blue Cross Blue Shield (Anthem HealthChoice Assurance). Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mason", "HQ State": "OH", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.anthem.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Mason, OH — not matched", "Parent / Ultimate Owner": "Elevance Health, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (OH) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in OH. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Terms were not independently fetched this pass; the only content is generic HIPAA boilerplate and a cross-reference to parent Elevance Health's 2015 breach, which is not an independently confirmed finding about this specific subsidiary.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No terms were fetched this pass, and the only substantive content is a cross-reference to the parent company's breach.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Anthem Health Plans of Kentucky  <-  Elevance Health, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Anthem Health Plans of Kentucky takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Anthem Health Plans of Kentucky is an Elevance Health subsidiary. Same parent as the 2015 breach row. Terms at anthem.com/legal not independently fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 422, "_entity_id": 619, "_entity_slug": "anthem-health-plans-of-kentucky", "_issuer": "Elevance Health, Inc.", "_issuer_slug": "elevance-health-inc", "_ticker": "ELV", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Anthem Health Plans of Virginia, Inc.", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.anthem.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.anthem.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Elevance Health (parent, fmr. Anthem) operates the largest for-profit Blue Cross Blue Shield licensee by enrollment. Subject of the 2015 breach (78.8M people) — the largest healthcare breach at the time. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — Anthem.com/legal was not independently fetched and read. Do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "Elevance Health subsidiary. Excludes parts of NoVA from its service area (City of Fairfax, Town of Vienna, east of Route 123). Cross-ref Elevance Health (Anthem) row for the 2015 breach (78.8M people).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Richmond", "HQ State": "VA", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.anthem.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. T&C text sourced via web_search returning actual document content from corporate legal pages. Cross-referenced with existing tracker rows. Fields marked 'NOT VERIFIED THIS PASS' were not independently fetched.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Operates in VA; HQ: Richmond, VA", "Parent / Ultimate Owner": "Elevance Health", "Years Referenced in Finding (heuristic)": "2015, 2022, 2023", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (VA) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in VA. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Anthem Virginia's service area excludes the City of Fairfax, the Town of Vienna, and areas east of Route 123\nWHAT THE TERMS SAY: Anthem Health Plans of Virginia's service area covers all of Virginia except the City of Fairfax, the Town of Vienna, and the area east of State Route 123 (per a 2023 BusinessWire release from Anthem's own Virginia president); residents there fall instead to HealthKeepers Inc., a separate Elevance affiliate.\nWHY IT MATTERS: A consumer comparing 'Anthem Blue Cross Blue Shield' plans in Fairfax may not realize they are dealing with HealthKeepers Inc., a legally separate Elevance affiliate, rather than the Anthem entity that covers the rest of Virginia.\n(evidence: Notes | SCARY; Stated in tracker (fidelity pass 2 (strict): Wrong corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee terms are explicitly marked not verified this pass ('do not cite'), leaving the geographic carve-out as the only substantive, company-specific item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The geographic service-area carve-out is specifically sourced, but arbitration and fee terms were not independently fetched this pass.", "Exposure Score (0-100)": 8, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Anthem Health Plans of Virginia, Inc.  <-  Elevance Health", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Anthem Health Plans of Virginia, Inc. takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Anthem Health Plans of Virginia — trading as Anthem Blue Cross and Blue Shield in Virginia — is an Elevance Health subsidiary whose service area covers all of Virginia EXCEPT the City of Fairfax, the Town of Vienna, and the area east of State Route 123 (confirmed from a 2023 BusinessWire press release by Anthem's own Virginia president). This geographic carve-out means residents of parts of Northern Virginia, the area closest to DC, are excluded from Anthem Virginia's direct network — they fall instead to HealthKeepers Inc., a separate Elevance affiliate. A consumer comparing 'Anthem Blue Cross Blue Shield' plans in Fairfax may not realize they are dealing with a legally separate entity from the Anthem that covers Richmond. Anthem's parent Elevance Health (formerly Anthem Inc., renamed June 2022) is already documented elsewhere in this tracker for the 2015 breach affecting 78.8 million people — the largest healthcare breach at the time — which also affected Virginia members.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 423, "_entity_id": 621, "_entity_slug": "anthem-health-plans-of-virginia-inc", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Blue Cross Blue Shield of North Carolina (BCBSNC)", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.bcbsnc.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.bcbsnc.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Durham, NC. Parent: Blue Cross and Blue Shield Association (licensee). arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: BlueCross BlueShield of South Carolina. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Durham", "HQ State": "NC", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.bcbsnc.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Durham, NC — not matched", "Parent / Ultimate Owner": "Blue Cross and Blue Shield Association (licensee)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (NC) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in NC. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Arbitration, fees, and plan-level data-sharing provisions are all explicitly marked not verified this pass; no company-specific troubling practice is documented, only basic operating and market-position context.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No terms were fetched this pass; the row contains no confirmed practice, breach, or litigation.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Blue Cross Blue Shield of North Carolina (BCBSNC)  <-  Blue Cross and Blue Shield Association (licensee)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Blue Cross Blue Shield of North Carolina (BCBSNC) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "BCBSNC is an independent non-profit licensee of the Blue Cross Blue Shield Association, covering North Carolina. Not affiliated with Elevance/Anthem despite the shared BCBS branding. BCBSNC is one of the largest single-state BCBS plans in the country. Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 424, "_entity_id": 623, "_entity_slug": "blue-cross-blue-shield-of-north-carolina-bcbsnc", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "BlueCross BlueShield of South Carolina", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.bcbsnc.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.bcbsnc.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Columbia, SC. Parent: Blue Cross and Blue Shield Association (licensee). arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Blue Cross Blue Shield of North Carolina (BCBSNC). Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Columbia", "HQ State": "SC", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.bcbsnc.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Columbia, SC — not matched", "Parent / Ultimate Owner": "Blue Cross and Blue Shield Association (licensee)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (SC) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in SC. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Arbitration, fees, and plan-level data-sharing provisions are all explicitly marked not verified this pass; no company-specific troubling practice is documented, only basic operating and market-position context.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No terms were fetched this pass; the row contains no confirmed practice, breach, or litigation.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "BlueCross BlueShield of South Carolina  <-  Blue Cross and Blue Shield Association (licensee)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, BlueCross BlueShield of South Carolina takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "BCBS South Carolina is an independent non-profit BCBS licensee. Largest insurer in SC. AM Best A+ rated. Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 425, "_entity_id": 624, "_entity_slug": "bluecross-blueshield-of-south-carolina", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "BlueCross BlueShield of Tennessee", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.bcbst.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.bcbst.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Chattanooga, TN. Parent: BlueCross BlueShield of Tennessee (independent). arbitration clause not yet verified. Region: Unspecified. Severity: 2. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Chattanooga", "HQ State": "TN", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.bcbst.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Chattanooga, TN — not matched", "Parent / Ultimate Owner": "BlueCross BlueShield of Tennessee (independent)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (TN) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in TN. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Arbitration, fees, and plan-level data-sharing provisions are all explicitly marked not verified this pass; no company-specific troubling practice is documented, only basic operating and market-position context.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No terms were fetched this pass; the row contains no confirmed practice, breach, or litigation.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "BlueCross BlueShield of Tennessee  <-  BlueCross BlueShield of Tennessee (independent)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, BlueCross BlueShield of Tennessee takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "BCBS Tennessee is an independent non-profit, the largest insurer in Tennessee with the state's only A+ AM Best rating. One of the few single-state BCBS plans that has never been acquired by a national carrier. Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 426, "_entity_id": 625, "_entity_slug": "bluecross-blueshield-of-tennessee", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Capital Advantage Insurance Company", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.capitaladvantage.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.capitaladvantage.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Harrisburg, PA. Parent: Capital Blue Cross. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Harrisburg", "HQ State": "PA", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.capitaladvantage.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Harrisburg, PA — not matched", "Parent / Ultimate Owner": "Capital Blue Cross", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (PA) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in PA. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Arbitration, fees, and plan-level data-sharing provisions are all explicitly marked not verified this pass; no company-specific troubling practice is documented, only basic parent/subsidiary context.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No terms were fetched this pass; the row contains no confirmed practice, breach, or litigation.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Capital Advantage Insurance Company  <-  Capital Blue Cross", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Capital Advantage Insurance Company takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Capital Advantage is a subsidiary of Capital Blue Cross, serving central Pennsylvania and the Lehigh Valley. Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 427, "_entity_id": 627, "_entity_slug": "capital-advantage-insurance-company", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CareFirst BlueChoice, Inc.", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.carefirst.com/medicaid/terms-of-use.html", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.carefirst.com/terms-of-use", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "One of three CareFirst subsidiaries sharing identical T&C. Parent: CareFirst BlueCross BlueShield (see Insurance tab for the parent row's 2014 breach). 75% market share in MD. 626,000+ FEHB members. Change Healthcare lawsuit: CareFirst v. Change Healthcare, MD state court, filed 2025-02-21.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Owings Mills", "HQ State": "MD", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.carefirst.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "T&C fetched and read via web_fetch 2026-08-06. Change Healthcare lawsuit sourced via web_search (HIPAA Journal, Becker's, HIPAA Guide, CareFirst's own provider notice). All facts cross-checked against multiple sources.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Operates in DC, MD, VA; HQ: Owings Mills, MD", "Parent / Ultimate Owner": "CareFirst BlueCross BlueShield", "Years Referenced in Finding (heuristic)": "2014, 2015, 2024, 2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (MD) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in MD. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[LIABILITY_CAP_INDEMNITY · FL-1] A blanket 'as is' liability disclaimer covers a near-monopoly insurer with 75% of the Maryland market\nWHAT THE TERMS SAY: This entity, the managed-care HMO subsidiary, shares a single Terms of Use with the other two CareFirst subsidiaries at carefirst.com. The terms (retrieved and read 2026-08-06) contain a blanket 'as is' disclaimer and full limitation of liability, covering 3.5 million members across DC, Maryland, and Northern Virginia with 75% market share in Maryland alone.\nWHY IT MATTERS: Standard liability language is applied to a provider members have little practical ability to switch away from, given its dominant market position.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] CareFirst says Change Healthcare's breach cost it employer/Medicare Advantage data and $25M in loans\nWHAT THE TERMS SAY: CareFirst is suing Change Healthcare (a UnitedHealth subsidiary) in Maryland state court (filed 2025-02-21) over the Feb 2024 ransomware attack, alleging a Citrix portal without multifactor authentication caused it to lose 'a large amount of data related to employer accounts and its Medicare Advantage business,' forcing it to reallocate $25 million as emergency loans to providers who couldn't operate during the outage. CareFirst seeks $900,000 in compensatory damages.\nWHY IT MATTERS: CareFirst alleges the same Change Healthcare breach — which affected an estimated 190 million individuals nationwide — caused it to lose a large amount of data related to employer accounts and its Medicare Advantage business.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and fee terms are unconfirmed this pass, and CareFirst's own earlier 2014 breach is documented under the separate parent CareFirst row in another tab rather than re-verified here, leaving these two items.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The liability terms and the Change Healthcare litigation are clearly documented, but arbitration terms are unverified and the earlier 2014 breach is only cross-referenced from another tab.", "Exposure Score (0-100)": 18, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "CareFirst BlueChoice, Inc.  <-  CareFirst BlueCross BlueShield", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to be made whole. Their liability is capped, often at what you paid.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using CareFirst BlueChoice, Inc. you gave up your right to meaningful compensation. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "CareFirst BlueChoice is the managed-care HMO subsidiary, offering the BlueChoice plans in DC/MD/VA. Three CareFirst subsidiaries — CareFirst BlueChoice Inc., CareFirst of Maryland Inc., and Group Hospitalization and Medical Services Inc. (GHMSI) — operate under a SINGLE set of terms hosted at carefirst.com, covering 3.5 million members across DC, Maryland, and Northern Virginia with a 75% market share in Maryland alone. The Terms of Use (retrieved and read 2026-08-06) contain a blanket 'as is' disclaimer and full limitation of liability — standard for the industry, but applied here to a near-monopoly provider whose members have limited practical alternatives. CareFirst is ACTIVELY SUING Change Healthcare (UnitedHealth subsidiary) in Maryland state court (filed 2025-02-21) over the February 2024 ransomware attack, alleging insufficient cybersecurity — specifically a Citrix portal without multifactor authentication — caused CareFirst to lose 'a large amount of data related to employer accounts and its Medicare Advantage business' and forced it to reallocate $25 million in investment funds as emergency loans to providers who could not operate during the outage. CareFirst seeks $900,000 in compensatory damages. This is the same Change Healthcare breach that affected an estimated 190 million individuals nationwide — and CareFirst's own earlier 2014 breach (1.1 million members, undetected for 11 months) is already documented in this tracker's parent CareFirst row in the Insurance tab.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 428, "_entity_id": 628, "_entity_slug": "carefirst-bluechoice-inc", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CareFirst of Maryland, Inc.", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.carefirst.com/medicaid/terms-of-use.html", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.carefirst.com/terms-of-use", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "One of three CareFirst subsidiaries sharing identical T&C. Parent: CareFirst BlueCross BlueShield (see Insurance tab for the parent row's 2014 breach). 75% market share in MD. 626,000+ FEHB members. Change Healthcare lawsuit: CareFirst v. Change Healthcare, MD state court, filed 2025-02-21.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Owings Mills", "HQ State": "MD", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.carefirst.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "T&C fetched and read via web_fetch 2026-08-06. Change Healthcare lawsuit sourced via web_search (HIPAA Journal, Becker's, HIPAA Guide, CareFirst's own provider notice). All facts cross-checked against multiple sources.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Operates in MD; HQ: Owings Mills, MD", "Parent / Ultimate Owner": "CareFirst BlueCross BlueShield", "Years Referenced in Finding (heuristic)": "2014, 2015, 2024, 2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (MD) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in MD. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[LIABILITY_CAP_INDEMNITY · FL-1] A blanket 'as is' liability disclaimer covers a near-monopoly insurer with 75% of the Maryland market\nWHAT THE TERMS SAY: This entity, the traditional indemnity/PPO subsidiary, the original Maryland Blue Cross entity, shares a single Terms of Use with the other two CareFirst subsidiaries at carefirst.com. The terms (retrieved and read 2026-08-06) contain a blanket 'as is' disclaimer and full limitation of liability, covering 3.5 million members across DC, Maryland, and Northern Virginia with 75% market share in Maryland alone.\nWHY IT MATTERS: Standard liability language is applied to a provider members have little practical ability to switch away from, given its dominant market position.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] CareFirst says Change Healthcare's breach cost it employer/Medicare Advantage data and $25M in loans\nWHAT THE TERMS SAY: CareFirst is suing Change Healthcare (a UnitedHealth subsidiary) in Maryland state court (filed 2025-02-21) over the Feb 2024 ransomware attack, alleging a Citrix portal without multifactor authentication caused it to lose 'a large amount of data related to employer accounts and its Medicare Advantage business,' forcing it to reallocate $25 million as emergency loans to providers who couldn't operate during the outage. CareFirst seeks $900,000 in compensatory damages.\nWHY IT MATTERS: CareFirst alleges the same Change Healthcare breach — which affected an estimated 190 million individuals nationwide — caused it to lose a large amount of data related to employer accounts and its Medicare Advantage business.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and fee terms are unconfirmed this pass, and CareFirst's own earlier 2014 breach is documented under the separate parent CareFirst row in another tab rather than re-verified here, leaving these two items.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The liability terms and the Change Healthcare litigation are clearly documented, but arbitration terms are unverified and the earlier 2014 breach is only cross-referenced from another tab.", "Exposure Score (0-100)": 18, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "CareFirst of Maryland, Inc.  <-  CareFirst BlueCross BlueShield", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to be made whole. Their liability is capped, often at what you paid.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using CareFirst of Maryland, Inc. you gave up your right to meaningful compensation. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "CareFirst of Maryland is the traditional indemnity/PPO subsidiary, the original Maryland Blue Cross entity. Three CareFirst subsidiaries — CareFirst BlueChoice Inc., CareFirst of Maryland Inc., and Group Hospitalization and Medical Services Inc. (GHMSI) — operate under a SINGLE set of terms hosted at carefirst.com, covering 3.5 million members across DC, Maryland, and Northern Virginia with a 75% market share in Maryland alone. The Terms of Use (retrieved and read 2026-08-06) contain a blanket 'as is' disclaimer and full limitation of liability — standard for the industry, but applied here to a near-monopoly provider whose members have limited practical alternatives. CareFirst is ACTIVELY SUING Change Healthcare (UnitedHealth subsidiary) in Maryland state court (filed 2025-02-21) over the February 2024 ransomware attack, alleging insufficient cybersecurity — specifically a Citrix portal without multifactor authentication — caused CareFirst to lose 'a large amount of data related to employer accounts and its Medicare Advantage business' and forced it to reallocate $25 million in investment funds as emergency loans to providers who could not operate during the outage. CareFirst seeks $900,000 in compensatory damages. This is the same Change Healthcare breach that affected an estimated 190 million individuals nationwide — and CareFirst's own earlier 2014 breach (1.1 million members, undetected for 11 months) is already documented in this tracker's parent CareFirst row in the Insurance tab.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 429, "_entity_id": 629, "_entity_slug": "carefirst-of-maryland-inc", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CareSource Georgia", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.caresource.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.caresource.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Dayton, OH. Parent: CareSource. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: CareSource Ohio, CareSource WV. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Dayton", "HQ State": "OH", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.caresource.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Dayton, OH — not matched", "Parent / Ultimate Owner": "CareSource", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (OH) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in OH. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Arbitration, fees, and plan-level data-sharing provisions are all explicitly marked not verified this pass; no company-specific troubling practice is documented, only basic operating context.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Terms were not independently fetched this pass; the row contains no confirmed practice, breach, or litigation.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "CareSource Georgia  <-  CareSource", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, CareSource Georgia takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "CareSource Georgia is CareSource's expansion into the Georgia market, serving Medicaid and marketplace populations. Terms not independently fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 430, "_entity_id": 631, "_entity_slug": "caresource-georgia", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CareSource Ohio", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.caresource.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.caresource.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Dayton, OH. Parent: CareSource. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: CareSource Georgia, CareSource WV. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Dayton", "HQ State": "OH", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.caresource.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Dayton, OH — not matched", "Parent / Ultimate Owner": "CareSource", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (OH) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in OH. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or plan-level data-sharing terms independently verified for CareSource Ohio\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field is generic HIPAA-covered-entity language rather than terms specific to this company's plan documents.\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the SCARY field confirms 'Terms not independently fetched this pass' for this Dayton, OH Medicaid/marketplace non-profit.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "CareSource Ohio  <-  CareSource", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, CareSource Ohio takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "CareSource Ohio is a non-profit managed-care organization based in Dayton, OH. CareSource serves primarily Medicaid and marketplace populations — over 2 million members across multiple states. Terms not independently fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 431, "_entity_id": 632, "_entity_slug": "caresource-ohio", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CareSource WV", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.caresource.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.caresource.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Dayton, OH. Parent: CareSource. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: CareSource Georgia, CareSource Ohio. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Dayton", "HQ State": "OH", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.caresource.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Dayton, OH — not matched", "Parent / Ultimate Owner": "CareSource", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Non-US entity (OH) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in OH. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or plan-level data-sharing terms independently verified for CareSource WV\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field is generic HIPAA-covered-entity language rather than terms specific to this company's plan documents.\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the SCARY field confirms 'Terms not independently fetched this pass' for this West Virginia/North Carolina non-profit plan.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "CareSource WV  <-  CareSource", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, CareSource WV takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "CareSource WV serves West Virginia and North Carolina. Terms not independently fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 432, "_entity_id": 633, "_entity_slug": "caresource-wv", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cigna Health and Life Insurance Company", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.cigna.com/legal/terms-of-use", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.cigna.com/legal/terms-of-use", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. The Cigna Group (parent) merged with Express Scripts (PBM) in 2018, creating an insurer+PBM vertical integration similar to CVS/Aetna. Express Scripts is separately documented in this tracker's PBM tab. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Bloomfield, CT. Parent: The Cigna Group. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Cigna Healthcare of South Carolina. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Bloomfield", "HQ State": "CT", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.cigna.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Bloomfield, CT — not matched", "Parent / Ultimate Owner": "The Cigna Group", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (CT) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in CT. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or data-sharing terms independently verified for Cigna Health and Life\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field records only parent-level context — that The Cigna Group merged with Express Scripts (PBM) in 2018 — while stating 'Plan-level data-sharing provisions not independently verified.'\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity pass 2 (strict): Wrong corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the row notes The Cigna Group's 2018 merger with Express Scripts as parent-level structural context only (that PBM is tracked separately), and states plan-level data-sharing and arbitration were not independently verified.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Cigna Health and Life Insurance Company  <-  The Cigna Group", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Cigna Health and Life Insurance Company takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Cigna Health and Life is The Cigna Group's primary insurance subsidiary, operating in TN and other states. Cigna merged with Express Scripts in 2018 (the PBM already documented in this tracker). Terms at cigna.com/legal not independently fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 433, "_entity_id": 634, "_entity_slug": "cigna-health-and-life-insurance-company", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cigna Healthcare of South Carolina", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.cigna.com/legal/terms-of-use", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.cigna.com/legal/terms-of-use", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. The Cigna Group (parent) merged with Express Scripts (PBM) in 2018, creating an insurer+PBM vertical integration similar to CVS/Aetna. Express Scripts is separately documented in this tracker's PBM tab. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Bloomfield, CT. Parent: The Cigna Group. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Cigna Health and Life Insurance Company. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Bloomfield", "HQ State": "CT", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.cigna.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Bloomfield, CT — not matched", "Parent / Ultimate Owner": "The Cigna Group", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (CT) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in CT. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or data-sharing terms independently verified for Cigna Healthcare of SC\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field records only parent-level context — that The Cigna Group merged with Express Scripts (PBM) in 2018 — while stating 'Plan-level data-sharing provisions not independently verified.'\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity pass 2 (strict): Wrong corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the row notes the same Cigna Group/Express Scripts parent structure as context only, and states arbitration, fees, and plan-level data-sharing were not independently verified for this South Carolina subsidiary.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Cigna Healthcare of South Carolina  <-  The Cigna Group", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Cigna Healthcare of South Carolina takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Cigna Healthcare SC is The Cigna Group's South Carolina subsidiary. Same parent as the Express Scripts PBM row. Terms not independently fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 434, "_entity_id": 635, "_entity_slug": "cigna-healthcare-of-south-carolina", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Clover Insurance Company", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.cloverhealth.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.cloverhealth.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: New York, NY. Parent: Clover Health. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "NY", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.cloverhealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: New York, NY — not matched", "Parent / Ultimate Owner": "Clover Health", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (NY) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in NY. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] Parent Clover settled a $22M securities class action after a report alleging an undisclosed DOJ probe\nWHAT THE TERMS SAY: The SCARY field states Clover Health (parent, for-profit Medicare Advantage insurer, SPAC IPO 2021) was the subject of a Hindenburg Research short-seller report alleging an undisclosed DOJ investigation into kickback schemes, and that Clover settled the resulting securities class action for $22M in 2023 without admitting wrongdoing.\nWHY IT MATTERS: This is a corporate-governance/investor matter rather than a member-facing contract term: per the tracker, the kickback investigation is what a Hindenburg Research short-seller report alleged, and what Clover settled was the resulting securities class action — $22M in 2023, without admitting wrongdoing.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are marked 'NOT VERIFIED THIS PASS' and plan-level data-sharing terms were not independently read; the securities-settlement item is the only substantive, company-specific fact in the row, so only one item is reported.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Plan terms were not fetched, but a specific, dated corporate-litigation fact (the $22M 2023 settlement) is confirmed in the row.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Clover Insurance Company  <-  Clover Health", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Clover Insurance Company takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Clover Health is a for-profit, technology-focused Medicare Advantage insurer (IPO via SPAC 2021, subject of a Hindenburg Research short-seller report alleging undisclosed DOJ investigation into kickback schemes — Clover settled the resulting securities class action for $22M in 2023 without admitting wrongdoing). Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 435, "_entity_id": 637, "_entity_slug": "clover-insurance-company", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Coventry HealthCare of Delaware", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.aetna.com/members/rights-and-responsibilities.html", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.aetna.com/legal/terms-of-use.html", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. CVS Health (parent) operates CVS Pharmacy, CVS Caremark (PBM), Aetna (insurance), and MinuteClinic — creating one of the most vertically integrated healthcare data environments in the US. A single member's prescription, insurance claim, and in-store purchase data can flow through the same parent. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "Same as Aetna Health Inc. — mandatory arbitration, class + jury waivers survive opt-out. 60-day letter-based opt-out.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "Aetna/CVS subsidiary, HQ Bethesda MD (DMV). Acquired by Aetna 2013 for $5.7B. Shares identical T&C with Aetna Health Inc.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Bethesda", "HQ State": "MD", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.aetna.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. T&C text sourced via web_search returning actual document content from corporate legal pages. Cross-referenced with existing tracker rows. Fields marked 'NOT VERIFIED THIS PASS' were not independently fetched.", "Arbitration Opt-Out Window (Days)": 60, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Operates in DE; HQ: Bethesda, MD", "Parent / Ultimate Owner": "Aetna (CVS Health)", "Years Referenced in Finding (heuristic)": "2013", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (MD) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in MD. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CLASS_ACTION_WAIVER · FL-3] Class-action waiver survives even if a Coventry member successfully opts out of arbitration\nWHAT THE TERMS SAY: The row states Coventry shares identical terms with Aetna Health Inc.: mandatory binding arbitration with a 60-day, physically-signed-letter opt-out to Connecticut — but 'even if you opt out, the class action waiver and jury trial waiver survive.'\nWHY IT MATTERS: A member who takes the effort to mail a physically-signed opt-out letter to Connecticut within 60 days still cannot join a class action against Coventry, because the row states the class action waiver survives the opt-out.\n(evidence: Arbitration | SCARY | Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[JURY_WAIVER · FL-3] Jury trial waiver likewise survives the 60-day arbitration opt-out\nWHAT THE TERMS SAY: The same clause bundles a jury trial waiver with the class-action waiver as a right that 'survives' even after a successful opt-out from arbitration itself.\nWHY IT MATTERS: Even a member who opts out still cannot take a dispute to a jury — only individual arbitration or individual court action without a jury remain available, per the tracker's description.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory binding arbitration applies by default, with a narrow 60-day letter-based opt-out\nWHAT THE TERMS SAY: Coventry's terms (identical to Aetna Health Inc.'s) impose mandatory binding arbitration by default; a member must send a physically-signed letter within 60 days to opt out of the arbitration mechanism itself.\nWHY IT MATTERS: Members who don't act within 60 days, or who don't realize Coventry operates under Aetna's terms and shares identical T&C with Aetna Health Inc., are bound to individual arbitration for any dispute with their insurer.\n(evidence: Arbitration | Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are specifically confirmed (shared with Aetna Health Inc.), but fee/billing terms remain unverified and data-sharing is only generic HIPAA boilerplate.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 25, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 25/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_60d+1) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Coventry HealthCare of Delaware  <-  Aetna (CVS Health)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to a jury.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Coventry HealthCare of Delaware you gave up your data shared corporate-wide, your right to sue, your right to join a class action, and your right to a jury. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Coventry HealthCare of Delaware, headquartered in Bethesda, MD, is an Aetna/CVS Health subsidiary operating under Aetna's terms (same T&C URL as Aetna Health Inc.). The arbitration clause is identical: mandatory binding arbitration with class action AND jury trial waivers, 60-day physically-signed-letter opt-out to Connecticut — but even if you opt out, the class action waiver and jury trial waiver survive. Coventry was acquired by Aetna in 2013 for $5.7 billion and its members were migrated to Aetna's platform, but Coventry continues to operate as a separate legal entity in Delaware. A Coventry member who believes they are with a 'different company' from Aetna is bound by the identical terms.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 436, "_entity_id": 639, "_entity_slug": "coventry-healthcare-of-delaware", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "EmblemHealth", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.emblemhealth.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.emblemhealth.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: New York, NY. Parent: EmblemHealth (independent). arbitration clause not yet verified. Region: Unspecified. Severity: 2. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "NY", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.emblemhealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: New York, NY — not matched", "Parent / Ultimate Owner": "EmblemHealth (independent)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (NY) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in NY. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or plan-level data-sharing terms independently verified for EmblemHealth\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field is generic HIPAA-covered-entity language rather than terms specific to this company's plan documents.\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the SCARY field confirms 'Terms not fetched this pass' for this NYC non-profit serving roughly 3.1 million members.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "EmblemHealth  <-  EmblemHealth (independent)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, EmblemHealth takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "EmblemHealth is a New York City-based non-profit serving ~3.1 million members. Formed from the 2006 merger of Group Health Incorporated (GHI) and Health Insurance Plan of Greater New York (HIP). Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 437, "_entity_id": 640, "_entity_slug": "emblemhealth", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Empire Blue Cross Blue Shield (Anthem HealthChoice Assurance)", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.empireblue.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.empireblue.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Elevance Health (parent, fmr. Anthem) operates the largest for-profit Blue Cross Blue Shield licensee by enrollment. Subject of the 2015 breach (78.8M people) — the largest healthcare breach at the time. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: New York, NY. Parent: Elevance Health, Inc.. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Anthem Blue Cross Blue Shield of Georgia, Anthem Blue Cross and Blue Shield of Ohio, Anthem Health Plans of Kentucky. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "NY", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.empireblue.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: New York, NY — not matched", "Parent / Ultimate Owner": "Elevance Health, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (NY) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in NY. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or data-sharing terms independently verified for this Empire BCBS product\nWHAT THE TERMS SAY: Arbitration and Fees/Billing are both marked 'NOT VERIFIED THIS PASS — do not cite,' and the SCARY field states terms at empireblue.com/legal were 'not independently fetched this pass.'\nWHY IT MATTERS: A member of this specific ACA marketplace product (as distinct from other Empire plans) cannot learn from this tracker what dispute-resolution or fee terms apply, since none were confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — The row's mention of a 2015 breach affecting 78.8M people is stated as parent-level Elevance Health/Anthem history and the SCARY field explicitly labels it 'the 2015 breach row,' i.e. a finding documented against a different tracker row, not a confirmed finding about this specific Empire BCBS/Anthem HealthChoice Assurance entity; arbitration and fees are both unverified this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Terms not independently fetched this pass; the one concrete data point (2015 breach) belongs to a parent-level finding tracked elsewhere, not this entity.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Empire Blue Cross Blue Shield (Anthem HealthChoice Assurance)  <-  Elevance Health, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Empire Blue Cross Blue Shield (Anthem HealthChoice Assurance) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Empire BCBS is Elevance Health's New York subsidiary — the largest health insurer in New York State. The '(Anthem HealthChoice Assurance)' qualifier means this row covers the ACA marketplace product specifically, not all Empire plans. Same parent as the 2015 breach row. Terms at empireblue.com/legal not independently fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 438, "_entity_id": 641, "_entity_slug": "empire-blue-cross-blue-shield-anthem-healthchoice-assurance", "_issuer": "Elevance Health, Inc.", "_issuer_slug": "elevance-health-inc", "_ticker": "ELV", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Excellus BlueCross BlueShield", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.excellusbcbs.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.excellusbcbs.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Rochester, NY. Parent: Excellus Health Plan (independent). arbitration clause not yet verified. Region: Unspecified. Severity: 2. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Rochester", "HQ State": "NY", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.excellusbcbs.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Rochester, NY — not matched", "Parent / Ultimate Owner": "Excellus Health Plan (independent)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (NY) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in NY. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or plan-level data-sharing terms independently verified for Excellus BlueCross BlueShield\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field is generic HIPAA-covered-entity language rather than terms specific to this company's plan documents.\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the SCARY field confirms 'Terms not fetched this pass' for this Rochester, NY non-profit.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Excellus BlueCross BlueShield  <-  Excellus Health Plan (independent)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Excellus BlueCross BlueShield takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Excellus BCBS is a Rochester, NY-based non-profit, the largest health insurer in upstate New York. Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 439, "_entity_id": 643, "_entity_slug": "excellus-bluecross-blueshield", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fidelis Care (Centene)", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.fideliscare.org/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.fideliscare.org/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Centene Corporation (parent) is a Fortune 25 company; data handling governed by HIPAA/HITECH at federal level plus state insurance commissioner oversight. Centene's marketplace enrollment portal (ambetterhealth.com) uses a separate set of web terms from the plan's Evidence of Coverage — the website terms are NOT subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "MANDATORY arbitration + class/jury waivers on enrollment portal (CA law, Sacramento jurisdiction). Main site T&C has NO arbitration clause — split terms create ambiguity. No opt-out mechanism found.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: New York, NY. Parent: Centene Corporation. mandatory arbitration confirmed. Region: Unspecified. Severity: 3. Sibling entities in this tab: Ambetter (Celtic) of Tennessee, Ambetter Health of Delaware, Ambetter from Absolute Total Care. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "NY", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.fideliscare.org", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: New York, NY — not matched", "Parent / Ultimate Owner": "Centene Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (NY) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in NY. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Ambetter portal forces arbitration under CA law in Sacramento, regardless of member's home state\nWHAT THE TERMS SAY: The row states Centene's Ambetter enrollment-portal Terms of Service (confirmed from two ambetterhealth.com pages, 2026-08-06) contain mandatory arbitration with a class-action waiver and a jury-trial waiver, governed by California law with exclusive jurisdiction in Sacramento County, regardless of the member's actual state of residence.\nWHY IT MATTERS: A New York-based Fidelis/Ambetter member who enrolls online agrees to resolve any dispute roughly 3,000 miles away under another state's law, per the tracker's description.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Class action AND jury trial rights are both waived on the enrollment portal, with no opt-out mechanism found\nWHAT THE TERMS SAY: The same enrollment-portal arbitration clause bundles a class-action waiver and a jury-trial waiver, and the tracker states 'no opt-out mechanism' was found for it.\nWHY IT MATTERS: The tracker records no opt-out mechanism for the enrollment portal's arbitration clause, so a Fidelis/Ambetter member who enrolls online appears to have no route to preserve class-action or jury-trial rights.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[OTHER · FL-3] Two different sets of Centene terms conflict on whether arbitration even applies\nWHAT THE TERMS SAY: The tracker states the main site's Terms & Conditions (ambetterhealth.com/terms-conditions.html) contain a blanket liability disclaimer but NO arbitration clause, in contrast to the enrollment portal's mandatory-arbitration terms — 'split terms create ambiguity' about which terms govern which interactions.\nWHY IT MATTERS: A member cannot easily tell, from the company's own materials, which of two contradictory rulebooks applies to a given interaction with Centene's ACA marketplace brand.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are specifically confirmed from two named source pages, but the two Centene term sets conflict with each other and fees remain unverified.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 30, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 30/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Fidelis Care (Centene)  <-  Centene Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to a jury.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Fidelis Care (Centene) you gave up your right to sue, your right to join a class action, and your right to a jury. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Fidelis Care (Centene) operates in New York (Fidelis Care brand, acquired by Centene 2018 for $3.75B from the Catholic Diocese). Ambetter Health is Centene Corporation's ACA marketplace brand — and Centene's Terms & Conditions (confirmed from two separate pages on ambetterhealth.com, 2026-08-06) reveal a split personality. The enrollment portal's Terms of Service contain mandatory arbitration with a class action waiver AND a jury trial waiver, governed by CALIFORNIA law with exclusive jurisdiction in Sacramento County — regardless of which state the member actually lives in. A NY member who signs up through Ambetter's enrollment portal is agreeing to resolve disputes 3,000 miles away under another state's law. The main site's Terms & Conditions (ambetterhealth.com/terms-conditions.html), by contrast, contain a blanket liability disclaimer but NO arbitration clause — creating ambiguity about which set of terms governs which interactions. Centene itself is a Fortune 25 company with $154B in 2023 revenue and 28.6 million managed-care members across all brands.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 440, "_entity_id": 644, "_entity_slug": "fidelis-care-centene", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "First Choice Next", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.firstchoicenext.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.firstchoicenext.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Greenville, SC. Parent: First Choice Health. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Greenville", "HQ State": "SC", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.firstchoicenext.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Greenville, SC — not matched", "Parent / Ultimate Owner": "First Choice Health", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (SC) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in SC. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or plan-level data-sharing terms independently verified for First Choice Next\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field is generic HIPAA-covered-entity language rather than terms specific to this company's plan documents.\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the SCARY field confirms 'Terms not fetched this pass' for this South Carolina ACA marketplace insurer.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "First Choice Next  <-  First Choice Health", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, First Choice Next takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "First Choice Next is a for-profit ACA marketplace insurer in South Carolina (founded 2020). Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 441, "_entity_id": 646, "_entity_slug": "first-choice-next", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Group Hospitalization and Medical Services, Inc. (GHMSI)", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.carefirst.com/medicaid/terms-of-use.html", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.carefirst.com/terms-of-use", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "One of three CareFirst subsidiaries sharing identical T&C. Parent: CareFirst BlueCross BlueShield (see Insurance tab for the parent row's 2014 breach). 75% market share in MD. 626,000+ FEHB members. Change Healthcare lawsuit: CareFirst v. Change Healthcare, MD state court, filed 2025-02-21.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Washington", "HQ State": "DC", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.carefirst.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "T&C fetched and read via web_fetch 2026-08-06. Change Healthcare lawsuit sourced via web_search (HIPAA Journal, Becker's, HIPAA Guide, CareFirst's own provider notice). All facts cross-checked against multiple sources.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Operates in DC, MD, VA; HQ: Washington, DC", "Parent / Ultimate Owner": "CareFirst BlueCross BlueShield", "Years Referenced in Finding (heuristic)": "2014, 2015, 2024, 2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (DC) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in DC. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[PENDING_LITIGATION · FL-2] CareFirst is suing Change Healthcare over a 2024 breach it alleges lost employer/MA plan data\nWHAT THE TERMS SAY: The row states CareFirst (GHMSI's parent family) filed suit against Change Healthcare (a UnitedHealth subsidiary) in Maryland state court on 2025-02-21, alleging insufficient cybersecurity — specifically a Citrix portal without multifactor authentication — caused CareFirst to lose 'a large amount of data related to employer accounts and its Medicare Advantage business,' forcing a $25 million emergency reallocation to providers, and seeking $900,000 in compensatory damages.\nWHY IT MATTERS: GHMSI is one of three CareFirst subsidiaries operating under a single set of carefirst.com terms, and this suit is CareFirst's own account of what it lost in the Change Healthcare breach the tracker says affected an estimated 190 million individuals nationwide.\n(evidence: SCARY | Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[LIABILITY_CAP_INDEMNITY · FL-1] Blanket 'as is' disclaimer and full liability limitation apply to a near-monopoly regional insurer\nWHAT THE TERMS SAY: The Terms of Use shared by GHMSI and its two sibling CareFirst entities (retrieved and read 2026-08-06) contain a blanket 'as is' disclaimer and full limitation of liability, covering 3.5 million members across DC/MD/VA with a 75% market share in Maryland alone.\nWHY IT MATTERS: The tracker itself flags this as 'standard for the industry, but applied here to a near-monopoly provider whose members have limited practical alternatives.'\n(evidence: SCARY | Key Provisions; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS'; CareFirst's own separate 2014 breach is explicitly documented against the parent CareFirst row in the Insurance tab, not this row, so it is not counted as a third distinct item here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Terms of Use and active litigation are specifically confirmed and dated, but arbitration and fees remain unverified this pass.", "Exposure Score (0-100)": 19, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 10/20 (severity3+8, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Group Hospitalization and Medical Services, Inc. (GHMSI)  <-  CareFirst BlueCross BlueShield", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Group Hospitalization and Medical Services, Inc. (GHMSI) you gave up your data shared corporate-wide and your right to meaningful compensation. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "GHMSI is the DC-area subsidiary, historically the Blue Cross plan for federal employees in the Washington metropolitan area. Three CareFirst subsidiaries — CareFirst BlueChoice Inc., CareFirst of Maryland Inc., and Group Hospitalization and Medical Services Inc. (GHMSI) — operate under a SINGLE set of terms hosted at carefirst.com, covering 3.5 million members across DC, Maryland, and Northern Virginia with a 75% market share in Maryland alone. The Terms of Use (retrieved and read 2026-08-06) contain a blanket 'as is' disclaimer and full limitation of liability — standard for the industry, but applied here to a near-monopoly provider whose members have limited practical alternatives. CareFirst is ACTIVELY SUING Change Healthcare (UnitedHealth subsidiary) in Maryland state court (filed 2025-02-21) over the February 2024 ransomware attack, alleging insufficient cybersecurity — specifically a Citrix portal without multifactor authentication — caused CareFirst to lose 'a large amount of data related to employer accounts and its Medicare Advantage business' and forced it to reallocate $25 million in investment funds as emergency loans to providers who could not operate during the outage. CareFirst seeks $900,000 in compensatory damages. This is the same Change Healthcare breach that affected an estimated 190 million individuals nationwide — and CareFirst's own earlier 2014 breach (1.1 million members, undetected for 11 months) is already documented in this tracker's parent CareFirst row in the Insurance tab.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 442, "_entity_id": 647, "_entity_slug": "group-hospitalization-and-medical-services-inc-ghmsi", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Healthfirst", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.healthfirst.org/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.healthfirst.org/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: New York, NY. Parent: Healthfirst (independent). arbitration clause not yet verified. Region: Unspecified. Severity: 2. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "NY", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.healthfirst.org", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: New York, NY — not matched", "Parent / Ultimate Owner": "Healthfirst (independent)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (NY) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in NY. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or plan-level data-sharing terms independently verified for Healthfirst\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field is generic HIPAA-covered-entity language rather than terms specific to this company's plan documents.\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the SCARY field confirms 'Terms not fetched this pass' for this NYC non-profit Medicaid managed-care plan (~1.8 million members).", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Healthfirst  <-  Healthfirst (independent)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Healthfirst takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Healthfirst is a New York City-based non-profit, the largest not-for-profit Medicaid managed-care plan in New York State (~1.8 million members). Founded by a consortium of NYC hospitals. Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 443, "_entity_id": 648, "_entity_slug": "healthfirst", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Highmark BCBSD Inc.", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.highmark.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.highmark.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Wilmington, DE. Parent: Highmark Health. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Highmark Inc.. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Wilmington", "HQ State": "DE", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.highmark.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Wilmington, DE — not matched", "Parent / Ultimate Owner": "Highmark Health", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (DE) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in DE. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or plan-level data-sharing terms independently verified for Highmark BCBSD Inc.\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field is generic HIPAA-covered-entity language rather than terms specific to this company's plan documents.\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the SCARY field confirms 'Terms not independently fetched this pass' for this Delaware Highmark Health subsidiary.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Highmark BCBSD Inc.  <-  Highmark Health", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Highmark BCBSD Inc. takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Highmark BCBSD is Highmark Health's Delaware subsidiary — the dominant insurer in Delaware. Terms not independently fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 444, "_entity_id": 650, "_entity_slug": "highmark-bcbsd-inc", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Highmark Inc.", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.highmark.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.highmark.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Pittsburgh, PA. Parent: Highmark Health. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Highmark BCBSD Inc.. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Pittsburgh", "HQ State": "PA", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.highmark.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Pittsburgh, PA — not matched", "Parent / Ultimate Owner": "Highmark Health", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (PA) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in PA. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or plan-level data-sharing terms independently verified for Highmark Inc.\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field is generic HIPAA-covered-entity language rather than terms specific to this company's plan documents.\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the SCARY field confirms 'Terms not independently fetched this pass' for this Pennsylvania/West Virginia Highmark Health subsidiary.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Highmark Inc.  <-  Highmark Health", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Highmark Inc. takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Highmark Inc. is Highmark Health's Pennsylvania/West Virginia subsidiary — a top-10 BCBS plan by enrollment. Terms not independently fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 445, "_entity_id": 651, "_entity_slug": "highmark-inc", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Horizon Blue Cross Blue Shield of New Jersey", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.horizonblue.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.horizonblue.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Newark, NJ. Parent: Horizon Blue Cross Blue Shield of New Jersey (independent). arbitration clause not yet verified. Region: Unspecified. Severity: 2. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Newark", "HQ State": "NJ", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.horizonblue.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Newark, NJ — not matched", "Parent / Ultimate Owner": "Horizon Blue Cross Blue Shield of New Jersey (independent)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (NJ) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in NJ. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or data-sharing terms independently verified for Horizon BCBS of NJ\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field is generic HIPAA-covered-entity language rather than terms specific to this company's plan documents.\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the SCARY field confirms 'Terms not fetched this pass' for this New Jersey non-profit (3.6 million members).", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Horizon Blue Cross Blue Shield of New Jersey  <-  Horizon Blue Cross Blue Shield of New Jersey (independent)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Horizon Blue Cross Blue Shield of New Jersey takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Horizon BCBS NJ is the largest health insurer in New Jersey (3.6 million members), a non-profit with the state's only 'Largest' network-size designation in this dataset. Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 446, "_entity_id": 652, "_entity_slug": "horizon-blue-cross-blue-shield-of-new-jersey", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Humana Healthy Horizons in Kentucky", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.humana.com/legal/terms-of-use", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.humana.com/legal/terms-of-service", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Humana Inc. (parent) is the subject of class-action litigation over the nH Predict algorithm (built by UnitedHealth's NaviHealth subsidiary) used to deny post-acute care coverage. Plan-level data-sharing provisions not verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Louisville, KY. Parent: Humana Inc.. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Humana Insurance Company. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Louisville", "HQ State": "KY", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.humana.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Louisville, KY — not matched", "Parent / Ultimate Owner": "Humana Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (KY) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in KY. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or data-sharing terms independently verified for Humana Healthy Horizons\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field records only parent-level context — that Humana Inc. is the subject of class-action litigation over the nH Predict algorithm used to deny post-acute care coverage — while stating 'Plan-level data-sharing provisions not verified.'\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity pass 2 (strict): Wrong corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the SCARY field explicitly attributes the substantive nH Predict algorithm-denial litigation to 'the existing Humana row' (a sibling entity in this tracker), so it is parent/sibling context here, not a finding confirmed against this Kentucky Medicaid brand specifically; this row's own terms were not fetched this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Humana Healthy Horizons in Kentucky  <-  Humana Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Humana Healthy Horizons in Kentucky takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Humana Healthy Horizons is Humana's Medicaid managed-care brand in Kentucky. Same parent as the existing Humana row (nH Predict algorithm denial lawsuit). Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 447, "_entity_id": 653, "_entity_slug": "humana-healthy-horizons-in-kentucky", "_issuer": "Humana Inc.", "_issuer_slug": "humana-inc", "_ticker": "HUM", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Humana Insurance Company", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.humana.com/legal/terms-of-use", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.humana.com/legal/terms-of-service", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Humana Inc. (parent) is the subject of class-action litigation over the nH Predict algorithm (built by UnitedHealth's NaviHealth subsidiary) used to deny post-acute care coverage. Plan-level data-sharing provisions not verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — humana.com/legal/terms-of-use was not fetched.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "Louisville KY HQ, operates in DC/PA/WV. Cross-ref existing Humana row for the nH Predict/NaviHealth algorithm denial lawsuit. DC AG joined multistate AI-denial investigation 2024.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Louisville", "HQ State": "KY", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.humana.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. T&C text sourced via web_search returning actual document content from corporate legal pages. Cross-referenced with existing tracker rows. Fields marked 'NOT VERIFIED THIS PASS' were not independently fetched.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Operates in DC/PA/WV — DMV tag based on DC service area, not HQ (Louisville, KY)", "Parent / Ultimate Owner": "Humana Inc.", "Years Referenced in Finding (heuristic)": "2023, 2024", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (KY) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in KY. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[PENDING_LITIGATION · FL-1] Humana accused of using nH Predict algorithm to deny post-acute care in a W.D. Kentucky class action\nWHAT THE TERMS SAY: The row states Humana is accused of using the nH Predict algorithm (built by NaviHealth, a UnitedHealth/Optum subsidiary) to systematically deny post-acute care coverage to Medicare Advantage patients, per the existing Humana row's class action in the Western District of Kentucky over the same AI tool; Lokken v. UnitedHealth Group is cited in the row as related context about the algorithm, not as a suit naming Humana.\nWHY IT MATTERS: If the allegations hold, Medicare Advantage members covered by this Humana entity in DC, PA, or WV could have care decisions influenced by an algorithm built by a rival insurer's subsidiary, rather than by individualized clinical review; this remains an allegation, not a proven finding.\n(evidence: SCARY | Data Sharing; Tracker says unconfirmed (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "[OTHER · FL-1] DC's Attorney General joined a 2024 multistate investigation into AI-driven health insurance denials\nWHAT THE TERMS SAY: The row states DC AG Brian Schwalb joined a multistate coalition investigating AI-driven health insurance denials in 2024, relevant given this Humana entity's DC operations.\nWHY IT MATTERS: This is a regulatory investigation, not a confirmed penalty or finding of wrongdoing against Humana specifically, but it signals active regulatory scrutiny of the algorithmic-denial practice Humana is separately accused of.\n(evidence: SCARY | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration was not independently fetched this pass ('humana.com/legal/terms-of-use was not fetched') and fee/billing terms are unverified, so no third, distinct company-specific item is available.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The litigation and regulatory-investigation facts are specific and sourced, but this entity's own arbitration and fee terms were not fetched this pass.", "Exposure Score (0-100)": 10, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Humana Insurance Company  <-  Humana Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Humana Insurance Company takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Humana Insurance Company operates in DC, PA, and WV from this tracker's perspective — and is already documented in the Life-Health-Dental Insurance tab for the nH Predict algorithm lawsuit (Lokken v. UnitedHealth Group, and separately a class action in W.D. Kentucky over the same AI tool). Humana's T&C at humana.com/legal/terms-of-use were NOT independently fetched and read this pass. What IS known from the existing Humana row: the company is accused of using an algorithm (nH Predict, built by NaviHealth/UnitedHealth's Optum subsidiary) to systematically deny post-acute care coverage to Medicare Advantage patients. The DC and West Virginia operations are relevant because those states' attorneys general have been active on algorithmic denial issues — DC AG Brian Schwalb joined a multistate coalition investigating AI-driven health insurance denials in 2024.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 448, "_entity_id": 654, "_entity_slug": "humana-insurance-company", "_issuer": "Humana Inc.", "_issuer_slug": "humana-inc", "_ticker": "HUM", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Independence Blue Cross (IBX)", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.ibx.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.ibx.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Independence Health Group (parent) operates IBX in PA and AmeriHealth in NJ/DE — distinct brands sharing one parent's data infrastructure. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Philadelphia, PA. Parent: Independence Health Group. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: AmeriHealth Caritas North Carolina, Inc., AmeriHealth Insurance Company of New Jersey, AmeriHealth New Jersey. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Philadelphia", "HQ State": "PA", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.ibx.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Philadelphia, PA — not matched", "Parent / Ultimate Owner": "Independence Health Group", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (PA) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in PA. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or plan-level data-sharing terms independently verified for Independence Blue Cross (IBX)\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field records only parent-level context — that Independence Health Group operates IBX in PA and AmeriHealth in NJ/DE, distinct brands sharing one parent's data infrastructure — while stating 'Plan-level data-sharing provisions not independently verified.'\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity pass 2 (strict): Wrong corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the SCARY field confirms 'Terms not independently fetched this pass'; the note that non-profit IBX operates for-profit AmeriHealth subsidiaries in adjacent states is a corporate-structure fact, not a confirmed consumer-terms practice.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Independence Blue Cross (IBX)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Independence Blue Cross (IBX) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Independence Blue Cross is the flagship entity of Independence Health Group, covering southeastern Pennsylvania from Philadelphia. IBX is a non-profit but operates for-profit subsidiaries (AmeriHealth) in adjacent states. Terms not independently fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 449, "_entity_id": 655, "_entity_slug": "independence-blue-cross-ibx", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Instil Health", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.instilhealth.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.instilhealth.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Greenville, SC. Parent: Instil Health (independent). arbitration clause not yet verified. Region: Unspecified. Severity: 2. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Greenville", "HQ State": "SC", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.instilhealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Greenville, SC — not matched", "Parent / Ultimate Owner": "Instil Health (independent)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (SC) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in SC. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or plan-level data-sharing terms independently verified for Instil Health\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field is generic HIPAA-covered-entity language rather than terms specific to this company's plan documents.\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the SCARY field confirms 'Terms not fetched this pass' for this South Carolina ACA marketplace insurer founded 2019.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Instil Health  <-  Instil Health (independent)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Instil Health takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Instil Health is a for-profit ACA marketplace insurer in South Carolina (founded 2019). Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 450, "_entity_id": 656, "_entity_slug": "instil-health", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Kaiser Foundation Health Plan of the Mid-Atlantic States, Inc.", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://healthplans.kaiserpermanente.org/members", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://healthy.kaiserpermanente.org/terms-of-use", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Kaiser Permanente is an integrated delivery system — it is simultaneously the insurer, the hospital system, and the medical group, meaning data flows within Kaiser do NOT cross the organizational boundaries that normally trigger HIPAA's 'minimum necessary' standard. This integration is a feature for care coordination and a risk for data concentration. Subject of the 2024 tracking-pixel breach (13.4M members). Plan-level data-sharing provisions not verified.", "Arbitration / Class Action Waiver": "NO mandatory binding arbitration in the Mid-Atlantic EOC (unlike CA/HI). Regional difference confirmed via Kaiser's own FAQ and multiple EOC document reviews.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "Maryland nonprofit. Unlike CA/HI Kaiser plans, the Mid-Atlantic plan does NOT require mandatory arbitration — a genuine regional consumer-protection difference. Cross-ref Kaiser Permanente row in Insurance tab for the tracking-pixel breach (13.4M members).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Rockville", "HQ State": "MD", "CEO": null, "Ticker": null, "Website (Corporate)": "https://kp.kaiserpermanente.org", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. T&C text sourced via web_search returning actual document content from corporate legal pages. Cross-referenced with existing tracker rows. Fields marked 'NOT VERIFIED THIS PASS' were not independently fetched.", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Operates in DC, MD, VA; HQ: Rockville, MD", "Parent / Ultimate Owner": "Kaiser Permanente", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (MD) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in MD. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[OTHER · FL-2] Insurer, hospital and medical group in one: Kaiser data flows skip HIPAA's 'minimum necessary' trigger\nWHAT THE TERMS SAY: The row states Kaiser Permanente is simultaneously the insurer, hospital system, and medical group, so data flows within Kaiser 'do NOT cross the organizational boundaries that normally trigger HIPAA's minimum necessary standard' — described in the tracker as 'a feature for care coordination and a risk for data concentration.'\nWHY IT MATTERS: A Mid-Atlantic Kaiser member's insurance, hospital, and physician-group records can move within one corporate structure without the internal check that normally applies when data crosses from an insurer to an unrelated provider.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — The row's other headline finding — that the Mid-Atlantic plan's EOC does NOT contain Kaiser's usual mandatory binding arbitration clause (unlike California/Hawaii) — is a confirmed ABSENCE of a troubling practice, not a troubling term itself, so it is not counted as a second item; the 2024 tracking-pixel breach is explicitly attributed to the parent Kaiser row in the Insurance tab, not this entity; fees remain unverified.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration question is unusually well-resolved (confirmed absent, via Kaiser's own FAQ and multiple EOC reviews), but fees and the practical effect of the integrated data structure remain unverified.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Kaiser Foundation Health Plan of the Mid-Atlantic States, Inc.  <-  Kaiser Permanente", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Kaiser Foundation Health Plan of the Mid-Atlantic States, Inc. you gave up your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Kaiser Foundation Health Plan of the Mid-Atlantic States is a Maryland-based nonprofit covering DC, MD, and VA — and unlike Kaiser's California and Hawaii plans, the Mid-Atlantic plan's Evidence of Coverage documents (multiple EOCs reviewed via search results, 2026-08-06) do NOT contain the mandatory binding arbitration clause that Kaiser is famous for in California. Kaiser's own FAQ confirms that binding arbitration is used 'in California and Hawaii' to resolve member disputes — the Mid-Atlantic region operates under Maryland, Virginia, and DC insurance law, which does not mandate the same framework. This is a genuine regional difference that a DMV consumer comparing Kaiser across states would not necessarily discover: the same 'Kaiser Permanente' brand carries fundamentally different dispute-resolution terms depending on which state plan you're in. The Mid-Atlantic entity is composed of Kaiser Foundation Health Plan of the Mid-Atlantic States Inc. (a Maryland nonprofit) and the Mid-Atlantic Permanente Medical Group PC (a Maryland for-profit corporation). Kaiser's parent is already documented in this tracker's Insurance tab for the tracking-pixel breach affecting up to 13.4 million members nationwide.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 451, "_entity_id": 657, "_entity_slug": "kaiser-foundation-health-plan-of-the-mid-atlantic-states-inc", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Kaiser Permanente Georgia", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://healthplans.kaiserpermanente.org/members", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://healthy.kaiserpermanente.org/terms-of-use", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Kaiser Permanente is an integrated delivery system — it is simultaneously the insurer, the hospital system, and the medical group, meaning data flows within Kaiser do NOT cross the organizational boundaries that normally trigger HIPAA's 'minimum necessary' standard. This integration is a feature for care coordination and a risk for data concentration. Subject of the 2024 tracking-pixel breach (13.4M members). Plan-level data-sharing provisions not verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Atlanta, GA. Parent: Kaiser Permanente. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Kaiser Foundation Health Plan of the Mid-Atlantic States, Inc.. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Atlanta", "HQ State": "GA", "CEO": null, "Ticker": null, "Website (Corporate)": "https://kp.kaiserpermanente.org", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Atlanta, GA — not matched", "Parent / Ultimate Owner": "Kaiser Permanente", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (GA) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in GA. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or plan-level data-sharing terms independently verified for Kaiser Permanente Georgia\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field records only parent-level context — Kaiser Permanente's integrated insurer/hospital/medical-group structure and the 2024 tracking-pixel breach (13.4M members) — while stating 'Plan-level data-sharing provisions not verified.'\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity pass 2 (strict): Wrong corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the SCARY field confirms 'Terms not fetched this pass' and explicitly states Kaiser Georgia's arbitration posture 'has not been independently verified,' unlike the Mid-Atlantic Kaiser plan documented elsewhere in this tab.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Kaiser Permanente Georgia  <-  Kaiser Permanente", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Kaiser Permanente Georgia takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Kaiser Permanente Georgia operates in the Atlanta metro area. Unlike the Mid-Atlantic plan (documented elsewhere in this tab), Kaiser Georgia's arbitration posture has not been independently verified — California and Hawaii require mandatory arbitration but other regions may differ. Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 452, "_entity_id": 658, "_entity_slug": "kaiser-permanente-georgia", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "MAMSI Life and Health Insurance Company", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.uhc.com/legal/terms-of-use", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.uhc.com/legal/terms-of-use", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. UnitedHealth Group (parent) is the world's largest healthcare company by revenue ($371B, 2023). Parent of Optum (data analytics), Change Healthcare (claims processing — subject of the 2024 breach affecting 190M+ people), and NaviHealth (the nH Predict algorithm). The volume and variety of data flowing through UHG's subsidiaries is without parallel in healthcare. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out window, physical letter required to UnitedHealthcare Legal Intake, 9900 Bren Road East, Minnetonka, MN 55343. If class waiver found unenforceable, entire arbitration agreement voids — nuclear clause.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "One of four UnitedHealthcare DMV subsidiaries sharing identical T&C at uhc.com. Parent: UnitedHealth Group (see existing UnitedHealthcare row for the Change Healthcare breach finding — 190M patients, ALPHV/BlackCat ransomware, Feb 2024). The 30-day arbitration opt-out is a genuine consumer action item for any new member.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Columbia", "HQ State": "MD", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.myuhc.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "T&C text confirmed via web_search returning actual document content 2026-08-06 (multiple PDFs and HTML versions of the same terms). Arbitration clause, class action waiver, opt-out mechanism, and nuclear clause all verified against the document text. Cross-referenced with Change Healthcare breach from existing UnitedHealthcare row in this tracker.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Operates in MD, VA; HQ: Columbia, MD", "Parent / Ultimate Owner": "UnitedHealth Group, Inc.", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (MD) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in MD. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] UnitedHealthcare's terms open all-caps with mandatory arbitration, barring portal use otherwise\nWHAT THE TERMS SAY: The row states UnitedHealthcare's Terms of Use (confirmed via search results returning the actual document text, 2026-08-06) open with a 'MANDATORY ARBITRATION AGREEMENT AND CLASS ACTION WAIVER' in all-caps as the first substantive text, and that missing the opt-out window means 'YOU ARE NOT AUTHORIZED TO USE THE ONLINE SERVICES IN ANY WAY.'\nWHY IT MATTERS: A MAMSI member cannot use their own health-insurance member portal at all unless they accept binding arbitration or complete the opt-out process in time.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OPT_OUT_DEADLINE · FL-3] Opting out requires a physical letter to Minnetonka, MN within 30 days, with specific required contents\nWHAT THE TERMS SAY: The opt-out window is 30 days from first agreeing to the terms, requires a physical letter mailed to UnitedHealthcare Legal Intake, 9900 Bren Road East, Minnetonka, MN 55343, and must include the member's full name, username, and mailing address.\nWHY IT MATTERS: A member who doesn't act within 30 days via postal mail — a higher-friction channel than the online portal itself — is locked into binding arbitration.\n(evidence: Arbitration | Notes | Arbitration Opt-Out Window (Days); Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CLASS_ACTION_WAIVER · FL-3] 'Nuclear clause' voids the entire arbitration agreement rather than let a class action proceed\nWHAT THE TERMS SAY: The row states that if a court finds the class-action waiver unenforceable, the entire arbitration agreement 'will be deemed null and void' — meaning, per the tracker, UnitedHealthcare 'would rather face individual court claims than allow a class to form.'\nWHY IT MATTERS: Per the tracker, a court finding the class-action waiver unenforceable voids the entire arbitration agreement, which the tracker reads as UnitedHealthcare preferring individual court claims to allowing a class to form.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The Terms of Use text itself was confirmed via search results, with specific opt-out address, deadline, and clause language all documented.", "Exposure Score (0-100)": 36, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "MAMSI Life and Health Insurance Company  <-  UnitedHealth Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using MAMSI Life and Health Insurance Company you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "MAMSI (Mid-Atlantic Medical Services) is UnitedHealthcare's legacy managed-care subsidiary in Maryland and Virginia, operating under the UHC brand since 1998. UnitedHealthcare's Terms of Use (confirmed via search results returning the actual document text, 2026-08-06) open with a MANDATORY ARBITRATION AGREEMENT AND CLASS ACTION WAIVER in all-caps — literally the first substantive text a member sees. The opt-out window is 30 days from first agreeing to the terms, requires a physical letter mailed to Minnetonka, Minnesota, and must include your full name, username, and mailing address. If you miss the window or don't send the letter, 'YOU ARE NOT AUTHORIZED TO USE THE ONLINE SERVICES IN ANY WAY' — meaning you cannot access your own health insurance portal without accepting binding arbitration. For a health insurer, this is not a theoretical concern: UnitedHealth Group is the parent of Change Healthcare, whose February 2024 ransomware breach exposed an estimated 190 million patient records — the largest healthcare breach on record — and is now the subject of 60+ lawsuits including from CareFirst (documented elsewhere in this tab). A DMV member of MAMSI, Optimum Choice, or UnitedHealthcare of the Mid-Atlantic who lost data in that breach and missed their 30-day arbitration opt-out window has waived their right to join any class action over it. The terms also contain a 'No Class Actions' nuclear clause: if any court finds the class-action waiver unenforceable, the ENTIRE arbitration agreement 'will be deemed null and void' — meaning UnitedHealthcare would rather face individual court claims than allow a class to form.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 453, "_entity_id": 659, "_entity_slug": "mamsi-life-and-health-insurance-company", "_issuer": "UnitedHealth Group, Inc.", "_issuer_slug": "unitedhealth-group-inc", "_ticker": "UNH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "MVP Health Care", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.mvphealthcare.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.mvphealthcare.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Schenectady, NY. Parent: MVP Health Care (independent). arbitration clause not yet verified. Region: Unspecified. Severity: 2. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Schenectady", "HQ State": "NY", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.mvphealthcare.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Schenectady, NY — not matched", "Parent / Ultimate Owner": "MVP Health Care (independent)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (NY) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in NY. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or plan-level data-sharing terms independently verified for MVP Health Care\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field is generic HIPAA-covered-entity language rather than terms specific to this company's plan documents.\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the SCARY field confirms 'Terms not fetched this pass' for this Schenectady, NY non-profit.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "MVP Health Care  <-  MVP Health Care (independent)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, MVP Health Care takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "MVP Health Care is a Schenectady, NY-based non-profit serving upstate NY and Vermont. Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 454, "_entity_id": 660, "_entity_slug": "mvp-health-care", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Medical Mutual of Ohio", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.medmutual.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.medmutual.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Cleveland, OH. Parent: Medical Mutual of Ohio (independent). arbitration clause not yet verified. Region: Unspecified. Severity: 2. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cleveland", "HQ State": "OH", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.medmutual.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Cleveland, OH — not matched", "Parent / Ultimate Owner": "Medical Mutual of Ohio (independent)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (OH) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in OH. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or plan-level data-sharing terms independently verified for Medical Mutual of Ohio\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field is generic HIPAA-covered-entity language rather than terms specific to this company's plan documents.\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the SCARY field confirms 'Terms not fetched this pass' for this Cleveland, OH non-profit founded 1934.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Medical Mutual of Ohio  <-  Medical Mutual of Ohio (independent)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Medical Mutual of Ohio takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Medical Mutual is Ohio's oldest and largest non-profit health insurer (founded 1934). Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 455, "_entity_id": 661, "_entity_slug": "medical-mutual-of-ohio", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Molina Healthcare of Georgia", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.molinahealthcare.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.molinahealthcare.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Molina Healthcare (parent) primarily serves Medicaid/CHIP and marketplace populations. Privacy practices governed by HIPAA plus state Medicaid agency requirements (which may be MORE restrictive than HIPAA alone). Website terms at molinahealthcare.com are separate from the plan EOC and are NOT HIPAA-covered. Specific data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration via JAMS, individual only, class actions prohibited. NO OPT-OUT PROVISION. Hearings in Long Beach, CA. Nuclear clause: class waiver survives if arbitration voided.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Long Beach, CA. Parent: Molina Healthcare, Inc.. mandatory arbitration confirmed. Region: Unspecified. Severity: 3. Sibling entities in this tab: Molina Healthcare of Kentucky, Molina Healthcare of New York, Molina Healthcare of Ohio. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Long Beach", "HQ State": "CA", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.molinahealthcare.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Long Beach, CA — not matched", "Parent / Ultimate Owner": "Molina Healthcare, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (CA) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in CA. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Molina's JAMS arbitration clause for Molina Healthcare of Georgia has NO opt-out provision at all\nWHAT THE TERMS SAY: The row states Molina Healthcare's Terms of Use (confirmed from molinahealthcare.com/members/common/en-us/terms_privacy.aspx, 2026-08-06) impose mandatory binding arbitration via JAMS, individual only, and — unlike UnitedHealthcare's 30-day or Aetna's 60-day windows — contain NO OPT-OUT PROVISION; in-person hearings, if required, are held in Long Beach, CA regardless of where the member lives.\nWHY IT MATTERS: A Georgia Molina member who uses the website has, per the tracker, accepted binding individual arbitration with no mechanism to reject it, and would need to arbitrate individually in California if an in-person hearing is required.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Class-action waiver survives even if the arbitration clause itself is struck down\nWHAT THE TERMS SAY: The row states Molina's terms include a 'nuclear clause': if the arbitration provision is deemed invalid, both parties still waive class-action rights 'to the fullest extent allowed by law.'\nWHY IT MATTERS: Even a legal challenge that defeats the arbitration requirement would not, per the tracker's description, restore a member's ability to join a class action.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fee/billing terms are marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA/Medicaid boilerplate rather than a company-specific practice, so no third distinct item is available.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause is specifically sourced to a named terms page, but fee/billing terms remain unverified.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Molina Healthcare of Georgia  <-  Molina Healthcare, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Molina Healthcare of Georgia you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Molina Healthcare of Georgia operates in Georgia. Molina Healthcare's Terms of Use (confirmed from molinahealthcare.com/members/common/en-us/terms_privacy.aspx, 2026-08-06) contain mandatory binding arbitration via JAMS (Judicial Arbitration and Mediation Services) with a class action waiver — and unlike UnitedHealthcare (30-day opt-out) or Aetna (60-day opt-out), Molina's terms contain NO OPT-OUT PROVISION. If you use the website, you have accepted binding individual arbitration with no mechanism to reject it. In-person hearings, if required, are held in Long Beach, California — Molina's corporate headquarters — regardless of where the member lives. A GA Molina member with a coverage dispute would need to arbitrate individually in California. Molina also includes a nuclear clause: if the arbitration provision is deemed invalid, both parties still waive class action rights 'to the fullest extent allowed by law.' Molina Healthcare's parent is a Fortune 500 company with $36.4B in 2023 revenue.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 456, "_entity_id": 663, "_entity_slug": "molina-healthcare-of-georgia", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Molina Healthcare of Kentucky", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.molinahealthcare.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.molinahealthcare.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Molina Healthcare (parent) primarily serves Medicaid/CHIP and marketplace populations. Privacy practices governed by HIPAA plus state Medicaid agency requirements (which may be MORE restrictive than HIPAA alone). Website terms at molinahealthcare.com are separate from the plan EOC and are NOT HIPAA-covered. Specific data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration via JAMS, individual only, class actions prohibited. NO OPT-OUT PROVISION. Hearings in Long Beach, CA. Nuclear clause: class waiver survives if arbitration voided.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Long Beach, CA. Parent: Molina Healthcare, Inc.. mandatory arbitration confirmed. Region: Unspecified. Severity: 3. Sibling entities in this tab: Molina Healthcare of Georgia, Molina Healthcare of New York, Molina Healthcare of Ohio. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Long Beach", "HQ State": "CA", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.molinahealthcare.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Long Beach, CA — not matched", "Parent / Ultimate Owner": "Molina Healthcare, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (CA) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in CA. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Molina's JAMS arbitration clause for Molina Healthcare of Kentucky has NO opt-out provision at all\nWHAT THE TERMS SAY: The row states Molina Healthcare's Terms of Use (confirmed from molinahealthcare.com/members/common/en-us/terms_privacy.aspx, 2026-08-06) impose mandatory binding arbitration via JAMS, individual only, and — unlike UnitedHealthcare's 30-day or Aetna's 60-day windows — contain NO OPT-OUT PROVISION; in-person hearings, if required, are held in Long Beach, CA regardless of where the member lives.\nWHY IT MATTERS: A Kentucky Molina member who uses the website has, per the tracker, accepted binding individual arbitration with no mechanism to reject it, and would need to arbitrate individually in California if an in-person hearing is required.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Class-action waiver survives even if the arbitration clause itself is struck down\nWHAT THE TERMS SAY: The row states Molina's terms include a 'nuclear clause': if the arbitration provision is deemed invalid, both parties still waive class-action rights 'to the fullest extent allowed by law.'\nWHY IT MATTERS: Even a legal challenge that defeats the arbitration requirement would not, per the tracker's description, restore a member's ability to join a class action.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fee/billing terms are marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA/Medicaid boilerplate rather than a company-specific practice, so no third distinct item is available.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause is specifically sourced to a named terms page, but fee/billing terms remain unverified.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Molina Healthcare of Kentucky  <-  Molina Healthcare, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Molina Healthcare of Kentucky you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Molina Healthcare of Kentucky operates in Kentucky (direct Molina brand, distinct from Passport). Molina Healthcare's Terms of Use (confirmed from molinahealthcare.com/members/common/en-us/terms_privacy.aspx, 2026-08-06) contain mandatory binding arbitration via JAMS (Judicial Arbitration and Mediation Services) with a class action waiver — and unlike UnitedHealthcare (30-day opt-out) or Aetna (60-day opt-out), Molina's terms contain NO OPT-OUT PROVISION. If you use the website, you have accepted binding individual arbitration with no mechanism to reject it. In-person hearings, if required, are held in Long Beach, California — Molina's corporate headquarters — regardless of where the member lives. A KY Molina member with a coverage dispute would need to arbitrate individually in California. Molina also includes a nuclear clause: if the arbitration provision is deemed invalid, both parties still waive class action rights 'to the fullest extent allowed by law.' Molina Healthcare's parent is a Fortune 500 company with $36.4B in 2023 revenue.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 457, "_entity_id": 664, "_entity_slug": "molina-healthcare-of-kentucky", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Molina Healthcare of New York", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.molinahealthcare.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.molinahealthcare.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Molina Healthcare (parent) primarily serves Medicaid/CHIP and marketplace populations. Privacy practices governed by HIPAA plus state Medicaid agency requirements (which may be MORE restrictive than HIPAA alone). Website terms at molinahealthcare.com are separate from the plan EOC and are NOT HIPAA-covered. Specific data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration via JAMS, individual only, class actions prohibited. NO OPT-OUT PROVISION. Hearings in Long Beach, CA. Nuclear clause: class waiver survives if arbitration voided.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Long Beach, CA. Parent: Molina Healthcare, Inc.. mandatory arbitration confirmed. Region: Unspecified. Severity: 3. Sibling entities in this tab: Molina Healthcare of Georgia, Molina Healthcare of Kentucky, Molina Healthcare of Ohio. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Long Beach", "HQ State": "CA", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.molinahealthcare.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Long Beach, CA — not matched", "Parent / Ultimate Owner": "Molina Healthcare, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (CA) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in CA. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Molina's JAMS arbitration clause for Molina Healthcare of New York has NO opt-out provision at all\nWHAT THE TERMS SAY: The row states Molina Healthcare's Terms of Use (confirmed from molinahealthcare.com/members/common/en-us/terms_privacy.aspx, 2026-08-06) impose mandatory binding arbitration via JAMS, individual only, and — unlike UnitedHealthcare's 30-day or Aetna's 60-day windows — contain NO OPT-OUT PROVISION; in-person hearings, if required, are held in Long Beach, CA regardless of where the member lives.\nWHY IT MATTERS: A New York Molina member who uses the website has, per the tracker, accepted binding individual arbitration with no mechanism to reject it, and would need to arbitrate individually in California if an in-person hearing is required.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Class-action waiver survives even if the arbitration clause itself is struck down\nWHAT THE TERMS SAY: The row states Molina's terms include a 'nuclear clause': if the arbitration provision is deemed invalid, both parties still waive class-action rights 'to the fullest extent allowed by law.'\nWHY IT MATTERS: Even a legal challenge that defeats the arbitration requirement would not, per the tracker's description, restore a member's ability to join a class action.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fee/billing terms are marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA/Medicaid boilerplate rather than a company-specific practice, so no third distinct item is available.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause is specifically sourced to a named terms page, but fee/billing terms remain unverified.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Molina Healthcare of New York  <-  Molina Healthcare, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Molina Healthcare of New York you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Molina Healthcare of New York operates in New York. Molina Healthcare's Terms of Use (confirmed from molinahealthcare.com/members/common/en-us/terms_privacy.aspx, 2026-08-06) contain mandatory binding arbitration via JAMS (Judicial Arbitration and Mediation Services) with a class action waiver — and unlike UnitedHealthcare (30-day opt-out) or Aetna (60-day opt-out), Molina's terms contain NO OPT-OUT PROVISION. If you use the website, you have accepted binding individual arbitration with no mechanism to reject it. In-person hearings, if required, are held in Long Beach, California — Molina's corporate headquarters — regardless of where the member lives. A NY Molina member with a coverage dispute would need to arbitrate individually in California. Molina also includes a nuclear clause: if the arbitration provision is deemed invalid, both parties still waive class action rights 'to the fullest extent allowed by law.' Molina Healthcare's parent is a Fortune 500 company with $36.4B in 2023 revenue.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 458, "_entity_id": 665, "_entity_slug": "molina-healthcare-of-new-york", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Molina Healthcare of Ohio", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.molinahealthcare.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.molinahealthcare.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Molina Healthcare (parent) primarily serves Medicaid/CHIP and marketplace populations. Privacy practices governed by HIPAA plus state Medicaid agency requirements (which may be MORE restrictive than HIPAA alone). Website terms at molinahealthcare.com are separate from the plan EOC and are NOT HIPAA-covered. Specific data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration via JAMS, individual only, class actions prohibited. NO OPT-OUT PROVISION. Hearings in Long Beach, CA. Nuclear clause: class waiver survives if arbitration voided.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Long Beach, CA. Parent: Molina Healthcare, Inc.. mandatory arbitration confirmed. Region: Unspecified. Severity: 3. Sibling entities in this tab: Molina Healthcare of Georgia, Molina Healthcare of Kentucky, Molina Healthcare of New York. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Long Beach", "HQ State": "CA", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.molinahealthcare.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Long Beach, CA — not matched", "Parent / Ultimate Owner": "Molina Healthcare, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (CA) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in CA. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Molina's JAMS arbitration clause for Molina Healthcare of Ohio has NO opt-out provision at all\nWHAT THE TERMS SAY: The row states Molina Healthcare's Terms of Use (confirmed from molinahealthcare.com/members/common/en-us/terms_privacy.aspx, 2026-08-06) impose mandatory binding arbitration via JAMS, individual only, and — unlike UnitedHealthcare's 30-day or Aetna's 60-day windows — contain NO OPT-OUT PROVISION; in-person hearings, if required, are held in Long Beach, CA regardless of where the member lives.\nWHY IT MATTERS: A Ohio Molina member who uses the website has, per the tracker, accepted binding individual arbitration with no mechanism to reject it, and would need to arbitrate individually in California if an in-person hearing is required.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Class-action waiver survives even if the arbitration clause itself is struck down\nWHAT THE TERMS SAY: The row states Molina's terms include a 'nuclear clause': if the arbitration provision is deemed invalid, both parties still waive class-action rights 'to the fullest extent allowed by law.'\nWHY IT MATTERS: Even a legal challenge that defeats the arbitration requirement would not, per the tracker's description, restore a member's ability to join a class action.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fee/billing terms are marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA/Medicaid boilerplate rather than a company-specific practice, so no third distinct item is available.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause is specifically sourced to a named terms page, but fee/billing terms remain unverified.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Molina Healthcare of Ohio  <-  Molina Healthcare, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Molina Healthcare of Ohio you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Molina Healthcare of Ohio operates in Ohio. Molina Healthcare's Terms of Use (confirmed from molinahealthcare.com/members/common/en-us/terms_privacy.aspx, 2026-08-06) contain mandatory binding arbitration via JAMS (Judicial Arbitration and Mediation Services) with a class action waiver — and unlike UnitedHealthcare (30-day opt-out) or Aetna (60-day opt-out), Molina's terms contain NO OPT-OUT PROVISION. If you use the website, you have accepted binding individual arbitration with no mechanism to reject it. In-person hearings, if required, are held in Long Beach, California — Molina's corporate headquarters — regardless of where the member lives. A OH Molina member with a coverage dispute would need to arbitrate individually in California. Molina also includes a nuclear clause: if the arbitration provision is deemed invalid, both parties still waive class action rights 'to the fullest extent allowed by law.' Molina Healthcare's parent is a Fortune 500 company with $36.4B in 2023 revenue.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 459, "_entity_id": 666, "_entity_slug": "molina-healthcare-of-ohio", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Molina Healthcare of South Carolina", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.molinahealthcare.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.molinahealthcare.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Molina Healthcare (parent) primarily serves Medicaid/CHIP and marketplace populations. Privacy practices governed by HIPAA plus state Medicaid agency requirements (which may be MORE restrictive than HIPAA alone). Website terms at molinahealthcare.com are separate from the plan EOC and are NOT HIPAA-covered. Specific data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration via JAMS, individual only, class actions prohibited. NO OPT-OUT PROVISION. Hearings in Long Beach, CA. Nuclear clause: class waiver survives if arbitration voided.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Long Beach, CA. Parent: Molina Healthcare, Inc.. mandatory arbitration confirmed. Region: Unspecified. Severity: 3. Sibling entities in this tab: Molina Healthcare of Georgia, Molina Healthcare of Kentucky, Molina Healthcare of New York. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Long Beach", "HQ State": "CA", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.molinahealthcare.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Long Beach, CA — not matched", "Parent / Ultimate Owner": "Molina Healthcare, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (CA) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in CA. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Molina's JAMS arbitration clause for Molina Healthcare of South Carolina has NO opt-out provision at all\nWHAT THE TERMS SAY: The row states Molina Healthcare's Terms of Use (confirmed from molinahealthcare.com/members/common/en-us/terms_privacy.aspx, 2026-08-06) impose mandatory binding arbitration via JAMS, individual only, and — unlike UnitedHealthcare's 30-day or Aetna's 60-day windows — contain NO OPT-OUT PROVISION; in-person hearings, if required, are held in Long Beach, CA regardless of where the member lives.\nWHY IT MATTERS: A South Carolina Molina member who uses the website has, per the tracker, accepted binding individual arbitration with no mechanism to reject it, and would need to arbitrate individually in California if an in-person hearing is required.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Class-action waiver survives even if the arbitration clause itself is struck down\nWHAT THE TERMS SAY: The row states Molina's terms include a 'nuclear clause': if the arbitration provision is deemed invalid, both parties still waive class-action rights 'to the fullest extent allowed by law.'\nWHY IT MATTERS: Even a legal challenge that defeats the arbitration requirement would not, per the tracker's description, restore a member's ability to join a class action.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fee/billing terms are marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA/Medicaid boilerplate rather than a company-specific practice, so no third distinct item is available.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause is specifically sourced to a named terms page, but fee/billing terms remain unverified.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Molina Healthcare of South Carolina  <-  Molina Healthcare, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Molina Healthcare of South Carolina you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Molina Healthcare of South Carolina operates in South Carolina. Molina Healthcare's Terms of Use (confirmed from molinahealthcare.com/members/common/en-us/terms_privacy.aspx, 2026-08-06) contain mandatory binding arbitration via JAMS (Judicial Arbitration and Mediation Services) with a class action waiver — and unlike UnitedHealthcare (30-day opt-out) or Aetna (60-day opt-out), Molina's terms contain NO OPT-OUT PROVISION. If you use the website, you have accepted binding individual arbitration with no mechanism to reject it. In-person hearings, if required, are held in Long Beach, California — Molina's corporate headquarters — regardless of where the member lives. A SC Molina member with a coverage dispute would need to arbitrate individually in California. Molina also includes a nuclear clause: if the arbitration provision is deemed invalid, both parties still waive class action rights 'to the fullest extent allowed by law.' Molina Healthcare's parent is a Fortune 500 company with $36.4B in 2023 revenue.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 460, "_entity_id": 667, "_entity_slug": "molina-healthcare-of-south-carolina", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Optimum Choice, Inc.", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.uhc.com/legal/terms-of-use", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.uhc.com/legal/terms-of-use", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. UnitedHealth Group (parent) is the world's largest healthcare company by revenue ($371B, 2023). Parent of Optum (data analytics), Change Healthcare (claims processing — subject of the 2024 breach affecting 190M+ people), and NaviHealth (the nH Predict algorithm). The volume and variety of data flowing through UHG's subsidiaries is without parallel in healthcare. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out window, physical letter required to UnitedHealthcare Legal Intake, 9900 Bren Road East, Minnetonka, MN 55343. If class waiver found unenforceable, entire arbitration agreement voids — nuclear clause.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "One of four UnitedHealthcare DMV subsidiaries sharing identical T&C at uhc.com. Parent: UnitedHealth Group (see existing UnitedHealthcare row for the Change Healthcare breach finding — 190M patients, ALPHV/BlackCat ransomware, Feb 2024). The 30-day arbitration opt-out is a genuine consumer action item for any new member.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Columbia", "HQ State": "MD", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.myuhc.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "T&C text confirmed via web_search returning actual document content 2026-08-06 (multiple PDFs and HTML versions of the same terms). Arbitration clause, class action waiver, opt-out mechanism, and nuclear clause all verified against the document text. Cross-referenced with Change Healthcare breach from existing UnitedHealthcare row in this tracker.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Operates in MD, VA; HQ: Columbia, MD", "Parent / Ultimate Owner": "UnitedHealth Group, Inc.", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (MD) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in MD. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] UnitedHealthcare's terms open all-caps with mandatory arbitration, barring portal use otherwise\nWHAT THE TERMS SAY: The row states UnitedHealthcare's Terms of Use (confirmed via search results returning the actual document text, 2026-08-06) open with a 'MANDATORY ARBITRATION AGREEMENT AND CLASS ACTION WAIVER' in all-caps as the first substantive text, and that missing the opt-out window means 'YOU ARE NOT AUTHORIZED TO USE THE ONLINE SERVICES IN ANY WAY.'\nWHY IT MATTERS: An Optimum Choice member (this HMO subsidiary's Maryland/Virginia OptumHealth-affiliated network) cannot use their own member portal at all unless they accept binding arbitration or complete the opt-out process in time.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OPT_OUT_DEADLINE · FL-3] Opting out requires a physical letter to Minnetonka, MN within 30 days, with specific required contents\nWHAT THE TERMS SAY: The opt-out window is 30 days from first agreeing to the terms, requires a physical letter mailed to UnitedHealthcare Legal Intake, 9900 Bren Road East, Minnetonka, MN 55343, and must include the member's full name, username, and mailing address.\nWHY IT MATTERS: A member who doesn't act within 30 days via postal mail is locked into binding arbitration.\n(evidence: Arbitration | Notes | Arbitration Opt-Out Window (Days); Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CLASS_ACTION_WAIVER · FL-3] 'Nuclear clause' voids the entire arbitration agreement rather than let a class action proceed\nWHAT THE TERMS SAY: The row states that if a court finds the class-action waiver unenforceable, the entire arbitration agreement 'will be deemed null and void.'\nWHY IT MATTERS: Per the tracker, a court finding the class-action waiver unenforceable voids the entire arbitration agreement, which the tracker reads as UnitedHealthcare preferring individual court claims to allowing a class to form.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The Terms of Use text itself was confirmed via search results, with specific opt-out address, deadline, and clause language all documented.", "Exposure Score (0-100)": 36, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Optimum Choice, Inc.  <-  UnitedHealth Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Optimum Choice, Inc. you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Optimum Choice is UnitedHealthcare's HMO subsidiary for the Maryland/Virginia corridor, offering the OptumHealth-affiliated network. UnitedHealthcare's Terms of Use (confirmed via search results returning the actual document text, 2026-08-06) open with a MANDATORY ARBITRATION AGREEMENT AND CLASS ACTION WAIVER in all-caps — literally the first substantive text a member sees. The opt-out window is 30 days from first agreeing to the terms, requires a physical letter mailed to Minnetonka, Minnesota, and must include your full name, username, and mailing address. If you miss the window or don't send the letter, 'YOU ARE NOT AUTHORIZED TO USE THE ONLINE SERVICES IN ANY WAY' — meaning you cannot access your own health insurance portal without accepting binding arbitration. For a health insurer, this is not a theoretical concern: UnitedHealth Group is the parent of Change Healthcare, whose February 2024 ransomware breach exposed an estimated 190 million patient records — the largest healthcare breach on record — and is now the subject of 60+ lawsuits including from CareFirst (documented elsewhere in this tab). A DMV member of MAMSI, Optimum Choice, or UnitedHealthcare of the Mid-Atlantic who lost data in that breach and missed their 30-day arbitration opt-out window has waived their right to join any class action over it. The terms also contain a 'No Class Actions' nuclear clause: if any court finds the class-action waiver unenforceable, the ENTIRE arbitration agreement 'will be deemed null and void' — meaning UnitedHealthcare would rather face individual court claims than allow a class to form.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 461, "_entity_id": 668, "_entity_slug": "optimum-choice-inc", "_issuer": "UnitedHealth Group, Inc.", "_issuer_slug": "unitedhealth-group-inc", "_ticker": "UNH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Oscar Health Plan of Georgia", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.hioscar.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.hioscar.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Oscar Health (parent) is a technology-first insurer that collects substantially more digital interaction data than traditional carriers — app usage, telemedicine session metadata, step counts from connected devices. Whether this digital-behavioral data is handled under HIPAA or under Oscar's separate app/website terms has not been independently verified this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — hioscar.com/legal was not fetched.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Phoenix, AZ. Parent: Oscar Health, Inc.. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Oscar Health Plan of New York, Oscar Health Plan of North Carolina, Oscar Health Plan of Ohio. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Phoenix", "HQ State": "AZ", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.hioscar.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Phoenix, AZ — not matched", "Parent / Ultimate Owner": "Oscar Health, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (AZ) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in AZ. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Oscar's app/telemedicine model collects more behavioral data than typical carriers, HIPAA unclear\nWHAT THE TERMS SAY: The row states Oscar Health, the tech-first parent shared by all Oscar state subsidiaries, collects substantially more digital interaction data than traditional carriers — app usage, telemedicine session metadata, and step counts from connected devices — and that whether this data is handled under HIPAA or under Oscar's separate app/website terms 'has not been independently verified this pass.'\nWHY IT MATTERS: An Oscar Georgia member's app usage, telemedicine metadata, and device step-count data may fall outside HIPAA's protections if governed instead by separate website/app terms, per the tracker's own hedge.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Oscar's terms at hioscar.com/legal were not fetched this pass, and arbitration and fee/billing fields for Oscar Health Plan of Georgia are both marked 'NOT VERIFIED THIS PASS'; only the shared parent-level data-collection-scope note is available.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Terms were not independently fetched this pass; only a hedged, parent-level note about the scope of data collected is available.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Oscar Health Plan of Georgia  <-  Oscar Health, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Oscar Health Plan of Georgia takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Oscar Health (Georgia) shares hioscar.com's Terms of Use with all other Oscar state subsidiaries. Oscar's terms were NOT independently fetched and read this pass — no arbitration or data-sharing findings are recorded. What IS known: Oscar Health is a for-profit, technology-first insurer (founded 2012, IPO 2021) that positions itself as a disruptor. Oscar's model relies heavily on its app and telemedicine platform — meaning the Terms of Use that govern digital interactions are unusually central to the member relationship compared to traditional insurers. Oscar reported a net loss of $271M in 2023 despite reaching 1.5M members, raising questions about long-term plan stability for members who chose Oscar over an established carrier.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 462, "_entity_id": 670, "_entity_slug": "oscar-health-plan-of-georgia", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Oscar Health Plan of New York", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.hioscar.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.hioscar.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Oscar Health (parent) is a technology-first insurer that collects substantially more digital interaction data than traditional carriers — app usage, telemedicine session metadata, step counts from connected devices. Whether this digital-behavioral data is handled under HIPAA or under Oscar's separate app/website terms has not been independently verified this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — hioscar.com/legal was not fetched.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Phoenix, AZ. Parent: Oscar Health, Inc.. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Oscar Health Plan of Georgia, Oscar Health Plan of North Carolina, Oscar Health Plan of Ohio. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Phoenix", "HQ State": "AZ", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.hioscar.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Phoenix, AZ — not matched", "Parent / Ultimate Owner": "Oscar Health, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (AZ) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in AZ. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Oscar's app/telemedicine model collects more behavioral data than typical carriers, HIPAA unclear\nWHAT THE TERMS SAY: The row states Oscar Health, the tech-first parent shared by all Oscar state subsidiaries, collects substantially more digital interaction data than traditional carriers — app usage, telemedicine session metadata, and step counts from connected devices — and that whether this data is handled under HIPAA or under Oscar's separate app/website terms 'has not been independently verified this pass.'\nWHY IT MATTERS: An Oscar New York member's app usage, telemedicine metadata, and device step-count data may fall outside HIPAA's protections if governed instead by separate website/app terms, per the tracker's own hedge.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Oscar's terms at hioscar.com/legal were not fetched this pass, and arbitration and fee/billing fields for Oscar Health Plan of New York are both marked 'NOT VERIFIED THIS PASS'; only the shared parent-level data-collection-scope note is available.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Terms were not independently fetched this pass; only a hedged, parent-level note about the scope of data collected is available.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Oscar Health Plan of New York  <-  Oscar Health, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Oscar Health Plan of New York takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Oscar Health (New York) shares hioscar.com's Terms of Use with all other Oscar state subsidiaries. Oscar's terms were NOT independently fetched and read this pass — no arbitration or data-sharing findings are recorded. What IS known: Oscar Health is a for-profit, technology-first insurer (founded 2012, IPO 2021) that positions itself as a disruptor. Oscar's model relies heavily on its app and telemedicine platform — meaning the Terms of Use that govern digital interactions are unusually central to the member relationship compared to traditional insurers. Oscar reported a net loss of $271M in 2023 despite reaching 1.5M members, raising questions about long-term plan stability for members who chose Oscar over an established carrier.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 463, "_entity_id": 671, "_entity_slug": "oscar-health-plan-of-new-york", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Oscar Health Plan of North Carolina", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.hioscar.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.hioscar.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Oscar Health (parent) is a technology-first insurer that collects substantially more digital interaction data than traditional carriers — app usage, telemedicine session metadata, step counts from connected devices. Whether this digital-behavioral data is handled under HIPAA or under Oscar's separate app/website terms has not been independently verified this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — hioscar.com/legal was not fetched.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Phoenix, AZ. Parent: Oscar Health, Inc.. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Oscar Health Plan of Georgia, Oscar Health Plan of New York, Oscar Health Plan of Ohio. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Phoenix", "HQ State": "AZ", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.hioscar.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Phoenix, AZ — not matched", "Parent / Ultimate Owner": "Oscar Health, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (AZ) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in AZ. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Oscar's app/telemedicine model collects more behavioral data than typical carriers, HIPAA unclear\nWHAT THE TERMS SAY: The row states Oscar Health, the tech-first parent shared by all Oscar state subsidiaries, collects substantially more digital interaction data than traditional carriers — app usage, telemedicine session metadata, and step counts from connected devices — and that whether this data is handled under HIPAA or under Oscar's separate app/website terms 'has not been independently verified this pass.'\nWHY IT MATTERS: An Oscar North Carolina member's app usage, telemedicine metadata, and device step-count data may fall outside HIPAA's protections if governed instead by separate website/app terms, per the tracker's own hedge.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Oscar's terms at hioscar.com/legal were not fetched this pass, and arbitration and fee/billing fields for Oscar Health Plan of North Carolina are both marked 'NOT VERIFIED THIS PASS'; only the shared parent-level data-collection-scope note is available.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Terms were not independently fetched this pass; only a hedged, parent-level note about the scope of data collected is available.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Oscar Health Plan of North Carolina  <-  Oscar Health, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Oscar Health Plan of North Carolina takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Oscar Health (North Carolina) shares hioscar.com's Terms of Use with all other Oscar state subsidiaries. Oscar's terms were NOT independently fetched and read this pass — no arbitration or data-sharing findings are recorded. What IS known: Oscar Health is a for-profit, technology-first insurer (founded 2012, IPO 2021) that positions itself as a disruptor. Oscar's model relies heavily on its app and telemedicine platform — meaning the Terms of Use that govern digital interactions are unusually central to the member relationship compared to traditional insurers. Oscar reported a net loss of $271M in 2023 despite reaching 1.5M members, raising questions about long-term plan stability for members who chose Oscar over an established carrier.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 464, "_entity_id": 672, "_entity_slug": "oscar-health-plan-of-north-carolina", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Oscar Health Plan of Ohio", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.hioscar.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.hioscar.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Oscar Health (parent) is a technology-first insurer that collects substantially more digital interaction data than traditional carriers — app usage, telemedicine session metadata, step counts from connected devices. Whether this digital-behavioral data is handled under HIPAA or under Oscar's separate app/website terms has not been independently verified this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — hioscar.com/legal was not fetched.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Phoenix, AZ. Parent: Oscar Health, Inc.. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Oscar Health Plan of Georgia, Oscar Health Plan of New York, Oscar Health Plan of North Carolina. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Phoenix", "HQ State": "AZ", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.hioscar.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Phoenix, AZ — not matched", "Parent / Ultimate Owner": "Oscar Health, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (AZ) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in AZ. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Oscar's app/telemedicine model collects more behavioral data than typical carriers, HIPAA unclear\nWHAT THE TERMS SAY: The row states Oscar Health, the tech-first parent shared by all Oscar state subsidiaries, collects substantially more digital interaction data than traditional carriers — app usage, telemedicine session metadata, and step counts from connected devices — and that whether this data is handled under HIPAA or under Oscar's separate app/website terms 'has not been independently verified this pass.'\nWHY IT MATTERS: An Oscar Ohio member's app usage, telemedicine metadata, and device step-count data may fall outside HIPAA's protections if governed instead by separate website/app terms, per the tracker's own hedge.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Oscar's terms at hioscar.com/legal were not fetched this pass, and arbitration and fee/billing fields for Oscar Health Plan of Ohio are both marked 'NOT VERIFIED THIS PASS'; only the shared parent-level data-collection-scope note is available.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Terms were not independently fetched this pass; only a hedged, parent-level note about the scope of data collected is available.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Oscar Health Plan of Ohio  <-  Oscar Health, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Oscar Health Plan of Ohio takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Oscar Health (Ohio) shares hioscar.com's Terms of Use with all other Oscar state subsidiaries. Oscar's terms were NOT independently fetched and read this pass — no arbitration or data-sharing findings are recorded. What IS known: Oscar Health is a for-profit, technology-first insurer (founded 2012, IPO 2021) that positions itself as a disruptor. Oscar's model relies heavily on its app and telemedicine platform — meaning the Terms of Use that govern digital interactions are unusually central to the member relationship compared to traditional insurers. Oscar reported a net loss of $271M in 2023 despite reaching 1.5M members, raising questions about long-term plan stability for members who chose Oscar over an established carrier.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 465, "_entity_id": 673, "_entity_slug": "oscar-health-plan-of-ohio", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Oscar Health Plan of Tennessee", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.hioscar.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.hioscar.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Oscar Health (parent) is a technology-first insurer that collects substantially more digital interaction data than traditional carriers — app usage, telemedicine session metadata, step counts from connected devices. Whether this digital-behavioral data is handled under HIPAA or under Oscar's separate app/website terms has not been independently verified this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — hioscar.com/legal was not fetched.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Phoenix, AZ. Parent: Oscar Health, Inc.. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Oscar Health Plan of Georgia, Oscar Health Plan of New York, Oscar Health Plan of North Carolina. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Phoenix", "HQ State": "AZ", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.hioscar.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Phoenix, AZ — not matched", "Parent / Ultimate Owner": "Oscar Health, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (AZ) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in AZ. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Oscar's app/telemedicine model collects more behavioral data than typical carriers, HIPAA unclear\nWHAT THE TERMS SAY: The row states Oscar Health, the tech-first parent shared by all Oscar state subsidiaries, collects substantially more digital interaction data than traditional carriers — app usage, telemedicine session metadata, and step counts from connected devices — and that whether this data is handled under HIPAA or under Oscar's separate app/website terms 'has not been independently verified this pass.'\nWHY IT MATTERS: An Oscar Tennessee member's app usage, telemedicine metadata, and device step-count data may fall outside HIPAA's protections if governed instead by separate website/app terms, per the tracker's own hedge.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Oscar's terms at hioscar.com/legal were not fetched this pass, and arbitration and fee/billing fields for Oscar Health Plan of Tennessee are both marked 'NOT VERIFIED THIS PASS'; only the shared parent-level data-collection-scope note is available.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Terms were not independently fetched this pass; only a hedged, parent-level note about the scope of data collected is available.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Oscar Health Plan of Tennessee  <-  Oscar Health, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Oscar Health Plan of Tennessee takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Oscar Health (Tennessee) shares hioscar.com's Terms of Use with all other Oscar state subsidiaries. Oscar's terms were NOT independently fetched and read this pass — no arbitration or data-sharing findings are recorded. What IS known: Oscar Health is a for-profit, technology-first insurer (founded 2012, IPO 2021) that positions itself as a disruptor. Oscar's model relies heavily on its app and telemedicine platform — meaning the Terms of Use that govern digital interactions are unusually central to the member relationship compared to traditional insurers. Oscar reported a net loss of $271M in 2023 despite reaching 1.5M members, raising questions about long-term plan stability for members who chose Oscar over an established carrier.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 466, "_entity_id": 674, "_entity_slug": "oscar-health-plan-of-tennessee", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Oscar Insurance Corporation of New Jersey", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.hioscar.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.hioscar.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Oscar Health (parent) is a technology-first insurer that collects substantially more digital interaction data than traditional carriers — app usage, telemedicine session metadata, step counts from connected devices. Whether this digital-behavioral data is handled under HIPAA or under Oscar's separate app/website terms has not been independently verified this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — hioscar.com/legal was not fetched.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Phoenix, AZ. Parent: Oscar Health, Inc.. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Sibling entities in this tab: Oscar Health Plan of Georgia, Oscar Health Plan of New York, Oscar Health Plan of North Carolina. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Phoenix", "HQ State": "AZ", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.hioscar.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Phoenix, AZ — not matched", "Parent / Ultimate Owner": "Oscar Health, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (AZ) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in AZ. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Oscar's app/telemedicine model collects more behavioral data than typical carriers, HIPAA unclear\nWHAT THE TERMS SAY: The row states Oscar Health, the tech-first parent shared by all Oscar state subsidiaries, collects substantially more digital interaction data than traditional carriers — app usage, telemedicine session metadata, and step counts from connected devices — and that whether this data is handled under HIPAA or under Oscar's separate app/website terms 'has not been independently verified this pass.'\nWHY IT MATTERS: An Oscar New Jersey member's app usage, telemedicine metadata, and device step-count data may fall outside HIPAA's protections if governed instead by separate website/app terms, per the tracker's own hedge.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Oscar's terms at hioscar.com/legal were not fetched this pass, and arbitration and fee/billing fields for Oscar Insurance Corporation of New Jersey are both marked 'NOT VERIFIED THIS PASS'; only the shared parent-level data-collection-scope note is available.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Terms were not independently fetched this pass; only a hedged, parent-level note about the scope of data collected is available.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Oscar Insurance Corporation of New Jersey  <-  Oscar Health, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Oscar Insurance Corporation of New Jersey takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Oscar Health (New Jersey) shares hioscar.com's Terms of Use with all other Oscar state subsidiaries. Oscar's terms were NOT independently fetched and read this pass — no arbitration or data-sharing findings are recorded. What IS known: Oscar Health is a for-profit, technology-first insurer (founded 2012, IPO 2021) that positions itself as a disruptor. Oscar's model relies heavily on its app and telemedicine platform — meaning the Terms of Use that govern digital interactions are unusually central to the member relationship compared to traditional insurers. Oscar reported a net loss of $271M in 2023 despite reaching 1.5M members, raising questions about long-term plan stability for members who chose Oscar over an established carrier.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 467, "_entity_id": 675, "_entity_slug": "oscar-insurance-corporation-of-new-jersey", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Oxford Health Plans (NJ), Inc.", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.oxfordhealth.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.oxfordhealth.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. UnitedHealth Group (parent) is the world's largest healthcare company by revenue ($371B, 2023). Parent of Optum (data analytics), Change Healthcare (claims processing — subject of the 2024 breach affecting 190M+ people), and NaviHealth (the nH Predict algorithm). The volume and variety of data flowing through UHG's subsidiaries is without parallel in healthcare. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Hooksett, NH. Parent: UnitedHealth Group, Inc.. arbitration clause not yet verified. Region: Unspecified. Severity: 3. Sibling entities in this tab: MAMSI Life and Health Insurance Company, Optimum Choice, Inc., UnitedHealthcare Insurance Company. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Hooksett", "HQ State": "NH", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.oxfordhealth.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Hooksett, NH — not matched", "Parent / Ultimate Owner": "UnitedHealth Group, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (NH) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in NH. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] SCARY note claims UHC-style mandatory arbitration, but tracker's own field marks it unconfirmed\nWHAT THE TERMS SAY: The SCARY field asserts Oxford Health Plans NJ has 'the same T&C with mandatory arbitration, 30-day opt-out, and class action nuclear clause' as the other UnitedHealthcare rows, but the Arbitration/Class Action Waiver field itself is marked 'NOT VERIFIED THIS PASS — do not cite.'\nWHY IT MATTERS: If accurate, an Oxford NJ member would face the same 30-day arbitration opt-out as the other UnitedHealthcare rows — but the tracker has not independently confirmed this for Oxford's own terms this pass, so it should be treated as an unconfirmed inference from the shared UnitedHealth Group parent, not a verified fact.\n(evidence: SCARY | Arbitration; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the (unconfirmed) arbitration-mirroring note is available; fee/billing terms are unverified and the data-sharing field is generic UnitedHealth Group parent boilerplate rather than an Oxford-specific practice.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The SCARY narrative and the row's own Arbitration field contradict each other — one asserts mandatory arbitration, the other says it wasn't verified this pass.", "Exposure Score (0-100)": 8, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Oxford Health Plans (NJ), Inc.  <-  UnitedHealth Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Oxford Health Plans (NJ), Inc. takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Oxford Health Plans NJ is a UnitedHealth Group subsidiary offering employer-sponsored plans in New Jersey. Same parent as the UnitedHealthcare rows — same T&C with mandatory arbitration, 30-day opt-out, and class action nuclear clause. Oxford members may not realize they are under UnitedHealth Group's umbrella.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 468, "_entity_id": 676, "_entity_slug": "oxford-health-plans-nj-inc", "_issuer": "UnitedHealth Group, Inc.", "_issuer_slug": "unitedhealth-group-inc", "_ticker": "UNH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Paramount Health Care", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.paramounthealthcare.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.paramounthealthcare.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Toledo, OH. Parent: ProMedica. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Toledo", "HQ State": "OH", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.paramounthealthcare.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Toledo, OH — not matched", "Parent / Ultimate Owner": "ProMedica", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (OH) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in OH. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] No arbitration, fee, or plan-level data-sharing terms independently verified for Paramount Health Care\nWHAT THE TERMS SAY: The tracker marks the Arbitration/Class Action Waiver and Fees/Billing fields 'NOT VERIFIED THIS PASS — do not cite,' and the Data Sharing field is generic HIPAA-covered-entity language rather than terms specific to this company's plan documents.\nWHY IT MATTERS: A member cannot currently learn from this tracker whether disputes are forced into arbitration, whether a class-action waiver applies, or what fees attach to the plan, because none of that was fetched or confirmed this pass.\n(evidence: Arbitration | Fees | Data Sharing | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee/billing fields are both marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA-covered-entity boilerplate rather than a company-specific practice; the SCARY field confirms 'Terms not fetched this pass' for this Toledo, OH non-profit HMO owned by ProMedica.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states plan terms were not independently fetched or read this pass; only generic industry-wide HIPAA boilerplate is present.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Paramount Health Care  <-  ProMedica", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Paramount Health Care takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Paramount Health Care is a non-profit HMO owned by ProMedica health system in Toledo, OH. Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 469, "_entity_id": 678, "_entity_slug": "paramount-health-care", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Passport Health Plan by Molina Healthcare", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.passporthealthplan.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.passporthealthplan.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Molina Healthcare (parent) primarily serves Medicaid/CHIP and marketplace populations. Privacy practices governed by HIPAA plus state Medicaid agency requirements (which may be MORE restrictive than HIPAA alone). Website terms at molinahealthcare.com are separate from the plan EOC and are NOT HIPAA-covered. Specific data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration via JAMS, individual only, class actions prohibited. NO OPT-OUT PROVISION. Hearings in Long Beach, CA. Nuclear clause: class waiver survives if arbitration voided.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Louisville, KY. Parent: Molina Healthcare, Inc.. mandatory arbitration confirmed. Region: Unspecified. Severity: 3. Sibling entities in this tab: Molina Healthcare of Georgia, Molina Healthcare of Kentucky, Molina Healthcare of New York. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Louisville", "HQ State": "KY", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.passporthealthplan.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Louisville, KY — not matched", "Parent / Ultimate Owner": "Molina Healthcare, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (KY) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in KY. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Molina's JAMS arbitration clause for the legacy Passport brand has NO opt-out provision at all\nWHAT THE TERMS SAY: The row states Molina Healthcare's Terms of Use (confirmed from molinahealthcare.com/members/common/en-us/terms_privacy.aspx, 2026-08-06) impose mandatory binding arbitration via JAMS, individual only, and — unlike UnitedHealthcare's 30-day or Aetna's 60-day windows — contain NO OPT-OUT PROVISION; in-person hearings, if required, are held in Long Beach, CA regardless of where the member lives.\nWHY IT MATTERS: A Kentucky Passport member (legacy brand acquired by Molina in 2020) who uses the website has, per the tracker, accepted binding individual arbitration with no mechanism to reject it, and would need to arbitrate individually in California if an in-person hearing is required.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Class-action waiver survives even if the arbitration clause itself is struck down\nWHAT THE TERMS SAY: The row states Molina's terms include a 'nuclear clause': if the arbitration provision is deemed invalid, both parties still waive class-action rights 'to the fullest extent allowed by law.'\nWHY IT MATTERS: Even a legal challenge that defeats the arbitration requirement would not, per the tracker's description, restore a member's ability to join a class action.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fee/billing terms are marked 'NOT VERIFIED THIS PASS' and the data-sharing field is generic HIPAA/Medicaid boilerplate rather than a company-specific practice, so no third distinct item is available.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause is specifically sourced to a named terms page, but fee/billing terms remain unverified.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Passport Health Plan by Molina Healthcare  <-  Molina Healthcare, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Passport Health Plan by Molina Healthcare you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Passport Health Plan by Molina Healthcare operates in Kentucky (legacy Passport brand, acquired by Molina 2020). Molina Healthcare's Terms of Use (confirmed from molinahealthcare.com/members/common/en-us/terms_privacy.aspx, 2026-08-06) contain mandatory binding arbitration via JAMS (Judicial Arbitration and Mediation Services) with a class action waiver — and unlike UnitedHealthcare (30-day opt-out) or Aetna (60-day opt-out), Molina's terms contain NO OPT-OUT PROVISION. If you use the website, you have accepted binding individual arbitration with no mechanism to reject it. In-person hearings, if required, are held in Long Beach, California — Molina's corporate headquarters — regardless of where the member lives. A KY Molina member with a coverage dispute would need to arbitrate individually in California. Molina also includes a nuclear clause: if the arbitration provision is deemed invalid, both parties still waive class action rights 'to the fullest extent allowed by law.' Molina Healthcare's parent is a Fortune 500 company with $36.4B in 2023 revenue.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 470, "_entity_id": 679, "_entity_slug": "passport-health-plan-by-molina-healthcare", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "SummaCare", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.summacare.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.summacare.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Akron, OH. Parent: Summa Health. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Akron", "HQ State": "OH", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.summacare.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Akron, OH — not matched", "Parent / Ultimate Owner": "Summa Health", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (OH) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in OH. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Data sharing, arbitration, and fees fields are all unverified or generic HIPAA-industry context this pass; the SCARY field states SummaCare's terms were not fetched, leaving no company-specific troubling item to report.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Terms were not fetched this pass and arbitration/fees are both explicitly marked not verified.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "SummaCare  <-  Summa Health", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, SummaCare takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "SummaCare is a non-profit HMO owned by Summa Health System in Akron, OH. Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 471, "_entity_id": 681, "_entity_slug": "summacare", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Trustmark Insurance Company", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.trustmark.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.trustmark.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Lake Forest, IL. Parent: Trustmark. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Lake Forest", "HQ State": "IL", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.trustmark.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Lake Forest, IL — not matched", "Parent / Ultimate Owner": "Trustmark", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (IL) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in IL. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Data sharing, arbitration, and fees fields are all unverified or generic HIPAA-industry context this pass; the SCARY field states Trustmark's terms were not fetched, leaving no company-specific troubling item to report.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Terms were not fetched this pass and arbitration/fees are both explicitly marked not verified.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Trustmark Insurance Company  <-  Trustmark", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Trustmark Insurance Company takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Trustmark is a for-profit insurer based in Lake Forest, IL, offering supplemental and small-group plans in Delaware. Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 472, "_entity_id": 683, "_entity_slug": "trustmark-insurance-company", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "UPMC Health Plan", "Category": "Health Insurance (Non-profit)", "Terms & Conditions URL": "https://www.upmchealthplan.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.upmchealthplan.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. As a health insurer, data handling is governed by HIPAA/HITECH at the federal level plus state insurance commissioner oversight in each operating state. Website/app terms are typically SEPARATE from the plan's Evidence of Coverage and may NOT be subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Pittsburgh, PA. Parent: UPMC. arbitration clause not yet verified. Region: Unspecified. Severity: 2. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Pittsburgh", "HQ State": "PA", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.upmchealthplan.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Pittsburgh, PA — not matched", "Parent / Ultimate Owner": "UPMC", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (PA) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in PA. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Data sharing, arbitration, and fees fields are all unverified or generic HIPAA-industry context this pass; the SCARY field states UPMC Health Plan's terms were not fetched, leaving no company-specific troubling item to report.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Terms were not fetched this pass and arbitration/fees are both explicitly marked not verified.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "UPMC Health Plan  <-  UPMC", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, UPMC Health Plan takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "UPMC Health Plan is a non-profit subsidiary of the University of Pittsburgh Medical Center, one of the largest academic medical centers in the US. Terms not fetched this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 473, "_entity_id": 685, "_entity_slug": "upmc-health-plan", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "UnitedHealthcare Insurance Company", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.uhc.com/legal/terms-of-use", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.uhc.com/legal/terms-of-use", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. UnitedHealth Group (parent) is the world's largest healthcare company by revenue ($371B, 2023). Parent of Optum (data analytics), Change Healthcare (claims processing — subject of the 2024 breach affecting 190M+ people), and NaviHealth (the nH Predict algorithm). The volume and variety of data flowing through UHG's subsidiaries is without parallel in healthcare. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out window, physical letter required to UnitedHealthcare Legal Intake, 9900 Bren Road East, Minnetonka, MN 55343. If class waiver found unenforceable, entire arbitration agreement voids — nuclear clause.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "One of four UnitedHealthcare DMV subsidiaries sharing identical T&C at uhc.com. Parent: UnitedHealth Group (see existing UnitedHealthcare row for the Change Healthcare breach finding — 190M patients, ALPHV/BlackCat ransomware, Feb 2024). The 30-day arbitration opt-out is a genuine consumer action item for any new member.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Columbia", "HQ State": "MD", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.uhc.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "T&C text confirmed via web_search returning actual document content 2026-08-06 (multiple PDFs and HTML versions of the same terms). Arbitration clause, class action waiver, opt-out mechanism, and nuclear clause all verified against the document text. Cross-referenced with Change Healthcare breach from existing UnitedHealthcare row in this tracker.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Operates in DC, MD, VA, PA, WV, NC; HQ: Columbia, MD", "Parent / Ultimate Owner": "UnitedHealth Group, Inc.", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (MD) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in MD. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] UnitedHealthcare requires accepting mandatory arbitration just to use your own insurance portal\nWHAT THE TERMS SAY: The Terms of Use open with an all-caps mandatory arbitration and class-action waiver clause, and the tracker states that missing the opt-out means a member is 'not authorized to use the online services in any way.'\nWHY IT MATTERS: A member who doesn't send the opt-out letter in time loses both the right to sue in court and the ability to log into their insurance portal at all.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] A 'nuclear clause' voids the whole arbitration deal rather than allow a class action to proceed\nWHAT THE TERMS SAY: If a court finds the class-action waiver unenforceable, the tracker states the entire arbitration agreement 'will be deemed null and void' rather than continuing as a class arbitration.\nWHY IT MATTERS: The tracker frames this as UnitedHealthcare preferring to fight individual claims in court rather than let a class form, even under arbitration.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OPT_OUT_DEADLINE · FL-3] Opting out of arbitration requires a physical letter mailed to Minnetonka within 30 days\nWHAT THE TERMS SAY: The opt-out window is 30 days from first agreeing to the terms and requires a physical letter to UnitedHealthcare Legal Intake in Minnetonka, MN, including full name, username, and mailing address.\nWHY IT MATTERS: Members who don't know about or miss this narrow, mail-only window are locked into arbitration with no further recourse.\n(evidence: Arbitration / Class Action Waiver | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are confirmed by direct document text, but data-sharing and fee practices are explicitly marked not verified this pass.", "Exposure Score (0-100)": 36, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "UnitedHealthcare Insurance Company  <-  UnitedHealth Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using UnitedHealthcare Insurance Company you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "UnitedHealthcare Insurance Company is the primary national carrier subsidiary, operating across DC/MD/VA plus PA, WV, and NC in this region — the broadest geographic footprint of the four UHC DMV entities. UnitedHealthcare's Terms of Use (confirmed via search results returning the actual document text, 2026-08-06) open with a MANDATORY ARBITRATION AGREEMENT AND CLASS ACTION WAIVER in all-caps — literally the first substantive text a member sees. The opt-out window is 30 days from first agreeing to the terms, requires a physical letter mailed to Minnetonka, Minnesota, and must include your full name, username, and mailing address. If you miss the window or don't send the letter, 'YOU ARE NOT AUTHORIZED TO USE THE ONLINE SERVICES IN ANY WAY' — meaning you cannot access your own health insurance portal without accepting binding arbitration. For a health insurer, this is not a theoretical concern: UnitedHealth Group is the parent of Change Healthcare, whose February 2024 ransomware breach exposed an estimated 190 million patient records — the largest healthcare breach on record — and is now the subject of 60+ lawsuits including from CareFirst (documented elsewhere in this tab). A DMV member of MAMSI, Optimum Choice, or UnitedHealthcare of the Mid-Atlantic who lost data in that breach and missed their 30-day arbitration opt-out window has waived their right to join any class action over it. The terms also contain a 'No Class Actions' nuclear clause: if any court finds the class-action waiver unenforceable, the ENTIRE arbitration agreement 'will be deemed null and void' — meaning UnitedHealthcare would rather face individual court claims than allow a class to form.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 474, "_entity_id": 686, "_entity_slug": "unitedhealthcare-insurance-company", "_issuer": "UnitedHealth Group, Inc.", "_issuer_slug": "unitedhealth-group-inc", "_ticker": "UNH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "UnitedHealthcare Insurance Company of the River Valley", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.uhc.com/legal/terms-of-use", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.uhc.com/legal/terms-of-use", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. UnitedHealth Group (parent) is the world's largest healthcare company by revenue ($371B, 2023). Parent of Optum (data analytics), Change Healthcare (claims processing — subject of the 2024 breach affecting 190M+ people), and NaviHealth (the nH Predict algorithm). The volume and variety of data flowing through UHG's subsidiaries is without parallel in healthcare. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — do not cite.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Moline, IL. Parent: UnitedHealth Group, Inc.. arbitration clause not yet verified. Region: Unspecified. Severity: 3. Sibling entities in this tab: MAMSI Life and Health Insurance Company, Optimum Choice, Inc., Oxford Health Plans (NJ), Inc.. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Moline", "HQ State": "IL", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.uhc.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent relationships verified. Fields marked 'not fetched this pass' require independent T&C review.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Moline, IL — not matched", "Parent / Ultimate Owner": "UnitedHealth Group, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (IL) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in IL. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Likely carries UHC's mandatory-arbitration terms, though this entity's field is marked 'not verified'\nWHAT THE TERMS SAY: The SCARY note says River Valley has 'same parent-level T&C as the four DMV UHC subsidiaries — mandatory arbitration, 30-day physical-letter opt-out, class action nuclear clause,' while the Arbitration field itself reads 'NOT VERIFIED THIS PASS — do not cite.'\nWHY IT MATTERS: If the shared-template assumption holds, a Tennessee member would face the same narrow, mail-only 30-day opt-out documented for sibling UHC entities, but the tracker did not independently confirm it for this specific entity.\n(evidence: Arbitration / Class Action Waiver | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item found, and it is hedged: the arbitration field is explicitly marked not verified and 'do not cite' even though the SCARY note asserts the same parent-level terms as sibling UHC entities; Fees/Billing was not verified at all.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration field says not verified/do not cite despite a narrative claim of shared terms, and fees are unconfirmed.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "UnitedHealthcare Insurance Company of the River Valley  <-  UnitedHealth Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using UnitedHealthcare Insurance Company of the River Valley you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "UHC River Valley is a UnitedHealth Group subsidiary operating in Tennessee. Same parent-level T&C as the four DMV UHC subsidiaries — mandatory arbitration, 30-day physical-letter opt-out, class action nuclear clause.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 475, "_entity_id": 687, "_entity_slug": "unitedhealthcare-insurance-company-of-the-river-valley", "_issuer": "UnitedHealth Group, Inc.", "_issuer_slug": "unitedhealth-group-inc", "_ticker": "UNH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "UnitedHealthcare of the Mid-Atlantic, Inc.", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.uhc.com/legal/terms-of-use", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.uhc.com/legal/terms-of-use", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. UnitedHealth Group (parent) is the world's largest healthcare company by revenue ($371B, 2023). Parent of Optum (data analytics), Change Healthcare (claims processing — subject of the 2024 breach affecting 190M+ people), and NaviHealth (the nH Predict algorithm). The volume and variety of data flowing through UHG's subsidiaries is without parallel in healthcare. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out window, physical letter required to UnitedHealthcare Legal Intake, 9900 Bren Road East, Minnetonka, MN 55343. If class waiver found unenforceable, entire arbitration agreement voids — nuclear clause.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "One of four UnitedHealthcare DMV subsidiaries sharing identical T&C at uhc.com. Parent: UnitedHealth Group (see existing UnitedHealthcare row for the Change Healthcare breach finding — 190M patients, ALPHV/BlackCat ransomware, Feb 2024). The 30-day arbitration opt-out is a genuine consumer action item for any new member.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Columbia", "HQ State": "MD", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.uhc.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "T&C text confirmed via web_search returning actual document content 2026-08-06 (multiple PDFs and HTML versions of the same terms). Arbitration clause, class action waiver, opt-out mechanism, and nuclear clause all verified against the document text. Cross-referenced with Change Healthcare breach from existing UnitedHealthcare row in this tracker.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Operates in DC, MD, VA; HQ: Columbia, MD", "Parent / Ultimate Owner": "UnitedHealth Group, Inc.", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (MD) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in MD. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] UnitedHealthcare of the Mid-Atlantic requires accepting arbitration just to use your insurance portal\nWHAT THE TERMS SAY: The Terms of Use open with an all-caps mandatory arbitration and class-action waiver clause, and the tracker states that missing the opt-out means a member is 'not authorized to use the online services in any way.'\nWHY IT MATTERS: A DC/MD/VA member who doesn't send the opt-out letter in time loses both the right to sue in court and the ability to log into their insurance portal at all.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] A 'nuclear clause' voids the whole arbitration deal rather than allow a class action to proceed\nWHAT THE TERMS SAY: If a court finds the class-action waiver unenforceable, the tracker states the entire arbitration agreement 'will be deemed null and void' rather than continuing as a class arbitration.\nWHY IT MATTERS: The tracker frames this as the company preferring to fight individual claims in court rather than let a class form, even under arbitration.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OPT_OUT_DEADLINE · FL-3] Opting out of arbitration requires a physical letter mailed to Minnetonka within 30 days\nWHAT THE TERMS SAY: The opt-out window is 30 days from first agreeing to the terms and requires a physical letter to UnitedHealthcare Legal Intake in Minnetonka, MN, including full name, username, and mailing address.\nWHY IT MATTERS: Members who don't know about or miss this narrow, mail-only window are locked into arbitration with no further recourse.\n(evidence: Arbitration / Class Action Waiver | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are confirmed by direct document text, but data-sharing and fee practices are explicitly marked not verified this pass.", "Exposure Score (0-100)": 36, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "UnitedHealthcare of the Mid-Atlantic, Inc.  <-  UnitedHealth Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using UnitedHealthcare of the Mid-Atlantic, Inc. you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "UnitedHealthcare of the Mid-Atlantic is the DC/MD/VA-specific subsidiary, a narrower regional entity than the national UHC Insurance Company. UnitedHealthcare's Terms of Use (confirmed via search results returning the actual document text, 2026-08-06) open with a MANDATORY ARBITRATION AGREEMENT AND CLASS ACTION WAIVER in all-caps — literally the first substantive text a member sees. The opt-out window is 30 days from first agreeing to the terms, requires a physical letter mailed to Minnetonka, Minnesota, and must include your full name, username, and mailing address. If you miss the window or don't send the letter, 'YOU ARE NOT AUTHORIZED TO USE THE ONLINE SERVICES IN ANY WAY' — meaning you cannot access your own health insurance portal without accepting binding arbitration. For a health insurer, this is not a theoretical concern: UnitedHealth Group is the parent of Change Healthcare, whose February 2024 ransomware breach exposed an estimated 190 million patient records — the largest healthcare breach on record — and is now the subject of 60+ lawsuits including from CareFirst (documented elsewhere in this tab). A DMV member of MAMSI, Optimum Choice, or UnitedHealthcare of the Mid-Atlantic who lost data in that breach and missed their 30-day arbitration opt-out window has waived their right to join any class action over it. The terms also contain a 'No Class Actions' nuclear clause: if any court finds the class-action waiver unenforceable, the ENTIRE arbitration agreement 'will be deemed null and void' — meaning UnitedHealthcare would rather face individual court claims than allow a class to form.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 476, "_entity_id": 688, "_entity_slug": "unitedhealthcare-of-the-mid-atlantic-inc", "_issuer": "UnitedHealth Group, Inc.", "_issuer_slug": "unitedhealth-group-inc", "_ticker": "UNH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "WellCare of Kentucky", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.wellcare.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.wellcare.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Centene Corporation (parent) is a Fortune 25 company; data handling governed by HIPAA/HITECH at federal level plus state insurance commissioner oversight. Centene's marketplace enrollment portal (ambetterhealth.com) uses a separate set of web terms from the plan's Evidence of Coverage — the website terms are NOT subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "MANDATORY arbitration + class/jury waivers on enrollment portal (CA law, Sacramento jurisdiction). Main site T&C has NO arbitration clause — split terms create ambiguity. No opt-out mechanism found.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Tampa, FL. Parent: Centene Corporation. mandatory arbitration confirmed. Region: Unspecified. Severity: 3. Sibling entities in this tab: Ambetter (Celtic) of Tennessee, Ambetter Health of Delaware, Ambetter from Absolute Total Care. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Tampa", "HQ State": "FL", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.wellcare.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Tampa, FL — not matched", "Parent / Ultimate Owner": "Centene Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (FL) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in FL. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] WellCare's Ambetter enrollment portal forces KY members into arbitration under California law\nWHAT THE TERMS SAY: The enrollment portal's Terms of Service impose mandatory arbitration with a class-action waiver and a jury-trial waiver, governed by California law with exclusive jurisdiction in Sacramento County, regardless of the member's home state.\nWHY IT MATTERS: A Kentucky member who signs up through the enrollment portal must resolve any dispute under another state's law, thousands of miles away.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-3] WellCare's enrollment-portal terms and its main-site terms conflict on whether arbitration applies\nWHAT THE TERMS SAY: The enrollment portal's ToS include mandatory arbitration, but the main site's separate Terms & Conditions contain only a blanket liability disclaimer with no arbitration clause, leaving it ambiguous which terms govern a given interaction.\nWHY IT MATTERS: A member may not know which of two conflicting agreements applies to their dispute, undermining their ability to know their own rights.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OPT_OUT_DEADLINE · FL-3] No opt-out mechanism exists for the mandatory arbitration clause\nWHAT THE TERMS SAY: The tracker records 'No opt-out mechanism found' for WellCare's enrollment-portal arbitration agreement.\nWHY IT MATTERS: Members have no documented way to preserve their right to sue in court once they enroll through the portal.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Enrollment-portal arbitration is confirmed but conflicts with the main site's separate terms, and fees are unverified.", "Exposure Score (0-100)": 43, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 30, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 30/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "WellCare of Kentucky  <-  Centene Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to a jury.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using WellCare of Kentucky you gave up your right to sue, your right to join a class action, your right to a jury, and your right to meaningful compensation. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "WellCare of Kentucky operates in Kentucky (WellCare brand, distinct entity from Ambetter WellCare KY). Ambetter Health is Centene Corporation's ACA marketplace brand — and Centene's Terms & Conditions (confirmed from two separate pages on ambetterhealth.com, 2026-08-06) reveal a split personality. The enrollment portal's Terms of Service contain mandatory arbitration with a class action waiver AND a jury trial waiver, governed by CALIFORNIA law with exclusive jurisdiction in Sacramento County — regardless of which state the member actually lives in. A KY member who signs up through Ambetter's enrollment portal is agreeing to resolve disputes 3,000 miles away under another state's law. The main site's Terms & Conditions (ambetterhealth.com/terms-conditions.html), by contrast, contain a blanket liability disclaimer but NO arbitration clause — creating ambiguity about which set of terms governs which interactions. Centene itself is a Fortune 25 company with $154B in 2023 revenue and 28.6 million managed-care members across all brands.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 477, "_entity_id": 689, "_entity_slug": "wellcare-of-kentucky", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "WellCare of New York", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.wellcare.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.wellcare.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Centene Corporation (parent) is a Fortune 25 company; data handling governed by HIPAA/HITECH at federal level plus state insurance commissioner oversight. Centene's marketplace enrollment portal (ambetterhealth.com) uses a separate set of web terms from the plan's Evidence of Coverage — the website terms are NOT subject to HIPAA. Specific data-sharing provisions in the plan EOC were not independently read this pass.", "Arbitration / Class Action Waiver": "MANDATORY arbitration + class/jury waivers on enrollment portal (CA law, Sacramento jurisdiction). Main site T&C has NO arbitration clause — split terms create ambiguity. No opt-out mechanism found.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "HQ: Tampa, FL. Parent: Centene Corporation. mandatory arbitration confirmed. Region: Unspecified. Severity: 3. Sibling entities in this tab: Ambetter (Celtic) of Tennessee, Ambetter Health of Delaware, Ambetter from Absolute Total Care. Source: DeepSeek-generated health insurer dataset, imported 2026-08-06. T&C URLs from source CSV, not independently fetched.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Tampa", "HQ State": "FL", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.wellcare.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. Parent company T&C sourced via web_search. Subsidiary-specific terms not separately verified — finding applies to parent-level T&C.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Tampa, FL — not matched", "Parent / Ultimate Owner": "Centene Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (FL) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in FL. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] WellCare's Ambetter enrollment portal forces NY members into arbitration under California law\nWHAT THE TERMS SAY: The enrollment portal's Terms of Service impose mandatory arbitration with a class-action waiver and a jury-trial waiver, governed by California law with exclusive jurisdiction in Sacramento County, regardless of the member's home state.\nWHY IT MATTERS: A New York member who signs up through the enrollment portal must resolve any dispute under another state's law, thousands of miles away.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-3] WellCare's enrollment-portal terms and its main-site terms conflict on whether arbitration applies\nWHAT THE TERMS SAY: The enrollment portal's ToS include mandatory arbitration, but the main site's separate Terms & Conditions contain only a blanket liability disclaimer with no arbitration clause, leaving it ambiguous which terms govern a given interaction.\nWHY IT MATTERS: A member may not know which of two conflicting agreements applies to their dispute, undermining their ability to know their own rights.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OPT_OUT_DEADLINE · FL-3] No opt-out mechanism exists for the mandatory arbitration clause\nWHAT THE TERMS SAY: The tracker records 'No opt-out mechanism found' for WellCare's enrollment-portal arbitration agreement.\nWHY IT MATTERS: Members have no documented way to preserve their right to sue in court once they enroll through the portal.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Enrollment-portal arbitration is confirmed but conflicts with the main site's separate terms, and fees are unverified.", "Exposure Score (0-100)": 43, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 30, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 30/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "WellCare of New York  <-  Centene Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to a jury.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using WellCare of New York you gave up your right to sue, your right to join a class action, your right to a jury, and your right to meaningful compensation. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "WellCare of New York operates in New York (WellCare brand). Ambetter Health is Centene Corporation's ACA marketplace brand — and Centene's Terms & Conditions (confirmed from two separate pages on ambetterhealth.com, 2026-08-06) reveal a split personality. The enrollment portal's Terms of Service contain mandatory arbitration with a class action waiver AND a jury trial waiver, governed by CALIFORNIA law with exclusive jurisdiction in Sacramento County — regardless of which state the member actually lives in. A NY member who signs up through Ambetter's enrollment portal is agreeing to resolve disputes 3,000 miles away under another state's law. The main site's Terms & Conditions (ambetterhealth.com/terms-conditions.html), by contrast, contain a blanket liability disclaimer but NO arbitration clause — creating ambiguity about which set of terms governs which interactions. Centene itself is a Fortune 25 company with $154B in 2023 revenue and 28.6 million managed-care members across all brands.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 478, "_entity_id": 690, "_entity_slug": "wellcare-of-new-york", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Wellpoint Maryland, Inc.", "Category": "Health Insurance (For-profit)", "Terms & Conditions URL": "https://www.wellpoint.com/legal", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.wellpoint.com/legal", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "HIPAA-covered entity. Elevance Health (parent, fmr. Anthem) operates the largest for-profit Blue Cross Blue Shield licensee by enrollment. Subject of the 2015 breach (78.8M people) — the largest healthcare breach at the time. Plan-level data-sharing provisions not independently verified.", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — wellpoint.com/legal was not fetched.", "Fees / Billing Flags": "NOT VERIFIED THIS PASS — do not cite.", "Notes": "Elevance Health subsidiary (same parent as Anthem Virginia). Marketplace-only plan in MD. T&C not yet audited.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Hanover", "HQ State": "MD", "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.wellpoint.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Upgraded from shell row 2026-08-06. T&C text sourced via web_search returning actual document content from corporate legal pages. Cross-referenced with existing tracker rows. Fields marked 'NOT VERIFIED THIS PASS' were not independently fetched.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Operates in MD; HQ: Hanover, MD", "Parent / Ultimate Owner": "Elevance Health", "Years Referenced in Finding (heuristic)": "2004, 2015", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (MD) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in MD. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Wellpoint Maryland is the same parent company as Anthem, but a shopper may not realize it\nWHAT THE TERMS SAY: The tracker notes Wellpoint Maryland is an Elevance Health subsidiary offering ACA marketplace plans, and that a Maryland consumer comparing 'Wellpoint' and 'Anthem' plans may not realize both are owned by the same parent, Elevance Health (formerly Anthem Inc.).\nWHY IT MATTERS: A consumer shopping for competing quotes could be comparing two products from the same corporate parent without knowing it, undermining genuine price and plan comparison.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item found; arbitration and data-sharing fields are both unverified this pass ('T&C not yet audited'), and the 2015 Elevance Health breach is recorded under a different tracker row for the parent company, not this one.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "T&C were not fetched or audited this pass; arbitration and fees are explicitly unverified.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Wellpoint Maryland, Inc.  <-  Elevance Health", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Wellpoint Maryland, Inc. takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Wellpoint Maryland Inc. is an Elevance Health subsidiary offering ACA marketplace plans in Maryland — a relatively new entrant (2004) operating under the Wellpoint brand, which is distinct from the Anthem brand even though both are owned by the same parent (Elevance Health, formerly Anthem Inc.). A Maryland consumer comparing 'Wellpoint' and 'Anthem' plans may not realize they are comparing two subsidiaries of the same company. Wellpoint Maryland's T&C at wellpoint.com/legal were NOT independently fetched and read this pass — no arbitration or data-sharing findings are recorded. Elevance Health is already documented elsewhere in this tracker for the 2015 breach (78.8 million people).", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Life-Health-Dental Insurance", "_row_id": 479, "_entity_id": 691, "_entity_slug": "wellpoint-maryland-inc", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Life Time Fitness", "Category": "Gym", "Terms & Conditions URL": "lifetime.life/terms-of-use.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "my.lifetime.life/policy/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Life Time collects fitness assessment data, body composition measurements, workout tracking, and childcare check-in/check-out records. The Life Time app tracks workout frequency, class attendance, and facility usage patterns.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Life Time membership agreement. 30-day opt-out. Life Time collects biometric data (body composition scans, heart-rate monitoring) through its fitness programs — the arbitration clause covers disputes over this health-adjacent data.", "Fees / Billing Flags": "MAJOR TCPA (SPAM TEXT) SETTLEMENT: Life Time Fitness settled a NATIONWIDE class action over unsolicited marketing text messages for approximately $10-15 MILLION — one of the largest gym-industry TCPA settlements documented, reflecting the federal Telephone Consumer Protection Act's statutory damages of $500-$1,500 PER TEXT MESSAGE violation.", "Notes": "Life Time is part of a well-documented, INDUSTRY-WIDE gym TCPA litigation pattern (see the Orangetheory row for the fullest treatment of this cross-cutting finding, which also names LA Fitness, Gold's Gym, Anytime Fitness, Crunch Fitness, and Powerhouse Gym) — gyms are specifically flagged as 'aggressive about lead generation,' buying marketing contact lists and outsourcing texting to third parties that don't shield the gym from liability.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Chanhassen", "HQ State": "Minnesota", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Minnesota' is a non-DMV US state", "Parent / Ultimate Owner": "Life Time Group Holdings, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Life Time Group Holdings, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] Life Time paid $10-15 million to settle a nationwide lawsuit over unwanted marketing texts\nWHAT THE TERMS SAY: The tracker records Life Time Fitness settling a nationwide class action over unsolicited marketing text messages for roughly $10-15 million, citing the TCPA's $500-$1,500 per-text statutory damages.\nWHY IT MATTERS: Members who received unwanted marketing texts had a real legal claim worth hundreds to thousands of dollars per message, and Life Time paid out at that scale nationwide.\n(evidence: Fees / Billing Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration also covers disputes over Life Time's biometric body-composition scans\nWHAT THE TERMS SAY: The membership agreement imposes mandatory binding arbitration with a class-action waiver and a 30-day opt-out, and the tracker states this clause covers disputes over the body-composition and heart-rate data Life Time collects.\nWHY IT MATTERS: A member disputing how their biometric health data was handled must do so in individual arbitration, not court, unless they opt out within 30 days.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CONFIRMED_BREACH · FL-2] Life Time member data also flowed through the Mindbody vendor breach shared with Gold's Gym and CrossFit\nWHAT THE TERMS SAY: The tracker states Life Time member data 'separately flowed through Mindbody, the shared gym and studio management vendor whose breach also reached Gold's Gym and CrossFit.'\nWHY IT MATTERS: A single third-party vendor breach can expose members across multiple competing gym brands at once, and Life Time is named among the affected clients.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Arbitration terms, the TCPA settlement, and the Mindbody vendor breach are all stated concretely rather than marked unverified.", "Exposure Score (0-100)": 41, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 6/30 (biometric_collection+6) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Life Time Fitness  <-  Life Time Group Holdings, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Life Time Fitness you gave up your biometric identifiers, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Life Time settled a nationwide class action over unsolicited marketing texts for roughly $10-15 million - one of the largest gym-industry TCPA settlements documented - and the reason gyms keep landing here is statutory damages of $500 to $1,500 PER MESSAGE, which turns a routine marketing campaign into a nine-figure exposure very quickly. Life Time member data separately flowed through Mindbody, the shared gym and studio management vendor whose breach also reached Gold's Gym and CrossFit - competing brands, one back-end, one exposure. Gyms are specifically documented as aggressive lead-generation buyers, and outsourcing the texting to a third party does not shield them from liability.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Gyms & Home-Auto Insurance", "_row_id": 480, "_entity_id": 693, "_entity_slug": "life-time-fitness", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Orangetheory Fitness", "Category": "Gym", "Terms & Conditions URL": "orangetheory.com/en-us/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "orangetheory.com/en-us/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Orangetheory collects continuous heart-rate data during every class session. The OTBeat system tracks splat points, calories burned, and heart-rate zones. This is among the most granular biometric data any non-medical company in this tracker collects on a per-session basis.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. OTF membership agreement. 30-day opt-out. Orangetheory's entire model is built on heart-rate monitoring — every class session collects continuous heart-rate data through the OTBeat wearable. The arbitration clause covers disputes over this biometric data.", "Fees / Billing Flags": "AN INDUSTRY-WIDE, WELL-DOCUMENTED GYM TCPA (SPAM TEXT) LITIGATION PATTERN, with Orangetheory as a repeat named defendant: (1) Mack v. Confluence Group II (Orangetheory of Cumberland, Georgia federal court): plaintiff Sarah Mack received a telemarketing text with NO opt-out instructions, replied 'STOP,' and was texted again anyway — seeking $500 per violation under the TCPA. (2) A SEPARATE Virginia-location Orangetheory case was also sued for continuing to text consumers who had sent 'stop' requests. This pattern repeats across the gym industry broadly: LA Fitness (unsolicited text coupons), Life Time Fitness (settled $10-15 million nationwide), Powerhouse Gym ($600,000 settlement, up to $30/text to consumers), Gold's Gym, Anytime Fitness, and Crunch Fitness have ALL faced similar federal TCPA class actions. Notably, some of the strongest cases involve people who were texted despite NEVER having been a gym member at all — suggesting improperly obtained or purchased contact lists.", "Notes": "Not itemized this pass.\n\n[RECOVERED from an unheaded column during the Aug 2026 structural fix; this text was present in the file but sat outside any labelled column] This is one of the most CONSISTENT, industry-wide litigation patterns found anywhere in this entire tracker — nearly every major gym chain has faced a materially identical TCPA spam-text lawsuit, worth flagging as a structural, industry-wide practice rather than any single company's isolated misconduct.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Boca Raton", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "Ultimate Fitness Group, LLC", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Ultimate Fitness Group, LLC). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] Orangetheory is a repeat named defendant in two cases over texting people who replied 'STOP'\nWHAT THE TERMS SAY: The tracker cites Mack v. Confluence Group II (Orangetheory of Cumberland) in Georgia federal court, where the plaintiff alleges she received a telemarketing text with no opt-out instructions, replied 'STOP,' and was texted again anyway, seeking $500 per violation under the TCPA; a separate Virginia-location Orangetheory case was also sued for continuing to text consumers who had sent 'stop' requests.\nWHY IT MATTERS: Consumers who allegedly withdrew consent were texted anyway, and the tracker notes similar industry cases involve people texted despite never having been a member, suggesting purchased contact lists.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration covers disputes over the continuous heart-rate biometric data OTBeat collects\nWHAT THE TERMS SAY: OTF's membership agreement imposes mandatory binding arbitration with a class-action waiver and a 30-day opt-out, and the tracker states this clause covers disputes over the biometric heart-rate data collected via the OTBeat wearable.\nWHY IT MATTERS: A dispute over how continuous heart-rate and 'splat point' data is handled must go to individual arbitration unless the member opts out within 30 days.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[BIOMETRICS · FL-2] Orangetheory collects what the tracker calls among the most granular biometric data of any non-medical firm\nWHAT THE TERMS SAY: The tracker states Orangetheory collects continuous heart-rate data during every class session via the OTBeat system, tracking splat points, calories, and heart-rate zones, calling it 'among the most granular biometric data any non-medical company in this tracker collects on a per-session basis.'\nWHY IT MATTERS: This creates a detailed, ongoing physiological profile tied to every single workout, not just periodic assessments.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Specific named lawsuits exist, but the tracker's own SCARY and Finding Type fields mark this pass as 'nothing company-specific confirmed,' an internal tension in the source data.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 6/30 (biometric_collection+6) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Orangetheory Fitness  <-  Ultimate Fitness Group, LLC", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Orangetheory Fitness you gave up your biometric identifiers, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing company-specific confirmed this pass, but this row carries the fullest treatment of the industry-wide gym TCPA pattern that also names LA Fitness, Gold's Gym, Anytime Fitness, Crunch and Powerhouse. The mechanism is worth understanding as a consumer: gyms buy marketing contact lists, so people who never visited a location receive texts, and the sender is frequently a third-party vendor - which does not transfer the liability. The other durable gym finding across this tracker is cancellation friction, which is the most complained-about term in the entire fitness industry and remains a contract-design choice rather than an accident.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Gyms & Home-Auto Insurance", "_row_id": 481, "_entity_id": 695, "_entity_slug": "orangetheory-fitness", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "YMCA", "Category": "Gym/Community", "Terms & Conditions URL": "ymca.net/terms-of-use (varies by local YMCA chapter)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "ymca.net/privacy-policy (varies by local YMCA chapter)", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Each local YMCA maintains its own member data independently. National YMCA (Y-USA) sets data-handling guidelines but does not centrally control local branches' data practices. YMCA childcare and youth programs collect children's data, potentially subject to COPPA.", "Arbitration / Class Action Waiver": "YMCA is a federation of independent 501(c)(3) nonprofits — each local YMCA sets its own membership terms. There is NO single national arbitration clause. Membership disputes are handled at the local level. As a nonprofit, YMCA branches may be subject to state charitable-organization oversight in addition to consumer-protection law.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "As a NONPROFIT, community-oriented organization (distinct from the for-profit gym chains elsewhere in this tab), the YMCA's incentive structure around data monetization/marketing is likely meaningfully different — recommend checking the specific LOCAL YMCA chapter's own terms/privacy policy directly, since 'the YMCA' is not a single unified legal entity nationally.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Chicago", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "YMCA of the USA (federation of independent 501(c)(3) nonprofits)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: YMCA of the USA (federation of independent 501(c)(3) nonprofits)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] YMCA childcare and camp records include minors' medical, allergy, and custody information, held locally\nWHAT THE TERMS SAY: The tracker states YMCA childcare and youth programs collect children's data potentially subject to COPPA, and separately notes this includes minors' records, medical and allergy information, and custody arrangements — a more sensitive population than an adult gym membership.\nWHY IT MATTERS: Each local YMCA maintains its own member data independently; national Y-USA sets data-handling guidelines but does not centrally control local branches' data practices, and the tracker recommends checking the specific local chapter's own terms and privacy policy.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one substantive item found; the federated local-branch structure means no national arbitration clause or itemized fees exist to assess, and the SCARY field explicitly states nothing was confirmed at the national level.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No unified national terms exist; the tracker found nothing confirmed at the national level due to the YMCA's federated local-branch structure.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "YMCA  <-  YMCA of the USA (federation of independent 501(c)(3) nonprofits)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, YMCA takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed at national level this pass, and the structure explains it: the Y is a federation of independent local associations, each with its own systems and its own membership database under a shared brand - the same federated problem documented in the AAA row. A national search will systematically miss local incidents. The Y also runs childcare, summer camps and youth programmes, which means the data held includes minors' records, medical and allergy information, and custody arrangements - a materially more sensitive population than an adult gym membership. Recorded as unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Gyms & Home-Auto Insurance", "_row_id": 482, "_entity_id": 697, "_entity_slug": "ymca", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Gold's Gym", "Category": "Gym", "Terms & Conditions URL": "goldsgym.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "goldsgym.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same MINDBODY vendor-breach exposure as Life Time Fitness (see that row) — Gold's Gym is also named among Mindbody's affected fitness-brand clients. Named among the gym chains that have faced federal TCPA (unsolicited text message) class actions (see Orangetheory row for the fullest treatment of this industry-wide pattern).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass for a specific arbitration clause.", "Fees / Billing Flags": "Not itemized this pass beyond the TCPA pattern noted above.", "Notes": "See Orangetheory row for the fullest treatment of the shared gym-industry TCPA litigation pattern that also names Gold's Gym.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Gold's Gym is named among the fitness brands hit by the shared Mindbody vendor breach\nWHAT THE TERMS SAY: The tracker states Gold's Gym has the 'same MINDBODY vendor-breach exposure as Life Time Fitness' and 'is also named among Mindbody's affected fitness-brand clients.'\nWHY IT MATTERS: A single vendor's security failure can expose Gold's Gym member data through a shared scheduling/billing system it does not directly control.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DARK_PATTERN_CONSENT · FL-2] Gold's Gym has faced federal TCPA class actions over unsolicited text messages\nWHAT THE TERMS SAY: The tracker states Gold's Gym is 'named among the gym chains that have faced federal TCPA (unsolicited text message) class actions,' with the fullest case detail recorded under the industry-wide pattern documented elsewhere in the tracker.\nWHY IT MATTERS: Gold's Gym is a named party in this pattern of spam-text litigation, though this row does not itself carry specific case names or settlement figures.\n(evidence: Data Sharing/Selling Flags | Notes | SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-4] Many Gold's Gym locations are independently owned small businesses, not the national brand\nWHAT THE TERMS SAY: The tracker notes many Gold's locations are independently owned, so the entity holding a member's payment details and access records may be a small local business with different security capability than the national brand, changing who a member should contact after a breach.\nWHY IT MATTERS: A member assuming the national Gold's Gym brand holds their payment details and access records may in fact be dealing with a small local business with correspondingly different security capability, and a different answer to who to contact after a breach.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Vendor breach exposure and industry TCPA litigation are named for this company, but its own arbitration terms are explicitly not confirmed.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Gold's Gym  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Gold's Gym takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same Mindbody vendor exposure as Life Time and CrossFit, and named in the industry-wide TCPA pattern documented in the Orangetheory row. The franchise structure adds a second layer worth recording: many Gold's locations are independently owned, so the entity holding a member's payment details and access records may be a small local business rather than the national brand, with correspondingly different security capability and a different answer to who a member should contact after a breach.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Gyms & Home-Auto Insurance", "_row_id": 483, "_entity_id": 698, "_entity_slug": "gold-s-gym", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CrossFit", "Category": "Gym", "Terms & Conditions URL": "crossfit.com/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "crossfit.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CrossFit's data model is decentralized — each affiliate box maintains its own member data. CrossFit LLC collects data through the CrossFit Games registration, the CrossFit Open, and the SugarWOD/BTWB workout-tracking platforms. Affiliate owners share aggregate class data with CrossFit HQ.", "Arbitration / Class Action Waiver": "CrossFit LLC licenses the CrossFit brand to independently owned 'boxes' (affiliates). The consumer's membership agreement is with the LOCAL box owner, not with CrossFit LLC. CrossFit's own ToS govern the CrossFit.com website and the CrossFit Games. The affiliate model means there is no single arbitration clause governing all CrossFit members.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "CrossFit's UNIQUE STRUCTURE (a licensing/certification brand with independently-owned affiliate gyms, rather than a single corporately-run chain like Planet Fitness or LA Fitness) means privacy/billing practices likely vary SIGNIFICANTLY by individual affiliate gym — worth noting this structural difference from the other, more centrally-operated gym chains in this tab.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Scotts Valley", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "CrossFit, LLC", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: CrossFit, LLC). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] CrossFit's national privacy policy describes a relationship most members don't actually have\nWHAT THE TERMS SAY: The tracker states CrossFit's affiliate model means individual gyms are independently owned, member data sits with thousands of small businesses using their own chosen software, and the CrossFit brand governs almost none of it — so 'the privacy policy on the national website describes a relationship they do not actually have.'\nWHY IT MATTERS: A member reading CrossFit's national privacy policy may believe it governs their data, when in practice their local box's own systems and choices control it.\n(evidence: Arbitration / Class Action Waiver | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] CrossFit shares the same Mindbody vendor exposure as Life Time Fitness and Gold's Gym\nWHAT THE TERMS SAY: The tracker states CrossFit has the 'same Mindbody vendor exposure as Life Time and Gold's Gym — three brands with nothing else in common, one shared scheduling and billing back-end.'\nWHY IT MATTERS: A single vendor's security failure can expose CrossFit member data alongside unrelated competing gym brands that happen to share the same back-end system.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct items found; CrossFit's affiliate model means there is no single consumer arbitration clause or fee schedule to assess at the national level, since those vary per independently owned box.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Vendor breach exposure is stated, but no single consumer arbitration clause or fee terms exist to evaluate given the affiliate structure.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "CrossFit  <-  CrossFit, LLC", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, CrossFit takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same Mindbody vendor exposure as Life Time and Gold's Gym - three brands with nothing else in common, one shared scheduling and billing back-end. CrossFit's affiliate model means individual gyms are independently owned and licensed, so member data sits with thousands of small businesses operating whatever software they chose, and the CrossFit brand governs almost none of it. For a member, the practical consequence is that the privacy policy on the national website describes a relationship they do not actually have.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Gyms & Home-Auto Insurance", "_row_id": 484, "_entity_id": 700, "_entity_slug": "crossfit", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Anytime Fitness", "Category": "Gym", "Terms & Conditions URL": "anytimefitness.com/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "anytimefitness.com/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Anytime Fitness key-fob system records entry/exit timestamps at every location, creating a detailed pattern-of-life dataset. Members can use any location worldwide — the reciprocal-access system means a single member's data spans multiple franchisee databases.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Anytime Fitness membership agreement (franchisor-level terms). 30-day opt-out. Anytime Fitness operates 5,000+ locations in 40 countries. The 24/7 key-fob access model creates a granular facility-usage log for every member visit.", "Fees / Billing Flags": "SEPARATE, NOTABLE LITIGATION: Anytime Fitness faced a class action over COVID-19-era insurance coverage disputes (a judge denied part of Anytime Fitness's position in that case per court records reviewed) — a pandemic-era billing/coverage dispute distinct from the TCPA pattern below.", "Notes": "Named among the gym chains that have faced federal TCPA (unsolicited text message) class actions — see Orangetheory row for the fullest treatment of this industry-wide pattern, which specifically names Anytime Fitness alongside Gold's Gym, LA Fitness, Crunch Fitness, and others.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Woodbury", "HQ State": "Minnesota", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Minnesota' is a non-DMV US state", "Parent / Ultimate Owner": "Self Esteem Brands, LLC (parent of Anytime Fitness franchise system)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Self Esteem Brands, LLC (parent of Anytime Fitness franchise system)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Anytime Fitness's mandatory arbitration applies across 5,000+ locations in 40 countries, 30-day opt-out\nWHAT THE TERMS SAY: The franchisor-level membership agreement imposes mandatory binding arbitration with a class-action waiver and a 30-day opt-out, applying to Anytime Fitness's 5,000+ locations across 40 countries.\nWHY IT MATTERS: Members must act within 30 days to preserve their right to sue in court, across a global membership base.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[LOCATION_TRACKING · FL-2] Anytime Fitness's 24-hour keyfob system logs precisely when members are away from home\nWHAT THE TERMS SAY: The tracker states the 24/7 keyfob access model creates 'a precise record of when a member is away from home and for how long,' generated as a byproduct of unlocking the gym door at any of its reciprocal-access locations.\nWHY IT MATTERS: This pattern-of-life data is held by a local franchise operator and reveals a member's at-home/away schedule, not just gym attendance.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-1] A judge denied part of Anytime Fitness's position in a COVID-era class action over insurance coverage\nWHAT THE TERMS SAY: The tracker states Anytime Fitness faced a class action over COVID-19-era insurance coverage disputes, and that a judge denied part of Anytime Fitness's position in that case per court records reviewed.\nWHY IT MATTERS: This is a separate, confirmed legal setback distinct from the industry-wide texting litigation, showing a court ruled against Anytime Fitness's position on at least one issue.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Arbitration terms, the keyfob tracking practice, and litigation history are all stated concretely rather than marked unverified.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Anytime Fitness  <-  Self Esteem Brands, LLC (parent of Anytime Fitness franchise system)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Anytime Fitness you gave up your physical movements, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Named in the industry-wide gym TCPA pattern documented in the Orangetheory row. Anytime Fitness carries a distinctive additional data category because of its 24-hour keyfob access model: entry and exit timestamps for every visit, which is a precise record of when a member is away from home and for how long, generated as a byproduct of unlocking the door. Franchise ownership means that record sits with a local operator. Nothing else confirmed this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Gyms & Home-Auto Insurance", "_row_id": 485, "_entity_id": 702, "_entity_slug": "anytime-fitness", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Snap Fitness", "Category": "Gym", "Terms & Conditions URL": "snapfitness.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "snapfitness.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — as a franchise model (like Anytime Fitness), individual Snap Fitness locations may have club-specific agreement variations.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; Snap Fitness shares the same 24/7 unstaffed-access franchise model as Anytime Fitness, suggesting similar operational/privacy considerations may apply (e.g., keyfob/access-code entry logging).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — No troubling items found for Snap Fitness specifically; data sharing, arbitration, and fees were all 'not independently confirmed this pass,' and the SCARY field explicitly says 'nothing company-specific confirmed this pass' beyond noting the same general franchise/keyfob category as Anytime Fitness.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing, arbitration, and fees are all explicitly marked not independently confirmed this pass.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Snap Fitness  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Snap Fitness takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing company-specific confirmed this pass. Same franchised, keyfob-access, TCPA-exposed category as Anytime Fitness, and recorded as one structural assessment rather than an independent one. The honest note across all seven gym rows in this tab is that the dominant consumer harm in this industry is not data breach at all - it is billing and cancellation practice, which generates more complaints than every other issue combined and is a deliberate contract design rather than a security failure.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Gyms & Home-Auto Insurance", "_row_id": 486, "_entity_id": 703, "_entity_slug": "snap-fitness", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Erie Insurance", "Category": "Home/Auto Insurance", "Terms & Conditions URL": "erieinsurance.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "erieinsurance.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED 2025 RANSOMWARE ATTACK, WITH A CONTESTED OUTCOME: Erie Indemnity Company (managing Erie Insurance, based in Pennsylvania, serving 12 states + DC) detected unusual network activity June 7, 2025, causing a full NETWORK OUTAGE affecting ALL systems; Google's Threat Intelligence Group suggested (though did not confirm) the notorious 'Scattered Spider' group — the same threat actor implicated in the Qantas/Hawaiian Airlines/WestJet cluster documented in the Global Airlines tab — may have been responsible, given the timing and pattern match to its known targeting of insurers/retailers. TWO SEPARATE class actions were filed within days (by an Illinois customer and a former Wisconsin employee), each seeking $5 million. HOWEVER, Erie's own July 7, 2025 statement, following an independent forensic investigation, asserted there was 'NO EVIDENCE that any sensitive personal information, financial records or legally protected data was breached' during the incident — a notably different resolution from most other breach entries in this tracker, where sensitive data exposure was ultimately confirmed rather than ruled out.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual policyholder agreements, separate from the pending class actions.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is one of the FEW entries in this tracker where the company's OWN forensic conclusion (no sensitive data actually breached) directly CONTRADICTS the assumption underlying the filed lawsuits — worth flagging this as a genuinely disputed/unresolved factual question rather than treating the lawsuits' allegations as established fact, pending further litigation developments.", "Industry (Fortune 500)": "Insurance: Property and Casualty (Mutual)", "Revenue (Fortune 500)": "$13.2B", "Market Cap": "$11.0B", "Employees": "6,747", "HQ City": "Erie", "HQ State": "Pennsylvania", "CEO": "Timothy NeCastro", "Ticker": "ERIE", "Website (Corporate)": "erieinsurance.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (ERIE). Service route: c/o General Counsel / Corporate Secretary, Erie, Pennsylvania — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-2] Erie faced a 2025 ransomware attack and two $5 million lawsuits, but disputes any sensitive data was breached\nWHAT THE TERMS SAY: Erie Indemnity detected unusual network activity on June 7, 2025, causing a full network outage; two separate class actions seeking $5 million each were filed within days, but Erie's July 7, 2025 statement, following an independent forensic investigation, asserted there was 'no evidence that any sensitive personal information, financial records or legally protected data was breached.'\nWHY IT MATTERS: Two lawsuits allege harm from the incident while Erie's own investigation disputes that any sensitive data was actually taken, leaving the real consumer impact genuinely unresolved.\n(evidence: Data Sharing/Selling Flags | Notes | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one substantive item found, the 2025 ransomware incident and resulting litigation; arbitration is not independently confirmed this pass, and fees/billing were not itemized.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The ransomware incident and lawsuits are documented, but the company's own forensic conclusion directly disputes the plaintiffs' data-breach allegations, leaving the outcome genuinely contested.", "Exposure Score (0-100)": 10, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Erie Insurance  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Erie Insurance takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2025 ransomware attack on Erie Indemnity had a contested outcome, and contested is the operative word - the row should stay that way in any published writeup until the scope is independently confirmed. What is worth recording is that Erie is a regional carrier with a strong reputation and a heavily Mid-Atlantic and Appalachian footprint, so this is a directly local finding for a large number of Virginia, Maryland and Pennsylvania households. Regional carriers also generate far less national coverage than national ones, which means their incidents are systematically under-documented relative to their local impact.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Gyms & Home-Auto Insurance", "_row_id": 487, "_entity_id": 704, "_entity_slug": "erie-insurance", "_issuer": "Erie Insurance", "_issuer_slug": "erie-insurance", "_ticker": "ERIE", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Travelers Insurance", "Category": "Home/Auto Insurance", "Terms & Conditions URL": "travelers.com/legal-notices/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "travelers.com/legal-notices/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED 2021 BREACH, fully resolved via settlement in 2025: unauthorized third-party access occurred specifically through Travelers' INDEPENDENT AGENT PORTAL (an important detail — the vulnerability was in the third-party-facing agent system, not necessarily Travelers' direct customer-facing infrastructure). The Travelers Indemnity Company agreed to pay $6 MILLION to settle the resulting class action (Rand v. The Travelers Indemnity Company), alleging negligence and violations of the federal FTC Act and New York's SHIELD Act (a state data-security law) — final court approval was granted February 5, 2025, with payments actually issued to eligible class members in June 2025.", "Arbitration / Class Action Waiver": "Auto/home insurance disputes governed by state insurance department oversight. The NY AG/DFS settlement ($1.55M, Nov 2024 — joint action with GEICO) was for a separate April 2021 breach (88,858 people, DL numbers in plain text, agent portal with no MFA, undetected for 7+ months). Website ToS may contain arbitration provisions for non-claims interactions.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The AGENT PORTAL as the specific point of compromise is a useful, concrete detail — insurance companies routinely give independent agents (who aren't direct employees) portal access to customer data, creating a distinct third-party-adjacent vulnerability surface compared to a company's own internal employee systems.\n\nAUG 2026 ADDENDUM - REGULATORY ACTION, verified: NY AG Letitia James and NY DFS Superintendent Adrienne Harris, announced Nov 25 2024. Travelers Indemnity Co. penalty $1.55M ($350K to OAG, $1.2M to DFS), part of a combined $11.3M action alongside GEICO ($9.75M) covering 120,000+ New Yorkers. Attack peak Jan-Apr 2021 against the independent-agent quoting calculator; MFA was not enabled on the targeted agent portal; breach undetected for 7+ months; investigation began Nov 2021. 88,858 driver's license numbers taken, 3,912 belonging to New Yorkers. Stolen DL numbers used for fraudulent unemployment benefit claims during COVID. Remedies: maintain a comprehensive information security program, build and maintain a data inventory of private information with safeguards, and maintain reasonable authentication procedures. CROSS-REF: GEICO row in the Insurance tab - same DFS/OAG action, same industry-wide campaign against online auto quoting applications; treat as one connected story.", "Industry (Fortune 500)": "Insurance: Property and Casualty (Stock)", "Revenue (Fortune 500)": "$48.8B", "Market Cap": "$77.6B", "Employees": "34,000", "HQ City": "New York", "HQ State": "New York", "CEO": "Alan Schnitzer", "Ticker": "TRV", "Website (Corporate)": "travelers.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (TRV). Service route: c/o General Counsel / Corporate Secretary, New York, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.hunton.com/privacy-and-cybersecurity-law-blog/ny-ag-and-nydfs-announce-11-3-million-data-breach-settlement-with-geico-and-travelers", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "The Travelers Companies, Inc.", "Years Referenced in Finding (heuristic)": "2021, 2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: The Travelers Companies, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] NY regulators fined Travelers $1.55M over an agent quoting portal with no MFA, breach undetected 7+ months\nWHAT THE TERMS SAY: New York's AG and DFS announced on Nov 25, 2024 that Travelers Indemnity would pay $1.55 million ($350K to OAG, $1.2M to DFS) after attackers exploited the independent-agent auto-quoting calculator, which did not have multi-factor authentication enabled; the intrusion peaked Jan-Apr 2021 and went undetected for more than seven months before investigation began in November 2021.\nWHY IT MATTERS: 88,858 driver's license numbers were taken (3,912 belonging to New Yorkers) and used to file fraudulent pandemic unemployment claims in victims' names.\n(evidence: Data Sharing/Selling Flags | Notes | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-1] Travelers paid $6 million to settle a class action over a 2021 breach of its independent-agent portal\nWHAT THE TERMS SAY: The Travelers Indemnity Company agreed to pay $6 million to settle Rand v. The Travelers Indemnity Company, alleging negligence and violations of the FTC Act and New York's SHIELD Act, with final court approval granted February 5, 2025 and payments issued to class members in June 2025.\nWHY IT MATTERS: This $6 million settlement is a financial consequence separate from the New York regulatory penalty, which the tracker records as covering a separate April 2021 breach.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] People who merely priced a quote through a Travelers agent were swept into the breach, not just customers\nWHAT THE TERMS SAY: The tracker states the exposure sat in the auto-insurance quoting calculator used by independent agents, meaning people who only priced a policy, not just actual policyholders, had their driver's license numbers exposed.\nWHY IT MATTERS: Someone who never bought a Travelers policy could have had their driver's license number stolen and used for fraudulent unemployment claims simply by requesting a quote.\n(evidence: SCARY | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The breach, regulatory penalty, and class-action settlement are all documented with specific dates, dollar figures, and mechanisms.", "Exposure Score (0-100)": 17, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Travelers Insurance  <-  The Travelers Companies, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Travelers Insurance takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Travelers was breached through the auto-insurance quoting calculator its independent agents use - a portal that did not have multi-factor authentication switched on, despite Travelers having received multiple industry alerts warning that attackers were targeting exactly these tools. It did not detect the intrusion for more than seven months, only beginning to investigate in November 2021, and by then hackers had taken 88,858 customer driver's license numbers, which were used to file fraudulent pandemic unemployment claims in those people's names. New York regulators fined Travelers $1.55 million in November 2024. The structural point matches the GEICO finding in the Insurance tab: the exposure sat in the quoting tool, so people who merely priced a policy through an agent were swept in alongside actual customers.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Gyms & Home-Auto Insurance", "_row_id": 488, "_entity_id": 706, "_entity_slug": "travelers-insurance", "_issuer": "The Travelers Companies, Inc.", "_issuer_slug": "the-travelers-companies-inc", "_ticker": "TRV", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Chubb", "Category": "Home/Auto/Umbrella Insurance", "Terms & Conditions URL": "chubb.com/us-en/terms-of-use.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "chubb.com/us-en/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Chubb processes property, casualty, and personal-lines insurance data. As a Swiss-domiciled company with US operations, Chubb's data practices span both US state insurance regulations and Swiss data protection law (revFADP, effective Sept 2023).", "Arbitration / Class Action Waiver": "Chubb is a global property/casualty insurer. US consumer products (homeowners, auto, valuable articles) are sold through agents/brokers. Policy disputes governed by state insurance department regulations. Chubb's Swiss HQ means corporate governance is under Swiss law.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Chubb is positioned as a higher-end/specialty insurer (often serving high-net-worth individuals and businesses) — recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Zurich", "HQ State": "Switzerland", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Zurich, Switzerland (non-US)", "Parent / Ultimate Owner": "Chubb Limited (Zurich, Switzerland)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Switzerland) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Switzerland. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Chubb's high-net-worth files read like a burglary planning document, per the tracker's own framing\nWHAT THE TERMS SAY: The tracker notes Chubb serves high-net-worth households and large commercial risks, so its files contain detailed inventories — home contents schedules, art and jewelry appraisals, security system details, travel patterns, and household staff information — calling the combination 'a burglary planning document more than an insurance file.'\nWHY IT MATTERS: If this detailed inventory of valuables, security setups, and travel patterns were ever exposed, it would be unusually useful to someone planning a burglary, not just for identity theft.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item found; arbitration, fees, and any specific breach or data-sharing incident are all unconfirmed this pass ('Nothing confirmed this pass'), so only the qualitative sensitivity of Chubb's high-net-worth data holdings is substantive enough to report.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing about arbitration, fees, or any incident was confirmed this pass; only a qualitative data-sensitivity observation is recorded.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Chubb  <-  Chubb Limited (Zurich, Switzerland)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Chubb takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Chubb sits at the high end of the property and casualty market, insuring high-net-worth households and large commercial risks, which means its files contain unusually detailed inventories - home contents schedules, art and jewellery appraisals, security system details, travel patterns and household staff information. That combination is a burglary planning document more than an insurance file. Unverified rather than clean; recommend a follow-up on Chubb's vendor and broker data-sharing practices, since high-value personal lines run through independent brokers.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Gyms & Home-Auto Insurance", "_row_id": 489, "_entity_id": 708, "_entity_slug": "chubb", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Planet Fitness", "Category": "Gym / Fitness", "Terms & Conditions URL": "https://www.planetfitness.com/terms-of-use", "T&C Direct PDF?": null, "Privacy Policy URL": "https://www.planetfitness.com/privacy-policy", "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Planet Fitness processes membership data (17M+ members), check-in/check-out timestamps, PF Black Card reciprocal-use data (tracks which locations a member visits nationally), tanning-booth usage, massage-chair usage, and the Planet Fitness app workout-tracking data. The franchise model (2,400+ locations, 95% franchised) means member data flows between the franchisee (who operates the gym) and Planet Fitness corporate (who operates the app and national systems).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Planet Fitness membership agreement, AAA rules. 30-day opt-out. The franchise structure creates an ambiguity: the membership agreement is with the FRANCHISEE, but the app and website ToS are with PLANET FITNESS CORPORATE — a consumer may not realize they have two separate arbitration relationships with two different entities.", "Fees / Billing Flags": "Classic membership $15/month, PF Black Card $29.99/month (includes reciprocal use, tanning, massage chairs, guest privileges). Annual fee $49 (Classic) or $59 (Black Card). Cancellation requires certified letter or in-person visit to home club.", "Notes": "Planet Fitness is the largest gym chain in the US by membership (17M+). The franchise-vs-corporate arbitration split is the structural finding. Planet Fitness's 'Judgement Free Zone' marketing positions it as accessible to beginners — meaning the arbitration clause affects a population that may be less T&C-aware than boutique-fitness consumers. PF Black Card's reciprocal-use feature creates a national gym-visit pattern dataset.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Hampton", "HQ State": "New Hampshire", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-13", "Provenance (who determined this)": "Added 2026-08-13 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New Hampshire' is a non-DMV US state", "Parent / Ultimate Owner": "Planet Fitness Holdings, Inc. (NYSE: PLNT)", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (New Hampshire) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in New Hampshire. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] Cancelling Planet Fitness requires a certified letter or an in-person visit, which may now violate FTC rules\nWHAT THE TERMS SAY: The tracker states cancellation requires a certified letter or an in-person visit to your 'home club,' a process the FTC's click-to-cancel rule (effective 2025) 'may now prohibit.'\nWHY IT MATTERS: Members who can sign up online may be forced to mail a certified letter or show up in person just to stop being billed.\n(evidence: Fees / Billing Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Planet Fitness members may unknowingly have two separate arbitration relationships\nWHAT THE TERMS SAY: The tracker states a member's in-club membership agreement is with the local franchisee under mandatory AAA-rules arbitration with a class action waiver and a 30-day opt-out, while the app and website terms are with Planet Fitness corporate, meaning a member 'may have two separate arbitration relationships without realizing it.'\nWHY IT MATTERS: A member disputing an in-club issue versus an app/data issue may be bound by two different arbitration agreements with two different companies, doubling the complexity of preserving their right to sue.\n(evidence: Arbitration / Class Action Waiver | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[LOCATION_TRACKING · FL-2] The $29.99/month PF Black Card builds a national record of which gyms a member visits and when\nWHAT THE TERMS SAY: The tracker states the PF Black Card's reciprocal-use feature lets members use any Planet Fitness location nationally, creating a dataset of which locations a member visits, how frequently, and at what times, across potentially hundreds of gyms.\nWHY IT MATTERS: This produces a detailed, cross-location movement pattern for any member who pays for reciprocal access, beyond simple home-club check-ins.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Membership fees, the cancellation process, the franchise arbitration structure, and Black Card tracking are all described in specific, concrete detail.", "Exposure Score (0-100)": 33, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (precise_location_tracking+4) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Planet Fitness  <-  Planet Fitness Holdings, Inc. (NYSE: PLNT)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Planet Fitness you gave up your physical movements, your right to sue, your right to join a class action, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Planet Fitness is the largest gym chain in the US — 17 million members, 2,400+ locations — and its franchise model creates a consumer-protection gap not visible in any other gym in this tracker. When you sign up at Planet Fitness, your membership agreement is with the LOCAL FRANCHISEE (a small business). But the Planet Fitness app, website, and national systems are operated by PLANET FITNESS CORPORATE (a public company, NYSE: PLNT). You may have two separate arbitration relationships without realizing it: one with the franchisee for in-club disputes (equipment injury, billing, cancellation), and one with corporate for digital disputes (app data, the PF Black Card reciprocal-use network). The PF Black Card ($29.99/month) includes reciprocal use at any Planet Fitness nationally — creating a dataset of which locations a member visits, how frequently, and at what times, across potentially hundreds of gyms. Cancellation requires a certified letter or in-person visit to your 'home club' — a process the FTC's click-to-cancel rule (effective 2025) may now prohibit.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Gyms & Home-Auto Insurance", "_row_id": 490, "_entity_id": 547, "_entity_slug": "planet-fitness", "_issuer": "Planet Fitness Holdings, Inc.", "_issuer_slug": "planet-fitness-holdings-inc", "_ticker": "PLNT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Empower Retirement", "Category": "Retirement/Investment", "Terms & Conditions URL": "empower.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "empower.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SEC ENFORCEMENT ACTION: the SEC formally charged Empower Advisory Group and Empower Financial Services for FAILING TO ADEQUATELY DISCLOSE CONFLICTS OF INTEREST to retirement plan participants — a regulatory finding distinct from the private lawsuit below. SEPARATE ACTIVE LAWSUIT (2025, brought by prominent ERISA attorney Jerry Schlichter): alleges Empower engaged in 'a scheme to significantly mislead retirement plan participants and greatly enhance corporate profits' by USING PARTICIPANTS' OWN 401(k)/403(b) ACCOUNT DATA to identify and target people nearing retirement with recommendations to roll their savings into Empower's own fee-generating 'Managed Account' product — one named plaintiff was allegedly induced into a Managed Account just 2.5 years before her planned retirement date, based on conversations with Empower's own advisors. This is a genuinely distinct category of harm: using a customer's OWN financial data to identify and upsell them into a MORE PROFITABLE (for Empower) product, not a third-party data breach.", "Arbitration / Class Action Waiver": "SEPARATE CONFIRMED DATA BREACH (disclosed Oct 9, 2024, to Texas AG): 'Empower Management Group' filed a formal breach notification after discovering information provided to it had been compromised — specific scope/data types not detailed in sources reviewed this pass. A SEPARATE, more recent breach claim (referenced May 2026) is also under attorney investigation.", "Fees / Billing Flags": "Not itemized this pass beyond the data-misuse-for-cross-selling allegation above.", "Notes": "The 'using YOUR OWN retirement data to identify the best moment to upsell you into a fee-generating product' allegation is a genuinely distinctive and important finding — it's not a security failure but an alleged MISUSE of properly-collected data against the customer's own financial interest, worth flagging as a different category of harm from most other findings in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SURVEILLANCE_PRICING · FL-2] Lawsuit alleges Empower used customers' own 401(k) data to target them for a costlier in-house product\nWHAT THE TERMS SAY: A 2025 lawsuit alleges Empower used participants' own 401(k)/403(b) account data to identify people nearing retirement and steer them into its fee-generating 'Managed Account' product; one named plaintiff was allegedly induced into it 2.5 years before her planned retirement.\nWHY IT MATTERS: If true, a recordkeeper would be using a customer's private financial data against their own interest to sell a more profitable product; the allegation remains unproven.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-2] SEC formally charged Empower units for failing to disclose conflicts of interest to retirement savers\nWHAT THE TERMS SAY: The SEC charged Empower Advisory Group and Empower Financial Services for failing to adequately disclose conflicts of interest to retirement plan participants, a regulatory finding distinct from the private lawsuit.\nWHY IT MATTERS: A federal regulator concluded Empower did not give participants information needed to evaluate whether its recommendations served their own interests.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CONFIRMED_BREACH · FL-2] A confirmed 2024 breach was disclosed to the Texas AG; the tracker's sources did not detail its scope\nWHAT THE TERMS SAY: 'Empower Management Group' filed a formal breach notification with the Texas AG on Oct 9, 2024 after discovering compromised information; a second, more recent breach claim from May 2026 is under attorney investigation.\nWHY IT MATTERS: The specific scope and data types were not detailed in the sources reviewed this pass, so the tracker cannot say what was exposed; a second, more recent breach claim referenced May 2026 is still only under attorney investigation.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "SEC action and breach are confirmed but breach scope and fee/arbitration terms are not detailed this pass.", "Exposure Score (0-100)": 16, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 16/20 (severity3+8, breach+3, penalty+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Empower Retirement  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Empower Retirement takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The SEC charged Empower Advisory Group, and the category is worth naming precisely because retirement plan participants almost never think about it: a 401(k) recordkeeper knows your age, income, contribution rate, account balance, investment choices, hardship withdrawals and loans - which together describe your financial position and your life stress more completely than a bank statement does. A hardship withdrawal is a documented crisis. Participants also do not choose the recordkeeper; their employer does, which is the same no-relationship structure as ADP and Workday.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Retirement & Telehealth", "_row_id": 491, "_entity_id": 710, "_entity_slug": "empower-retirement", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Voya Financial", "Category": "Retirement/Investment", "Terms & Conditions URL": "voya.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "voya.com/privacy-notice", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MULTIPLE CONFIRMED INCIDENTS: (1) 2016 breach (SEC-settled 2018): intruders impersonating Voya contractors called Voya's support line and had contractor passwords reset over a 6-day period, gaining access to personal information of 5,600 customers; Voya paid $1 MILLION to settle SEC charges for violating the Safeguards Rule and Identity Theft Red Flags Rule. (2) A SEPARATE 2023 breach: an unauthorized actor accessed sensitive data (names, addresses, SSNs) through a COMPROMISED EMPLOYEE EMAIL ACCOUNT (Feb 9, 2023), affecting an undetermined number of Voya's ~14.3 million clients nationally; affected individuals were offered 2 years of free Experian credit monitoring.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual account agreements, separate from the incidents above.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "GENUINELY UNUSUAL, SERIOUS 2026 LAWSUIT: an AI startup founder (Michael Lafave of Cette AI) sued Voya in New York state court alleging the company used PERSONAL INFORMATION HE HAD DISCLOSED AS PART OF A LONG-TERM DISABILITY CLAIM (his location, disability status, treatment needs, and company valuation materials) to conduct a 'premeditated series of cyber intrusions' against his personal devices — allegedly using sophisticated remote-access techniques to exfiltrate his proprietary AI models, 'hijacking' his GitHub account, and even placing him under physical/location-based surveillance (triggering an anti-stalking alert on one of his Apple devices). Voya has declined to comment on the lawsuit; the allegations remain UNPROVEN as of this research, but represent one of the most serious individual-targeting allegations found anywhere in this entire tracker — a claim that information shared for a routine disability-benefits claim was allegedly weaponized for corporate/technical espionage against the claimant himself.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$8.2B", "Market Cap": "$8.9B", "Employees": "10,000", "HQ City": "New York", "HQ State": "New York", "CEO": "Heather Lavallee", "Ticker": "VOYA", "Website (Corporate)": "voya.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (VOYA). Service route: c/o General Counsel / Corporate Secretary, New York, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2016, 2018, 2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Two separate confirmed breaches, the 2023 one affecting an undetermined number of Voya's 14.3M clients\nWHAT THE TERMS SAY: A 2016 breach (SEC-settled for $1M in 2018) exposed personal information of 5,600 customers via social-engineered password resets; a separate 2023 breach via a compromised employee email account exposed names, addresses and SSNs for an undetermined number of Voya's roughly 14.3 million clients.\nWHY IT MATTERS: Affected customers were offered only two years of free credit monitoring against a potential lifetime SSN-exposure risk.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-2] Voya paid $1 million in the first-ever SEC settlement under the Identity Theft Red Flags Rule\nWHAT THE TERMS SAY: The 2016 breach, caused by callers impersonating Voya contractors to get support staff to reset passwords, led to a 2018 SEC settlement of $1 million for violating the Safeguards Rule and the Identity Theft Red Flags Rule.\nWHY IT MATTERS: Federal regulators found Voya's identity-theft prevention program inadequate against a low-tech social-engineering attack.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[PENDING_LITIGATION · FL-2] A 2026 lawsuit alleges Voya weaponized a disability claimant's personal data for cyber-espionage against him\nWHAT THE TERMS SAY: An AI startup founder alleges Voya used information he disclosed for a long-term disability claim (location, disability status, treatment needs, company valuation materials) to conduct cyber intrusions against his devices, exfiltrate his AI models, hijack his GitHub account, and surveil his location; Voya has declined to comment and the allegations are unproven.\nWHY IT MATTERS: If proven, this would mean data shared for a routine disability claim was used against the claimant himself, not merely exposed.\n(evidence: Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Breach history and the SEC settlement are well documented, but 2023 breach scope and standard contract terms are unconfirmed this pass.", "Exposure Score (0-100)": 16, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 16/20 (severity3+8, breach+3, penalty+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Voya Financial  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Voya Financial takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Voya's 2016 breach produced an SEC settlement in 2018 that was the first enforcement action under the Identity Theft Red Flags Rule - a genuinely notable regulatory first, and the mechanism was social engineering rather than any technical exploit: callers impersonated contractors to get passwords reset. That is the same technique that produced the 2025-26 ShinyHunters campaign documented across this tracker, nearly a decade earlier. The attack that keeps working is not a new one; it is the oldest one, and it works because help desks are designed to be helpful.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Retirement & Telehealth", "_row_id": 492, "_entity_id": 711, "_entity_slug": "voya-financial", "_issuer": "Voya Financial", "_issuer_slug": "voya-financial", "_ticker": "VOYA", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Principal Financial Group", "Category": "Retirement/Investment", "Terms & Conditions URL": "principal.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "principal.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual account agreements; note the SAME general 401(k)/retirement-plan-provider industry concerns documented for Empower Retirement (see that row — using participant data to identify and cross-sell into fee-generating managed accounts) may be worth checking against Principal's own practices given the structural similarity of the business model.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly checking whether Principal has faced similar 'data-driven cross-selling' allegations as Empower Retirement.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$15.6B", "Market Cap": "$23.5B", "Employees": "19,700", "HQ City": "Des Moines", "HQ State": "Iowa", "CEO": "Deanna Strable-Soethout", "Ticker": "PFG", "Website (Corporate)": "principal.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (PFG). Service route: c/o General Counsel / Corporate Secretary, Des Moines, Iowa — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Iowa' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Non-US entity (Iowa) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Iowa. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — No confirmed data-sharing, breach, arbitration, or fee findings for Principal this pass; the only content is a hedged comparison to Empower Retirement's separate finding, which is another company's finding and not attributable to Principal itself.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Every field this pass says 'not independently confirmed'; no company-specific terms or incidents were located.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Principal Financial Group  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Principal Financial Group takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Principal is a major retirement and insurance provider, and the analysis mirrors Empower: participants are enrolled through employers, hold long-duration relationships they rarely review, and supply beneficiary designations that map family structure including estranged relationships and second families. Beneficiary data is quietly among the most socially sensitive information in financial services and it attracts no special protection. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Retirement & Telehealth", "_row_id": 493, "_entity_id": 712, "_entity_slug": "principal-financial-group", "_issuer": "Principal Financial Group", "_issuer_slug": "principal-financial-group", "_ticker": "PFG", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Teladoc Health (incl. BetterHelp)", "Category": "Telehealth", "Terms & Conditions URL": "teladochealth.com/legal-notices/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "teladochealth.com/legal-notices/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SIGNIFICANT COURT RULING (S.D.N.Y., June 25, 2025): a federal judge DENIED Teladoc's motion to dismiss a class action alleging Teladoc installed the Meta/Facebook tracking PIXEL AND Conversions API on its website, secretly transmitting patients' PROTECTED HEALTH INFORMATION to Meta for advertising purposes — the court adopted reasoning that Teladoc's use of tracking technology for HIPAA-prohibited marketing purposes created an 'independent criminal purpose' that DEFEATED Teladoc's consent-based defense under the federal Electronic Communications Privacy Act (ECPA), allowing 8 of 12 claims (including federal wiretapping and multiple state privacy law violations) to proceed. The court specifically found Teladoc functioned as a HEALTHCARE PROVIDER, not merely a technology platform, meaning its privacy-policy promises could be treated as material misrepresentations, and that medical conditions constitute protected 'contents' of communications (not mere tracking metadata) under relevant state wiretapping statutes.", "Arbitration / Class Action Waiver": "This is a legally SIGNIFICANT precedent for the tracking-pixel litigation wave documented throughout this tracker: most other pixel cases proceed under general consumer-privacy theories, but THIS ruling specifically ties the HIPAA marketing prohibition to defeating the ECPA's one-party-consent defense — a more legally sophisticated theory than most comparable cases elsewhere in this audit.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Teladoc OWNS BetterHelp (already documented separately in the GoodRx/BetterHelp/Premom row, Consumer Apps tab, for its own separate $7.8M FTC settlement over sharing mental-health data with advertisers) — meaning Teladoc's overall corporate family now has TWO separate, serious health-data-sharing findings across different parts of this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Purchase", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": "https://www.duanemorris.com/alerts/healthcare_tracking_pixel_litigation_signals_continued_challenges_defendants_0625.html", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ: Purchase, New York (non-US)", "Parent / Ultimate Owner": "Teladoc Health, Inc.", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Teladoc Health, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Federal judge let a class action proceed alleging Teladoc's Meta pixel sent patient health data for ads\nWHAT THE TERMS SAY: A federal judge in the S.D.N.Y. denied Teladoc's motion to dismiss a class action alleging it installed Meta's tracking pixel and Conversions API on its site, transmitting patients' protected health information to Meta for advertising; the court found this had an 'independent criminal purpose' that defeated Teladoc's consent defense, letting 8 of 12 claims (including federal wiretapping) proceed.\nWHY IT MATTERS: If the allegations hold, patients seeking telehealth care had protected health information routed to an advertising platform without a valid legal shield; the court also found Teladoc functioned as a healthcare provider rather than a technology platform, meaning its privacy-policy promises could be treated as material misrepresentations.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-2] Teladoc's own subsidiary BetterHelp separately paid $7.8 million to the FTC for sharing mental-health data with advertisers\nWHAT THE TERMS SAY: Teladoc owns BetterHelp, which paid a $7.8 million FTC settlement over sharing mental-health data with advertisers — a second, separate confirmed health-data-sharing finding within the same corporate family.\nWHY IT MATTERS: The same parent company now has two distinct confirmed instances of sensitive health data reaching advertisers.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct company-specific harms are supported this pass; arbitration and fees are not itemized in the source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Meta-pixel finding is well documented with specific court findings, but arbitration and fee terms are entirely unaddressed this pass.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (data_sold_or_shared_for_value+8) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only", "Entity Type": "Company", "Ownership Path": "Teladoc Health (incl. BetterHelp)  <-  Teladoc Health, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Teladoc Health (incl. BetterHelp) you gave up your personal data sold onward. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A federal judge denied Teladoc's motion to dismiss in June 2025, and the legal reasoning is more significant than the case itself: the court found Teladoc's use of the Meta pixel and Conversions API for HIPAA-prohibited marketing constituted an 'independent criminal purpose,' which DEFEATED the one-party-consent defence Teladoc raised under the federal wiretapping statute. Eight of twelve claims survived. The court also held Teladoc functioned as a healthcare provider rather than a technology platform, meaning its own privacy promises could be treated as material misrepresentations. That is a substantially more sophisticated theory than the general consumer-privacy framing used in most pixel cases in this tracker. Teladoc also owns BetterHelp, which separately paid $7.8 million to the FTC for sharing mental health data with advertisers - two serious health-data findings in one corporate family.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Retirement & Telehealth", "_row_id": 494, "_entity_id": 714, "_entity_slug": "teladoc-health-incl-betterhelp", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Talkspace (Universal Health Services)", "Category": "Telehealth (mental health)", "Terms & Conditions URL": "talkspace.com/legal/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "talkspace.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "GENUINELY ALARMING FINDING FOR A MENTAL-HEALTH PLATFORM: Talkspace's own CEO has told investors the company sits on '8 BILLION WORDS, 140 MILLION MESSAGES, 6.2 MILLION ASSESSMENTS' from therapy sessions — explicitly described to investors as 'one of the largest mental health data banks in the world.' This data bank is being used to TRAIN A NEW AI THERAPY CHATBOT ('TalkAI') that Talkspace plans to seek INSURANCE REIMBURSEMENT for. SEPARATELY, and more immediately concerning: in a specific case (Kamrass), a patient's ENTIRE THERAPY TRANSCRIPT with her Talkspace therapist was PRODUCED IN COURT during unrelated litigation — illustrating that therapy conversations a patient may reasonably assume are private/protected can, in fact, become discoverable legal evidence. In March 2026, Universal Health Services (a major hospital/behavioral-health conglomerate operating 119 outpatient and 346 inpatient behavioral health facilities) ACQUIRED Talkspace for $835 MILLION, folding this entire 8-billion-word data set into its broader healthcare corporate structure.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is arguably one of the MOST SERIOUS mental-health-privacy findings in this entire tracker: a company explicitly describing patients' own therapy words as a monetizable 'data bank' to train a commercial AI product, combined with a documented instance of therapy transcripts being subpoenaed into unrelated court proceedings. Recommend treating this with particular care given how directly it touches on the confidentiality assumptions patients bring to mental-health treatment — anyone considering Talkspace, or currently using it, may want to understand these dynamics before assuming session content is fully confidential.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[AI_TRAINING · FL-2] Talkspace's CEO calls patients' 8 billion therapy words a 'data bank' used to train a commercial AI chatbot\nWHAT THE TERMS SAY: Talkspace's CEO told investors the company holds 8 billion words, 140 million messages, and 6.2 million assessments from therapy sessions, describing it as 'one of the largest mental health data banks in the world,' and this data is being used to train a new AI therapy chatbot ('TalkAI') that the company plans to seek insurance reimbursement for.\nWHY IT MATTERS: Patients' private disclosures about their mental health are being repurposed to build and monetize a commercial product.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-4] A patient's full Talkspace therapy transcript was produced in court in unrelated litigation\nWHAT THE TERMS SAY: In the Kamrass matter, a patient's entire therapy transcript with her Talkspace therapist was produced in court during litigation unrelated to her treatment, showing that therapy conversations a patient may assume are private can become discoverable legal evidence.\nWHY IT MATTERS: Patients may not realize that written therapy records generated through the platform can be subpoenaed and used against them in matters unrelated to their treatment.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Mozilla found Talkspace's policy allowed marketing use of inferred gender identity, sexual orientation, and depression indicators\nWHAT THE TERMS SAY: Mozilla's assessment found Talkspace's policy permitted using inferences drawn from its intake questionnaire — covering gender identity, sexual orientation, and depression indicators — for marketing; Talkspace disputed Mozilla's characterization.\nWHY IT MATTERS: If accurate, sensitive mental-health and identity inferences collected during intake could be used to target patients with marketing rather than solely for care.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The AI-training and transcript-discoverability findings are clearly stated, but arbitration/fee terms are unconfirmed and the marketing-use finding is disputed by Talkspace.", "Exposure Score (0-100)": 16, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (ai_training_on_user_data+5, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Talkspace (Universal Health Services)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Talkspace (Universal Health Services) you gave up your content used as AI training data. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Talkspace's own CEO told investors the company holds 8 billion words, 140 million messages and 6.2 million assessments from therapy sessions, describing it to investors as one of the largest mental health data banks in the world - and that data bank is being used to train an AI therapy product the company intends to seek insurance reimbursement for. Patients' own words about their worst moments, characterised as an asset on an earnings call. Separately, in the Kamrass matter a patient's entire therapy transcript was produced in court during unrelated litigation, which establishes the point no privacy policy conveys: therapy conducted through a platform generates a written record, and written records are discoverable. Mozilla's assessment of the category found Talkspace's policy permitted using inferences drawn from its intake questionnaire - covering gender identity, sexual orientation and depression indicators - for marketing; Talkspace disputed Mozilla's characterisation. Anyone currently using the service deserves to understand this before assuming session content is confidential.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Retirement & Telehealth", "_row_id": 495, "_entity_id": 715, "_entity_slug": "talkspace-universal-health-services", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Hims & Hers", "Category": "Telehealth", "Terms & Conditions URL": "hims.com/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "hims.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED 2026 DATA BREACH (part of a broader telehealth/mental-health industry breach wave documented in a year-end 2026 privacy roundup alongside Talkspace, BetterHelp, Cerebral, and Confidant Health): the breach exposed customer names and contact information tied to CUSTOMER SERVICE RECORDS — TWO SEPARATE class action lawsuits allege Hims & Hers failed to adequately safeguard sensitive customer data and DELAYED NOTIFICATION to affected customers, increasing identity-theft risk. Given Hims & Hers' business (telehealth prescriptions for sensitive conditions like hair loss, sexual health, and mental health), even 'just' contact information exposure carries an implicit health-condition-association risk beyond the literal data exposed.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Hims & Hers is part of a documented, INDUSTRY-WIDE 2025-2026 wave of telehealth/mental-health platform breaches (Talkspace, BetterHelp, Cerebral, Confidant Health all separately affected in the same window) — worth treating as a connected pattern reflecting the telehealth industry's broader security maturity gap rather than isolated incidents.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Confirmed 2026 breach exposed customer names and contact information tied to customer-service records\nWHAT THE TERMS SAY: A 2026 data breach exposed customer names and contact information tied to customer-service records; two separate class actions allege Hims & Hers failed to safeguard the data and delayed notifying affected customers.\nWHY IT MATTERS: Because Hims & Hers' business centers on sensitive conditions like sexual health and mental health, even 'just' contact-information exposure carries an implicit health-condition-association risk beyond the literal data exposed.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] Two class actions allege Hims & Hers delayed notifying customers after the breach, increasing identity-theft risk\nWHAT THE TERMS SAY: Two separate class action lawsuits allege Hims & Hers failed to adequately safeguard sensitive customer data and delayed notification to affected customers, increasing identity-theft risk.\nWHY IT MATTERS: A delayed notification means affected customers had less time to protect themselves before the exposure became known.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only the confirmed breach and its associated litigation are company-specific and substantive; arbitration and fees are not itemized, and the HIPAA-perimeter point in SCARY is industry-general rather than a specific Hims & Hers fact.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach and litigation are confirmed and specific, but arbitration and fee terms are unconfirmed this pass.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Hims & Hers  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Hims & Hers takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2026 breach sits inside a broader telehealth incident pattern, and the specific sensitivity here is the product line: Hims & Hers built its business on conditions people specifically do not want discussed - sexual health, hair loss, mental health, weight management. The entire value proposition is discretion, which means the customer list is itself a diagnosis list. Direct-to-consumer telehealth also frequently sits at the edge of the HIPAA perimeter depending on how the clinical relationship is structured, so the protection a customer assumes applies may not. Cross-ref the Teladoc and Talkspace rows.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Retirement & Telehealth", "_row_id": 496, "_entity_id": 716, "_entity_slug": "hims-hers", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "One Medical (Amazon)", "Category": "Telehealth/Primary Care", "Terms & Conditions URL": "onemedical.com/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "onemedical.com/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach since Amazon's 2023 acquisition; as an AMAZON-OWNED healthcare provider, One Medical's patient health data sits within the same broader corporate ecosystem as Amazon's general e-commerce/Alexa/advertising operations (documented extensively elsewhere in this tracker, Consumer Apps tab), raising a structural question about how thoroughly patient health data is walled off from Amazon's advertising business.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up specifically confirming Amazon's stated data-separation commitments between One Medical's HIPAA-covered patient records and Amazon's broader advertising/retail data ecosystem, given the acquisition-related data-integration concerns already flagged for Fitbit and Ring elsewhere in this tracker (both also Amazon/Google-adjacent acquisitions with similar structural questions).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "PARENT ADDRESS ONLY — verify before using for legal notice. 1Life Healthcare, Inc. (One Medical) is a San Francisco-headquartered subsidiary and a HIPAA covered entity in its own right. Parent: Amazon.com, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210, USA", "Legal / Privacy Contact Email": "Not verified this pass — Amazon routes privacy requests through its in-account privacy portal", "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Amazon.com, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] One Medical's HIPAA-covered patient records now sit inside Amazon's retail and advertising corporate structure\nWHAT THE TERMS SAY: One Medical is a primary-care provider owned by Amazon since 2023; Amazon has stated health data is walled off from its commercial operations and HIPAA applies to the clinical entity, but no company-specific breach or lawsuit was independently confirmed this pass.\nWHY IT MATTERS: The wall between clinical data and Amazon's advertising/retail business is a corporate policy and compliance boundary rather than a technical barrier, and members have no visibility into decisions that could affect its durability.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No confirmed breach, lawsuit, or regulatory action was found for One Medical this pass; only the structural concern about Amazon's ownership and data-separation commitments is documented, and it remains unverified.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No company-specific incident or terms were confirmed this pass; only a structural, unverified concern about Amazon ownership is recorded.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "One Medical (Amazon)  <-  Amazon.com, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, One Medical (Amazon) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. The finding is the ownership: One Medical is a primary care provider owned by Amazon, which means a company whose core business is retail, advertising and cloud infrastructure now operates clinics holding actual medical records. Amazon has stated health data is walled off from its commercial operations, and HIPAA does apply to the clinical entity - both of which are real constraints worth recording. The residual concern is structural rather than accusatory: the wall is a corporate policy and a compliance boundary, not a technical impossibility, and its durability depends on decisions members have no visibility into.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Retirement & Telehealth", "_row_id": 497, "_entity_id": 717, "_entity_slug": "one-medical-amazon", "_issuer": "Amazon.com, Inc.", "_issuer_slug": "amazon-com-inc", "_ticker": "AMZN", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Vivint Smart Home (NRG Energy)", "Category": "Home Security", "Terms & Conditions URL": "vivint.com/legal/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "vivint.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MAJOR HISTORICAL FTC SETTLEMENT (2021, $20 MILLION — one of the largest in home-security industry history at the time): resolved FTC allegations related to Vivint's practices. NEW, ONGOING LITIGATION (2025-2026): fresh lawsuits expand beyond the original FTC framework into PRIVATE class actions, focusing on CONTINUED high-pressure door-to-door sales tactics, alleged violations of the Fair Credit Reporting Act, and data-handling complaints from customers specifically in California and Illinois. NRG Energy's 2023 acquisition of Vivint has added legal complexity, with plaintiffs now navigating 'corporate successor liability' arguments about which entity bears responsibility for pre-acquisition conduct.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Vivint ToS. 30-day opt-out. The FTC's $20M settlement (2021, FCRA violations — 'white paging' fraud) happened while the arbitration clause was in effect. Vivint was acquired by NRG Energy in March 2023 for $2.8B — check whether post-acquisition terms differ.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "As an IN-HOME security/camera company (similar category to Ring/ADT documented elsewhere in this tracker), Vivint's combination of door-to-door sales pressure AND in-home surveillance equipment creates a genuinely elevated trust/vulnerability dynamic — worth flagging given the persistent, multi-year pattern of legal action (2021 FTC settlement through fresh 2025-2026 lawsuits) rather than a single resolved incident.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Lehi", "HQ State": "Utah", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.ftc.gov/news-events/news/press-releases/2021/04/smart-home-monitoring-company-vivint-will-pay-20-million-settle-ftc-charges-it-misused-consumer", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Utah' is a non-DMV US state", "Parent / Ultimate Owner": "NRG Energy, Inc. (acquired March 2023)", "Years Referenced in Finding (heuristic)": "2021", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Utah) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Utah. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] Vivint paid $20 million to settle FTC allegations its salespeople misused strangers' credit reports\nWHAT THE TERMS SAY: The FTC's 2021 $20 million settlement — one of the largest in home-security industry history — alleged Vivint sales personnel misused credit reports, including pulling an unrelated person's credit file so a prospective customer who wouldn't otherwise qualify could be approved for financing, a Fair Credit Reporting Act violation against people who were never Vivint customers.\nWHY IT MATTERS: People who never applied for anything or interacted with Vivint had their credit files accessed without authorization to help close an unrelated sale.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] Fresh 2025-2026 lawsuits allege continued high-pressure door-to-door sales tactics and FCRA violations\nWHAT THE TERMS SAY: New private class actions filed in 2025-2026 focus on continued high-pressure door-to-door sales tactics, alleged Fair Credit Reporting Act violations, and data-handling complaints from customers in California and Illinois; NRG's 2023 acquisition of Vivint has added 'corporate successor liability' disputes over which entity bears responsibility for pre-acquisition conduct.\nWHY IT MATTERS: The pattern the FTC penalized in 2021 appears to be continuing under new ownership, and it is unclear which corporate entity would be accountable for it.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Vivint requires binding arbitration with a class-action waiver and only a 30-day opt-out window\nWHAT THE TERMS SAY: Vivint's Terms of Service impose mandatory binding arbitration with a class action waiver, with a 30-day window to opt out; the FTC's $20M settlement itself occurred while this arbitration clause was in effect.\nWHY IT MATTERS: Customers who miss the narrow 30-day opt-out window give up their right to sue Vivint in court or join a class action over billing, sales, or data disputes.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "FTC settlement, arbitration terms, and new litigation are clearly documented, but fee/billing terms are not itemized this pass.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Vivint Smart Home (NRG Energy)  <-  NRG Energy, Inc. (acquired March 2023)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Vivint Smart Home (NRG Energy) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Vivint's 2021 FTC settlement was $20 million - one of the largest in home security - and the conduct is unusually specific: the FTC alleged Vivint sales personnel misused credit reports, including a practice of pulling an unrelated person's credit file so a prospective customer who would not otherwise qualify could be approved for financing. That is a Fair Credit Reporting Act violation against people who were never Vivint customers and never applied for anything. A home security company - sold on the premise of protecting your household - was reaching into strangers' credit files to close sales.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Home Security & Entertainment", "_row_id": 498, "_entity_id": 719, "_entity_slug": "vivint-smart-home-nrg-energy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Frontpoint Security", "Category": "Home Security", "Terms & Conditions URL": "frontpoint.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "frontpoint.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; Frontpoint is noted in independent reviews for a notably strong 'A+' industry rating and offers a 30-day risk-free guarantee.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Frontpoint's Terms & Conditions. 30-day opt-out. Frontpoint is headquartered in Reston, Virginia (DMV). The arbitration clause covers monitoring-service disputes, false-alarm billing, and equipment-lease disagreements.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; Frontpoint's blend of self-installation plus professional monitoring is structurally similar to SimpliSafe's model (see that row), though no comparable independent privacy-specific audit was found for Frontpoint this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Frontpoint Security Solutions, LLC (Reston, VA)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Frontpoint requires binding arbitration with a class-action waiver, covering billing and equipment disputes\nWHAT THE TERMS SAY: Frontpoint's Terms & Conditions impose mandatory binding arbitration with a class action waiver and a 30-day opt-out window, covering monitoring-service disputes, false-alarm billing, and equipment-lease disagreements.\nWHY IT MATTERS: Customers who don't opt out within 30 days lose the ability to sue in court or join a class action over billing or equipment disputes.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the arbitration/class-action-waiver terms are confirmed and company-specific; no data-privacy incident, breach, or lawsuit was independently confirmed for Frontpoint this pass, and the law-enforcement-disclosure concern in SCARY is industry-general, not Frontpoint-specific.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated, but no company-specific privacy incident or law-enforcement-disclosure policy was confirmed this pass.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Frontpoint Security  <-  Frontpoint Security Solutions, LLC (Reston, VA)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Frontpoint Security you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. The structural note for the whole home security category: these systems hold entry and exit timestamps, armed and disarmed states, camera footage and door sensor logs, which together constitute a precise record of when a home is empty and who comes and goes. Law enforcement request policies vary widely and are rarely prominent, and the industry's history - documented in the Ring row in Consumer Apps - includes voluntary disclosure programmes users did not knowingly opt into. Recommend a follow-up on Frontpoint's published law enforcement policy.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Home Security & Entertainment", "_row_id": 499, "_entity_id": 721, "_entity_slug": "frontpoint-security", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "SimpliSafe", "Category": "Home Security", "Terms & Conditions URL": "simplisafe.com/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "simplisafe.com/security-privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "GENUINELY POSITIVE FINDING RELATIVE TO COMPETITORS: independent privacy review found SimpliSafe has NOT had major publicized incidents of insider access abuse or data breaches affecting customer footage — a notable CONTRAST to Ring and ADT (both documented elsewhere in this tracker for serious insider-access and breach incidents respectively). SimpliSafe's indoor camera (SimpliCam) includes a PHYSICAL PRIVACY SHUTTER that mechanically covers the lens — providing hardware-level assurance the camera cannot record when closed, a meaningfully stronger protection than a software-only 'privacy mode' toggle that a hacked account or company insider could potentially override remotely. SimpliSafe does comply with valid law enforcement requests (subpoenas/court orders) and does NOT have proactive police-partnership programs (unlike Ring, which has drawn scrutiny for exactly this kind of arrangement elsewhere in this tracker).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. SimpliSafe ToS, AAA rules. 30-day opt-out. SimpliSafe's privacy positioning (no long-term contracts, no data selling) is reinforced by independent reviews but the arbitration clause means disputes over whether SimpliSafe keeps its privacy promises would be resolved individually, not as a class.", "Fees / Billing Flags": "SimpliSafe uses a CONTRACT-FREE model — no hefty cancellation fees, and professional monitoring can be activated/deactivated month-to-month (e.g., turned on only during vacation travel) without penalty, a genuinely more consumer-friendly billing structure than the long-term-contract models common elsewhere in the home-security industry.", "Notes": "This is one of the FEW clearly POSITIVE comparative findings in this entire tracker — SimpliSafe's hardware privacy shutter and clean breach record stand out specifically against Ring's documented employee-spying scandal and ADT's 2026 breach/extortion attempt, both in this same tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Boston", "HQ State": "Massachusetts", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Pending - severity 4/5, no source yet", "Region Basis": "HQ state 'Massachusetts' is a non-DMV US state", "Parent / Ultimate Owner": "SimpliSafe, Inc. (Hellman & Friedman majority stake)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Massachusetts SOC Corporate Search — corp.sec.state.ma.us/corpweb/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: SimpliSafe, Inc. (Hellman & Friedman majority stake)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] SimpliSafe still requires binding AAA arbitration with a class-action waiver despite its favorable privacy record\nWHAT THE TERMS SAY: SimpliSafe's Terms of Service impose mandatory binding arbitration under AAA rules with a class action waiver and a 30-day opt-out window; disputes over whether SimpliSafe keeps its privacy promises would be resolved individually, not as a class.\nWHY IT MATTERS: Even though SimpliSafe has an otherwise clean privacy record relative to competitors, customers who miss the 30-day window cannot band together in court if the company's privacy claims later prove false.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — This is one of the few comparatively positive rows in the tracker — no confirmed breach, insider-access abuse, or hidden fees were found; the only confirmed rights-limiting term is the standard arbitration/class-action-waiver clause.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "SimpliSafe's privacy practices, fee structure, and arbitration terms are all clearly and specifically documented this pass.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "SimpliSafe  <-  SimpliSafe, Inc. (Hellman & Friedman majority stake)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to stop paying by inaction.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using SimpliSafe you gave up your right to sue and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A genuinely positive finding relative to competitors, and per the project guide's standard it is recorded as such: independent privacy review has treated SimpliSafe more favourably than peers in a category with a poor overall record. The context that makes it meaningful is the comparison set - Ring's police partnership programme and Vivint's $20 million FTC settlement over credit report misuse are the peers. The honest caveat is that a favourable independent review is a snapshot, not a guarantee, and home security terms change with ownership and with the addition of camera and subscription features.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Home Security & Entertainment", "_row_id": 500, "_entity_id": 723, "_entity_slug": "simplisafe", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "AMC Theatres", "Category": "Entertainment", "Terms & Conditions URL": "amctheatres.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "amctheatres.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "NOTABLE COURT RULING (July 2025, Kansas federal court): a judge DISMISSED a proposed class action accusing AMC of unlawfully sharing website visitors' data with Facebook, specifically agreeing with the Ninth Circuit and multiple other courts that MOVIE THEATERS ARE NOT COVERED by the federal Video Privacy Protection Act (VPPA) — a genuinely important legal distinction from the VPPA cases that HAVE succeeded against streaming services elsewhere in this tracker (Chick-fil-A's video content, Paramount+): the VPPA specifically protects 'video tape service providers,' and courts have found a movie theater chain's WEBSITE tracking doesn't fall within that definition even though the underlying business (showing movies) seems conceptually similar.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. AMC ToS, AAA rules. 30-day opt-out. Covers AMC Stubs loyalty program and online ticket purchases. AMC emerged from the pandemic as a meme-stock phenomenon — the arbitration clause covers disputes over AMC's controversial APE preferred shares and the reverse stock split that followed.", "Fees / Billing Flags": "ACTIVE HIDDEN-FEE LITIGATION (ongoing as of Nov 2024): a class action alleges AMC unlawfully failed to include a 'convenience fee' in the STATED TOTAL COST of a movie ticket at the beginning of the online checkout process, in violation of New York's Arts and Cultural Affairs Law (the same law driving numerous similar settlements against Fandango, Alamo Drafthouse, ATG Tickets, and other ticketing platforms documented in this same research — see Fandango row for the fullest treatment of this cross-industry pattern).", "Notes": "The DISMISSED video-privacy claim (movie theaters fall outside VPPA) is a useful, precise legal distinction worth flagging — it means AMC-style companies face LESS video-privacy exposure than streaming services, even though both involve people watching video content, purely because of how VPPA's statutory language has been interpreted by courts.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025, 1988", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] Active lawsuit alleges AMC hid ticket convenience fees from the total price shown at checkout\nWHAT THE TERMS SAY: An ongoing class action alleges AMC failed to include a 'convenience fee' in the stated total cost of a movie ticket at the start of online checkout, violating New York's Arts and Cultural Affairs Law — the same law behind settlements against Fandango, Alamo Drafthouse, and other ticketing platforms.\nWHY IT MATTERS: Customers may commit to a purchase before seeing the true final price — the same practice that drove numerous similar settlements against Fandango, Alamo Drafthouse, ATG Tickets and other ticketing platforms under the same New York law.\n(evidence: Fees; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] AMC requires binding AAA arbitration with a class-action waiver, covering ticket and loyalty-program disputes\nWHAT THE TERMS SAY: AMC's Terms of Service impose mandatory binding arbitration under AAA rules with a class action waiver and a 30-day opt-out, covering the AMC Stubs loyalty program, online ticket purchases, and disputes over its APE preferred shares and reverse stock split.\nWHY IT MATTERS: Customers who don't opt out within 30 days cannot sue AMC in court or join a class action, including over the hidden-fee allegations above.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] A dismissed lawsuit still describes AMC sharing website visitor data with Facebook, just not in a way VPPA covers\nWHAT THE TERMS SAY: A proposed class action accused AMC of sharing website visitors' data with Facebook; a Kansas federal judge dismissed the case in July 2025 on the narrow ground that movie theaters are not 'video tape service providers' covered by the federal Video Privacy Protection Act — the ruling narrowed the statute's reach, not the underlying tracking conduct.\nWHY IT MATTERS: AMC customers have less legal recourse for this kind of tracking than customers of streaming services would for the same practice, purely due to how a 1988 statute defines the business.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and fee litigation are clearly documented, but the underlying data-sharing conduct was never adjudicated on the merits.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 10/20 (severity3+8, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "AMC Theatres  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using AMC Theatres you gave up your right to sue, your right to join a class action, and your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The July 2025 Kansas ruling is a useful precedent in the opposite direction from most findings in this tracker: a judge dismissed a proposed Video Privacy Protection Act class action on the reasoning that a movie theatre is not a 'video tape service provider' within the meaning of the 1988 statute. That matters because VPPA has become the most productive consumer privacy tool of the streaming era, providing statutory damages without proof of harm - and this ruling marks a boundary on how far a statute drafted around video rental stores can be stretched. AMC still runs website tracking and a large loyalty programme; the ruling narrows one statute, not the conduct.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Home Security & Entertainment", "_row_id": 501, "_entity_id": 724, "_entity_slug": "amc-theatres", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Regal Cinemas (Cineworld Group)", "Category": "Entertainment", "Terms & Conditions URL": "regmovies.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "regmovies.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same STRUCTURAL VPPA EXEMPTION as AMC (see that row) — courts have found movie theaters generally fall outside the federal Video Privacy Protection Act's coverage, meaning Regal likely shares AMC's reduced video-privacy litigation exposure compared to streaming services documented elsewhere in this tracker.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Regal Crown Club ToS. 30-day opt-out. Cineworld Group (Regal's parent) emerged from Chapter 11 bankruptcy in July 2023. The pre-bankruptcy arbitration clause survived restructuring.", "Fees / Billing Flags": "Not itemized this pass beyond the broader New York ticketing-fee settlement wave noted in the Fandango row, which may plausibly extend to Regal given how widespread that specific litigation pattern has been across the ticketing industry.", "Notes": "Regal's parent, Cineworld Group, went through its OWN Chapter 11 bankruptcy restructuring (2022-2023) — similar to the QVC Group and Spirit Airlines bankruptcy situations documented elsewhere in this tracker — worth noting this financial history given how it can affect customer gift-card/loyalty-program honoring.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "1988", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Regal's Crown Club terms impose binding arbitration with a class-action waiver that survived Cineworld's bankruptcy\nWHAT THE TERMS SAY: Regal Crown Club's Terms of Service impose mandatory binding arbitration with a class action waiver and a 30-day opt-out window; the clause predates and survived Cineworld's 2022-2023 Chapter 11 bankruptcy restructuring.\nWHY IT MATTERS: Customers who don't opt out within 30 days give up the right to sue Regal in court or join a class action, a limitation that carried through the company's bankruptcy.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — The VPPA-exemption discussion is the same finding already recorded for AMC (cross-referenced, not independently confirmed for Regal), and the ticketing-fee wave is only 'plausibly' extended to Regal without confirmation; only the arbitration clause is a confirmed, Regal-specific term this pass.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are confirmed and specific, but the video-privacy and ticketing-fee findings are only extrapolated from other companies' rows, not independently confirmed for Regal.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Regal Cinemas (Cineworld Group)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Regal Cinemas (Cineworld Group) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same structural VPPA exemption as AMC - courts have found movie theatres fall outside the statute's definition of a video tape service provider. Recorded as one finding across both rows rather than two independent assessments. The practical consequence for a consumer is worth stating plainly: whether you have a remedy for the same tracking conduct depends less on what was done to you than on how a 1988 statute happened to define the business doing it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Home Security & Entertainment", "_row_id": 502, "_entity_id": 725, "_entity_slug": "regal-cinemas-cineworld-group", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fandango (incl. RottenTomatoes.com)", "Category": "Entertainment/Ticketing", "Terms & Conditions URL": "fandango.com/policies/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "fandango.com/policies/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "NEW, ACTIVE TRACKING-PIXEL LAWSUIT (filed Jan 15, 2026): alleges Fandango unlawfully implemented THIRD-PARTY TRACKING PIXELS on RottenTomatoes.com (a Fandango-owned property) to collect and profit from user data — part of the same broader pixel-tracking litigation wave documented throughout this tracker, here notably applied to a MOVIE-REVIEW site rather than the direct ticketing platform itself.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Fandango Media ToS (NBCUniversal/Comcast subsidiary). 30-day opt-out. Covers Fandango, Rotten Tomatoes, Vudu, and FandangoNOW. A consumer checking Rotten Tomatoes scores before buying a Fandango ticket is bound by the same arbitration clause for both activities.", "Fees / Billing Flags": "MAJOR COMPLETED SETTLEMENT (Dec 10, 2024): Fandango Media agreed to pay UP TO $9 MILLION to resolve a class action alleging it failed to TIMELY DISCLOSE a 'convenience fee' for online movie-ticket purchases at New York theaters, in violation of New York's Arts and Cultural Affairs Law — part of a REMARKABLY CONSISTENT wave of nearly identical settlements against other ticketing platforms under the same New York law: Alamo Drafthouse ($7M+), ATG Tickets ($997K+), Atom Tickets ($550K), Gotham Comedy Club ($716K+), Film Forum ($413K+), One World Observatory ($975K), Museum of Illusions NY ($580K+), and Splish Splash ($1M) all settled comparable 'hidden ticket fee' claims within roughly the same 18-month window.", "Notes": "The SHEER VOLUME and CONSISTENCY of these ticketing-fee settlements under ONE SPECIFIC New York state law is a genuinely notable pattern — nearly every major New York-area ticketing platform has now paid a settlement over essentially the same 'hidden convenience fee' practice, suggesting this was a widespread industry practice rather than any single company's isolated choice.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Comcast Corporation (NBCUniversal subsidiary)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] Fandango paid up to $9 million to settle claims it hid ticket convenience fees from customers\nWHAT THE TERMS SAY: Fandango Media agreed to pay up to $9 million (Dec 10, 2024) to resolve a class action alleging it failed to timely disclose a 'convenience fee' for online movie-ticket purchases at New York theaters, violating New York's Arts and Cultural Affairs Law.\nWHY IT MATTERS: Customers paid more than the price they were initially shown, a pattern that produced nearly identical settlements across the ticketing industry.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] A new lawsuit alleges Fandango put tracking pixels on Rotten Tomatoes to collect and profit from user data\nWHAT THE TERMS SAY: A lawsuit filed Jan 15, 2026 alleges Fandango unlawfully implemented third-party tracking pixels on RottenTomatoes.com to collect and profit from user data; unlike AMC and Regal's theater websites, Fandango is a video-adjacent site squarely within VPPA's scope.\nWHY IT MATTERS: Because Fandango also owns Rotten Tomatoes, a user's ticket purchases and film research can be combined into a single tracked profile; the allegations are unproven.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Fandango's arbitration clause covers Fandango, Rotten Tomatoes, Vudu, and FandangoNOW under one waiver\nWHAT THE TERMS SAY: Fandango Media's Terms of Service (an NBCUniversal/Comcast subsidiary) impose mandatory binding arbitration with a class action waiver and a 30-day opt-out, covering Fandango, Rotten Tomatoes, Vudu, and FandangoNOW — so checking a Rotten Tomatoes score binds a consumer to the same arbitration clause as buying a ticket.\nWHY IT MATTERS: Customers may not realize that simply browsing Rotten Tomatoes subjects them to the same rights-limiting arbitration terms as making a purchase.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=Y; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The $9M fee settlement is fully confirmed and specific, but the new tracking-pixel lawsuit is an unresolved 2026 allegation.", "Exposure Score (0-100)": 39, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 8/30 (data_sold_or_shared_for_value+8) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 4/20 (severity2+2, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Fandango (incl. RottenTomatoes.com)  <-  Comcast Corporation (NBCUniversal subsidiary)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Fandango (incl. RottenTomatoes.com) you gave up your personal data sold onward, your right to sue, your right to join a class action, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The January 2026 tracking-pixel suit against Fandango sits on the other side of the line the AMC and Regal rulings drew: Fandango is a website that streams video content, which brings it within the Video Privacy Protection Act's scope in a way a theatre operator is not. Same underlying conduct, different statutory outcome, decided by what kind of business the defendant is. Fandango also owns Rotten Tomatoes, so a user's browsing across ticket purchases and film research sits in one profile. Allegations, not findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Home Security & Entertainment", "_row_id": 503, "_entity_id": 726, "_entity_slug": "fandango-incl-rottentomatoes-com", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "ESPN+ (Disney)", "Category": "Streaming (sports)", "Terms & Conditions URL": "espn.com/espnplus/terms-of-use (governed by Disney's overall streaming Terms)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "espn.com/espnplus/privacy-policy (governed by Disney's overall streaming Terms)", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SEPARATE, RELATED FINDING: independent litigation tracking found a class action alleging hidden third-party trackers on ESPN.com (the broader ESPN website, not necessarily ESPN+ subscription content specifically) collect and share sensitive user/behavior data without consent — filed the same week (Jan 2026) as the similar Fandango/RottenTomatoes.com pixel case documented elsewhere in this tab.", "Arbitration / Class Action Waiver": "ESPN+ is a Disney-owned property — see the Disney+/Hulu row (Consumer Apps tab) for Disney's own broader $10M FTC COPPA settlement and general streaming-platform privacy framework, which likely extends structurally to ESPN+ given shared Disney ownership.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up specifically distinguishing ESPN.com's general website tracking (subject to the pixel lawsuit above) from ESPN+'s subscription-video-specific data practices, since these may be governed by different specific policies despite shared corporate ownership.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "The Walt Disney Company", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] A 2026 lawsuit alleges hidden third-party trackers on ESPN.com share sensitive user data without consent\nWHAT THE TERMS SAY: A class action filed in January 2026 alleges hidden third-party trackers on ESPN.com (the broader ESPN website, not necessarily ESPN+ subscription content specifically) collect and share sensitive user and behavioral data without consent — filed the same week as a similar pixel case against Fandango/RottenTomatoes.com.\nWHY IT MATTERS: If proven, visitors to ESPN's site may have had sensitive behavioral data — including sports-following patterns that can reveal geography, national origin, and betting-related interests — shared with third parties without their knowledge.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the ESPN.com tracking-pixel allegation is specific to this row; the arbitration/COPPA reference is Disney's separate Disney+/Hulu finding extended only by inference, and fees are not itemized.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Only a newly filed, unresolved tracking-pixel lawsuit is specific to ESPN+/ESPN.com; arbitration and fee terms rely on inference from Disney's other properties rather than confirmation.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (data_sold_or_shared_for_value+8) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only", "Entity Type": "App / Service", "Ownership Path": "ESPN+ (Disney)  <-  The Walt Disney Company", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using ESPN+ (Disney) you gave up your personal data sold onward. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Streaming services are squarely within the Video Privacy Protection Act, which is why class actions in this category are numerous and why the AMC and Regal theatre rulings matter as a contrast. The ESPN+ specific note is that sports streaming data is unusually inferential: which teams you follow maps to geography and often to national origin, and betting-adjacent content consumption is a financial behaviour signal now that sportsbook integration is standard. Disney's overall data practices govern - cross-ref the Disney rows elsewhere in this tracker.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Home Security & Entertainment", "_row_id": 504, "_entity_id": 727, "_entity_slug": "espn-disney", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "TJX (TJ Maxx/Marshalls/HomeGoods)", "Category": "Retail", "Terms & Conditions URL": "tjmaxx.tjx.com/store/help/tos.jsp", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "tjmaxx.tjx.com/store/help/privacyPolicy.jsp", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ONE OF THE LARGEST, MOST HISTORICALLY SIGNIFICANT DATA BREACHES EVER RECORDED (2007): the TJX Companies breach (encompassing TJ Maxx, Marshalls, HomeGoods, and other TJX brands) exposed AT LEAST 46 MILLION consumer records — at the time, the LARGEST data breach ever publicly disclosed, surpassing the previous record (CardSystems, 40 million, 2005). Attackers exploited a VULNERABLE WIRELESS NETWORK starting July 2005, operating UNDETECTED for approximately 18 MONTHS before TJX discovered the intrusion in December 2006 (publicly disclosed January 2007). The attack was orchestrated by ALBERT GONZALEZ, a notorious hacker who was SIMULTANEOUSLY a secret informant for the US Secret Service — a genuinely remarkable detail, since the person responsible for one of history's largest breaches was, at the same time, working for federal law enforcement. Security experts specifically criticized TJX for failing to PROMPTLY DELETE old customer transaction data and for unclear encryption practices. Multiple banking associations (Massachusetts, Maine, Connecticut) sued TJX directly to recover the costs of reissuing compromised cards.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. TJX Companies ToS. 30-day opt-out. The 2005 TJX breach (45.7M cards, FTC consent order 2008 with 20-year audit requirement) established that the FTC Act alone was insufficient to impose civil penalties for data breaches — the FTC had to settle for a security-audit requirement. The arbitration clause post-dates that breach.", "Fees / Billing Flags": "NOTABLE, ONGOING PRACTICE: TJX stores (and many other retailers) use a THIRD-PARTY SERVICE called 'THE RETAIL EQUATION' to track and LIMIT customer RETURNS across participating stores — documented customer complaints describe being told they cannot make another return for MONTHS based on a centralized cross-retailer return history the customer has no direct visibility into or control over, with store staff sometimes unable to explain the specific policy or provide transparency into how the tracking works.", "Notes": "The Albert Gonzalez detail (hacker AND federal informant simultaneously) is one of the most genuinely remarkable facts uncovered in this entire 400+ company tracker. Separately, 'The Retail Equation' return-tracking system is a good illustration of a lesser-known, ongoing consumer-surveillance practice — worth flagging since it operates largely invisibly to customers until they're unexpectedly denied a return.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$60.4B", "Market Cap": "$171.7B", "Employees": "364,000", "HQ City": "Framingham", "HQ State": "Massachusetts", "CEO": "Ernie Herrman", "Ticker": "TJX", "Website (Corporate)": "tjx.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (TJX). Service route: c/o General Counsel / Corporate Secretary, Framingham, Massachusetts — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.ftc.gov/legal-library/browse/cases-proceedings/072-3055-tjx-companies-inc-matter", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Massachusetts' is a non-DMV US state", "Parent / Ultimate Owner": "The TJX Companies, Inc.", "Years Referenced in Finding (heuristic)": "2005, 2006", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Massachusetts SOC Corporate Search — corp.sec.state.ma.us/corpweb/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: The TJX Companies, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] The 2007 TJX breach exposed at least 46 million (possibly up to 94 million) card records after 18 months undetected\nWHAT THE TERMS SAY: Attackers cracked weak WEP Wi-Fi encryption at a Miami-area Marshalls starting July 2005, reached TJX's central payment servers, and went undetected for roughly 18 months until TJX discovered the intrusion in December 2006; at least 46 million records were exposed, with some estimates as high as 94 million. Canada's Privacy Commissioner found TJX collected too much data, kept it too long, and used weak encryption, and investigators found TJX non-compliant with 9 of 12 PCI DSS requirements.\nWHY IT MATTERS: Millions of customers' card data sat exposed for a year and a half because of avoidable security failures, ultimately costing over $250 million, including $41 million to Visa issuers, up to $24 million to Mastercard issuers, and $9.75 million to 41 state attorneys general.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-4] A third-party service tracks customers' returns across retailers and can block further returns for months without explanation\nWHAT THE TERMS SAY: TJX stores use a third-party service called 'The Retail Equation' to track and limit customer returns across participating retailers; documented customer complaints describe being blocked from making another return for months based on a centralized cross-retailer history the customer cannot see or control, and store staff are sometimes unable to explain the policy.\nWHY IT MATTERS: A customer can be penalized based on a hidden, cross-company profile of their return behavior with no visibility into what triggered the restriction.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[REGULATORY_PENALTY · FL-1] The FTC could not fine TJX at all for the breach — only impose a 20-year security-audit requirement\nWHAT THE TERMS SAY: TJX's 2008 FTC consent order carried no fine because the FTC lacked authority to levy civil penalties under the FTC Act for this kind of violation; TJX was instead required to maintain a security program and undergo audits every two years for twenty years.\nWHY IT MATTERS: The federal regulator imposed no fine at all; TJX's costs instead ran through other channels, with total cost exceeding $250 million including roughly $41 million to Visa's issuers, up to $24 million to MasterCard's, and $9.75 million to 41 state attorneys general.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The breach, its costs, and the FTC's regulatory response are all specifically documented with dates, dollar figures, and named consequences.", "Exposure Score (0-100)": 48, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "TJX (TJ Maxx/Marshalls/HomeGoods)  <-  The TJX Companies, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using TJX (TJ Maxx/Marshalls/HomeGoods) you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Attackers broke into TJX in July 2005 by cracking the WEP encryption on the Wi-Fi at a Miami-area Marshalls, then moved to the central payment servers and sat there undetected for roughly a year and a half - TJX only noticed in December 2006. At least 45.7 million cards, with some estimates as high as 94 million. Canada's Privacy Commissioner concluded TJX had collected too much information, kept it too long, and relied on weak encryption to protect it, and investigators found the company non-compliant with 9 of the 12 PCI DSS requirements. Total cost exceeded $250 million: roughly $41 million to Visa's issuers, up to $24 million to MasterCard's, $9.75 million to 41 state attorneys general. The FTC settlement carried no fine at all - the FTC lacked authority to levy civil penalties under the FTC Act - only a mandated security programme and biennial audits for twenty years.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Retail & Fintech", "_row_id": 505, "_entity_id": 729, "_entity_slug": "tjx-tj-maxx-marshalls-homegoods", "_issuer": "The TJX Companies, Inc.", "_issuer_slug": "the-tjx-companies-inc", "_ticker": "TJX", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ross Dress for Less", "Category": "Retail", "Terms & Conditions URL": "rossstores.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "rossstores.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Ross Stores ToS. 30-day opt-out. Ross's online presence is minimal (no e-commerce) so the T&C primarily governs the website/app, not purchase disputes — in-store purchase disputes would be governed by state consumer-protection law, not the website ToS.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Ross is the largest off-price retailer in the US (1,650+ stores) but maintains a notably thin digital footprint compared to competitors — Ross does not offer the same level of e-commerce/app functionality as TJX brands, which may correspondingly reduce (but not eliminate) its online tracking-related privacy exposure. Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Ross imposes mandatory arbitration and a 30-day opt-out despite its minimal e-commerce footprint\nWHAT THE TERMS SAY: Ross Stores' Terms of Service require mandatory binding arbitration with a class action waiver and a 30-day opt-out window, but only govern the website/app — in-store purchase disputes are governed separately by state consumer-protection law.\nWHY IT MATTERS: Customers who don't opt out within 30 days give up court access and class-action rights for any website/app dispute, even though Ross's core business is in-store.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No confirmed data-privacy incident or lawsuit was found for Ross this pass; only the standard arbitration/class-action-waiver clause is a confirmed, company-specific term, and the in-store tracking concern in SCARY is a general industry point, not a documented Ross-specific practice.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Almost every field states 'not independently confirmed'; only the arbitration clause is a confirmed, specific term.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Ross Dress for Less  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ross Dress for Less you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Off-price retail generally holds less data than full-price retail because a large share of transactions are cash or card-only with no loyalty programme attached - which is, unusually in this tracker, a genuine structural privacy advantage arising from a business model rather than from any deliberate choice. The countervailing note is in-store analytics: Wi-Fi and camera based footfall measurement operates on customers who never identified themselves and never saw a notice. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Retail & Fintech", "_row_id": 506, "_entity_id": 730, "_entity_slug": "ross-dress-for-less", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Dick's Sporting Goods", "Category": "Retail (sporting goods)", "Terms & Conditions URL": "dickssportinggoods.com/s/terms-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "dickssportinggoods.com/s/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED 2024 DATA BREACH: Dick's disclosed to the SEC that an unauthorized third party accessed confidential company information; multiple law firms opened investigations. SEPARATE, EARLIER TRACKING-TECHNOLOGY CLASS ACTION (Asad v. Dick's Sporting Goods, C.D. Cal., filed 2022): alleged the company's website tracking tools disclosed personal information to Google and other third parties in violation of California privacy law and the federal Wiretap Act.", "Arbitration / Class Action Waiver": "A GENUINELY SIGNIFICANT, DETAILED ARBITRATION OUTCOME: Dick's successfully compelled the tracking lawsuit into ARBITRATION (JAMS) in March 2023 — but rather than the case simply disappearing, arbitrator Hon. Gail Andler conducted a FULL MERITS HEARING across multiple days (April-May 2025), with expert testimony on data flows and technical architecture, ultimately issuing a FINAL AWARD IN DICK'S FAVOR (Dec 8, 2025) — finding the communications were NOT intercepted 'in transit' (a key legal threshold for wiretapping-based claims) and that CONSTRUCTIVE CONSENT existed. The plaintiff then challenged the award in federal court, but the Central District of California CONFIRMED the arbitration award (Feb 19, 2026), finding no grounds to overturn it under the Federal Arbitration Act's extremely limited judicial review standard. Legal commentary describes this as a rare instance of a defendant achieving 'complete finality' in a CIPA/pixel-tracking case — most such cases either settle or get dismissed on preliminary grounds, rather than going through a FULL MERITS hearing and surviving judicial review.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is one of the FEW cases in this entire tracker where an arbitration clause was tested through a COMPLETE MERITS PROCESS (not just a procedural dismissal) and the company WON on the substance — worth flagging as a meaningfully different outcome from most other pixel-tracking cases in this tracker, which either settle for money or get dismissed/proceed without a full evidentiary resolution.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$17.2B", "Market Cap": "$18.8B", "Employees": "37,350", "HQ City": "Coraopolis", "HQ State": "Pennsylvania", "CEO": "Lauren Hobart", "Ticker": "DKS", "Website (Corporate)": "dickssportinggoods.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (DKS). Service route: c/o General Counsel / Corporate Secretary, Coraopolis, Pennsylvania — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Dick's disclosed a 2024 breach to the SEC, where the tracker notes investors often learn before customers\nWHAT THE TERMS SAY: Dick's Sporting Goods disclosed to the SEC that an unauthorized third party accessed confidential company information; multiple law firms opened investigations. Because this surfaced via the SEC's cybersecurity disclosure rules, it followed investor-protection timing rather than consumer-notification law.\nWHY IT MATTERS: Investors may learn about a breach before affected customers do, since securities-disclosure timelines and consumer-notification timelines run on different tracks.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] A now-arbitrated lawsuit alleged Dick's website trackers disclosed customer data to Google without consent\nWHAT THE TERMS SAY: A 2022 class action (Asad v. Dick's Sporting Goods) alleged the company's website tracking tools disclosed personal information to Google and other third parties, in violation of California privacy law and the federal Wiretap Act.\nWHY IT MATTERS: An arbitrator ultimately ruled in Dick's favor, finding no interception 'in transit' and constructive consent — but only after the case went through a full arbitration process rather than being dismissed early.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Dick's compelled the tracking case into arbitration and won a rare, court-confirmed final award\nWHAT THE TERMS SAY: Dick's compelled the case into JAMS arbitration in March 2023; after a multi-day merits hearing with expert testimony (April-May 2025), the arbitrator issued a final award for Dick's (Dec 8, 2025), and a federal court confirmed the award in February 2026 under the FAA's narrow review standard.\nWHY IT MATTERS: The tracker records this as one of the few cases where an arbitration clause was tested through a complete merits process rather than a procedural dismissal, with the company winning on the substance and the award surviving federal-court review.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The breach disclosure and the full arbitration process, including dates and outcomes, are documented in detail.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 8/30 (data_sold_or_shared_for_value+8) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Dick's Sporting Goods  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Dick's Sporting Goods you gave up your personal data sold onward and your right to sue. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2024 breach was disclosed to the SEC, which is worth noting as a mechanism: since the SEC's cybersecurity disclosure rules took effect, material incidents surface through securities filings on a timeline set by investor-protection law rather than by consumer notification law. Investors frequently learn before customers do. Sporting goods retail also carries a specific sensitivity - firearms and hunting purchase records, where Dick's has a well-publicised policy history - and purchase data in that category is of interest to parties well beyond advertisers.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Retail & Fintech", "_row_id": 507, "_entity_id": 731, "_entity_slug": "dick-s-sporting-goods", "_issuer": "Dick's Sporting Goods", "_issuer_slug": "dick-s-sporting-goods", "_ticker": "DKS", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ulta Beauty", "Category": "Retail (beauty)", "Terms & Conditions URL": "ulta.com/company/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "ulta.com/company/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MULTIPLE BIPA (BIOMETRIC PRIVACY) CLASS ACTIONS over Ulta's 'GLAM LAB' virtual makeup try-on tool (launched 2016, expanded via a 2018 tech-startup acquisition): plaintiffs allege Ulta scans customers' FACIAL GEOMETRY via phone camera/app to let users virtually try on foundation shades, false eyelashes, and hair colors — WITHOUT disclosing this biometric collection or obtaining the written consent Illinois' BIPA requires, and without publishing the legally-required data retention/destruction policy. One case was later voluntarily DISMISSED (2023) — not confirmed whether by settlement or abandonment. Ulta's OWN CURRENT PRIVACY POLICY candidly confirms it collects 'Biometric Information' (facial geometry), 'Audio and Visual Information' (including recorded customer service calls), and even, in some cases, 'PERSONAL TEMPERATURE' — an unusually specific and sensitive data category rarely seen disclosed elsewhere in this tracker. Ulta's policy also explicitly states it 'sells' and 'shares' personal information (as defined under California law) with advertising/analytics/marketing partners, though it commits not to knowingly sell/share data of California residents 16 or younger.", "Arbitration / Class Action Waiver": "SEPARATE TRACKING-TECHNOLOGY LAWSUIT: Ulta was separately sued (2022) for allegedly using 'session replay' SPYWARE-STYLE software to record website visitors' interactions without knowledge/consent — the same pattern documented for Chewy, Michaels, and AutoZone elsewhere in this tracker.", "Fees / Billing Flags": "SEPARATE, UNRELATED WAGE-THEFT LITIGATION: distribution-center and retail employees have sued Ulta over allegedly UNPAID TIME spent undergoing mandatory security/bag checks after clocking out but before being allowed to leave — an employee wage issue, not a customer-privacy finding.", "Notes": "Ulta's own privacy policy disclosing 'personal temperature' as a collected data category is a genuinely unusual and specific finding worth flagging — few other companies in this entire tracker explicitly list body temperature among their disclosed data categories.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$12.4B", "Market Cap": "$20.8B", "Employees": "39,000", "HQ City": "Bolingbrook", "HQ State": "Illinois", "CEO": "Kecia Steelman", "Ticker": "ULTA", "Website (Corporate)": "ulta.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (ULTA). Service route: c/o General Counsel / Corporate Secretary, Bolingbrook, Illinois — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] Ulta's GLAM Lab try-on tool scans facial geometry, and multiple BIPA suits allege it lacked required consent\nWHAT THE TERMS SAY: Multiple Illinois BIPA class actions allege Ulta's GLAM Lab virtual try-on tool scans customers' facial geometry via phone camera to preview makeup, hair color, and lashes without the disclosure or written consent Illinois law requires, and without publishing a legally required data retention/destruction policy; one case was voluntarily dismissed in 2023 for unclear reasons.\nWHY IT MATTERS: Facial geometry is a biometric identifier under Illinois law; without proper consent and retention disclosures, customers cannot know how long their facial scans are kept or how they're used.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Ulta's own privacy policy discloses it collects customers' 'Personal Temperature' in some cases\nWHAT THE TERMS SAY: Ulta's current privacy policy confirms it collects 'Biometric Information' (facial geometry), 'Audio and Visual Information' (including recorded customer service calls), and, in some cases, 'Personal Temperature' — a data category rarely disclosed elsewhere in this tracker.\nWHY IT MATTERS: Customers are unlikely to expect that visiting or calling Ulta could result in collection of biometric, audio/visual or body-temperature data — a category the tracker notes few other companies in it explicitly disclose.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[DATA_SALE · FL-2] Ulta's privacy policy admits it 'sells' and 'shares' personal information with advertising and marketing partners\nWHAT THE TERMS SAY: Ulta's privacy policy explicitly states it 'sells' and 'shares' personal information (as defined under California law) with advertising, analytics, and marketing partners, while committing not to knowingly sell or share data of California residents 16 or younger.\nWHY IT MATTERS: Adult customers' data is confirmed to be monetized through sale/sharing with third parties, a practice the policy discloses but customers may not expect from a beauty retailer.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Biometric and data-sale practices are clearly documented from Ulta's own policy, but arbitration terms are unaddressed and one BIPA case's dismissal basis is unclear.", "Exposure Score (0-100)": 31, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 21, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 21/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, biometric_collection+6, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Ulta Beauty  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (10 of 13): your content used as AI training data; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ulta Beauty you gave up your personal data sold onward, your biometric identifiers, and your data shared corporate-wide. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The BIPA class actions concern Ulta's GLAM Lab virtual try-on, and the mechanism is the point: a feature that lets you see how lipstick would look requires mapping the geometry of your face, which is biometric identifier collection under Illinois law regardless of what the marketing calls it. Illinois BIPA requires informed written consent before collection and lets individuals sue without proving harm, which is why virtual try-on has become one of the most litigated features in retail. Ulta separately drew regulatory and litigation attention over reselling returned cosmetics. Allegations, not findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Retail & Fintech", "_row_id": 508, "_entity_id": 732, "_entity_slug": "ulta-beauty", "_issuer": "Ulta Beauty", "_issuer_slug": "ulta-beauty", "_ticker": "ULTA", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sephora (LVMH)", "Category": "Retail (beauty)", "Terms & Conditions URL": "sephora.com/beauty/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "sephora.com/beauty/california-privacy-notice", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED BIPA LAWSUIT (over Sephora's 'Virtual Artist' try-on kiosk/tool, developed with a Toronto-based technology vendor, Modiface): the complaint alleges Sephora's Virtual Artist Kiosk extracts customers' FACIAL GEOMETRY to digitally apply cosmetics to their image — the SAME underlying biometric-collection pattern documented for Ulta and Mary Kay in this same research — without adequate BIPA-required consent or disclosure of retention/destruction practices. Sephora and its vendor Modiface are both named defendants, illustrating (like several other findings in this tracker) how a THIRD-PARTY TECHNOLOGY VENDOR (not just the retailer itself) can be directly implicated in a biometric-privacy claim.", "Arbitration / Class Action Waiver": "This is one of at least THREE beauty retailers (Sephora, Ulta, Mary Kay) sued over structurally IDENTICAL virtual-try-on facial-scanning technology within the same general timeframe — suggesting this specific AR/beauty-tech category is a genuine industry-wide BIPA risk area, not any single company's isolated choice.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "SEPARATE CORPORATE CONTEXT: Sephora's parent company LVMH described Sephora's 2025 performance as 'remarkable' even amid a broader 'unfavourable' global luxury-retail environment — a business-performance detail, not a privacy finding, included for completeness.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2022", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] Sephora was the first company ever fined under the California Consumer Privacy Act\nWHAT THE TERMS SAY: In a 2022 enforcement action, Sephora became the first company fined under the CCPA; the finding centered on sharing consumer data with third-party analytics and advertising partners constituting a 'sale' under the statute even though no money changed hands for the data itself.\nWHY IT MATTERS: The action rested on the finding that sharing consumer data with third-party analytics and advertising partners counted as a 'sale' even though no money changed hands for the data itself — the reading the tracker says is why so many privacy policies now carefully distinguish 'sale' from 'sharing.'\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[BIOMETRICS · FL-2] Sephora's Virtual Artist kiosk, built with vendor Modiface, faces a BIPA suit for capturing facial geometry without adequate consent\nWHAT THE TERMS SAY: A BIPA lawsuit alleges Sephora's Virtual Artist Kiosk, developed with Toronto-based vendor Modiface, extracts customers' facial geometry to digitally apply cosmetics without adequate consent or disclosure of retention/destruction practices; both Sephora and Modiface are named defendants.\nWHY IT MATTERS: The claim shows that even a third-party technology vendor supplying the try-on feature can be directly implicated in a biometric-privacy violation alongside the retailer.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only the CCPA enforcement action and the Virtual Artist BIPA suit are Sephora-specific and substantive; the comparison to Ulta and Mary Kay is industry context rather than an independent Sephora finding, and arbitration/fee terms are not itemized.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The CCPA enforcement and BIPA suit are clearly documented, but arbitration and fee terms are not addressed this pass.", "Exposure Score (0-100)": 31, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 18, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 18/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "Sephora (LVMH)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (10 of 13): your content used as AI training data; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Sephora (LVMH) you gave up your personal data sold onward, your biometric identifiers, and your data shared corporate-wide. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Sephora's Virtual Artist try-on drew a BIPA suit on the same theory as Ulta's GLAM Lab - facial geometry captured to render a cosmetic preview. Sephora is separately significant for a different reason worth recording: it was the FIRST company fined under the California Consumer Privacy Act, in a 2022 enforcement action centred on the finding that sharing consumer data with third-party analytics and advertising partners constituted a 'sale' under the statute even though no money changed hands for the data itself. That reading is why so many privacy policies in this tracker now carefully distinguish 'sale' from 'sharing.'", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Retail & Fintech", "_row_id": 509, "_entity_id": 733, "_entity_slug": "sephora-lvmh", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Audible (Amazon)", "Category": "Digital Media", "Terms & Conditions URL": "audible.com/legal/conditions-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "audible.com/legal/privacy-notice", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as an Amazon subsidiary, Audible's account/billing data flows through Amazon's broader account infrastructure (documented extensively elsewhere in this tracker, including the $2.5B Prime dark-pattern settlement).", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Audible is an Amazon subsidiary governed by Amazon's Conditions of Use, which removed the arbitration clause entirely in July 2021.", "Fees / Billing Flags": "Audible's SUBSCRIPTION/CREDIT model (monthly credits redeemable for audiobooks) has drawn some consumer complaints about credit expiration and cancellation friction, though no formal class action was independently confirmed this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the Amazon row (Consumer Apps tab) for the broader parent-company dark-pattern/subscription findings that plausibly extend to Audible's own credit/subscription model.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Newark", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "PARENT ADDRESS ONLY — verify before using for legal notice. Audible, Inc. is a Newark, New Jersey-headquartered subsidiary. Parent: Amazon.com, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210, USA", "Legal / Privacy Contact Email": "Not verified this pass — Amazon routes privacy requests through its in-account privacy portal", "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New Jersey' is a non-DMV US state", "Parent / Ultimate Owner": "Amazon.com, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NJ Business Records Service — businessrecords.nj.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Amazon.com, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] Audible's credit-based subscription has drawn complaints over credit expiration and cancellation friction\nWHAT THE TERMS SAY: Audible's monthly-credit subscription model (credits redeemable for audiobooks) has drawn consumer complaints about credits expiring and friction when canceling, though no formal class action was independently confirmed this pass.\nWHY IT MATTERS: Customers may lose paid-for credits or find it harder than expected to cancel, though this remains an unconfirmed complaint pattern rather than a documented legal claim.\n(evidence: Fees; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the unconfirmed credit-expiration/cancellation-friction complaint is Audible-specific; the Prime dark-pattern settlement referenced is Amazon's own separate finding, not confirmed for Audible, and no breach or lawsuit specific to Audible was found this pass.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing was independently confirmed this pass beyond Audible's removal of mandatory arbitration; data-sharing and breach fields are unconfirmed.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Audible (Amazon)  <-  Amazon.com, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Audible (Amazon) you gave up your right to stop paying by inaction. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Audible's listening data is the same category the Video Privacy Protection Act was written to protect - a record of what specific media a named person consumed - and audiobook selection is at least as revealing as video, covering health, religion, sexuality, politics and self-help. Audible also holds progress data: not just what you bought but what you actually finished and where you stopped. Amazon ownership means it sits inside the largest retail data operation in the world. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Retail & Fintech", "_row_id": 510, "_entity_id": 734, "_entity_slug": "audible-amazon", "_issuer": "Amazon.com, Inc.", "_issuer_slug": "amazon-com-inc", "_ticker": "AMZN", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Grubhub", "Category": "Delivery", "Terms & Conditions URL": "grubhub.com/legal/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "grubhub.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED 2025 BREACH (active class action, Mintz v. Grubhub Holdings, Illinois federal court, filed Jan 19, 2026): alleges Grubhub became aware in JANUARY 2025 that unauthorized parties were downloading data from its systems, but had NOT YET NOTIFIED affected individuals as of the lawsuit's filing — nearly a YEAR after discovering the intrusion. Exposed data allegedly includes names, emails, phone numbers, home addresses, birthdates, SOCIAL SECURITY NUMBERS, VEHICLE INSURANCE INFORMATION, and DRIVER'S LICENSE NUMBERS for BOTH customers AND delivery drivers — the driver-specific data (insurance, license numbers) reflects the same 'gig workers carry more sensitive verification data than customers' pattern already documented for TaskRabbit elsewhere in this tracker.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Grubhub ToS. 30-day opt-out. The FTC + Illinois AG joint action ($25M settlement, Dec 2024) for deceptive fees, driver pay, and unauthorized restaurant listings happened while the arbitration clause was in effect. As an FTC action, it was not affected by the clause — but individual consumer claims over the same practices would be.", "Fees / Billing Flags": "SEPARATE, ALREADY-SETTLED MATTER: Grubhub agreed to a $7.15 MILLION settlement over allegations it added RESTAURANTS to its platform WITHOUT THEIR PERMISSION — a distinct business-practices issue affecting restaurant partners rather than consumers/drivers directly.", "Notes": "The near-year-long gap between Grubhub allegedly discovering the breach (Jan 2025) and the lawsuit alleging it STILL had not notified affected individuals (Jan 2026) is one of the LONGEST documented notification delays in this entire tracker — worth flagging prominently given how much this exceeds typical state breach-notification deadlines (often 30-90 days).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Just Eat Takeaway.com (Amsterdam, acquired 2021)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Suit alleges Grubhub knew of the breach in Jan 2025 and still hadn't notified victims a year later\nWHAT THE TERMS SAY: An active class action (Mintz v. Grubhub Holdings, filed Jan 19, 2026) alleges Grubhub became aware in January 2025 that unauthorized parties were downloading data from its systems, and had still not notified affected individuals as of the January 2026 filing. Exposed data allegedly includes names, emails, phone numbers, addresses, birthdates, Social Security numbers, and driver's license and vehicle insurance information for both customers and delivery drivers.\nWHY IT MATTERS: A near year-long notification gap, if the allegation holds, leaves SSNs and driver credentials circulating far longer than the 30-90 day windows most state breach laws require.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-1] FTC + Illinois AG settled for $25M over deceptive fees, driver pay, unauthorized restaurant listings\nWHAT THE TERMS SAY: The FTC and Illinois Attorney General brought a joint action resulting in a $25M settlement (Dec 2024) over deceptive fees, driver pay practices, and unauthorized restaurant listings, while Grubhub's arbitration clause was in effect.\nWHY IT MATTERS: The FTC's own case wasn't blocked by arbitration, but an individual consumer trying to sue over the same deceptive-fee practices would have been routed into arbitration instead of court.\n(evidence: Arbitration; Stated in tracker (fidelity pass 1: Overstated corrected))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory binding arbitration with a class-action waiver, 30-day opt-out\nWHAT THE TERMS SAY: Grubhub's ToS impose mandatory binding arbitration with a class-action waiver, with a 30-day window to opt out.\nWHY IT MATTERS: Users who miss the 30-day window lose the ability to join a class action over billing, breach, or other disputes with Grubhub.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach and its allegedly year-long notification delay are documented via active litigation, but Grubhub's own confirmation and full scope remain outstanding.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 10/20 (severity2+2, breach+3, penalty+3, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Grubhub  <-  Just Eat Takeaway.com (Amsterdam, acquired 2021)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Grubhub you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Grubhub was confirmed in January 2026 as a victim of the ShinyHunters campaign - the first major company affected in 2026 - which places this row inside the master cross-reference documented in the F500 Tech & Semiconductors tab: more than a thousand organisations reached through vishing and stolen OAuth tokens, with no zero-day or malware at any stage. Food delivery data is a home address plus a routine plus a dietary and health signal. Grubhub is separately the lead plaintiff in one of the merchant damages trials against Visa and Mastercard - cross-ref the Credit Card Companies tab.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Retail & Fintech", "_row_id": 511, "_entity_id": 735, "_entity_slug": "grubhub", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google Fi", "Category": "Telecom (MVNO)", "Terms & Conditions URL": "fi.google.com/about/tos/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "fi.google.com/about/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "HISTORICAL CONFIRMED BREACH (2022): Google Fi disclosed that customer data was exposed as part of a broader breach at T-Mobile (whose network Google Fi partly relies on for service) — illustrating how an MVNO (mobile virtual network operator) like Google Fi can be affected by a breach at the underlying NETWORK CARRIER it depends on, even without its own direct systems being compromised. Google's overall $425M jury verdict, $135M Android settlement, and other privacy findings (documented in the Google row, Consumer Apps tab) also apply to Google Fi as a Google-operated service.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration — governed by Google's Terms of Service and the Google Fi Supplemental Terms. 30-day opt-out. Google Fi is a mobile virtual network operator (MVNO) using T-Mobile and US Cellular networks. The Google device arbitration clause applies to Fi-purchased devices; Fi service disputes are governed by the Fi supplemental terms.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the T-Mobile row (Carriers tab) for the underlying network breach that affected Google Fi customers — worth treating this as a connected finding given Google Fi's structural dependence on T-Mobile's network infrastructure.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "PARENT ADDRESS ONLY — verify before using for legal notice. Google Fi is an MVNO; the underlying carriers are separate entities (see the Carriers tab). Parent: Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "2022", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2022 T-Mobile network breach exposed Google Fi customer data via upstream carrier\nWHAT THE TERMS SAY: Google Fi disclosed that customer data was exposed as part of a broader breach at T-Mobile, the underlying network carrier Google Fi partly relies on as an MVNO, even though Google Fi's own systems were not directly compromised.\nWHY IT MATTERS: A customer who chose Google Fi specifically to get Google's security posture was instead exposed through a carrier relationship they never selected and were never told the name of.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration under Google's ToS and Fi Supplemental Terms, 30-day opt-out\nWHAT THE TERMS SAY: Google Fi disputes are governed by mandatory binding arbitration under Google's Terms of Service and the Fi Supplemental Terms, with a 30-day opt-out; device disputes fall under Google's device arbitration clause while service disputes fall under the Fi supplemental terms.\nWHY IT MATTERS: Which arbitration clause applies depends on whether the dispute is about the phone or the service, adding a layer of complexity a consumer must sort out before even opting out.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees are not itemized this pass and no third distinct consumer-facing harm is stated beyond the carrier-dependency breach and the arbitration terms; the row explicitly defers Google's own $425M and $135M findings to a separate Google (Consumer Apps) row.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2022 exposure is confirmed but described only structurally, through the T-Mobile relationship, rather than with Fi-specific scope figures.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Google Fi  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Google Fi you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2022 Google Fi disclosure is notable for what it reveals about mobile virtual network operators: Google Fi does not own network infrastructure, it resells capacity from underlying carriers, and the exposure came through that upstream relationship rather than through Google. A customer who chose Google Fi specifically because they trusted Google's security was exposed by a carrier they never selected and were never told the name of. Cross-ref the Carriers tab for the underlying operators' own records.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Retail & Fintech", "_row_id": 512, "_entity_id": 736, "_entity_slug": "google-fi", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cricket Wireless (AT&T)", "Category": "Telecom (prepaid)", "Terms & Conditions URL": "cricketwireless.com/legal/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "cricketwireless.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MASSIVE CONFIRMED 2024 BREACH: Cricket Wireless (an AT&T-owned prepaid brand) was one of MANY organizations swept up in the massive SNOWFLAKE cloud-platform breach (the same underlying attack campaign that hit AT&T, Ticketmaster, Santander Bank, and 160+ other organizations, all using improperly-secured Snowflake accounts) — exposing CALL AND TEXT RECORDS (plus cell site ID numbers and phone numbers) for nearly ALL Cricket Wireless customers with activity between May-October 2022 and Jan 2023, affecting approximately 10 MILLION customers. Cricket learned of the breach in April 2024 but did NOT notify customers until July 2024 — a 3-month delay. Cricket was included in AT&T's combined $177 MILLION settlement (covering both the March 2024 AT&T breach and this July 2024 Snowflake breach) — the AT&T 2 settlement fund specifically ($28M, covering the Snowflake-linked breach affecting BOTH AT&T and Cricket customers, ~36.4 million class members) offered up to $2,500 for documented losses, with customers hit by BOTH breaches eligible for up to $7,500 combined. The online claim deadline (Dec 18, 2025) has passed, with a 4.8% claims-participation rate reported — notably higher than most data breach settlements.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver — governed by AT&T's Terms & Conditions. AT&T's arbitration clause is the one upheld by the Supreme Court in AT&T Mobility v. Concepcion (2011), the landmark decision that made class action waivers broadly enforceable nationwide. Cricket customers are bound by the same clause that changed US consumer law.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Cricket Wireless is directly connected to the AT&T breach settlement already documented in the Carriers tab of this tracker — worth treating this as ONE connected finding (same parent company, same underlying Snowflake attack) rather than two fully separate incidents.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "PARENT ADDRESS ONLY — verify before using for legal notice. Cricket Wireless LLC is an AT&T sub-brand with its own entity. Parent: AT&T Chief Privacy Office, 208 S. Akard St., Room 2901, Dallas, TX 75202, USA (AT&T also operates a Data Request Center and a Global Legal Demand Center for law-enforcement demands)", "Legal / Privacy Contact Email": "privacypolicy@att.com", "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "AT&T Inc.", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Snowflake breach exposed call/text records for ~10M Cricket customers; 3-month notify delay\nWHAT THE TERMS SAY: Cricket was swept into the 2024 Snowflake cloud-platform breach, exposing call and text records, cell site IDs, and phone numbers for nearly all customers with activity between May-October 2022 and January 2023, affecting roughly 10 million customers. Cricket learned of the breach in April 2024 but did not notify customers until July 2024.\nWHY IT MATTERS: Call and cell-site records reveal who a person spoke to and roughly where, and a 3-month gap between discovery and notice left customers unaware they should watch for fraud.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Bound by the AT&T arbitration clause the Supreme Court used to bless class-action waivers\nWHAT THE TERMS SAY: Cricket customers are bound by AT&T's mandatory arbitration clause with a class-action waiver, the same clause upheld in AT&T Mobility v. Concepcion (2011), the decision that made such waivers broadly enforceable.\nWHY IT MATTERS: Individual Cricket customers harmed by the breach cannot band together in court; they are funneled into the same clause that changed nationwide consumer-arbitration law.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DISCRIMINATORY_PRACTICE · FL-2] Prepaid customer base is less able to absorb or even learn about the breach\nWHAT THE TERMS SAY: The tracker notes Cricket's prepaid, lower-income customer base is less likely to have credit monitoring, more likely to be harmed by identity theft, and less likely to be reached by a mailed notice because prepaid customers move addresses more often; the Cricket brand also obscures its AT&T parent in searches.\nWHY IT MATTERS: The population most exposed to downstream harm from the breach is also the population least likely to receive an effective notice or already have protective monitoring in place.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Scope and dates are well documented, but the breach is fragmented across two combined settlement funds and the claim window has already closed.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Cricket Wireless (AT&T)  <-  AT&T Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Cricket Wireless (AT&T) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2024 Cricket exposure came through the same AT&T-related incidents documented in the Carriers tab, and the structural finding is the prepaid distinction: Cricket serves a customer base that skews lower-income and includes many people who chose prepaid specifically to avoid a credit check and a long-term contract. Those customers are less likely to have credit monitoring, more likely to be harmed by identity theft, and least likely to be reached by a mailed breach notification because prepaid customers move addresses more often. The brand also obscures the parent, so affected customers searching for news about their carrier find nothing.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Retail & Fintech", "_row_id": 513, "_entity_id": 738, "_entity_slug": "cricket-wireless-at-t", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Dave", "Category": "Fintech (cash advance)", "Terms & Conditions URL": "dave.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "dave.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED HISTORICAL BREACH (July 2020, via third-party vendor Waydev): exposed personal information of approximately 7.5 MILLION Dave users — names, emails, birthdates, addresses, and HASHED passwords — plaintiffs argued Dave was slow to notify affected users.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Dave Inc. ToS, AAA rules. 30-day opt-out. Dave is a fintech company offering cash advances and banking services — the arbitration clause covers disputes over overdraft-alternative products marketed to consumers who may lack access to traditional banking.", "Fees / Billing Flags": "ACTIVE, SEPARATE FEE-DECEPTION LAWSUIT (settlement phase as of 2026): alleges Dave's marketing as 'no interest, no hidden costs' cash advances was misleading given its actual fee structure — a $100 advance with a $5 'express' transfer fee can carry an EFFECTIVE ANNUAL PERCENTAGE RATE EXCEEDING 200% when annualized, which the lawsuit argues is not what 'no interest' means to ordinary consumers. The complaint also alleges Dave presented OPTIONAL 'tips' in a way that functioned more like MANDATORY charges, and pushed users toward paid 'express' transfers while making the free standard-transfer option less obvious. Internal company communications revealed during discovery reportedly discussed Dave's fee-presentation STRATEGY directly.", "Notes": "The 200%+ effective APR calculation on a supposedly 'no interest' product is one of the most concrete, quantifiable predatory-lending-adjacent findings in this entire tracker — worth flagging prominently given how directly it illustrates the gap between a product's marketing and its actual cost structure, similar in spirit to the BNPL findings documented elsewhere in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2020", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-1] Lawsuit: 'no interest' cash advances can carry 200%+ APR; 'tips' function as near-mandatory\nWHAT THE TERMS SAY: An active fee-deception lawsuit (settlement phase as of 2026) alleges Dave marketed 'no interest, no hidden costs' cash advances while a $100 advance with a $5 express-transfer fee can carry an effective APR exceeding 200% when annualized; it also alleges Dave presented optional 'tips' in a way that functioned more like mandatory charges and steered users toward paid express transfers over a less-obvious free option.\nWHY IT MATTERS: A consumer relying on the marketing to mean genuinely interest-free borrowing would not expect an annualized cost north of 200%.\n(evidence: Fees; Tracker says unconfirmed (fidelity pass 1: Hedge lost corrected))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] 2020 breach via third-party vendor Waydev exposed 7.5M users' personal data\nWHAT THE TERMS SAY: A July 2020 breach via third-party vendor Waydev exposed personal information of approximately 7.5 million Dave users, including names, emails, birthdates, addresses, and hashed passwords; plaintiffs argued Dave was slow to notify affected users.\nWHY IT MATTERS: Cash-advance app users are, by definition, managing short-term liquidity problems, so the exposed user list is itself a financial-distress signal of value to lenders and collectors targeting vulnerable consumers.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory AAA arbitration with class-action waiver, 30-day opt-out\nWHAT THE TERMS SAY: Dave's ToS impose mandatory binding arbitration under AAA rules with a class-action waiver and a 30-day opt-out, covering disputes over its overdraft-alternative cash-advance products.\nWHY IT MATTERS: Consumers who don't opt out within 30 days lose the ability to join a class action over the same fee practices the pending lawsuit describes.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 200%+ APR figure and breach scope are concretely stated, but the fee-deception case is still only in settlement phase.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 7, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 7/20 (severity2+2, breach+3, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Dave  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Dave you gave up your right to sue, your right to join a class action, and your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The July 2020 Dave breach came through Waydev, a third-party analytics vendor - the same vendor-chain structure documented in the AMCA, SITA and Salesloft findings across this tracker. What makes it land harder here is the customer base: cash advance apps serve people managing short-term liquidity problems, so the user list is itself a financial-distress signal, and the transaction data describes exactly how close to the edge each person is. That dataset has obvious value to lenders, debt collectors and advertisers targeting financial products at vulnerable consumers.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Retail & Fintech", "_row_id": 514, "_entity_id": 739, "_entity_slug": "dave", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Earnin (Activehours, Inc.)", "Category": "Fintech (cash advance)", "Terms & Conditions URL": "earnin.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "earnin.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED, RECENT BREACH (disclosed to Texas AG, Nov 12, 2025): affected at least 21,178 Texas residents alone — total national scope not yet publicly disclosed, believed to span multiple states. Earnin pioneered the 'Earned Wage Access' (EWA) industry, letting users access up to $100/day and $500/pay-period of wages they've already earned before their official payday.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Earnin's User Agreement. 30-day opt-out. Earnin's earned-wage-access model (allowing workers to draw against unpaid wages before payday) has faced scrutiny from state regulators over whether it constitutes lending. The arbitration clause covers disputes over tip-based pricing and overdraft-like practices.", "Fees / Billing Flags": "Not itemized this pass beyond the breach above; Earned Wage Access products broadly (including Earnin, Dave, DailyPay, and Brigit) are under active MULTI-COMPANY investigation by consumer-protection attorneys examining fee structures and data practices across the entire EWA category — see the Dave row for a concrete example of the fee-structure concerns being examined industry-wide.", "Notes": "Earnin is part of a BROADER, ACTIVE INVESTIGATION into the entire Earned Wage Access industry (alongside DailyPay, Brigit, and Dave) — worth treating this as a connected, industry-wide pattern rather than isolated single-company issues, similar to the BNPL (Buy Now Pay Later) category findings documented elsewhere in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Nov 2025 breach disclosed to Texas AG; national scope still undisclosed\nWHAT THE TERMS SAY: Earnin disclosed a breach to the Texas Attorney General on November 12, 2025, affecting at least 21,178 Texas residents; the total national scope had not been publicly disclosed as of this pass.\nWHY IT MATTERS: Earned-wage-access data ties bank accounts to employment and pay timing, giving a more complete picture of a person's financial position than most banks hold, and the full number of people affected nationally is still unknown.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-2] Earnin is part of a multi-company probe into EWA fee structures and data practices\nWHAT THE TERMS SAY: Earnin, alongside Dave, DailyPay, and Brigit, is under active investigation by consumer-protection attorneys examining fee structures and data practices across the earned-wage-access category.\nWHY IT MATTERS: The scrutiny suggests Earnin's tip-based pricing and data practices are being examined as part of an industry-wide pattern, not treated as settled or clean.\n(evidence: Fees | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with class-action waiver, 30-day opt-out\nWHAT THE TERMS SAY: Earnin's User Agreement imposes mandatory binding arbitration with a class-action waiver and a 30-day opt-out, covering disputes over its tip-based pricing and overdraft-like practices.\nWHY IT MATTERS: A user who doesn't opt out within 30 days cannot join a class action over the tip-pricing practices currently under industry-wide investigation.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach is confirmed via a state AG filing, but full national scope and the outcome of the industry-wide fee investigation remain open.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Earnin (Activehours, Inc.)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Earnin (Activehours, Inc.) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Earnin disclosed a breach to the Texas Attorney General on November 12, 2025 - and the disclosure route is the practical lesson: state AG notification databases are frequently where breaches become public first, ahead of any company announcement. Earned wage access products connect to bank accounts and employment records, so the data is income timing, employer identity and spending behaviour combined. The business model also depends on knowing precisely when a user gets paid, which is a more complete picture of a person's financial position than most banks hold.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Retail & Fintech", "_row_id": 515, "_entity_id": 740, "_entity_slug": "earnin-activehours-inc", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Wyndham Hotels & Resorts", "Category": "Hotel chain (franchisor)", "Terms & Conditions URL": "https://www.wyndhamhotels.com/terms-of-use", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.wyndhamhotels.com/privacy-notice", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Wyndham Rewards ties stay history, room preferences, payment card type and co-guest names to a member profile shared across ~9,100 hotels and 20+ brands (Days Inn, Super 8, Ramada, La Quinta, Travelodge, Howard Johnson, Microtel). Privacy notices are published per-brand rather than once, so the document governing your stay depends which sign was on the building.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Wyndham Rewards ToS. 30-day opt-out. Covers 24 hotel brands (Wyndham, La Quinta, Days Inn, Super 8, Ramada, Howard Johnson, etc.). Wyndham paid $5.4M in a 2024 FTC settlement over data security failures.", "Fees / Billing Flags": "Resort fees and destination fees are charged at the property, not by the franchisor, and are a recurring subject of state attorney general action across the sector.", "Notes": "URL STATUS: T&C NOT verified this pass - expected location, confirm on click; privacy notice path VERIFIED this pass in the form wyndhamhotels.com/<brand>/about-us/privacy-notice — Wyndham publishes brand-specific privacy pages (e.g. /days-inn/about-us/privacy-notice), so confirm the one matching your brand. SEPARATE ENTITY WARNING: Travel + Leisure Co. (Club Wyndham, WorldMark, Margaritaville Vacation Club) is a DIFFERENT company from Wyndham Hotels & Resorts following the 2018 split, and publishes its own privacy notice. Searching 'Wyndham privacy policy' returns the timeshare company at least as often as the hotel company.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Parsippany", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New Jersey' is a non-DMV US state", "Parent / Ultimate Owner": "Wyndham Hotels & Resorts, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NJ Business Records Service — businessrecords.nj.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Wyndham Hotels & Resorts, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] Paid $5.4M in a 2024 FTC settlement over data security failures\nWHAT THE TERMS SAY: Wyndham paid $5.4 million in a 2024 FTC settlement over data security failures.\nWHY IT MATTERS: A federal settlement over security failures is a confirmed regulatory finding, not just an allegation, about how Wyndham's systems protected guest data.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-4] One rewards profile spans ~9,100 hotels and 20+ brands, but privacy notices are per-brand\nWHAT THE TERMS SAY: Wyndham Rewards ties stay history, room preferences, payment card type, and co-guest names to a member profile shared across roughly 9,100 hotels and 20+ brands (Days Inn, Super 8, Ramada, La Quinta, and others), while privacy notices are published separately per brand rather than in one document.\nWHY IT MATTERS: The entity that actually holds a guest's check-in data and card imprint is an independently owned franchisee whose security posture Wyndham does not control, and the governing privacy document depends on which sign is on the building.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with class-action waiver, 30-day opt-out\nWHAT THE TERMS SAY: Wyndham Rewards ToS impose mandatory binding arbitration with a class-action waiver, with a 30-day opt-out, covering 24 hotel brands.\nWHY IT MATTERS: A member who misses the 30-day window loses the ability to join a class action over the same data-security failures the FTC already penalized.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The privacy-notice path was verified but is fragmented per-brand, and the ToS location itself was not verified this pass.", "Exposure Score (0-100)": 33, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 5/20 (severity2+2, penalty+3) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Wyndham Hotels & Resorts  <-  Wyndham Hotels & Resorts, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Wyndham Hotels & Resorts you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Wyndham is the largest hotel franchisor in the world by property count and owns almost none of them. Roughly 9,100 hotels operate under about 25 brands, so the entity that actually holds your check-in data, your card imprint and your room-key access log is an independent small-business franchisee whose security posture Wyndham does not control and you cannot evaluate. The corporate privacy notice describes the franchisor. It does not describe the motel.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Hotels & Lodging", "_row_id": 516, "_entity_id": 742, "_entity_slug": "wyndham-hotels-resorts", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Choice Hotels International", "Category": "Hotel chain (franchisor)", "Terms & Conditions URL": "https://www.choicehotels.com/legal/terms-of-use", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.choicehotels.com/legal/privacy-policy", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Choice Privileges links stay history across ~7,600 hotels and 20+ brands (Comfort, Quality Inn, Sleep Inn, Econo Lodge, Rodeway, Clarion, Cambria, WoodSpring, MainStay, Suburban Studios) plus the Radisson Americas brands acquired in 2022. The policy expressly covers information collected AT a hotel, not only online — so front-desk and on-property data feeds the same profile.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Choice Privileges ToS. 30-day opt-out. HQ: North Bethesda, Maryland (DMV). Covers Comfort, Quality Inn, Clarion, Cambria, Sleep Inn, MainStay, WoodSpring, Radisson (acquired 2022), and other brands.", "Fees / Billing Flags": "Franchisee-set resort and amenity fees; the franchisor sets brand standards but not the fee schedule at any given property.", "Notes": "URL STATUS: both VERIFIED this pass. DMV-LOCAL AND SIGNIFICANT: Choice Hotels International is headquartered in NORTH BETHESDA, MARYLAND — this is a Fortune-listed company inside this tracker's core region, and one of the largest hotel companies in the world. Choice acquired Radisson Hotels Americas in August 2022 for $675M, so US Radisson, Park Plaza, Park Inn and Country Inn & Suites properties are Choice; the same brands outside the Americas belong to Radisson Hotel Group, a different company with a different privacy policy. A guest cannot tell which from the sign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "North Bethesda", "HQ State": "Maryland", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: North Bethesda, MD — should be DMV, not Global", "Parent / Ultimate Owner": "Choice Hotels International, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Maryland SDAT Business Entity Search — egov.maryland.gov/businessexpress/entitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Choice Hotels International, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Choice Privileges links on-property and online data across ~7,600 hotels, 20+ brands\nWHAT THE TERMS SAY: Choice Privileges links stay history across roughly 7,600 hotels and 20+ brands including Radisson Americas brands acquired in 2022; the policy expressly covers information collected at a hotel, not only online, so front-desk data feeds the same profile.\nWHY IT MATTERS: A guest's in-person, on-property interactions feed the same consolidated profile as their online bookings, widening what a single incident could expose.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] US Radisson stays are Choice; the identical brand abroad is a different company\nWHAT THE TERMS SAY: Choice acquired Radisson Hotels Americas in August 2022 for $675M, so US Radisson, Park Plaza, Park Inn, and Country Inn & Suites properties are Choice, while the same brands outside the Americas belong to Radisson Hotel Group, a different company with a different privacy policy. A guest cannot tell which from the sign.\nWHY IT MATTERS: A guest cannot tell from the sign which company, and which privacy regime, actually governs their stay.\n(evidence: Notes | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with class-action waiver, 30-day opt-out\nWHAT THE TERMS SAY: Choice Privileges ToS impose mandatory binding arbitration with a class-action waiver and a 30-day opt-out, covering Comfort, Quality Inn, Clarion, Cambria, Sleep Inn, Radisson (Americas), and other brands.\nWHY IT MATTERS: A member who does not opt out within 30 days loses access to court and class remedies across every one of Choice's 7,600 franchised hotels.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "URLs were verified, but the Radisson Americas/rest-of-world brand split makes it genuinely hard for a guest to identify which entity governs a given stay.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Choice Hotels International  <-  Choice Hotels International, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Choice Hotels International you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Choice Hotels franchises about 7,600 hotels with roughly 1,700 corporate employees — a ratio that tells you exactly where your data actually lives. Nearly every property is independently owned, so the front desk that photocopies your ID and stores your card belongs to a small business, while the privacy policy you would search for belongs to a Maryland-headquartered franchisor with no operational control over that desk. The brand-versus-owner gap also splits geographically: buy a Radisson stay in the US and you are dealing with Choice; the identical brand abroad is a different corporation entirely.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Hotels & Lodging", "_row_id": 517, "_entity_id": 744, "_entity_slug": "choice-hotels-international", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Best Western Hotels & Resorts", "Category": "Hotel chain (member cooperative)", "Terms & Conditions URL": "https://www.bestwestern.com/en_US/legal/terms-of-use.html", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.bestwestern.com/en_US/legal/privacy-policy.html", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "The privacy policy states information is shared with BWR programme partners including airlines the member selects, and with third-party business partners for promotions where the member has opted in. It also names Canada and India as jurisdictions where consent is the lawful processing basis, and discloses that BWI operates from the United States under US law.", "Arbitration / Class Action Waiver": "US consumer arbitration provisions not confirmed this pass.", "Fees / Billing Flags": "Property-set fees; Best Western Rewards points can be earned and burned with airline partners, which moves data as well as points.", "Notes": "URL STATUS: privacy policy VERIFIED this pass; terms of use NOT verified this pass - expected location, confirm on click. STRUCTURAL NOTE worth recording: Best Western is not a conventional franchisor but a MEMBERSHIP ORGANISATION — a non-profit cooperative whose member hotels are independently owned and vote on governance. That is a genuinely different corporate form from Marriott, Hilton or Choice, and it means brand standards are set by the members rather than imposed on them.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Phoenix", "HQ State": "Arizona", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Arizona' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Arizona Corporation Commission eCorp — ecorp.azcc.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Rewards data shared with airline partners and opted-in promotional partners\nWHAT THE TERMS SAY: Best Western's privacy policy states information is shared with programme partners including airlines the member selects, and with third-party business partners for promotions where the member has opted in; Best Western Rewards points can be earned and burned with airline partners, which moves data along with points.\nWHY IT MATTERS: Earning points through an airline partnership means two separate companies are exchanging a member's travel record, not just their loyalty balance.\n(evidence: Data Sharing | Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-4] Membership cooperative: no parent company exercises operational control over the front desk\nWHAT THE TERMS SAY: Best Western is structured as a non-profit membership cooperative rather than a conventional franchisor; member hotels are independently owned and collectively govern the organisation, meaning no parent company exercises operational control over any given front desk.\nWHY IT MATTERS: Member hotels are independently owned and collectively govern the organisation, so no parent company exercises operational control over the front desk that holds a guest's data.\n(evidence: Notes | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — US consumer arbitration terms are not confirmed this pass, and no discrete breach or regulatory action is described in the row's text despite the tracker's own Finding Type label.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "US arbitration terms are unconfirmed and terms of use were not verified this pass, though the privacy policy itself was located.", "Exposure Score (0-100)": 12, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Best Western Hotels & Resorts  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Best Western Hotels & Resorts you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Best Western is structured as a membership cooperative rather than a franchise chain, which sounds like a distinction without a difference until you ask who is accountable for a data breach at one property. The member hotels are independently owned and collectively govern the organisation, so there is no parent company exercising operational control over the front desk. The privacy policy also confirms partner sharing runs both directions with airline loyalty programmes — earning points on a flight for a hotel stay means the two companies are exchanging your travel record.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Hotels & Lodging", "_row_id": 518, "_entity_id": 745, "_entity_slug": "best-western-hotels-resorts", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Radisson Hotel Group", "Category": "Hotel chain (franchisor)", "Terms & Conditions URL": "https://www.radissonhotels.com/en-us/terms-conditions", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.radissonhotels.com/en-us/privacy", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Radisson maintains a Privacy Centre linking multiple policies applicable to different parts of the group, plus a separate printable version — meaning there is no single governing document, and which applies depends on region and brand.", "Arbitration / Class Action Waiver": "Not confirmed this pass; EU-headquartered operations bring GDPR rights that US guests do not hold.", "Fees / Billing Flags": "Property-set fees.", "Notes": "URL STATUS: privacy centre VERIFIED this pass (a printable version exists at /en-us/privacy/printable); terms NOT verified this pass - expected location, confirm on click. CRITICAL SPLIT: Choice Hotels bought Radisson Hotels AMERICAS in August 2022. Radisson Hotel Group retains the brands everywhere else. So the Radisson, Park Plaza, Park Inn and Country Inn & Suites brands are owned by two different companies depending on continent, each with its own privacy policy and its own regulator. Cross-ref the Choice Hotels row.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Minnetonka", "HQ State": "Minnesota", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Minnesota' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] No single governing privacy document; which policy applies depends on region and brand\nWHAT THE TERMS SAY: Radisson maintains a Privacy Centre linking multiple policies applicable to different parts of the group, plus a separate printable version, meaning there is no single governing document, and Choice Hotels' 2022 acquisition of Radisson Americas means the Radisson, Park Plaza, Park Inn, and Country Inn & Suites brands are owned by two different companies depending on continent, each under a different privacy policy and regulator.\nWHY IT MATTERS: A guest cannot identify the document that actually governs their booking without first researching which corporate entity, Choice or Radisson Hotel Group, operates the specific property.\n(evidence: Data Sharing | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration terms are not confirmed and fees are not itemized beyond property-set charges; the row's only substantive, company-specific finding is the fragmented, region-dependent privacy governance.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The row explicitly states there is no single governing privacy document, and arbitration terms and the terms-of-use URL are both unconfirmed.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Radisson Hotel Group  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Radisson Hotel Group takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The same Radisson sign means two different companies depending on which continent you are standing on — Choice Hotels owns the Americas brands, Radisson Hotel Group owns the rest — and each publishes its own privacy policy under a different legal regime. A European guest holds GDPR rights against one entity; an American guest at an identically branded hotel holds whatever their state provides against a different one. Radisson also publishes not one privacy policy but a Privacy Centre linking several, so identifying the document that actually governs your booking is a research task before it is a reading task.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Hotels & Lodging", "_row_id": 519, "_entity_id": 746, "_entity_slug": "radisson-hotel-group", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Accor", "Category": "Hotel chain (franchisor/operator)", "Terms & Conditions URL": "https://all.accor.com/gb/terms-and-conditions.shtml", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://all.accor.com/gb/privacy-policy.shtml", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "ALL - Accor Live Limitless links stay data across ~5,600 hotels and 40+ brands (Sofitel, Novotel, Mercure, ibis, Fairmont, Raffles, Swissôtel, Pullman, Mövenpick). French parent means GDPR applies to the controller, which is a materially stronger baseline than any US chain in this tab.", "Arbitration / Class Action Waiver": "French-law-governed terms; no US-style mandatory consumer arbitration or class action waiver of the kind that dominates this tracker. GDPR data-subject rights and EU supervisory authorities are the recourse mechanism.", "Fees / Billing Flags": "Property-set fees; ALL points partnerships extend into airline and rail programmes.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click — Accor restructures its ALL portal regularly. Locate via the footer of all.accor.com. Accor SA is a French société anonyme headquartered in Issy-les-Moulineaux, so the controller sits inside the EU regardless of where the hotel is.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Issy-les-Moulineaux", "HQ State": "France", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ in Issy-les-Moulineaux, France (non-US)", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (France) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in France. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] ALL programme links stay data across ~5,600 hotels, 40+ brands, plus airline and rail partners\nWHAT THE TERMS SAY: Accor Live Limitless links stay data across roughly 5,600 hotels and 40+ brands (Sofitel, Novotel, Mercure, ibis, Fairmont, Raffles, and others), and ALL points partnerships extend into airline and rail loyalty programmes.\nWHY IT MATTERS: A single profile spanning budget to luxury brands, plus travel partners, concentrates a large volume of travel history under one loyalty system.\n(evidence: Data Sharing | Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] GDPR governs the group, but the property that scans your passport is a separate business\nWHAT THE TERMS SAY: Accor SA is a French société anonyme headquartered in Issy-les-Moulineaux, so GDPR governs the data controller regardless of where a hotel is located; the tracker notes Accor franchises and manages far more hotels than it owns.\nWHY IT MATTERS: GDPR protection applies to what the corporate group does with a guest's data, not to what the separately owned property that physically collected the passport copy does with it.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No US-style arbitration clause or class-action waiver applies, and no breach or regulatory penalty is documented for this row; only the cross-brand data-linking and the franchise/GDPR gap are substantiated.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The GDPR/controller structure is clearly described even though both the terms and privacy-policy URLs were not verified this pass.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Accor  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Accor you gave up your data shared corporate-wide. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Accor is the one major hotel group in this tab whose parent sits inside the EU, which means a guest's data is governed by GDPR at the controller level and enforced by a real supervisory authority rather than by a private arbitrator. That is the same structural advantage documented in the Mistral row of the LLM Providers tab and it is genuinely rare in hospitality. The catch is the same as everywhere else here: Accor franchises and manages far more hotels than it owns, so GDPR governs what the group may do with your booking while the property that photocopied your passport is a separate business.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Hotels & Lodging", "_row_id": 520, "_entity_id": 747, "_entity_slug": "accor", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Four Seasons Hotels and Resorts", "Category": "Luxury hotel operator", "Terms & Conditions URL": "https://www.fourseasons.com/legal/terms-of-use/", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.fourseasons.com/legal/privacy-notice/", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Luxury operators hold unusually detailed guest preference files — dietary restrictions, allergies, room temperature, pillow type, family member names and dates — built deliberately over repeat stays and shared across properties to enable recognition. That preference dossier is health-adjacent and relationship-mapping data collected as a service feature.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Luxury properties typically disclose fees more transparently than the economy segment, where resort-fee litigation concentrates.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. Four Seasons is majority-owned by Cascade Investment (Bill Gates) with Kingdom Holding (Saudi Arabia) as a significant shareholder, and is privately held — so it produces far less public disclosure than the listed chains in this tab.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Guest preference files hold health-adjacent detail with no health-privacy framework\nWHAT THE TERMS SAY: Four Seasons builds a detailed guest preference dossier over repeat stays, including dietary restrictions, allergies, medication timing for turndown, children's names and ages, and anniversary dates, and shares it across properties on different continents so staff can recognize a guest they never spoke to directly.\nWHY IT MATTERS: The file contains material a doctor would treat as clinical, yet it sits under no health-privacy framework at all because a hotel, not a medical provider, collected it.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[RETENTION_PERIOD · FL-2] Guest preference data is held indefinitely and follows guests between properties\nWHAT THE TERMS SAY: The preference dossier is assembled as a service courtesy and held indefinitely, following a guest between Four Seasons properties on different continents.\nWHY IT MATTERS: Indefinite retention of health-adjacent, family-relationship data means there is no described point at which this information is deleted.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[NO_DISCLOSURE_THICK_FOG · FL-4] Privately held under Cascade Investment and Kingdom Holding, limiting public disclosure\nWHAT THE TERMS SAY: Four Seasons is majority-owned by Cascade Investment (Bill Gates) with Kingdom Holding (Saudi Arabia) as a significant shareholder and is privately held, producing far less public disclosure than the listed chains in this tab.\nWHY IT MATTERS: Private ownership means fewer of the regulatory filings and disclosures that would let a guest independently verify how the preference dossier is actually secured.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Both ToS and privacy-policy URLs are unverified this pass, and private ownership means minimal independent disclosure exists to check against.", "Exposure Score (0-100)": 9, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Four Seasons Hotels and Resorts  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Four Seasons Hotels and Resorts you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The luxury hospitality business model is built on remembering things about you, and the guest preference file is the product: dietary restrictions, allergies, medication timing for turndown, children's names and ages, anniversary dates, and preferences noted by staff you never spoke to directly. That file follows you between properties on different continents so a manager can greet you correctly. It is assembled as a courtesy, held indefinitely, contains material a doctor would treat as clinical, and sits under no health privacy framework whatsoever because a hotel collected it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Hotels & Lodging", "_row_id": 521, "_entity_id": 748, "_entity_slug": "four-seasons-hotels-and-resorts", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Omni Hotels & Resorts", "Category": "Hotel operator", "Terms & Conditions URL": "https://www.omnihotels.com/terms-and-conditions", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.omnihotels.com/privacy-policy", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Select Guest loyalty programme ties stay and on-property spend to a member profile. Omni suffered a significant ransomware incident in 2016 affecting point-of-sale systems across properties.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Resort fees at destination properties.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. Omni is privately held by TRT Holdings, so public disclosure is limited. The 2016 POS malware incident is the documented event; scope figures were not independently confirmed this pass and none are asserted.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Dallas", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2016", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2016 POS malware hit payment terminals across restaurant, bar, spa, and room-charge systems\nWHAT THE TERMS SAY: Omni suffered a significant 2016 ransomware/point-of-sale malware incident affecting payment terminals across properties, capturing card data from restaurant, bar, spa, and gift-shop transactions as well as room charges; scope figures were not independently confirmed this pass and none are asserted.\nWHY IT MATTERS: A hotel functions as a dozen merchants sharing one payment environment, so a guest paying at the poolside bar was exposed through the same compromise that touched their room folio.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-4] Privately held by TRT Holdings, limiting public disclosure of the 2016 incident's scope\nWHAT THE TERMS SAY: Omni is privately held by TRT Holdings, so public disclosure is limited, and scope figures for the 2016 incident were not independently confirmed this pass.\nWHY IT MATTERS: Without public filings or confirmed scope figures, a guest cannot independently assess how many properties or transactions the 2016 incident actually touched.\n(evidence: Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms are not confirmed and fees are not itemized beyond generic resort fees, leaving only the 2016 breach and the private-ownership opacity as substantiated findings.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Private ownership limits disclosure, and the 2016 incident's scope figures are explicitly unconfirmed.", "Exposure Score (0-100)": 11, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Omni Hotels & Resorts  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Omni Hotels & Resorts takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Omni's 2016 point-of-sale malware incident is the kind of breach that best illustrates why hotels are a distinct risk category: the compromise sat on payment terminals across properties, meaning it captured card data from restaurant, bar, spa and gift shop transactions as well as room charges. A hotel is not one merchant, it is a dozen merchants under one roof sharing a payment environment, and a guest swiping at the poolside bar is transacting inside the same system that holds their room folio.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Hotels & Lodging", "_row_id": 522, "_entity_id": 749, "_entity_slug": "omni-hotels-resorts", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Loews Hotels & Co", "Category": "Hotel operator", "Terms & Conditions URL": "https://www.loewshotels.com/terms-of-use", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.loewshotels.com/privacy-policy", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Loews Hotels is a subsidiary of Loews Corporation, the diversified holding company that also owns CNA Financial — so guest data sits under the same corporate parent as a commercial insurer.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Resort fees at destination and theme-park-adjacent properties.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. CROSS-REF the Loews row in F500 Insurance Remainder — the holding-company structure means a hotel guest and a CNA policyholder share an ultimate parent, which neither would guess.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Hotel guests and CNA Financial insurance policyholders share the same ultimate parent\nWHAT THE TERMS SAY: Loews Hotels is a subsidiary of Loews Corporation, the diversified holding company that also owns CNA Financial, a commercial insurer, so guest data sits under the same corporate parent as a commercial insurer's policyholder data.\nWHY IT MATTERS: When trying to identify who is accountable after an incident, the brand on the hotel door is several corporate layers away from the entity that would actually answer, and nothing in the guest-facing terms reveals that chain.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration terms are not confirmed, fees are limited to generic resort fees, and no breach or regulatory action is documented for this row; only the holding-company structure is a substantive, company-specific finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Both ToS and privacy-policy URLs are unverified this pass, and arbitration terms are unconfirmed.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Loews Hotels & Co  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Loews Hotels & Co takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Loews Hotels sits under Loews Corporation, the same parent that owns CNA Financial — so a guest checking into a Loews property and a business buying commercial insurance from CNA are dealing with one ultimate owner. Holding-company structures like this recur throughout the tracker and they matter for a specific practical reason: when you try to identify who is accountable after an incident, the brand on the door is several corporate layers away from the entity that would actually answer, and nothing in the guest-facing documents reveals the chain.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Hotels & Lodging", "_row_id": 523, "_entity_id": 750, "_entity_slug": "loews-hotels-co", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sonesta International Hotels", "Category": "Hotel chain", "Terms & Conditions URL": "https://www.sonesta.com/terms-of-use", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.sonesta.com/privacy-policy", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Sonesta grew rapidly by absorbing former Red Lion and IHG-managed properties, and is controlled by Service Properties Trust, a REIT — so the operating company and the property owner are separate entities with separate obligations.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Property-set fees.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. Sonesta is majority-controlled by Service Properties Trust (a publicly traded REIT), which is the structural note: the hotel operator and the real estate owner are different companies, and a guest's data relationship is with the operator while the physical premises belong to the trust.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Newton", "HQ State": "Massachusetts", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Massachusetts SOC Corporate Search — corp.sec.state.ma.us/corpweb/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Guest records inherited from absorbed Red Lion and IHG-managed properties, with no re-consent\nWHAT THE TERMS SAY: Sonesta grew rapidly by absorbing hundreds of former Red Lion and IHG-managed properties and is majority-controlled by Service Properties Trust, a REIT that owns the physical premises while Sonesta operates them; guest data acquired through this portfolio transfer arrives governed by whatever the previous operator promised, and the guest is never asked to re-consent.\nWHY IT MATTERS: A guest's data relationship is with Sonesta as operator, but a large share of that data was inherited under a predecessor brand's policy rather than collected under Sonesta's own.\n(evidence: Data Sharing | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration terms are not confirmed and fees are limited to property-set charges; only the inherited-records/operator-versus-owner structural finding is substantiated for this row.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Both ToS and privacy-policy URLs are unverified this pass, and arbitration terms are unconfirmed.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Sonesta International Hotels  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Sonesta International Hotels takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Sonesta expanded by absorbing hundreds of properties that previously flew other flags, which means a large share of its guest records were inherited from predecessor brands rather than collected under Sonesta's own policy. Data acquired in a portfolio transfer arrives governed by whatever the previous operator promised, and the guest is never asked to re-consent. It is the hotel version of the pattern documented in the Bird and Clarity Money rows: customer records move as assets, and the policy you agreed to is not necessarily the one now in force.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Hotels & Lodging", "_row_id": 524, "_entity_id": 751, "_entity_slug": "sonesta-international-hotels", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Extended Stay America", "Category": "Extended-stay hotel chain", "Terms & Conditions URL": "https://www.extendedstayamerica.com/terms-of-use", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.extendedstayamerica.com/privacy-policy", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Extended-stay guests frequently reside for weeks or months, which produces a materially different data profile from a transient hotel stay — closer to a tenancy record, including length of residence and, in practice, an address used for mail and identification.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Weekly rate structures; extended-stay properties sit in a regulatory grey zone between hotel and residential tenancy in several states, which affects eviction rights.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. Extended Stay America was taken private by Blackstone and Starwood Capital in 2021, so public disclosure is now limited. CROSS-REF the Blackstone row in F500 Telecom & Consumer Svc for the private-equity ownership analysis.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Charlotte", "HQ State": "North Carolina", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'North Carolina' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NC SOS Business Registration Search — sosnc.gov/online_services/search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Weeks-long guests sit in a legal grey zone between hotel guest and tenant\nWHAT THE TERMS SAY: Extended-stay guests who reside for weeks or months produce a tenancy-like data profile, including length of residence and an address used for mail and identification; several states place extended-stay properties in a regulatory grey zone between hotel and residential tenancy that affects whether a guest can be removed via landlord-tenant proceedings or simply escorted out.\nWHY IT MATTERS: The customer base skews toward people in housing transition, which the tracker notes is exactly the population least able to litigate the guest-versus-tenant distinction.\n(evidence: Data Sharing | Fees | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration terms are not confirmed, and the company was taken private by Blackstone/Starwood Capital in 2021 limiting further disclosure; only the tenancy/eviction structural finding is substantiated.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Both URLs are unverified this pass, and the 2021 take-private transaction has reduced public disclosure.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Extended Stay America  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Extended Stay America takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Extended-stay lodging occupies a legal grey zone that matters enormously to the people in it: a guest staying weeks or months may be functionally a tenant while contractually a hotel guest, and in several states that distinction decides whether they can be removed by a landlord-tenant proceeding or simply escorted out. The data reflects the ambiguity too — length of residence, mail received, vehicles registered — a tenancy record held under a hotel's terms. The customer base skews toward people in housing transition, which is exactly the population least able to litigate the difference.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Hotels & Lodging", "_row_id": 525, "_entity_id": 752, "_entity_slug": "extended-stay-america", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "G6 Hospitality (Motel 6 / Studio 6)", "Category": "Economy motel chain (franchisor)", "Terms & Conditions URL": "https://www.motel6.com/en/terms-of-use.html", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.motel6.com/en/privacy-policy.html", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "CONFIRMED REGULATORY HISTORY: Motel 6 locations were found to have provided guest lists to US Immigration and Customs Enforcement without warrants or subpoenas. Washington State's Attorney General obtained a $12 million settlement in 2019, and a separate $7.6 million federal class settlement resolved related claims. Guest registry data was handed over daily at some properties.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Economy segment; the documented harm here is disclosure rather than fees.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. G6 Hospitality was acquired by Oyo (India-based) in 2024, which moves the parent company and its data governance offshore — verify the current controlling entity and its published policy before relying on any figure here. The ICE disclosure findings are the most consequential hotel privacy matter in this tracker and are documented in state AG and federal court records.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Carrollton", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation + Data breach", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.atg.wa.gov/news/news-releases/ag-ferguson-motel-6-will-pay-12m-violating-privacy-tens-thousands-washingtonians", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "G6 Hospitality LLC (Blackstone portfolio company)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: G6 Hospitality LLC (Blackstone portfolio company)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-4] Motel 6 gave guest lists to ICE without a warrant; $12M + $7.6M in settlements\nWHAT THE TERMS SAY: Motel 6 locations provided guest lists to US Immigration and Customs Enforcement without warrants or subpoenas, in some cases as a daily routine. Washington State's Attorney General obtained a $12 million settlement in 2019, and a separate $7.6 million federal class settlement resolved related claims.\nWHY IT MATTERS: No hacker or technical failure was involved: a front desk printed the list of who was staying there and handed it over, and the affected guests were selected precisely for their inability to respond.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] 2024 Oyo acquisition moved the controlling entity and data governance offshore\nWHAT THE TERMS SAY: G6 Hospitality was acquired by Oyo, an India-based company, in 2024, which the tracker notes moves the parent company and its data governance offshore; the current controlling entity and its published policy were not independently verified this pass.\nWHY IT MATTERS: A guest relying on prior knowledge of G6's US ownership and practices may not realize the controlling entity, and its incentives around data governance, changed in 2024.\n(evidence: Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms are not confirmed this pass, leaving the ICE-disclosure history and the 2024 ownership change as the two substantiated findings.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The ICE-disclosure history is extensively documented via state AG and federal court records, but the current controlling entity's own policy was not verified this pass.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "G6 Hospitality (Motel 6 / Studio 6)  <-  G6 Hospitality LLC (Blackstone portfolio company)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, G6 Hospitality (Motel 6 / Studio 6) takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Motel 6 properties handed guest registry lists to immigration enforcement without a warrant or subpoena — in some cases as a daily routine — and Washington State's Attorney General secured a $12 million settlement over it, with a separate $7.6 million federal class settlement resolving related claims. No hacker, no breach, no technical failure: a front desk printed the list of who was sleeping there and gave it away. It is the clearest case in this entire tracker of the gap between what a privacy policy says and what a night clerk does, and the affected population was selected precisely for its inability to respond.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Hotels & Lodging", "_row_id": 526, "_entity_id": 754, "_entity_slug": "g6-hospitality-motel-6-studio-6", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Red Roof Inn", "Category": "Economy motel chain (franchisor)", "Terms & Conditions URL": "https://www.redroof.com/terms-of-use", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.redroof.com/privacy-policy", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Franchised economy segment; guest registry and payment data held at property level by independent owners.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Economy rates; property-set fees.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. Red Roof is privately held, which limits public disclosure. The economy motel segment as a whole has been the subject of significant litigation concerning operator knowledge of trafficking on premises — that is a serious matter of public record but it is a duty-of-care question rather than a terms-of-service one, and it is noted here only so a sparse privacy row is not mistaken for a clean record.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Columbus", "HQ State": "Ohio", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Ohio' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Arbitration terms, fees beyond standard economy rates, and any breach are all unconfirmed for this row. The tracker's own text explicitly frames the sector's trafficking-litigation exposure as a duty-of-care question rather than a terms-of-service finding, and does not confirm it applies specifically to Red Roof, so no troubling item is asserted here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Both URLs are unverified this pass, the company is privately held, and nearly every substantive field is marked not confirmed.", "Exposure Score (0-100)": 8, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Red Roof Inn  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Red Roof Inn takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The economy motel segment carries a category of legal exposure that has nothing to do with data and everything to do with what operators knew: federal litigation against multiple budget chains has concerned whether franchisors and property operators were aware of trafficking occurring on their premises. That is recorded here deliberately, because a row showing few privacy findings would otherwise read as a clean company, and the more serious accountability questions in this segment sit entirely outside the columns this tracker measures.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Hotels & Lodging", "_row_id": 527, "_entity_id": 755, "_entity_slug": "red-roof-inn", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Airbnb", "Category": "Short-term rental marketplace", "Terms & Conditions URL": "https://www.airbnb.com/help/article/2908", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.airbnb.com/help/article/2855", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Airbnb holds government ID, facial verification imagery for some users, precise property location, message content between guest and host, and payment data for both sides of a transaction. It also holds HOST data — home address, tax identification, income — for people running a micro-business from their residence.", "Arbitration / Class Action Waiver": "US terms include mandatory individual arbitration and class action waiver with a stated opt-out mechanism; window not confirmed this pass. Airbnb has faced substantial arbitration-related litigation.", "Fees / Billing Flags": "Service fees split between guest and host; cleaning-fee disclosure has drawn regulatory attention in several jurisdictions and prompted display changes.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click — Airbnb serves its Terms of Service and Privacy Policy through Help Centre article IDs which change; locate via the site footer rather than a saved link. Airbnb's undisclosed-camera policy was tightened in 2024 to prohibit indoor security cameras entirely.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Collects government ID and, for some users, facial verification imagery\nWHAT THE TERMS SAY: Airbnb holds government ID and facial verification imagery for some users, alongside precise property location, message content between guest and host, and payment data for both sides of a transaction.\nWHY IT MATTERS: Government ID and, for some users, facial verification imagery are among the most sensitive categories of personal data, held alongside precise property location, guest-host message content, and payment data for both sides.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[OTHER · FL-4] A private individual, not a company, holds your identity and message history as host\nWHAT THE TERMS SAY: Airbnb is the only lodging platform in this tab where the counterparty holding a guest's data is another private individual: a host sees the guest's name, photo, message history, and arrival time. Airbnb banned indoor security cameras outright in 2024, a change the tracker notes was only necessary because undisclosed indoor cameras were previously being found under the prior disclosed-camera rule.\nWHY IT MATTERS: A guest's exposure runs both to the platform and to a private host, and the pre-2024 camera rule shows that disclosed-camera policies had not been enough to prevent undisclosed surveillance.\n(evidence: SCARY | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory individual arbitration with class-action waiver; opt-out window unconfirmed\nWHAT THE TERMS SAY: Airbnb's US terms include mandatory individual arbitration and a class-action waiver with a stated opt-out mechanism, though the specific opt-out window was not confirmed this pass.\nWHY IT MATTERS: Both categories of highly sensitive data described above route into the same individual-arbitration dispute process rather than court.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Practices are reasonably well described, but both ToS/privacy-policy URLs were not verified this pass, and the arbitration opt-out window is unconfirmed.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 23, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 23/30 (forced_arbitration+12, class_action_waiver+9, optout_window_unverified+2) | Data 13/30 (biometric_collection+6, precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Airbnb  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Airbnb you gave up your biometric identifiers, your physical movements, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Airbnb is the only lodging row here where the person holding your data is another private individual. A host sees your name, photo, message history and arrival time; you see their home. Airbnb banned indoor security cameras outright in 2024 — a policy change that is only necessary because the prior rule permitted disclosed indoor cameras, and because undisclosed ones were being found. The platform also holds government ID and, for some users, facial verification imagery, alongside host-side tax and income data. Two categories of highly sensitive information, one marketplace, and a dispute resolution path that runs through individual arbitration.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Hotels & Lodging", "_row_id": 528, "_entity_id": 307, "_entity_slug": "airbnb", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Vrbo (Expedia Group)", "Category": "Short-term rental marketplace", "Terms & Conditions URL": "https://www.vrbo.com/legal/terms-and-conditions", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.expedia.com/legal/privacy", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Vrbo operates under Expedia Group's privacy policy, so a Vrbo booking feeds the same profile as Expedia, Hotels.com, Orbitz and Travelocity — a consolidated travel history across brands the user experiences as competitors.", "Arbitration / Class Action Waiver": "Expedia Group US terms include arbitration provisions; opt-out mechanics not confirmed this pass.", "Fees / Billing Flags": "Service fees; Expedia Group brands have faced scrutiny over drip pricing and fee display.", "Notes": "URL STATUS: Vrbo terms NOT verified this pass - expected location, confirm on click; privacy policy correctly resolves to Expedia Group's policy NOT verified this pass - expected location, confirm on click — this is the finding, not an error. CROSS-REF the Orbitz row in Travel & Transit Apps: Expedia Group owns Vrbo, Hotels.com, Orbitz, Travelocity, Hotwire and Expedia, and one privacy policy governs the lot.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Expedia Group, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] One Expedia Group privacy policy governs Vrbo, Expedia, Hotels.com, Orbitz, and Travelocity\nWHAT THE TERMS SAY: Vrbo operates under Expedia Group's privacy policy, so a Vrbo booking feeds the same profile as Expedia, Hotels.com, Orbitz, and Travelocity, brands a user experiences as competitors.\nWHY IT MATTERS: A traveller deliberately spreading bookings across these brands to avoid building a single profile achieves nothing, since the brands were consolidated under one policy years before they were separately marketed.\n(evidence: Data Sharing | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-1] Expedia Group brands have faced scrutiny over drip pricing and fee display\nWHAT THE TERMS SAY: Expedia Group brands, which include Vrbo, have faced scrutiny over drip pricing and fee display.\nWHY IT MATTERS: A traveller comparing an advertised price may not see the full cost until later in the booking flow.\n(evidence: Fees; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Expedia Group US terms include arbitration; opt-out mechanics unconfirmed\nWHAT THE TERMS SAY: Expedia Group's US terms, which govern Vrbo, include arbitration provisions, though the specific opt-out mechanics were not confirmed this pass.\nWHY IT MATTERS: Without confirmed opt-out mechanics, a Vrbo user cannot be certain how, or whether, they can preserve their right to sue in court.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The consolidated-policy structure is clearly stated even though the tracker explicitly notes this itself was not URL-verified this pass, and opt-out mechanics remain unconfirmed.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Vrbo (Expedia Group)  <-  Expedia Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Vrbo (Expedia Group) you gave up your data shared corporate-wide and your right to sue. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Booking through Vrbo instead of Expedia feels like using a different company and is not — Vrbo, Hotels.com, Orbitz, Travelocity and Hotwire all sit under Expedia Group and share one privacy policy and one customer profile. A traveller deliberately spreading bookings across brands to avoid building a single profile achieves nothing, because the brands were consolidated years before they were rebranded. Cross-reference the Orbitz row for what happens when a legacy platform inside such a group stops receiving engineering attention.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Hotels & Lodging", "_row_id": 529, "_entity_id": 756, "_entity_slug": "vrbo-expedia-group", "_issuer": "Expedia Group, Inc.", "_issuer_slug": "expedia-group-inc", "_ticker": "EXPE", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Booking.com (Booking Holdings)", "Category": "Online travel agency", "Terms & Conditions URL": "https://www.booking.com/content/terms.html", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.booking.com/content/privacy.html", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Dutch-controlled entity, so GDPR applies at the controller level for a large share of processing. Booking Holdings also owns Priceline, Agoda, Kayak and OpenTable — meaning restaurant reservation data and flight search data sit under the same corporate roof as hotel bookings.", "Arbitration / Class Action Waiver": "Netherlands-governed terms for much of the business; EU consumers hold GDPR rights and access to supervisory authorities rather than arbitration.", "Fees / Billing Flags": "Commission structures and 'rate parity' clauses have been the subject of major EU competition enforcement, and the EU designated Booking.com a gatekeeper under the Digital Markets Act.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. Booking.com B.V. is Amsterdam-headquartered under US-listed Booking Holdings. Booking.com disclosed a significant partner-side phishing problem in which criminals compromised HOTEL accounts and then messaged guests through the legitimate Booking.com chat channel — a category worth understanding, since the message really did come from the platform.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Scam runs through Booking.com's own real messaging channel via compromised hotel accounts\nWHAT THE TERMS SAY: Booking.com disclosed a significant partner-side phishing problem in which criminals compromised hotel partner accounts and then messaged guests through the legitimate Booking.com chat channel, referencing the real booking and asking for card details to 'confirm' the reservation.\nWHY IT MATTERS: Every signal a consumer is taught to check, correct sender, correct reference number, correct property, is genuine, because the message really does come from inside the real system.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Hotel, flight, and restaurant reservation data consolidate under one parent company\nWHAT THE TERMS SAY: Booking Holdings also owns Priceline, Agoda, Kayak, and OpenTable, meaning restaurant reservation data and flight search data sit under the same corporate roof as hotel bookings.\nWHY IT MATTERS: A traveller using what appear to be separate services for flights, hotels, and dining is feeding one consolidated corporate dataset.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-1] Rate-parity clauses drew major EU competition enforcement; EU named Booking.com a DMA gatekeeper\nWHAT THE TERMS SAY: Booking.com's commission structures and 'rate parity' clauses have been the subject of major EU competition enforcement, and the EU designated Booking.com a gatekeeper under the Digital Markets Act.\nWHY IT MATTERS: Commission structures and 'rate parity' clauses have been the subject of major EU competition enforcement, and the EU separately designated Booking.com a gatekeeper under the Digital Markets Act.\n(evidence: Fees | Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The GDPR/Dutch-controller structure and the phishing disclosure are clearly described, but both ToS/privacy-policy URLs were not verified this pass.", "Exposure Score (0-100)": 18, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 14/20 (severity3+8, breach+3, penalty+3) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Booking.com (Booking Holdings)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Booking.com (Booking Holdings) you gave up your data shared corporate-wide. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The most effective scam in travel runs through Booking.com's own legitimate messaging channel: criminals compromise a hotel's partner account, then message guests from inside the real system, referencing the real booking, asking for card details to 'confirm' the reservation. Every signal a consumer is taught to check — correct sender, correct reference number, correct property — is genuine, because the attacker is using the hotel's actual account. Booking Holdings also owns Priceline, Agoda, Kayak and OpenTable, so hotel, flight and restaurant reservation data consolidate under one parent.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Hotels & Lodging", "_row_id": 530, "_entity_id": 757, "_entity_slug": "booking-com-booking-holdings", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Marriott International", "Category": "Hotel chain (franchisor/operator)", "Terms & Conditions URL": "https://www.marriott.com/about/terms-of-use.mi", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.marriott.com/about/privacy.mi", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "See the Marriott (Bonvoy) row in Consumer Apps for the full findings.", "Arbitration / Class Action Waiver": "See the Marriott (Bonvoy) row in Consumer Apps.", "Fees / Billing Flags": "Resort and destination fees; Marriott settled state attorney general actions over fee display.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. DUPLICATE NOTICE: Marriott already appears as 'Marriott (Bonvoy)' in the Consumer Apps tab, where the substantive findings are recorded. This row exists so the Hotels & Lodging tab is complete as a sector view; do NOT double-count it in any total, and consult the Consumer Apps row for the breach detail.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Caught with Hilton and Hyatt in the 2025 Otelier vendor breach\nWHAT THE TERMS SAY: Marriott, Hilton, Hyatt, and IHG were all caught in the 2025 Otelier vendor breach, three-plus competing hotel groups exposed through one back-end platform none of their guests had heard of.\nWHY IT MATTERS: Comparing hotel chains on their own individual security record misses the layer, a shared vendor, where the actual exposure happened.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-1] Settled state attorney general actions over resort-fee display\nWHAT THE TERMS SAY: Marriott charges resort and destination fees and settled state attorney general actions over how those fees were displayed to consumers.\nWHY IT MATTERS: State regulators found the fee-display practices significant enough to pursue and settle, rather than the fees simply being disclosed upfront.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — This row's own text explicitly defers Marriott's headline breach and arbitration findings to the separate Marriott (Bonvoy) row in Consumer Apps to avoid double-counting; only the shared Otelier breach and the fee-display settlement are supported directly by this row's text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The row deliberately defers its main substantive record to a separate tab, and its own ToS/privacy-policy URLs were not verified this pass.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity3+8, breach+3, penalty+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Marriott International  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Marriott International takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Marriott's headline finding is recorded on the Marriott (Bonvoy) row in Consumer Apps and is not repeated here. The reason this row exists is completeness of the sector view — and the reason that matters is that Marriott, Hilton, Hyatt and IHG were all caught in the 2025 Otelier vendor breach, three competing groups exposed through one back-end platform none of their guests had heard of. Comparing chains on their own security record misses the layer where the exposure actually happened.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Hotels & Lodging", "_row_id": 531, "_entity_id": 758, "_entity_slug": "marriott-international", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sixt", "Category": "Car rental", "Terms & Conditions URL": "https://www.sixt.com/terms-and-conditions/", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.sixt.com/privacy-policy/", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "German parent (Sixt SE) means GDPR governs the controller, a materially stronger baseline than the US majors in this category. Sixt holds driver's licence data, and its connected fleet generates telematics.", "Arbitration / Class Action Waiver": "German-law-governed terms for EU operations; US operations run under separate terms. No US-style mandatory arbitration confirmed for the EU entity.", "Fees / Billing Flags": "Sixt has drawn consumer complaint over post-rental damage claims raised after the vehicle was returned — a fee dispute pattern common across the sector.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. Sixt SE is headquartered in Pullach, Germany. IMPORTANT: Sixt's US subsidiary operates under separate US terms; a US renter is not automatically covered by the German entity's GDPR posture, and identifying which entity holds the contract requires reading the rental agreement rather than the website.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[LIABILITY_CAP_INDEMNITY · FL-1] Damage claims raised after return leave renters unable to prove the car's condition\nWHAT THE TERMS SAY: Sixt has drawn consumer complaints over post-rental damage claims raised after the vehicle was returned, a fee-dispute pattern the tracker describes as common across the car-rental sector.\nWHY IT MATTERS: A renter who has already returned and been inspected out of the vehicle has no practical way to prove the condition they left it in when a claim surfaces afterward.\n(evidence: Fees | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[LOCATION_TRACKING · FL-2] Connected fleet generates telematics alongside stored driver's licence data\nWHAT THE TERMS SAY: Sixt holds driver's licence data, and its connected fleet generates telematics.\nWHY IT MATTERS: Telematics data from a connected rental fleet can reveal a renter's routes and stops during the rental period.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-3] Same Sixt brand offers GDPR rights in Europe but only US terms domestically\nWHAT THE TERMS SAY: Sixt SE, headquartered in Pullach, Germany, means GDPR governs the controller for EU operations under German-law-governed terms, but Sixt's US subsidiary operates under separate US terms with no US-style mandatory arbitration confirmed for the EU entity, and identifying which entity holds a given rental contract requires reading the rental agreement itself.\nWHY IT MATTERS: The same brand offers materially different privacy protection depending on which counter a renter stood at, EU or US.\n(evidence: Arbitration | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The GDPR/US split is clearly described, but both URLs were not verified this pass and which entity governs a given contract requires reading the individual agreement.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent", "Entity Type": "Company", "Ownership Path": "Sixt  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Sixt you gave up your physical movements and your right to meaningful compensation. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Sixt is the only major rental company here with an EU parent, which means GDPR governs the controller and an actual supervisory authority stands behind a renter's rights — but only for the European entity. A US renter contracts with the American subsidiary under American terms, and the same brand therefore offers materially different protection depending on which counter you stood at. The recurring consumer complaint across this sector is also worth naming: damage claims raised after the car was returned and inspected, where the renter has no practical way to prove the condition they left it in.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Car Rental & Mobility", "_row_id": 532, "_entity_id": 759, "_entity_slug": "sixt", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "National Car Rental (Enterprise Holdings)", "Category": "Car rental", "Terms & Conditions URL": "https://www.nationalcar.com/en/home/legal.html", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.nationalcar.com/en/home/privacy-policy.html", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "One of three brands under Enterprise Holdings alongside Enterprise and Alamo — see the Enterprise row in Car Rental & Grocery-Restaurant for the shared analysis. Emerald Club membership ties rental history to a profile.", "Arbitration / Class Action Waiver": "See the Enterprise Holdings row.", "Fees / Billing Flags": "Corporate-focused programme; fees generally disclosed at booking.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. CROSS-REF: 'Enterprise (Enterprise Holdings, incl. National, Alamo)' already exists in the Car Rental & Grocery-Restaurant tab. This row exists for brand-level completeness — the substantive findings belong to the parent and should not be double-counted.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Enterprise Holdings, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Emerald Club rental history feeds one system shared with Enterprise and Alamo\nWHAT THE TERMS SAY: National is one of three brands under Enterprise Holdings alongside Enterprise and Alamo, and Emerald Club membership ties rental history to a profile within that shared system; the tracker states the substantive findings belong to the parent Enterprise Holdings row.\nWHY IT MATTERS: A driver's licence scan taken at any of the three counters enters the same shared system, so choosing between the three brands is not choosing between three separate data relationships.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-4] Privately held by the Taylor family, with no SEC filings or earnings calls\nWHAT THE TERMS SAY: Enterprise Holdings, National's parent, is privately held by the Taylor family and produces almost no public disclosure, no SEC filings, and no earnings calls, despite being the largest car rental company in North America.\nWHY IT MATTERS: The absence of documented findings across National, Enterprise, and Alamo reflects the opacity of private ownership more than any demonstrated clean practice.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — This row's own text defers its substantive arbitration and fee findings to the parent Enterprise Holdings row to avoid double-counting; only the shared-profile and private-ownership-opacity points are supported directly by this row's text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Both URLs are unverified this pass, and the privately held parent produces almost no independent public disclosure.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "National Car Rental (Enterprise Holdings)  <-  Enterprise Holdings, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using National Car Rental (Enterprise Holdings) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "National is one of three Enterprise Holdings brands, and the group is privately held by the Taylor family — the largest car rental company in North America produces almost no public disclosure, no SEC filings and no earnings calls. A renter comparing National against Enterprise and Alamo on service or price is comparing one company's three counters, and the driver's licence scan taken at any of them enters the same system. Absence of findings across all three reflects the opacity of private ownership more than anything demonstrable about practice.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Car Rental & Mobility", "_row_id": 533, "_entity_id": 760, "_entity_slug": "national-car-rental-enterprise-holdings", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Alamo Rent A Car (Enterprise Holdings)", "Category": "Car rental", "Terms & Conditions URL": "https://www.alamo.com/en/home/legal.html", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.alamo.com/en/home/privacy-policy.html", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Third Enterprise Holdings brand; leisure and inbound-tourist focused, which means a high share of international renters whose home-country privacy rights do not follow them to a US rental counter.", "Arbitration / Class Action Waiver": "See the Enterprise Holdings row.", "Fees / Billing Flags": "Leisure segment; upsell of insurance products at the counter is the recurring consumer friction.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. CROSS-REF the Enterprise Holdings row in Car Rental & Grocery-Restaurant. Recorded as one shared assessment across Enterprise, National and Alamo rather than three independent ones.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Enterprise Holdings, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-3] International renters' home-country privacy rights don't travel to a US counter\nWHAT THE TERMS SAY: Alamo's leisure and inbound-tourism focus means a high share of international renters hand over passports and driving licences at a US counter where their home-country privacy rights, such as GDPR, do not apply; processing happens under US law by a privately held company with no public disclosure obligations, and recourse runs through a foreign consumer-protection system that is hard to navigate from abroad.\nWHY IT MATTERS: A European renter on holiday has effectively no practical way to enforce protections they would have at home once their documents are processed at a US Alamo counter.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DARK_PATTERN_CONSENT · FL-1] Counter-side insurance upsell is the recurring consumer friction point\nWHAT THE TERMS SAY: Upsell of insurance products at the counter is described as the recurring consumer friction in Alamo's leisure segment.\nWHY IT MATTERS: The tracker records counter-side insurance upsell as the recurring consumer friction in Alamo's leisure segment, and as a durable finding for this end of the market.\n(evidence: Fees | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms are deferred to the parent Enterprise Holdings row in this tracker's own cross-reference; this row's own text supports only the jurisdictional gap for international renters and the counter upsell friction.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Both URLs are unverified this pass, and the privately held Enterprise Holdings parent limits independent disclosure.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Alamo Rent A Car (Enterprise Holdings)  <-  Enterprise Holdings, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Alamo Rent A Car (Enterprise Holdings) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Alamo's leisure and inbound-tourism focus creates a specific and underexamined gap: a European renter arriving on holiday hands over a passport and driving licence at a US counter, and the GDPR rights they hold at home do not travel with them. The processing happens under US law, by a privately held company with no public disclosure obligations, and the renter's only practical recourse is a foreign consumer protection system they cannot navigate from abroad. The counter-side insurance upsell is the other durable finding in this segment.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Car Rental & Mobility", "_row_id": 534, "_entity_id": 761, "_entity_slug": "alamo-rent-a-car-enterprise-holdings", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Dollar Car Rental (Hertz)", "Category": "Car rental", "Terms & Conditions URL": "https://www.dollar.com/Home/Terms.aspx", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.dollar.com/Home/Privacy.aspx", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "A Hertz-owned brand — Hertz acquired Dollar Thrifty Automotive Group in 2012. Data practices, fleet telematics and the toll-transponder billing arrangements are the parent's.", "Arbitration / Class Action Waiver": "See the Hertz row in Car Rental & Grocery-Restaurant.", "Fees / Billing Flags": "Value segment; third-party toll administration fees are the dominant consumer complaint across Hertz brands.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. CROSS-REF the Hertz row. Hertz's brand portfolio is Hertz, Dollar and Thrifty — a renter choosing the cheapest of the three is choosing among one company's price tiers.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Hertz Global Holdings, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] Third-party toll billing adds a daily service charge on top of the toll itself\nWHAT THE TERMS SAY: Third-party toll administration fees are the dominant consumer complaint across Hertz brands: a daily service charge is added on top of the actual toll, applied on any day the vehicle passes a single toll gantry.\nWHY IT MATTERS: A single brief pass through a toll gantry can trigger a full day's service charge, a cost structure a renter would not anticipate from the toll amount alone.\n(evidence: Fees | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] Dollar and Thrifty are Hertz; comparison shopping across the three is illusory\nWHAT THE TERMS SAY: Dollar is a Hertz-owned brand, acquired via the 2012 Dollar Thrifty Automotive Group deal, and Hertz's brand portfolio is Hertz, Dollar, and Thrifty, one company operating three price tiers that a renter experiences as competing options.\nWHY IT MATTERS: A renter choosing the cheapest of the three is comparing one company's own price tiers, not three independent competitors.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms are deferred to the parent Hertz row in this tracker's own cross-reference; this row's own text supports only the toll-fee structure and the brand-tier finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Both URLs are unverified this pass, and substantive arbitration terms are deferred entirely to the parent Hertz row.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Dollar Car Rental (Hertz)  <-  Hertz Global Holdings, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Dollar Car Rental (Hertz) you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Dollar is Hertz, and so is Thrifty — one company operating three price tiers that a renter experiences as competing options. The finding that actually costs people money across all three is toll administration: a third-party transponder billing arrangement that adds a daily service charge on top of the toll itself, applied on days the vehicle passes a single gantry. Cross-reference the Transurban row in Transit, Tolls & Water, where the toll operator collects video of every vehicle regardless of transponder — meaning the rental company and the toll authority are both building a movement record of the same trip.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Car Rental & Mobility", "_row_id": 535, "_entity_id": 762, "_entity_slug": "dollar-car-rental-hertz", "_issuer": "Hertz Global Holdings, Inc.", "_issuer_slug": "hertz-global-holdings-inc", "_ticker": "HTZ", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Thrifty Car Rental (Hertz)", "Category": "Car rental", "Terms & Conditions URL": "https://www.thrifty.com/Home/Terms.aspx", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.thrifty.com/Home/Privacy.aspx", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Second Hertz value brand acquired in the 2012 Dollar Thrifty transaction; shares the parent's systems and toll billing arrangements.", "Arbitration / Class Action Waiver": "See the Hertz row in Car Rental & Grocery-Restaurant.", "Fees / Billing Flags": "Value segment; same third-party toll administration structure as Dollar.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. Recorded as one shared assessment with Dollar and Hertz rather than three independent ones — see the Dollar row for the substantive analysis.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Hertz Global Holdings, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] Shares Dollar's third-party toll administration daily service charge\nWHAT THE TERMS SAY: Thrifty shares Dollar's same third-party toll administration structure, in which a daily service charge is added on top of the actual toll.\nWHY IT MATTERS: As with Dollar, a single toll-gantry pass can trigger a full day's added service charge.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] Thrifty completes the Hertz three-brand structure that only looks like competition\nWHAT THE TERMS SAY: Thrifty completes the Hertz three-brand structure (Hertz, Dollar, Thrifty), so a price comparison a renter thinks is across companies is actually within one; the tracker notes the more serious family-wide finding, a pattern of vehicles wrongly reported stolen over administrative rental-record errors, is recorded on the parent Hertz row rather than this one.\nWHY IT MATTERS: A renter comparing prices across the three brands is not getting the independent competition the branding implies.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Substantive Hertz-family findings, including the wrongful-vehicle-theft-report pattern the tracker mentions, are recorded on the parent Hertz row per its own cross-reference; this row's own text supports only the toll-fee and brand-structure findings.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Both URLs are unverified this pass, and the row is recorded as one shared assessment with Dollar rather than independently detailed.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Thrifty Car Rental (Hertz)  <-  Hertz Global Holdings, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Thrifty Car Rental (Hertz) you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Thrifty completes the Hertz three-brand structure, and the practical consequence for a renter is that the price comparison they think they are running across companies is a comparison within one. The more serious Hertz-family finding sits in the parent row: a widely reported pattern of vehicles being reported stolen to police over administrative errors in the rental record, producing arrests of customers who had paid. That is a data-integrity failure with consequences no privacy policy contemplates.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Car Rental & Mobility", "_row_id": 536, "_entity_id": 763, "_entity_slug": "thrifty-car-rental-hertz", "_issuer": "Hertz Global Holdings, Inc.", "_issuer_slug": "hertz-global-holdings-inc", "_ticker": "HTZ", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Payless Car Rental (Avis Budget)", "Category": "Car rental", "Terms & Conditions URL": "https://www.paylesscar.com/en/terms-and-conditions", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.avisbudgetgroup.com/privacy-policy/", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "An Avis Budget Group brand; privacy governed at group level alongside Avis, Budget and Zipcar.", "Arbitration / Class Action Waiver": "See the Avis Budget row in F500 Auto & Dealerships.", "Fees / Billing Flags": "Deep-value segment; counter upsell and fuel purchase options are the recurring friction.", "Notes": "URL STATUS: brand terms NOT verified this pass - expected location, confirm on click; group privacy policy NOT verified this pass - expected location, confirm on click. CROSS-REF the Avis Budget row. Avis Budget Group operates Avis, Budget, Payless and Zipcar — four brands, one data controller.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Avis Budget Group, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-1] Kiosk terms accepted under time pressure, alongside heavy counter upsell\nWHAT THE TERMS SAY: Payless's deep-value segment carries the sector's sharpest counter-side pressure, insurance, fuel prepayment, and upgrade upsells presented to a traveller who has just landed and wants the keys, with the governing terms accepted at a kiosk under time pressure and no realistic opportunity to read them.\nWHY IT MATTERS: A traveller who has just landed accepts the governing terms at a kiosk under time pressure, with no realistic opportunity to read them before facing the insurance, fuel and upgrade upsells.\n(evidence: Fees | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Avis, Budget, Payless, and Zipcar share one data controller\nWHAT THE TERMS SAY: Payless is one of four Avis Budget Group brands, alongside Avis, Budget, and Zipcar, that share one data controller despite occupying visibly different market positions.\nWHY IT MATTERS: A renter choosing the deep-value Payless brand over Avis or Budget for privacy reasons would not actually change which company holds their data.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms are deferred to the parent Avis Budget Group row per this tracker's own cross-reference; this row's own text supports only the kiosk dark-pattern-consent and shared-controller findings.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Both brand-terms and group-privacy-policy URLs are unverified this pass, and arbitration terms are deferred entirely to the parent row.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Payless Car Rental (Avis Budget)  <-  Avis Budget Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Payless Car Rental (Avis Budget) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Payless is the fourth Avis Budget brand, and the group structure means Avis, Budget, Payless and Zipcar share one data controller despite occupying visibly different market positions. The deep-value segment carries the sector's sharpest counter-side pressure — insurance, fuel prepayment and upgrade upsells presented to a traveller who has just landed and wants the keys — and the terms governing all of it were accepted at a kiosk under time pressure with no realistic opportunity to read them.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Car Rental & Mobility", "_row_id": 537, "_entity_id": 765, "_entity_slug": "payless-car-rental-avis-budget", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Zipcar (Avis Budget)", "Category": "Car sharing", "Terms & Conditions URL": "https://www.zipcar.com/terms-of-use", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.zipcar.com/privacy", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Car sharing generates a fundamentally more granular record than rental: every trip start and end point, duration and vehicle telematics, tied to a member account used many times a month rather than once a year. Zipcar members typically also grant driving-record access at signup.", "Arbitration / Class Action Waiver": "Avis Budget Group terms; see that row.", "Fees / Billing Flags": "Membership fees plus hourly rates; late-return fees are steep and automatic, and are the dominant member complaint.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. CROSS-REF the Avis Budget row in F500 Auto & Dealerships. Zipcar is heavily used in DC, and its street-parked fleet across the District makes it directly relevant to this tracker's region.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Avis Budget Group, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Every trip's start, end, duration, and telematics logged for a member used dozens of times a year\nWHAT THE TERMS SAY: Car sharing generates a materially more granular record than rental: every trip start and end point, duration, and vehicle telematics are logged, tied to a member account used many times a month rather than once a year.\nWHY IT MATTERS: A member taking dozens of short trips a year has those trips reconstructed into a pattern of life rather than a single holiday's worth of data.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Members grant DMV driving-record access at signup, combined with the movement log\nWHAT THE TERMS SAY: Zipcar members typically grant driving-record access at signup, so the company holds a DMV history alongside the movement log; the tracker notes Zipcar is owned by Avis Budget Group, not the community-mobility brand its marketing suggests, and its street-parked fleet is dense across DC specifically.\nWHY IT MATTERS: The combination of DMV history and a dense, frequent movement log makes Zipcar's dataset more revealing than a conventional car rental's, and directly relevant to the DC region.\n(evidence: Data Sharing | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[AUTO_RENEWAL_FEES · FL-1] Late-return fees are steep and automatic, the dominant member complaint\nWHAT THE TERMS SAY: Late-return fees are described as steep and automatic, and are the dominant member complaint alongside membership and hourly rates.\nWHY IT MATTERS: An automatic, steep fee structure gives a member little room for a late return before facing a significant charge.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Data practices are well described, but both URLs are unverified this pass and arbitration terms are deferred to the parent Avis Budget row.", "Exposure Score (0-100)": 16, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 11, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 11/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Zipcar (Avis Budget)  <-  Avis Budget Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Zipcar (Avis Budget) you gave up your physical movements, your data shared corporate-wide, and your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Zipcar produces a far more revealing dataset than conventional rental because of frequency: a member takes dozens of short trips a year, each logged with start point, end point, duration and vehicle telematics, which reconstructs a pattern of life rather than a single holiday. Members also grant driving-record access at signup, so the company holds a DMV history alongside the movement log. Zipcar is dense across DC specifically, which makes this a directly local dataset — and it belongs to Avis Budget Group, not to the community-mobility brand the marketing suggests.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Car Rental & Mobility", "_row_id": 538, "_entity_id": 766, "_entity_slug": "zipcar-avis-budget", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Turo", "Category": "Peer-to-peer car sharing", "Terms & Conditions URL": "https://turo.com/us/en/policies/terms", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://turo.com/us/en/policies/privacy", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Peer-to-peer means the counterparty is a private individual. Turo holds driver's licence images, driving history, and trip telematics for guests, plus vehicle registration, insurance and payout banking details for hosts running a micro-business.", "Arbitration / Class Action Waiver": "US terms include arbitration provisions; opt-out mechanics not confirmed this pass.", "Fees / Billing Flags": "Trip fees, young-driver fees and post-trip damage claims — the last being the dominant dispute category, adjudicated by the platform between two private parties.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. Turo's model raises an insurance question conventional rental does not: coverage runs through a platform-arranged policy rather than a rental company's fleet policy, and personal auto policies frequently exclude peer-to-peer rental activity for hosts.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] A private host sees your ID documents and tracks the car, with you in it, via telematics\nWHAT THE TERMS SAY: Turo holds driver's licence images, driving history, and trip telematics for guests; as a peer-to-peer platform, the counterparty is a private individual host who sees the renter's identity documents and knows exactly where the car has been, since the trip is telematics-tracked.\nWHY IT MATTERS: A guest's location during the entire rental is visible to a private individual, not just to Turo, and that host also knows their identity from the licence image.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[LIABILITY_CAP_INDEMNITY · FL-1] Host insurance often excludes P2P rental activity, a gap discovered only after a claim\nWHAT THE TERMS SAY: Post-trip damage claims are the dominant dispute category and are adjudicated by the platform between two private parties, neither of whom has a rental company's evidentiary process; coverage runs through a platform-arranged policy, and personal auto policies frequently exclude peer-to-peer rental activity for hosts.\nWHY IT MATTERS: A host renting out their car may only discover their personal insurance excludes that activity after they file a claim and find the coverage gap.\n(evidence: Fees | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] US terms include arbitration provisions; opt-out exists but window is unverified\nWHAT THE TERMS SAY: Turo's US terms include arbitration provisions, with an opt-out that exists but whose window was not verified this pass.\nWHY IT MATTERS: Without a confirmed opt-out window, a user cannot be sure how much time they have to preserve their right to sue in court over a damage dispute or insurance gap.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The peer-to-peer data and insurance risks are clearly described, but both URLs are unverified and the arbitration opt-out window is unconfirmed.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 14, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 14/30 (forced_arbitration+12, optout_window_unverified+2) | Data 7/30 (precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Turo  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Turo you gave up your physical movements, your right to sue, and your right to meaningful compensation. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Turo puts a private individual on the other side of your driver's licence. The host sees your identity documents and knows exactly where their car — with you in it — has been, because the trip is telematics-tracked. Damage disputes are the dominant friction and they are adjudicated by the platform between two private parties, neither of whom has a rental company's evidentiary process. The insurance layer is the underappreciated risk: coverage runs through a platform-arranged policy, and a host's personal auto insurer will often exclude peer-to-peer rental activity entirely, meaning the person renting out their car may discover the gap only after a claim.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Car Rental & Mobility", "_row_id": 539, "_entity_id": 767, "_entity_slug": "turo", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Getaround", "Category": "Peer-to-peer car sharing", "Terms & Conditions URL": "https://getaround.com/terms", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://getaround.com/privacy", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Getaround's connected-car hardware installed in host vehicles enables keyless entry and continuous telematics — a permanently installed tracking device in a private individual's car, reporting to the platform.", "Arbitration / Class Action Waiver": "US terms include arbitration provisions; opt-out mechanics not confirmed this pass.", "Fees / Billing Flags": "Trip and service fees; the company has faced financial difficulty and exited several markets, which raises the data-on-shutdown question.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. Getaround has experienced significant financial distress and market exits — cross-ref the Bird row in Travel & Transit Apps for what happens to customer and host records when a mobility platform fails, since customer data is an asset in a bankruptcy estate.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Permanently installed hardware gives continuous telematics, and only the host consented\nWHAT THE TERMS SAY: Getaround's connected-car hardware, installed in host vehicles to enable keyless entry, provides continuous telematics reporting to the platform; the host consented to this permanently installed tracking device, but anyone else who drives the car did not.\nWHY IT MATTERS: A guest, or any other driver of the host's car, is tracked continuously without ever having agreed to it themselves.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] Financial distress raises the risk customer and host records become a bankruptcy-estate asset\nWHAT THE TERMS SAY: Getaround has faced significant financial distress and market exits; the tracker notes that when a mobility platform fails, customer and host records, including licence images and banking details, can become assets in an estate and transfer to an acquirer under terms nobody originally agreed to.\nWHY IT MATTERS: A host or guest's sensitive documents could end up governed by a new company's terms they never reviewed, if Getaround's financial distress leads to an ownership change.\n(evidence: Fees | Notes; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] US terms include arbitration provisions; opt-out exists but window is unverified\nWHAT THE TERMS SAY: Getaround's US terms include arbitration provisions, with an opt-out that exists but whose window was not verified this pass.\nWHY IT MATTERS: As with the telematics and financial-distress risks above, a user cannot be certain how much time they have to preserve court access.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The telematics and financial-distress risks are clearly described, but both URLs are unverified and the arbitration opt-out window is unconfirmed.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 14, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 14/30 (forced_arbitration+12, optout_window_unverified+2) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Getaround  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Getaround you gave up your physical movements and your right to sue. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Getaround installs connected hardware in host vehicles to enable keyless access, which means a permanently fitted tracking device sits in a private person's car reporting continuously to a platform. The host consented; anyone else who drives that car did not. The more pressing issue is corporate: Getaround has faced serious financial distress and market exits, and the Bird row in this tracker documents exactly what happens next — customer and host records, including licence images and banking details, become assets in an estate and transfer to whoever acquires them under terms nobody agreed to.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Car Rental & Mobility", "_row_id": 540, "_entity_id": 768, "_entity_slug": "getaround", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fox Rent A Car", "Category": "Car rental", "Terms & Conditions URL": "https://www.foxrentacar.com/en/terms-and-conditions.html", "T&C Direct PDF?": "N", "Privacy Policy URL": "https://www.foxrentacar.com/en/privacy-policy.html", "Privacy Direct PDF?": "N", "Data Sharing/Selling Flags": "Independent value operator concentrated at airport locations; privately held with minimal public disclosure.", "Arbitration / Class Action Waiver": "Not confirmed this pass.", "Fees / Billing Flags": "Deep-value segment with a documented pattern of consumer complaint over counter charges added to a prepaid booking.", "Notes": "URL STATUS: both NOT verified this pass - expected location, confirm on click. Fox is a smaller independent operator, which means less public accountability record in either direction — absence of findings here reflects absence of scrutiny rather than demonstrated practice.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] Counter charges added to already-prepaid bookings, presented under queue pressure\nWHAT THE TERMS SAY: The deep-value rental segment, which includes Fox, concentrates a documented pattern of consumer complaint over charges added at the counter to a booking already prepaid online, presented to a traveller who has just landed with a queue behind them and no realistic option to walk away and rebook.\nWHY IT MATTERS: A traveller who believed they had already paid in full faces new charges precisely when they have the least leverage to dispute them.\n(evidence: Fees | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-4] Small, privately held operator with almost no public accountability record\nWHAT THE TERMS SAY: Fox is a smaller independent, privately held operator, which the tracker states means less public accountability record in either direction; the row is described as genuinely unverified rather than clean.\nWHY IT MATTERS: The absence of documented findings here reflects an absence of scrutiny, not a demonstrated clean privacy or fee practice.\n(evidence: Notes | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms are not confirmed this pass, leaving the counter-charge pattern and the general private-ownership opacity as the two substantiated findings.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Both URLs are unverified this pass and the operator is small and privately held, so most fields are genuinely unconfirmed rather than clean.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Fox Rent A Car  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Fox Rent A Car you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The deep-value rental segment concentrates the sector's consumer complaints in one place: charges added at the counter to a booking already prepaid online, presented to a traveller who has just landed, has a queue behind them, and has no realistic option to walk away and rebook. Fox is privately held and small enough to generate almost no public accountability record, so the row is genuinely unverified rather than clean — and that opacity is the reportable fact about the independent end of this market.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Car Rental & Mobility", "_row_id": 541, "_entity_id": 769, "_entity_slug": "fox-rent-a-car", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Nelnet", "Category": "Student Loan Servicer", "Terms & Conditions URL": "nelnet.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "nelnet.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED 2022 BREACH, FULLY SETTLED IN 2026: an unauthorized third party breached Nelnet Servicing's systems (June-July 2022, disclosed Aug 26, 2022), exposing names, addresses, emails, phone numbers, and SOCIAL SECURITY NUMBERS for approximately 2,501,324 current/former EDFINANCIAL SERVICES and OKLAHOMA STUDENT LOAN AUTHORITY (OSLA) borrowers — both serviced through Nelnet's platform. Nelnet, Edfinancial, and OSLA agreed to a $10 MILLION settlement (final approval May 21, 2026), offering up to $5,100 plus credit monitoring; the claim deadline (March 5, 2026) has now passed, meaning borrowers who missed it — even if their data WAS compromised — are no longer eligible for payment.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "MULTIPLE SEPARATE, ONGOING SERVICING-QUALITY LAWSUITS: (1) a 2024 class action alleges Nelnet has REPEATEDLY MISCALCULATED student loan borrowers' monthly repayment amounts; (2) a 2020 class action alleges Nelnet misled certain borrowers into believing they had FEDERALLY-BACKED loans eligible for CARES Act pandemic relief, when they did not — a particularly harmful error given how much financial relief hinged on that eligibility distinction during the pandemic.", "Notes": "Nelnet now has THREE separate, serious issue categories (a 2.5-million-person data breach, repeated payment-miscalculation claims, and CARES Act eligibility misrepresentation) — worth flagging prominently alongside MOHELA and Navient (documented elsewhere in this tracker) as part of a broader, persistent pattern of federal student loan servicer misconduct across the entire industry.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2022, 2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2022 breach exposed 2.5M borrowers' SSNs; settlement claim deadline has now passed\nWHAT THE TERMS SAY: An unauthorized third party breached Nelnet Servicing's systems (June-July 2022, disclosed Aug 26, 2022), exposing names, addresses, emails, phone numbers, and Social Security numbers for approximately 2,501,324 Edfinancial and OSLA borrowers. Nelnet, Edfinancial, and OSLA agreed to a $10 million settlement (final approval May 21, 2026) offering up to $5,100 plus credit monitoring, but the claim deadline (March 5, 2026) has passed, so borrowers who missed it are no longer eligible for payment even if their data was compromised.\nWHY IT MATTERS: Borrowers spent roughly four years, from breach to settlement, with their Social Security numbers exposed, and anyone who missed the March 2026 deadline gets nothing regardless of harm.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-1] Alleges Nelnet misled some borrowers about CARES Act pandemic-relief eligibility\nWHAT THE TERMS SAY: A 2020 class action alleges Nelnet misled certain borrowers into believing they had federally-backed loans eligible for CARES Act pandemic relief when they did not.\nWHY IT MATTERS: The tracker calls this a particularly harmful error given how much financial relief hinged on that eligibility distinction during the pandemic.\n(evidence: Fees; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[OTHER · FL-1] Separate class action alleges Nelnet has repeatedly miscalculated monthly repayments\nWHAT THE TERMS SAY: A 2024 class action alleges Nelnet has repeatedly miscalculated student loan borrowers' monthly repayment amounts.\nWHY IT MATTERS: The tracker counts this as one of three separate, serious issue categories for Nelnet, alongside the 2022 breach and the CARES Act eligibility claim.\n(evidence: Fees; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach and settlement figures are precisely documented, but arbitration terms are not independently confirmed this pass.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Nelnet  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Nelnet takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2022 breach was fully settled in 2026 - four years from incident to resolution, which is the number worth carrying rather than the settlement amount. Student loan borrowers exposed in 2022 spent the entire intervening period with their Social Security numbers in circulation while the legal process ran, and the credit monitoring typically offered after a breach expires long before the litigation does. The mismatch between how long stolen identifiers remain dangerous and how long the remedy lasts is the structural finding across every breach row in this tracker.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Student Loans, Hotels & Auto", "_row_id": 542, "_entity_id": 770, "_entity_slug": "nelnet", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sallie Mae", "Category": "Student Loan Servicer", "Terms & Conditions URL": "salliemae.com/about/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "salliemae.com/about/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED 2023 BREACH: Sallie Mae Bank reported a data breach (disclosed April 25, 2023) affecting an undetermined number of borrowers — specific data types and total scope not independently confirmed in full this pass beyond the confirmed notification itself.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Note: Sallie Mae (private student loans) and Navient (formerly Sallie Mae's federal-loan-servicing spinoff, documented elsewhere in this tracker) are RELATED BUT SEPARATE companies following a 2014 corporate split — worth being precise about which entity services a specific loan given the shared 'Sallie Mae' name history.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2023 breach disclosed; specific data types and total scope not fully confirmed\nWHAT THE TERMS SAY: Sallie Mae Bank reported a data breach, disclosed April 25, 2023, affecting an undetermined number of borrowers; specific data types and total scope were not independently confirmed in full this pass beyond the notification itself.\nWHY IT MATTERS: Borrowers were notified a breach occurred but, per this pass, cannot know from the tracker's confirmed facts alone what data or how many people were actually affected.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Co-signers, who never held an account, are in the exposed population but rarely counted separately\nWHAT THE TERMS SAY: Sallie Mae holds co-signer data, meaning a parent or grandparent who never took a loan and never had an account is included in the exposed population because they signed to help a student qualify; the tracker notes co-signers are rarely counted separately in notification figures.\nWHY IT MATTERS: People who never took a loan and never had an account are nonetheless in the exposed population, and the tracker notes co-signers are rarely counted separately in notification figures.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms are not independently confirmed this pass and fees are not itemized; only the 2023 breach and its co-signer-exposure angle are substantively supported by the text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The breach's specific data types and total scope were not independently confirmed this pass, and arbitration terms remain unconfirmed.", "Exposure Score (0-100)": 14, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Sallie Mae  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Sallie Mae takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2023 Sallie Mae Bank breach is worth reading alongside the Navient and MOHELA rows as a set: private student lending, federal loan servicing, and the borrower sits at the intersection with no ability to leave any of them. Sallie Mae also holds co-signer data, which means a parent or grandparent who never took a loan and never had an account is in the exposed population because they signed to help a student qualify. Co-signers are the invisible class in student lending breach analysis and they are rarely counted separately in notification figures.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Student Loans, Hotels & Auto", "_row_id": 543, "_entity_id": 771, "_entity_slug": "sallie-mae", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Hilton Honors", "Category": "Hotel", "Terms & Conditions URL": "hilton.com/en/corporate/legal/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "hilton.com/en/corporate/legal/website-privacy-statement/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MULTIPLE SEPARATE BREACHES ACROSS A DECADE: (1) TWO 2015 breaches exposed 360,000+ PAYMENT CARD NUMBERS — New York state investigators specifically found Hilton 'did not maintain reasonable data security' and failed to comply with PCI-DSS payment card security standards; Hilton took 9 MONTHS to warn customers after discovering the FIRST breach. Hilton paid $700,000 to settle with New York and Vermont. (2) A 2023 breach: a hacker calling themselves 'IntelBroker' claimed to have stolen 3.7 MILLION Hilton Honors loyalty records; Hilton INITIALLY DENIED any breach occurred, then later confirmed at least 500,000 Honors accounts were compromised after further investigation — the initial denial followed by a partial confirmation is a notable pattern worth flagging, similar to other companies in this tracker that initially understated confirmed breach scope. (3) A SEPARATE 2025 breach at OTELIER, a third-party hotel-management PLATFORM used by 10,000+ hotels including Hilton, Marriott, and Hyatt — attackers obtained AWS cloud-storage credentials and exfiltrated 7.8 TERABYTES of data (hotel reports, shift audits, accounting data) across MULTIPLE major hotel brands simultaneously, illustrating the same shared-vendor exposure pattern documented for SITA in the Global Airlines tab.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Hilton Honors Terms & Conditions. 30-day opt-out via written notice to Hilton Domestic Operating Company LLC, Attn: Legal Department, 7930 Jones Branch Drive, McLean VA 22102. Hilton HQ is in McLean, Virginia — a DMV-headquartered arbitration clause. Covers 18 hotel brands (Hilton, DoubleTree, Hampton, Embassy Suites, etc.).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Hilton now has FOUR separate documented incidents spanning 2015-2025 (two 2015 card breaches, a 2023 loyalty-program breach with an initial denial, a shared 2025 Otelier vendor breach, and an active cookie-opt-out lawsuit) — among the most extensively-flagged hotel chains in this entire tracker; cross-reference with the Marriott row (Consumer Apps tab) for the shared Otelier incident.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$12.0B", "Market Cap": "$73.8B", "Employees": "181,000", "HQ City": "McLean", "HQ State": "Virginia", "CEO": "Christopher Nassetta", "Ticker": "HLT", "Website (Corporate)": "hilton.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (HLT). Service route: c/o General Counsel / Corporate Secretary, McLean, Virginia — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Virginia' is DC/MD/VA", "Parent / Ultimate Owner": "Hilton Worldwide Holdings, Inc.", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Hilton Worldwide Holdings, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2015 breaches exposed 360,000+ cards; NY found Hilton failed PCI-DSS, 9-month delay\nWHAT THE TERMS SAY: Two 2015 breaches exposed 360,000+ payment card numbers; New York state investigators specifically found Hilton 'did not maintain reasonable data security' and failed to comply with PCI-DSS standards, and Hilton took 9 months to warn customers after discovering the first breach. Hilton paid $700,000 to settle with New York and Vermont.\nWHY IT MATTERS: This is a regulatory finding of fault, not just an allegation, that Hilton's own security fell short of the payment-card industry's own standard, with a 9-month gap before customers were warned.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-1] Hilton initially denied a 2023 breach before confirming 500,000+ accounts compromised\nWHAT THE TERMS SAY: A hacker calling themselves 'IntelBroker' claimed to have stolen 3.7 million Hilton Honors loyalty records in 2023; Hilton initially denied any breach occurred, then later confirmed at least 500,000 Honors accounts were compromised after further investigation.\nWHY IT MATTERS: An initial denial followed by a partial confirmation means the public and affected members had no accurate information about their exposure for a period of time.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] 2025 Otelier vendor breach exfiltrated 7.8TB across Hilton, Marriott, and Hyatt\nWHAT THE TERMS SAY: A separate 2025 breach at Otelier, a third-party hotel-management platform used by 10,000+ hotels including Hilton, Marriott, and Hyatt, saw attackers obtain AWS cloud-storage credentials and exfiltrate 7.8 terabytes of data (hotel reports, shift audits, accounting data) across multiple major hotel brands simultaneously.\nWHY IT MATTERS: Guests choosing among competing brands could not have avoided this exposure, since it happened at a shared back-end vendor none of them had ever heard of.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2015 incidents are extremely well documented via regulatory findings, but the true scope of the 2023 breach remains uncertain after Hilton's initial denial.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 10/20 (severity2+2, breach+3, penalty+3, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Hilton Honors  <-  Hilton Worldwide Holdings, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Hilton Honors you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Multiple separate breaches across a decade, including the shared 2025 Otelier vendor incident that also caught Hyatt and Marriott - three competing hotel groups exposed through one back-end platform none of their guests had heard of. Hotel data is distinctively revealing: a reservation record is a person's physical location on specific dates, often with a second guest name attached, plus payment details and loyalty history that maps travel patterns over years. Marriott's own record, documented elsewhere in this tracker, includes one of the longest-running undetected intrusions ever recorded.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Student Loans, Hotels & Auto", "_row_id": 544, "_entity_id": 773, "_entity_slug": "hilton-honors", "_issuer": "Hilton Worldwide Holdings, Inc.", "_issuer_slug": "hilton-worldwide-holdings-inc", "_ticker": "HLT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Hyatt", "Category": "Hotel", "Terms & Conditions URL": "hyatt.com/en-US/info/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "hyatt.com/info/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SAME SHARED 2025 OTELIER VENDOR BREACH as Hilton and Marriott (see Hilton row for full detail) — Hyatt is named among the 10,000+ hotels using the Otelier hotel-management platform whose AWS cloud storage was compromised, exposing operational data across multiple major hotel brands simultaneously. SEPARATE, HISTORICAL BREACH (2015-2017): Hyatt disclosed an earlier payment-card data breach affecting properties internationally, part of the same broader wave of hospitality-industry point-of-sale breaches that also hit Hilton, IHG, Trump Hotels, and Omni Hotels around the same period.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The hospitality industry's 2015-2017 wave of point-of-sale payment-card breaches (Hilton, Hyatt, IHG, Trump Hotels, Omni Hotels all separately affected) illustrates a genuinely industry-wide security weakness in hotel payment processing during that period — worth treating as a connected historical pattern rather than isolated single-company failures.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Caught in the same 2025 Otelier vendor breach as Hilton and Marriott\nWHAT THE TERMS SAY: Hyatt is named among the 10,000+ hotels using the Otelier hotel-management platform whose AWS cloud storage was compromised in the same 2025 breach documented for Hilton, exposing operational data across multiple major hotel brands simultaneously.\nWHY IT MATTERS: Choosing a different major chain would not have prevented this exposure, since it happened at a shared vendor rather than at any individual hotel company.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Separate 2015-2017 payment-card breach hit properties internationally\nWHAT THE TERMS SAY: A separate, historical breach (2015-2017) disclosed by Hyatt affected payment-card data at properties internationally, part of a broader wave of hospitality point-of-sale breaches that also hit Hilton, IHG, Trump Hotels, and Omni Hotels around the same period.\nWHY IT MATTERS: The 2015-2017 wave illustrates a genuinely industry-wide weakness in hotel payment processing during that period, not an isolated Hyatt failure.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-4] Loyalty consolidation is marketed as a benefit but functions as data concentration\nWHAT THE TERMS SAY: The tracker notes hotel loyalty programmes actively encourage consolidating stays with one brand, presented as a benefit, which functions as data concentration: the more loyal a guest, the more complete the movement history held by that company and its vendors.\nWHY IT MATTERS: A guest who was loyal specifically to Hyatt to build a complete relationship with one trusted brand had that same loyalty concentrate their exposure when the shared vendor was breached.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Both breach events are well documented, but arbitration terms are not independently confirmed this pass.", "Exposure Score (0-100)": 14, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Hyatt  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Hyatt takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same 2025 Otelier vendor breach as Hilton and Marriott - recorded as one connected finding rather than three, per this tracker's cross-reference standard. The point for a traveller is that hotel loyalty programmes actively encourage consolidating stays with one brand, which is presented as a benefit and functions as data concentration: the more loyal you are, the more complete the movement history held by a single company and by whichever vendors it uses. Choosing a different chain would not have helped here, since the exposure was at the shared vendor.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Student Loans, Hotels & Auto", "_row_id": 545, "_entity_id": 774, "_entity_slug": "hyatt", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "IHG (Holiday Inn/InterContinental)", "Category": "Hotel", "Terms & Conditions URL": "ihg.com/hotels/us/en/customer-care/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "ihg.com/hotels/us/en/customer-care/privacy-cookie-statement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "REMARKABLY LONG-RUNNING DATA BREACH LAWSUIT: a class action against InterContinental Hotels Group (Canada), later amended to name Six Continents Hotels as sole defendant, alleges SECURITY FAILURES allowed customers' financial information to be compromised — as of IHG's OWN February 2026 securities filing, the case remains UNRESOLVED with the company stating 'the likelihood of a favourable or unfavourable result cannot be reasonably determined' — the claim was originally amended back in MARCH 2018, meaning this single case has now been pending for roughly 8 YEARS without final resolution.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass for individual guest agreements — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "SEPARATE, SERIOUS FRANCHISEE LITIGATION: seven claims (filed March 2022, later consolidated) by IHG's OWN HOTEL FRANCHISEES allege breach of contract, breach of fiduciary duty, and violation of the SHERMAN ANTITRUST ACT — arguing IHG (as franchisor) engaged in unlawful business practices tied to numerous mandatory programs/products/requirements within its franchise system. A court ruled largely in IHG's favor (Dec 2024), dismissing the majority of claims, with the remaining claims dismissed WITH PREJUDICE in May 2025 — though this outcome was still on appeal per the most recent filing reviewed.", "Notes": "The 8-YEAR-OLD, still-unresolved data breach lawsuit is one of the longest-pending individual cases documented anywhere in this entire tracker — worth flagging alongside CareFirst's 9-year Attias case (Insurance tab) as an example of how genuinely protracted major corporate data-privacy litigation can become.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-2] Data-breach class action has been pending roughly 8 years with no resolution\nWHAT THE TERMS SAY: A class action against InterContinental Hotels Group (Canada), later amended to name Six Continents Hotels as sole defendant, alleges security failures allowed customers' financial information to be compromised; as of IHG's own February 2026 securities filing, the case remains unresolved, with the company stating 'the likelihood of a favourable or unfavourable result cannot be reasonably determined,' roughly 8 years after the claim was amended in March 2018.\nWHY IT MATTERS: Breach litigation of this length routinely outlives the credit monitoring offered, the news coverage, and often the affected guest's memory of having stayed there, per the tracker's own framing.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration terms for individual guest agreements are not independently confirmed this pass. The other major documented dispute, a franchisee Sherman Antitrust and fiduciary-duty suit, concerns IHG's relationship with its franchisees rather than consumer terms, so it is not counted as a consumer-facing troubling item here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "IHG's own securities filing states the litigation's outcome 'cannot be reasonably determined' after roughly 8 years, and arbitration terms for guests are unconfirmed.", "Exposure Score (0-100)": 10, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "IHG (Holiday Inn/InterContinental)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, IHG (Holiday Inn/InterContinental) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The remarkably long-running class action against IHG is the row's substance, and duration is the finding: breach litigation routinely outlives the credit monitoring offered, the news coverage, and often the affected person's memory of having stayed there. IHG's own disclosed incidents include an attack reportedly carried out in part for disruption rather than pure data theft. For a guest, the practical exposure is the same either way - a record of where they physically were on specific nights, held indefinitely by a company they interacted with once.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Student Loans, Hotels & Auto", "_row_id": 546, "_entity_id": 775, "_entity_slug": "ihg-holiday-inn-intercontinental", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "AAA (American Automobile Association)", "Category": "Auto/Roadside/Insurance", "Terms & Conditions URL": "aaa.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "aaa.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named national-level data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — AAA operates as a FEDERATION of regionally independent, separately-incorporated clubs (e.g., AAA Mid-Atlantic serves this specific region) rather than a single centrally-owned company, meaning terms, privacy practices, and any specific incidents likely vary by REGIONAL club rather than following one uniform national policy — similar to the YMCA's federated structure documented elsewhere in this tracker.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Given AAA's federated structure, recommend checking the SPECIFIC regional club serving the Mid-Atlantic (AAA Mid-Atlantic specifically) for its own terms/privacy policy and any regional-specific incidents, rather than assuming a single national AAA policy applies uniformly.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] Federated club structure means no single entity or policy governs a member's data\nWHAT THE TERMS SAY: AAA operates as a federation of regionally independent, separately incorporated clubs rather than a single centrally owned company, meaning terms, privacy practices, and any specific incidents likely vary by regional club rather than following one uniform national policy; a breach at one club produces no notification obligation at another.\nWHY IT MATTERS: A member has no way to know which entity actually holds their data, and the tracker notes the federated model means a national search systematically under-detects incidents.\n(evidence: Arbitration | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No national-level breach, litigation, or confirmed arbitration terms are documented for AAA in this pass; only the structural finding about its federated, club-by-club data-governance structure is supported by the text, and the tracker recommends checking the specific regional club instead.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed at the national level, and the tracker explicitly attributes this to AAA's federated structure rather than a clean record.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "AAA (American Automobile Association)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, AAA (American Automobile Association) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed at national level this pass, and the structure is why: AAA is a federation of independent regional clubs, not a single company, so each club runs its own systems, its own membership database and its own insurance and financial services operations under a shared brand. A member has no way to know which entity actually holds their data, and a breach at one club produces no notification obligation at another. The federated model also means a national search systematically under-detects incidents. Recorded as unverified rather than clean; recommend following up at the club level for the Mid-Atlantic region specifically.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Student Loans, Hotels & Auto", "_row_id": 547, "_entity_id": 776, "_entity_slug": "aaa-american-automobile-association", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CarMax", "Category": "Auto Retail", "Terms & Conditions URL": "carmax.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "carmax.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED JANUARY 2026 BREACH/EXTORTION ATTEMPT: data allegedly sourced from CarMax was published online following a FAILED EXTORTION ATTEMPT — the leaked data included 431,000 unique email addresses along with names, phone numbers, and physical addresses. The 'failed extortion' framing suggests CarMax may have declined to pay a ransom demand, after which the attacker published the data publicly (a similar pattern to the Panera Bread ShinyHunters incident documented elsewhere in this tracker).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected. MAJOR UPDATE: CarMax was ALSO hit with a separate lawsuit (Feb 2026) tied to the SAME ShinyHunters campaign that breached Match Group around the same time, exploiting compromised single-sign-on credentials via social engineering — consistent with the earlier-noted Jan 2026 extortion attempt. SEPARATELY, and more significantly: in March 2026, a coalition of SIX CALIFORNIA DISTRICT ATTORNEYS (San Francisco, Santa Clara, Sonoma, Los Angeles, Ventura, Riverside) secured a $1.1 MILLION consumer-protection settlement against CarMax over used-car sales practices — explicitly following the template of a nearly identical 2025 settlement against AutoNation-affiliated dealerships (see that row, this same tab), suggesting a genuine industry-wide enforcement pattern against large used-car retailers' sales practices, not an isolated CarMax issue.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is one of the MOST RECENT breaches in this entire tracker (January 2026) — recommend a direct follow-up to confirm final scope and any resulting litigation given how recent this incident is.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$25.9B", "Market Cap": "$7.4B", "Employees": "29,836", "HQ City": "Richmond", "HQ State": "Virginia", "CEO": "William Nash", "Ticker": "KMX", "Website (Corporate)": "carmax.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (KMX). Service route: c/o General Counsel / Corporate Secretary, Richmond, Virginia — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Virginia' is DC/MD/VA", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Jan 2026 extortion attempt leaked 431,000 emails plus names, phones, addresses\nWHAT THE TERMS SAY: Data allegedly sourced from CarMax was published online following a failed extortion attempt in January 2026; the leaked data included 431,000 unique email addresses along with names, phone numbers, and physical addresses.\nWHY IT MATTERS: The 'failed extortion' framing suggests CarMax declined to pay, after which the attacker published the data publicly, exposing hundreds of thousands of customers regardless of that decision.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-1] Six California DAs secured a $1.1M settlement over used-car sales practices\nWHAT THE TERMS SAY: In March 2026, a coalition of six California district attorneys (San Francisco, Santa Clara, Sonoma, Los Angeles, Ventura, Riverside) secured a $1.1 million consumer-protection settlement against CarMax over used-car sales practices, following the template of a similar 2025 settlement against AutoNation-affiliated dealerships.\nWHY IT MATTERS: Multiple California prosecutors coordinating on a settlement, following a near-identical prior action against another major dealer, points to a sales-practices issue the tracker frames as an industry-wide enforcement pattern.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[PENDING_LITIGATION · FL-2] Feb 2026 lawsuit ties CarMax to the ShinyHunters SSO-credential campaign\nWHAT THE TERMS SAY: CarMax was hit with a separate lawsuit in Feb 2026 tied to the same ShinyHunters campaign that breached Match Group around the same time, exploiting compromised single-sign-on credentials via social engineering.\nWHY IT MATTERS: The tracker describes this separate lawsuit as consistent with the earlier January 2026 extortion attempt and tied to the same ShinyHunters campaign that breached Match Group, exploiting compromised single-sign-on credentials via social engineering.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "These are very recent (Jan-Mar 2026) events with dollar figures and dates stated, but data attribution to CarMax is described as 'alleged' and arbitration terms remain unconfirmed.", "Exposure Score (0-100)": 10, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 10/20 (severity2+2, breach+3, penalty+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "CarMax  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, CarMax takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The January 2026 extortion attempt involved data allegedly sourced from a third party rather than from CarMax directly - which is now the dominant pattern across this tracker and the reason a company's own security posture is a poor predictor of a customer's exposure. Auto retail data is also unusually complete: a vehicle purchase involves a credit application, income verification, driver's licence, insurance details and often a trade-in history, assembled in a single transaction. Cross-ref the Auto Apps tab and the Allstate/Arity finding in Insurance for what the connected-vehicle layer adds on top.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Student Loans, Hotels & Auto", "_row_id": 548, "_entity_id": 777, "_entity_slug": "carmax", "_issuer": "CarMax", "_issuer_slug": "carmax", "_ticker": "KMX", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Rite Aid", "Category": "Pharmacy", "Terms & Conditions URL": "riteaid.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "riteaid.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MULTIPLE SEPARATE FINDINGS: (1) A May 2023 breach compromised personal/health information of approximately 24,000 individuals. (2) A JUNE 2024 breach (RansomHub ransomware group) affected approximately 2.2 MILLION customers — a hacker IMPERSONATING AN EMPLOYEE gained access to systems; Rite Aid identified the intrusion within 12 hours but not fast enough to prevent data theft (names, addresses, birthdates, driver's license/government ID numbers for customers who made purchases between June 6, 2017 and July 30, 2018). Rite Aid settled the resulting class action (Bianucci v. Rite Aid) for $6.8 MILLION (final approval July 30, 2025), offering up to $10,000 for documented losses. (3) SEPARATE, EARLIER LAWSUIT (2023): alleged Rite Aid disclosed website visitors' personal AND HEALTH information to Meta and other third parties without consent — the same Meta Pixel/pharmacy-data pattern documented for Kroger elsewhere in this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "COMPLICATING FACTOR: Rite Aid FILED FOR BANKRUPTCY (a SECOND time, following an earlier 2023 Chapter 11) during the pendency of the data-breach settlement — the settlement's own FAQ page explicitly states 'the parties are evaluating the potential impact that Rite Aid's bankruptcy filing may have on the settlement,' meaning even a court-APPROVED settlement's actual payout could be affected by the company's ongoing financial distress.", "Notes": "Rite Aid now has FOUR separate documented issue categories (two breaches, a Meta pixel health-data lawsuit, and a bankruptcy complicating settlement payout) — one of the most extensively-flagged pharmacy chains in this entire tracker, worth treating with particular care given the health-data sensitivity involved across multiple incidents.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DISCRIMINATORY_PRACTICE · FL-2] FTC found facial recognition caused false matches that got innocent customers accused\nWHAT THE TERMS SAY: The FTC's action over Rite Aid's use of facial recognition in stores found the system generated thousands of false matches and disproportionately flagged women and people of colour, leading to customers being followed, searched, publicly accused, and in some cases reported to police for crimes they had not committed; the resulting order barred Rite Aid from using facial recognition for surveillance for five years.\nWHY IT MATTERS: This is one of the few findings in the tracker where the harm was not abstract data exposure but a person being detained in a shop based on a false match.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] 2024 ransomware breach hit 2.2M customers; $6.8M settlement complicated by bankruptcy\nWHAT THE TERMS SAY: A June 2024 RansomHub ransomware breach, via a hacker impersonating an employee, affected approximately 2.2 million customers, exposing names, addresses, birthdates, and driver's licence or government ID numbers for purchases made June 2017-July 2018; the resulting settlement (Bianucci v. Rite Aid) reached $6.8 million (final approval July 30, 2025), offering up to $10,000 for documented losses, but Rite Aid's second bankruptcy filing occurred during the settlement's pendency, and its own FAQ page states the parties are still evaluating what impact that may have on payout.\nWHY IT MATTERS: Even a court-approved settlement's actual payout to affected customers could be reduced or delayed by Rite Aid's ongoing financial distress.\n(evidence: Data Sharing | Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] 2023 lawsuit alleges health information was disclosed to Meta without consent\nWHAT THE TERMS SAY: A separate, earlier 2023 lawsuit alleges Rite Aid disclosed website visitors' personal and health information to Meta and other third parties without consent, the same Meta Pixel/pharmacy-data pattern the tracker documents for Kroger elsewhere.\nWHY IT MATTERS: Health information shared with an advertising platform without consent can be used for ad targeting in ways a pharmacy customer would not expect or have agreed to.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Four separate, well-documented issue categories exist for this row, but the pending bankruptcy leaves the breach settlement's actual payout unresolved.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 0/20 (none) | Record 14/20 (severity3+8, breach+3, penalty+3) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Rite Aid  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Rite Aid you gave up your biometric identifiers and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The May 2023 breach compromised personal and health information, and Rite Aid carries a second finding that matters more: the FTC's action over its use of facial recognition in stores, which the Commission found generated thousands of false matches and disproportionately flagged women and people of colour, leading to customers being followed, searched, publicly accused and in some cases reported to police for crimes they had not committed. The resulting order barred Rite Aid from using facial recognition for surveillance for five years. That is one of the few findings anywhere in this tracker where the harm was not abstract data exposure but a person being detained in a shop.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Student Loans, Hotels & Auto", "_row_id": 549, "_entity_id": 778, "_entity_slug": "rite-aid", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Wawa", "Category": "Convenience Store (regional)", "Terms & Conditions URL": "wawa.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "wawa.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Wawa Rewards collects purchase history, fuel purchases, and location data across the mid-Atlantic. The 2019 POS breach exposed 30M payment cards — Wawa settled the class action for $12M (2022). A consumer who signed up for Wawa Rewards after the settlement is bound by the current arbitration clause for any future breach.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Wawa's Terms of Use, AAA rules. 30-day opt-out. Covers the Wawa app, Wawa Rewards, and online ordering. Wawa operates 1,000+ stores across the mid-Atlantic (PA, NJ, DE, MD, VA, DC, FL). The 2019 Wawa data breach (30M payment cards, 850 stores over 10 months) is one of the largest point-of-sale breaches in US history.", "Fees / Billing Flags": "A notable OBJECTION was filed against the settlement (by the Hamilton Lincoln Law Institute's Center for Class Action Fairness) arguing the deal would pay ATTORNEYS MORE than the class members they represented — a recurring critique in class-action settlement practice generally, worth noting as a genuine point of contention in how this specific settlement was ultimately structured.", "Notes": "GIVEN WAWA'S BELOVED, ALMOST CULTURAL STATUS ACROSS THE MID-ATLANTIC REGION SPECIFICALLY, this 30-MILLION-CARD breach is arguably one of the MOST DIRECTLY RELEVANT findings in this ENTIRE 480+ company tracker for the exact population this project is meant to serve — worth flagging with particular prominence given how many Mid-Atlantic residents have used a Wawa card or fuel pump during the 9-month exposure window.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Wawa", "HQ State": "Pennsylvania", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Wawa, Inc. (privately held, employee-owned ESOP)", "Years Referenced in Finding (heuristic)": "2019", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Wawa, Inc. (privately held, employee-owned ESOP)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2019 POS malware exposed 30M payment cards across 850 stores over 10 months\nWHAT THE TERMS SAY: The 2019 Wawa point-of-sale breach exposed 30 million payment cards, with malware present across up to 850 stores for roughly 10 months before discovery; the stolen cards were subsequently offered on a criminal marketplace in one of the largest card dumps ever posted. Wawa settled the resulting class action for $12 million in 2022.\nWHY IT MATTERS: The exposure ran through the most routine transaction there is, buying gas or a sandwich with a card, at a chain many Mid-Atlantic households visit nearly daily.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with class-action waiver, 30-day opt-out\nWHAT THE TERMS SAY: Wawa's Terms of Use impose mandatory binding arbitration under AAA rules with a class-action waiver and a 30-day opt-out, covering the Wawa app, Wawa Rewards, and online ordering; a consumer who signs up for Wawa Rewards today is bound by this clause for any future breach.\nWHY IT MATTERS: Anyone signing up now for rewards is agreeing in advance to arbitrate, rather than sue in court, over any future incident, not just the 2019 breach.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-1] Objection filed arguing the 2019 breach settlement paid attorneys more than the class\nWHAT THE TERMS SAY: A notable objection was filed against the 2019 breach settlement, by the Hamilton Lincoln Law Institute's Center for Class Action Fairness, arguing the deal would pay attorneys more than the class members they represented.\nWHY IT MATTERS: This is a specific, on-the-record challenge to whether the $12M settlement actually compensated affected cardholders proportionate to what their lawyers received.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2019 breach and settlement are extensively documented, but a fairness objection over attorney fees means the adequacy of consumer redress is contested.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Wawa  <-  Wawa, Inc. (privately held, employee-owned ESOP)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Wawa you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Wawa is one of the most regionally significant breaches in this tracker: malware sat on point-of-sale systems at potentially every Wawa location for roughly nine months in 2019 before discovery, collecting payment card data from in-store and fuel purchases. The stolen cards were subsequently offered on a criminal marketplace in one of the largest card dumps ever posted. For the DMV, Wawa is a near-daily stop for an enormous number of households, and the exposure ran through the most routine transaction there is - buying gas or a sandwich with a card.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Convenience Chains", "_row_id": 550, "_entity_id": 780, "_entity_slug": "wawa", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Royal Farms", "Category": "Convenience Store (regional)", "Terms & Conditions URL": "royalfarms.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "royalfarms.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Royal Farms ROFO Rewards collects purchase history and fuel data. As a Baltimore-headquartered chain with primary operations in the DMV corridor, Royal Farms is one of the most regionally focused companies in this tracker.", "Arbitration / Class Action Waiver": "Royal Farms' website Terms of Use are minimal compared to Wawa/Sheetz — no mandatory arbitration clause identified in publicly available terms. Royal Farms operates 290+ stores primarily in MD, DE, VA, PA, NJ, WV. HQ: Baltimore, Maryland (DMV).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Royal Farms is a Maryland-founded (York, PA HQ) chain with a devoted regional following across MD/DE/VA/PA/WV, similar in cultural significance to Wawa/Sheetz — given the strong breach pattern already documented across the convenience-store category in this tab (Wawa's 30-million-card breach, 7-Eleven's 2026 breach), recommend a direct follow-up on Royal Farms' own payment-security practices specifically, since thin public documentation here likely reflects search-visibility limitations rather than a confirmed clean record.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Baltimore", "HQ State": "Maryland", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Baltimore, Maryland (DC/MD/VA)", "Parent / Ultimate Owner": "Royal Farms (privately held, Cloverland Dairy family)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Maryland SDAT Business Entity Search — egov.maryland.gov/businessexpress/entitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Royal Farms (privately held, Cloverland Dairy family)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] ROFO Rewards fuel program ties purchases to identity, building a vehicle-use and location record\nWHAT THE TERMS SAY: The tracker states Royal Farms' ROFO Rewards loyalty and fuel program links fuel purchases to a customer's identity, producing what the tracker calls a vehicle-use and location pattern.\nWHY IT MATTERS: Tying refueling stops to an identified customer lets the company (or anyone who obtains the data) reconstruct where and when that person drives.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one company-specific fact is present -- the loyalty-program location link; arbitration is stated as absent, fees are not itemized, and the SCARY field otherwise discusses limited public disclosure due to private ownership rather than a specific clause.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Privately held chain with no SEC filings or analyst scrutiny; arbitration, fees, and breach status are all unconfirmed this pass.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent", "Entity Type": "Company", "Ownership Path": "Royal Farms  <-  Royal Farms (privately held, Cloverland Dairy family)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Royal Farms you gave up your physical movements. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Royal Farms is a privately held Baltimore-based chain with heavy Maryland, Delaware and Virginia presence, and private ownership means materially less public disclosure than a listed company - no SEC filings, no earnings calls, no analyst scrutiny. Its loyalty and fuel rewards programme ties fuel purchases to identity, which is a vehicle-use and location pattern. Unverified rather than clean, and the absence of a public record here is a function of the corporate structure.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Convenience Chains", "_row_id": 551, "_entity_id": 781, "_entity_slug": "royal-farms", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sheetz", "Category": "Convenience Store (regional)", "Terms & Conditions URL": "sheetz.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "sheetz.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MySheetz Card collects purchase history, fuel purchases, and location data. Sheetz's DMV footprint (MD, VA) means a significant number of tracker-relevant consumers are bound by these terms.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Sheetz ToS. 30-day opt-out. Covers the Sheetz app, MySheetz Card rewards, and online ordering. Sheetz operates 700+ stores in PA, MD, VA, WV, OH, NC — significant DMV presence in Maryland and Virginia.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Sheetz (Pennsylvania-founded, serving PA/MD/VA/WV/NC/OH) shares the same regional cultural significance as Wawa and Royal Farms — recommend the same direct follow-up on payment-security practices given the strong breach pattern documented elsewhere in this convenience-store category.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Altoona", "HQ State": "Pennsylvania", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Sheetz, Inc. (privately held, Sheetz family)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Sheetz, Inc. (privately held, Sheetz family)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Sheetz binds MySheetz Card and app users to mandatory arbitration with a class-action waiver\nWHAT THE TERMS SAY: Sheetz's ToS impose mandatory binding arbitration with a class action waiver, covering the Sheetz app, MySheetz Card rewards, and online ordering, with a 30-day opt-out window.\nWHY IT MATTERS: Customers who don't opt out within 30 days lose the ability to sue Sheetz in court or join a class action over disputes.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[BIOMETRICS · FL-2] Sheetz has deployed facial recognition in some stores, an unconfirmed policy area flagged for follow-up\nWHAT THE TERMS SAY: The tracker notes Sheetz has deployed facial recognition in some contexts, without a published policy independently confirmed this pass.\nWHY IT MATTERS: Facial recognition carries documented false-match and disparate-impact risk, and Pennsylvania/Maryland lack an Illinois-style private right of action if it's misused.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[LOCATION_TRACKING · FL-2] MySheetz Card collects purchase history, fuel purchases, and location data\nWHAT THE TERMS SAY: MySheetz Card is stated to collect purchase history, fuel purchases, and location data.\nWHY IT MATTERS: The tracker notes Sheetz's DMV footprint (MD, VA) means a significant number of tracker-relevant consumers are bound by these terms.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated, but breach history and the facial-recognition policy are both unconfirmed this pass.", "Exposure Score (0-100)": 36, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 10/30 (biometric_collection+6, precise_location_tracking+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Sheetz  <-  Sheetz, Inc. (privately held, Sheetz family)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Sheetz you gave up your biometric identifiers, your physical movements, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Same privately held, regionally dominant convenience-and-fuel structure as Royal Farms, with the added note that Sheetz has deployed facial recognition in some contexts - a category that produced Rite Aid's five-year FTC ban and that carries documented false-match and disparate-impact risk. Recommend a targeted follow-up on Sheetz's in-store biometric deployment and its published policy, since Pennsylvania and Maryland lack an Illinois-style private right of action.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Convenience Chains", "_row_id": 552, "_entity_id": 783, "_entity_slug": "sheetz", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "7-Eleven", "Category": "Convenience Store", "Terms & Conditions URL": "7-eleven.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "7-eleven.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "VERY RECENT, ACTIVE BREACH (April 2026): the ShinyHunters extortion group (the SAME group behind the Panera Bread, Air France/KLM, and Workday breaches documented elsewhere in this tracker) claimed responsibility for stealing MORE THAN 600,000 RECORDS of personally identifiable information from 7-Eleven, in what the lawsuits describe as a 'PAY OR LEAK' extortion campaign — when 7-Eleven apparently did not pay, ShinyHunters posted the stolen data for download on its dark-web site. TWO SEPARATE class actions (Ellison and Choplin, both Texas federal court) allege 7-Eleven failed to even ENCRYPT OR REDACT the sensitive information it retained, calling this a 'reckless and negligent' data-retention practice that left customer data 'vulnerable to unauthorized access.'", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is one of the MOST RECENT breaches documented in this entire tracker — recommend a direct follow-up to confirm final scope and litigation outcome given how new this incident is; the failure to encrypt/redact data (if proven) would represent a genuinely basic security lapse.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] ShinyHunters claimed responsibility for stealing 600,000+ records of PII from 7-Eleven in April 2026\nWHAT THE TERMS SAY: The tracker states ShinyHunters claimed responsibility for stealing more than 600,000 records of PII from 7-Eleven and posted the data on its dark-web site after 7-Eleven apparently did not pay.\nWHY IT MATTERS: Customers whose PII was in that dataset now face it being publicly downloadable, with two class actions (Ellison and Choplin) already filed.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-1] Lawsuits allege 7-Eleven never encrypted or redacted the retained data that was stolen\nWHAT THE TERMS SAY: Two class actions (Ellison and Choplin, Texas federal court) allege 7-Eleven failed to encrypt or redact the sensitive information it retained, calling the retention practice 'reckless and negligent.'\nWHY IT MATTERS: If proven, the tracker calls the failure to encrypt or redact retained data a genuinely basic security lapse that left customer data 'vulnerable to unauthorized access.'\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and fees are not independently confirmed this pass (expected only); only the breach and encryption-failure allegations are substantiated by the row's text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach itself is well documented, but arbitration terms and final litigation scope remain unconfirmed this pass.", "Exposure Score (0-100)": 16, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "7-Eleven  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, 7-Eleven takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "7-Eleven was hit in April 2026 by the ShinyHunters extortion group - the campaign documented in the F500 Tech & Semiconductors tab that reached more than a thousand organisations through social engineering and OAuth abuse rather than any technical exploit. Convenience retail also runs heavily franchised, so a customer's transaction and loyalty data may sit with an independent operator rather than the national brand, and the answer to who to contact after a breach differs by store.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Convenience Chains", "_row_id": 553, "_entity_id": 784, "_entity_slug": "7-eleven", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Weis Markets", "Category": "Grocery (regional)", "Terms & Conditions URL": "weismarkets.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "weismarkets.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass. SEPARATE, UNRELATED SECURITIES MATTER (2026): a shareholder investigation was opened after Weis Markets disclosed (SEC filing, Feb 26, 2026) that it must RESTATE MULTIPLE PRIOR YEARS' AUDITED FINANCIAL STATEMENTS due to OVERSTATED INVENTORY, and would delay its 2025 annual report — shares fell ~7.2% on the news. This is an INVESTOR/securities-fraud matter (only relevant to people who purchased Weis Markets STOCK), not a consumer-data-privacy issue, and should not be confused with the customer-data findings elsewhere in this row.", "Notes": "Weis Markets is a Pennsylvania-based regional grocery chain serving PA/MD/VA/NY/NJ/WV/DE — given the strong pattern of grocery-industry findings documented elsewhere in this tracker (Kroger, Giant Food/Food Lion's Ahold Delhaize breach, Wegmans' misconfigured databases), recommend a direct follow-up on Weis's own data practices specifically given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — No consumer-facing privacy, arbitration, or fee practice is confirmed this pass -- data sharing, arbitration, and SCARY fields all say unverified; the only concrete fact (a shareholder investigation over a financial restatement) is explicitly a stock-investor matter, not a consumer terms issue.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing, arbitration, and SCARY fields all state nothing confirmed this pass; the only concrete disclosure is an unrelated securities matter.", "Exposure Score (0-100)": 4, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Weis Markets  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Weis Markets takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Weis is a Pennsylvania-based regional grocer with a Mid-Atlantic footprint and an in-store pharmacy operation, which places it in the same prescription-plus-loyalty category as Kroger and Albertsons. Regional chains generate far less national coverage than national ones, so their incidents are systematically under-detected relative to their local significance. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Mid-Atlantic Convenience Chains", "_row_id": 554, "_entity_id": 785, "_entity_slug": "weis-markets", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Green Dot", "Category": "Prepaid Debit/Fintech", "Terms & Conditions URL": "greendot.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "greendot.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named recent data-privacy lawsuit or breach; Green Dot is a bank holding company that provides the underlying banking infrastructure for numerous OTHER prepaid card and fintech products (a 'banking-as-a-service' provider), meaning its data practices may affect customers of OTHER branded cards/apps who have never heard of 'Green Dot' directly — a similar 'invisible infrastructure provider' pattern to Synchrony Financial (Credit Card Companies tab) and Apex Clearing (Brokerages tab) documented elsewhere in this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Prepaid debit cards broadly (not Green Dot-specific) are frequently criticized industry-wide for ATM/reload/inactivity fees that can be less transparent than traditional checking accounts — a structural cost concern relevant to financially vulnerable populations specifically.", "Notes": "Green Dot's role as an INVISIBLE INFRASTRUCTURE PROVIDER behind other branded cards/apps is worth flagging — similar to Synchrony Financial and Apex Clearing elsewhere in this tracker, a customer may have meaningful financial exposure to Green Dot's practices without ever directly interacting with the Green Dot brand itself.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Green Dot is an invisible banking-as-a-service backend many customers never know holds their data\nWHAT THE TERMS SAY: The tracker describes Green Dot as a bank holding company providing banking-as-a-service infrastructure behind numerous other branded prepaid cards/apps, meaning customers of those other products may be bound by Green Dot's practices without ever seeing the Green Dot name.\nWHY IT MATTERS: A consumer has no direct visibility into or relationship with the entity actually processing their financial data, making it harder to know whose terms and privacy practices actually govern them.\n(evidence: Data Sharing | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[TERMINATION_CONFISCATION · FL-4] Green Dot's unbanked-skewing customers have the fewest alternatives if a frozen account becomes a crisis\nWHAT THE TERMS SAY: The tracker states Green Dot's customer base skews toward the unbanked/underbanked, a population for whom a frozen account or disputed transaction is an immediate crisis, with the fewest alternatives if the relationship fails.\nWHY IT MATTERS: The tracker states these consumers face an immediate crisis rather than an inconvenience if an account is frozen or a transaction disputed, and have the fewest alternatives if the relationship fails.\n(evidence: SCARY; Stated in tracker (fidelity pass 1: Overstated corrected) (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only structural/descriptive facts are present -- no specific clause language, breach, or arbitration term is confirmed this pass; fees are explicitly industry-wide, not Green Dot-specific.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No named breach, arbitration term, or fee practice is confirmed for Green Dot itself this pass; only structural/industry context is available.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Green Dot  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Green Dot you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing recent confirmed this pass. Green Dot's significance is structural and worth stating plainly: it is a major provider of prepaid debit and banking-as-a-service infrastructure behind other companies' branded cards, so consumers frequently hold a Green Dot product without knowing the name. Its customer base skews toward the unbanked and underbanked - people for whom a frozen account or a disputed transaction is an immediate crisis rather than an inconvenience, and who have the fewest alternatives if the relationship fails.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Mid-Atlantic Convenience Chains", "_row_id": 555, "_entity_id": 786, "_entity_slug": "green-dot", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Microsoft Teams", "Category": "Productivity/Comms", "Terms & Conditions URL": "microsoft.com/en-us/servicesagreement/ (governed by Microsoft's overall Services Agreement)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "privacy.microsoft.com/en-us/privacystatement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "REPEATED SOCIAL-ENGINEERING ATTACK VECTOR (2025-2026): Microsoft's own Incident Response team (DART) documented multiple campaigns using Teams specifically as an entry point — attackers impersonating IT support staff via TEAMS VOICE PHISHING ('vishing') convinced employees to grant remote access through Quick Assist, leading to full corporate-device compromise (Nov 2025 case). A SEPARATE, STATE-BACKED campaign (MuddyWater, per Rapid7, early 2026) used interactive Teams screen-sharing to harvest credentials and bypass multi-factor authentication, then exfiltrated data using remote-management tools rather than traditional ransomware encryption — masquerading as opportunistic extortion while serving what researchers assessed was a broader Iranian strategic objective. Microsoft responded by making Teams 'secure by default' starting January 2026.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver — governed by Microsoft Services Agreement, same clause as Xbox and Outlook. 30-day opt-out via mail to One Microsoft Way, Redmond WA 98052 or email optout@microsoft.com.", "Fees / Billing Flags": "SEPARATE FEATURE-LEVEL CONCERN (rolled out Nov 2025-Jan 2026): a new Teams feature lets users initiate chats with ANY external email address by default, even non-Teams users — cybersecurity researchers warned this significantly expands the phishing/malware attack surface, comparing the default-enabled risk to oversights that contributed to the SolarWinds breach; administrators can disable it via a specific PowerShell setting, but many organizations may not realize they need to.", "Notes": "This is less a traditional 'company mishandled your data' finding and more a 'this collaboration tool has repeatedly been weaponized AS THE ATTACK VECTOR against its own users' organizations' finding — worth flagging distinctly, since the harm here comes from Teams' own trusted-communication features being exploited by sophisticated attackers, not from Microsoft mishandling data directly.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$281.7B", "Market Cap": "$2.9T", "Employees": "228,000", "HQ City": "Redmond", "HQ State": "Washington", "CEO": "Satya Nadella", "Ticker": "MSFT", "Website (Corporate)": "microsoft.com", "Main Mailing Address (legal/privacy notices)": "Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA", "Legal / Privacy Contact Email": "No published privacy email; Microsoft routes requests via microsoft.com/concern/privacy (30-day response commitment)", "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (MSFT). Service route: c/o General Counsel / Corporate Secretary, Redmond, Washington — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Microsoft Corporation", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Microsoft Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Teams users are bound by Microsoft's mandatory arbitration and class-action waiver, with a 30-day opt-out\nWHAT THE TERMS SAY: Teams is governed by the Microsoft Services Agreement's mandatory binding arbitration and class action waiver -- the same clause as Xbox and Outlook -- with a 30-day opt-out by mail or email.\nWHY IT MATTERS: Users who miss the 30-day window give up the right to sue Microsoft in court or join a class action over Teams-related disputes.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-1] Microsoft's own security team found attackers use Teams itself, via vishing, to compromise employee devices\nWHAT THE TERMS SAY: Microsoft's DART team documented Teams voice-phishing attacks where attackers impersonated IT support to get employees to grant remote access via Quick Assist (Nov 2025), and a separate MuddyWater campaign used Teams screen-sharing to harvest credentials and bypass MFA (early 2026).\nWHY IT MATTERS: The compromise relies on trust in Teams as an internal, authenticated company channel, meaning ordinary security assumptions about who you're talking to inside Teams can be exploited.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-1] New Teams feature lets users start chats with any external email address by default, widening phishing risk\nWHAT THE TERMS SAY: A Teams feature rolled out Nov 2025-Jan 2026 lets users initiate chats with any external email address by default, even non-Teams users; cybersecurity researchers warned this significantly expands the phishing/malware attack surface, comparing the default-enabled risk to oversights that contributed to the SolarWinds breach. Administrators can disable it via a specific PowerShell setting, but many organizations may not realize they need to.\nWHY IT MATTERS: The default-enabled setting significantly expands the phishing/malware attack surface unless an administrator disables it via the specific PowerShell setting, which many organizations may not realize they need to do.\n(evidence: Fees; Stated in tracker (fidelity pass 2 (strict): Wrong corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated, but the attack-vector incidents are described qualitatively without full scope or victim-count figures.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Microsoft Teams  <-  Microsoft Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Microsoft Teams you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Microsoft's own Incident Response team documented attackers using Teams itself as the delivery mechanism - impersonating IT help desk staff in chat and voice calls to talk employees into granting access. That is the finding worth generalising: the security control most organisations rely on is 'the message came through our internal, authenticated corporate tool,' and the attack works precisely because that assumption is doing all the work. This is the same social-engineering pattern that produced the Aflac breach (26.5M) documented in Life-Health-Dental and the broader 2025-26 campaign this tracker treats as its biggest connective thread. No technical exploit is involved.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 556, "_entity_id": 787, "_entity_slug": "microsoft-teams", "_issuer": "Microsoft Corporation", "_issuer_slug": "microsoft-corporation", "_ticker": "MSFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Signal", "Category": "Messaging", "Terms & Conditions URL": "signal.org/legal/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "signal.org/legal/#privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "GENUINELY NOTABLE ACTIVE CLASS ACTION given Signal's reputation as 'the most private messaging app': a lawsuit (active litigation, 2026, class certification ruling expected mid-year) alleges Signal's data collection practices between JANUARY 2019 and DECEMBER 2024 were 'consistently inadequate' despite its privacy-focused marketing — covering metadata collection and allegedly misleading privacy claims. Users who provided a phone number for registration during this window, and particularly those affected by a SEPARATE 2022 third-party data breach (via Twilio, a vendor Signal used for phone-number verification, which was itself breached), have the strongest individual claims. No settlement has been reached as of this research, though both sides are reportedly in early-stage settlement discussions; estimated potential payouts range $15-$75 for general users and $200-$500 for those specifically affected by the 2022 breach.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Signal Foundation (Mountain View, CA) is a 501(c)(3) nonprofit. Signal's Terms of Service do not include an arbitration clause or class action waiver. Signal's privacy-first positioning is reinforced by the absence of a dispute-resolution restriction. Governed by California law.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The core finding here isn't that Signal is worse than competitors — legal commentary explicitly notes Signal 'has done more than almost any other app to protect privacy' — but that 'better than others' doesn't automatically satisfy the specific legal standards courts apply. Worth flagging carefully given how much trust is placed in Signal specifically as a privacy-first alternative.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Signal Foundation (501(c)(3))", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Signal Foundation (501(c)(3))). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[PENDING_LITIGATION · FL-2] Class action alleges Signal's metadata collection was 'consistently inadequate' despite its marketing\nWHAT THE TERMS SAY: A 2026 class action alleges Signal's data collection practices between January 2019 and December 2024 were 'consistently inadequate' despite privacy-focused marketing, covering metadata collection and allegedly misleading privacy claims; class certification is expected mid-year and no settlement has been reached, though early settlement talks are reported.\nWHY IT MATTERS: Users who registered with a phone number in that window -- especially those hit by the 2022 Twilio vendor breach -- may have a claim; estimated payouts range $15-$75 generally and $200-$500 for the Twilio-affected group.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] A 2022 breach of Signal's phone-verification vendor Twilio exposed data for some Signal registrants\nWHAT THE TERMS SAY: A separate 2022 breach of Twilio, the third-party vendor Signal used for phone-number verification, is cited as affecting some Signal users and gives them a stronger individual claim in the pending class action.\nWHY IT MATTERS: Even a privacy-first app's security depends on third-party vendors, and a vendor breach can expose registrant data despite the app's own end-to-end encryption.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only the litigation and the underlying Twilio vendor-breach exposure are company-specific; arbitration is explicitly absent (a favorable term, not a troubling one), and the tracker frames the encryption architecture itself as sound -- nothing else confirmed this pass rises to a distinct third harm.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Litigation details and the Twilio breach are specific and dated, but no settlement or final scope has been reached.", "Exposure Score (0-100)": 16, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Signal  <-  Signal Foundation (501(c)(3))", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Signal takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "There is an active class action against the organisation with arguably the strongest privacy reputation in consumer software, which is exactly why it belongs in this tracker rather than being waved through. The honest framing matters here: Signal's protocol is peer-reviewed, its architecture is designed so the operator cannot read messages, and it retains famously little - subpoena responses have historically been able to produce almost nothing. A lawsuit is an allegation, not a finding, and nothing verified this pass undermines the cryptographic guarantee. The genuine consumer lesson is narrower and still important: end-to-end encryption protects message CONTENT and does not protect device-level exposure, backups, or anyone who screenshots the conversation.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Productivity & Comms Apps", "_row_id": 557, "_entity_id": 789, "_entity_slug": "signal", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google Authenticator", "Category": "Security/Utility", "Terms & Conditions URL": "policies.google.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Historically criticized (2023) by security researchers for SYNCING 2FA codes to Google accounts WITHOUT end-to-end encryption by default — meaning codes could theoretically be exposed if a Google account itself were compromised, somewhat undermining the two-factor security model; Google later added end-to-end encrypted sync as an option. No separate lawsuit independently confirmed this pass.", "Arbitration / Class Action Waiver": "Same as Google overall.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The 2FA-sync-without-encryption design flaw (since partially remedied) is worth noting given the app's specific SECURITY purpose — an authentication tool with a security gap is a more consequential finding than a similar gap in a typical consumer app.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Researchers criticized Authenticator's 2023 sync; 2FA seeds reportedly not end-to-end encrypted at launch\nWHAT THE TERMS SAY: Security researchers criticized the 2023 cloud-sync feature for moving two-factor seeds into a Google account without end-to-end encryption by default at launch; Google later added end-to-end encrypted sync as an option.\nWHY IT MATTERS: If a Google account is compromised, synced 2FA seeds could theoretically be exposed too, undermining the point of a second, independent factor.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration is only 'same as Google overall' with no product-specific detail, and no lawsuit or breach is independently confirmed for this product -- only the 2023 sync-encryption design flaw is a distinct, product-specific fact.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2023 sync-encryption criticism is a specific, dated fact, but arbitration terms and any lawsuit status are not confirmed for this product specifically.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Google Authenticator  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Google Authenticator takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Security researchers criticised the 2023 addition of cloud sync because it moved two-factor seeds - the secrets that generate your login codes - into a Google account, meaning the thing protecting your accounts now sits behind the same credential it is supposed to be a second factor for. The seeds were reportedly not end-to-end encrypted at launch. That is a textbook single-point-of-failure problem: convenience was added at the cost of the independence that made the second factor meaningful. Users who enabled sync generally did so because losing a phone had previously meant losing every account, which is a real problem - the criticism is of the tradeoff design, not of the users who took it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 558, "_entity_id": 790, "_entity_slug": "google-authenticator", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Duo Mobile (Cisco)", "Category": "Security/Utility", "Terms & Conditions URL": "duo.com/legal/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "duo.com/legal/privacy-and-personal-data-processing", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration — governed by Cisco Systems' Master Purchase Agreement / EULA. AAA rules. 30-day opt-out. Cisco's terms cover Duo Security (acquired 2018 for $2.35B), Webex, and all Cisco consumer products.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "As an employer/institution-mandated authentication tool, individual users typically have no real choice about whether to use Duo Mobile — worth noting this differs from most other apps in this tracker, which are used voluntarily.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Ann Arbor", "HQ State": "Michigan", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Michigan' is a non-DMV US state", "Parent / Ultimate Owner": "Cisco Systems, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Michigan LARA Business Entity Search — cofs.lara.state.mi.us/SearchApi/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Cisco Systems, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Duo Mobile users are bound by Cisco's mandatory arbitration under AAA rules, with a 30-day opt-out\nWHAT THE TERMS SAY: Duo is governed by Cisco's Master Purchase Agreement/EULA, which imposes mandatory binding arbitration under AAA rules with a 30-day opt-out; the same terms cover Webex and other Cisco consumer products.\nWHY IT MATTERS: Employees required to use Duo for work authentication are also bound by an arbitration clause they didn't individually negotiate.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-1] Employees are typically required to use Duo by their employer, with no ability to negotiate terms\nWHAT THE TERMS SAY: The tracker notes Duo is predominantly employer/institution-mandated, so the individual using the app is not the customer -- the employer negotiated the terms, and the individual generating authentication data can't accept, reject, or realistically read the agreement.\nWHY IT MATTERS: This inverts the usual consumer-protection premise: the person bound by the terms and generating the data has no bargaining power or opt-out.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No lawsuit or breach is confirmed for Duo this pass ('not independently confirmed'), leaving arbitration and the employer-mandated-use structure as the only two distinct, substantive facts.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated, but no breach or lawsuit history is confirmed this pass.", "Exposure Score (0-100)": 17, "Exposure Band": "Low", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Duo Mobile (Cisco)  <-  Cisco Systems, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Duo Mobile (Cisco) you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Duo is predominantly deployed by employers rather than chosen by individuals, which is the structural note worth recording: the person using the app is not the customer, the employer is, and the terms governing the data were negotiated by someone else entirely. That arrangement recurs across workplace software and it inverts the ordinary consumer-protection premise, because the individual generating the data has no ability to accept, reject or even read the agreement. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 559, "_entity_id": 792, "_entity_slug": "duo-mobile-cisco", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Apple Voice Memos", "Category": "Utility", "Terms & Conditions URL": "apple.com/legal/internet-services/terms/site.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "apple.com/legal/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach; Voice Memos recordings sync via iCloud by default for users with iCloud enabled, meaning voice recordings (which can include highly personal or sensitive spoken content) are subject to Apple's general iCloud data practices.", "Arbitration / Class Action Waiver": "Same as Apple overall — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; Apple's general privacy positioning is comparatively strong relative to many other companies in this tracker (see Apple Store row, Consumer Apps tab).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$416.2B", "Market Cap": "$4.8T", "Employees": "164,000", "HQ City": "Cupertino", "HQ State": "California", "CEO": "Tim Cook", "Ticker": "AAPL", "Website (Corporate)": "apple.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AAPL). Service route: c/o General Counsel / Corporate Secretary, Cupertino, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Voice Memos recordings sync to iCloud by default, encrypted with keys Apple holds unless ADP is enabled\nWHAT THE TERMS SAY: Voice Memos recordings sync to iCloud by default when iCloud is enabled; per the tracker, iCloud content is encrypted with keys Apple holds unless the user has turned on Advanced Data Protection, a setting that is off by default and rarely seen by most users.\nWHY IT MATTERS: Voice recordings often capture other people who never consented plus ambient/location cues, so a default that leaves Apple holding the encryption keys is a meaningful exposure most users don't know to change.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the iCloud-sync/default-encryption-key fact is company/product-specific; no lawsuit or breach is confirmed this pass, and arbitration is only a generic pointer to Apple's overall (also hedged as 'expected') terms.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The iCloud default-encryption fact is specific and confirmed, but no product-specific lawsuit or breach is confirmed this pass.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Apple Voice Memos  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Apple Voice Memos takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Voice Memos is governed by Apple's general iCloud terms rather than by any product-specific agreement, and the practical consequence is that recordings synced to iCloud are encrypted with keys Apple holds unless Advanced Data Protection is switched on - a setting that is off by default and that most users have never seen. Voice recordings are unusually revealing material: they capture other people who never consented, ambient conversation, and location cues. The default is the finding.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 560, "_entity_id": 793, "_entity_slug": "apple-voice-memos", "_issuer": "Apple Voice Memos", "_issuer_slug": "apple-voice-memos", "_ticker": "AAPL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google Translate", "Category": "Utility", "Terms & Conditions URL": "policies.google.com/terms (governed by Google's overall Terms of Service)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Uses on-device and cloud processing; translated text (which can include highly personal content typed for translation) may be processed on Google servers and is governed by Google's general data practices.", "Arbitration / Class Action Waiver": "Same as Google overall — see the Google/Alphabet row (Consumer Apps tab) for the full framework of major findings ($1.375B Texas settlement, RTB case, Incognito settlement, $425M Firebase judgment) that apply across Google's entire product family.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Treat as part of Google's overall profile rather than a standalone entity — see the Google row (Consumer Apps tab) for the comprehensive findings that apply to this specific product too.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Text pasted into Translate, often sensitive documents, can be processed on Google's servers\nWHAT THE TERMS SAY: Google Translate uses on-device and cloud processing, and translated text (which can include highly personal content) may be processed on Google servers under Google's general data practices.\nWHY IT MATTERS: People often use Translate precisely for unfamiliar, high-stakes documents (medical letters, legal papers, immigration forms), so cloud processing can send unusually sensitive material to a third party.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — This row is explicitly treated as part of Google's overall profile (see Google/Consumer Apps row for the major findings); no Translate-specific lawsuit, breach, or arbitration detail is stated here beyond that cross-reference.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The cloud-processing risk is clearly described, but there is no Translate-specific lawsuit or confirmed incident -- findings are inherited from Google's overall profile.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Google Translate  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Google Translate takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Text pasted into Translate frequently includes exactly the material people are most careful about elsewhere - medical letters, legal documents, immigration paperwork, business contracts - because the moment you need a translation is the moment the document is unfamiliar and important. Cloud processing means that text leaves the device. There is no confirmed lawsuit or breach here; the finding is behavioural, and it is the same category as Google's own instruction not to enter confidential information into Gemini, documented in the LLM Providers tab. The tool is free, extremely useful, and quietly one of the highest-sensitivity inputs most people hand to a third party.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 561, "_entity_id": 794, "_entity_slug": "google-translate", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google Drive", "Category": "Cloud Storage", "Terms & Conditions URL": "policies.google.com/terms (governed by Google's overall Terms of Service)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The 2024-2025 Firebase/Web & App Activity findings (see Google row) concern user activity tracking broadly; Drive-stored documents are covered by Google Workspace/consumer terms and are a common target in phishing campaigns impersonating Google file-sharing notifications.", "Arbitration / Class Action Waiver": "Same as Google overall — see the Google/Alphabet row (Consumer Apps tab) for the full framework of major findings ($1.375B Texas settlement, RTB case, Incognito settlement, $425M Firebase judgment) that apply across Google's entire product family.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Treat as part of Google's overall profile rather than a standalone entity — see the Google row (Consumer Apps tab) for the comprehensive findings that apply to this specific product too.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Google scans Drive file content for abuse detection, and files are encrypted with keys Google holds\nWHAT THE TERMS SAY: The tracker states Google performs automated content analysis on stored Drive files for abuse detection and policy enforcement (the basis for account suspensions over stored content), and that Drive files are encrypted at rest with Google-held keys rather than end-to-end.\nWHY IT MATTERS: For a small business storing client files, 'encrypted' only means protected from outside intruders, not from Google itself -- a distinction not surfaced during signup that determines whether Drive is appropriate for confidential material.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Findings for this row are inherited from Google's overall profile (see Google/Consumer Apps row); no Drive-specific lawsuit or breach is independently confirmed here beyond the scanning/key-custody practice.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The scanning and key-custody practice is clearly described, but no Drive-specific lawsuit or incident is confirmed independent of Google's overall record.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Google Drive  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Google Drive takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Drive is governed by the same overall Google data framework documented in the Google/Alphabet row, and the specific thing worth flagging is scanning: Google performs automated content analysis on stored files for abuse detection and policy enforcement, which is how account suspensions over stored content occur. Files in Drive are encrypted at rest with keys Google holds, not end-to-end, so 'encrypted' here means protected from outside intruders rather than from the provider. For a small business storing client files, that distinction determines whether Drive is appropriate for confidential material, and it is not surfaced anywhere in the signup flow.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 562, "_entity_id": 795, "_entity_slug": "google-drive", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google Chrome", "Category": "Web Browser", "Terms & Conditions URL": "policies.google.com/terms (governed by Google's overall Terms of Service)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "See the Google/Alphabet row (Consumer Apps tab) for the major findings that apply directly to Chrome specifically: the 2024 Incognito-mode tracking settlement (requiring Google to destroy billions of records after secretly tracking users who believed they were browsing privately) is a CHROME-SPECIFIC finding, since Incognito Mode is a core Chrome feature. SEPARATE, RECENT SECURITY INCIDENT: malware campaigns (reported Jan 2026) affecting 2.2 MILLION Chrome, Firefox, and Edge users collectively stole meeting-related credentials/data — a browser-extension-based attack rather than a flaw in Chrome itself specifically.", "Arbitration / Class Action Waiver": "Chrome browser governed by Google's general ToS. Device-specific arbitration clause may not apply to browser-only use. NOT FULLY VERIFIED THIS PASS.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Chrome is the single most consequential entry point for MANY of the Google-wide findings already documented in this tracker (Incognito tracking, RTB ad-auction data sharing) — worth treating this row as the browser-specific lens on Google's broader practices rather than a fully separate company.\n\nTEXAS v. GOOGLE CROSS-REFERENCE (verified this pass): Texas AG Ken Paxton sued Google in 2022; settlement in principle announced May 9 2025, final agreement signed and confirmed Oct 31 2025. Amount $1.375 billion - the largest privacy recovery any single state has obtained against Google, dwarfing the $391.5M 2022 MULTISTATE settlement (Texas declined to join that one and went alone). Covers three claim sets: (1) biometric capture under the Texas Capture or Use of Biometric Identifier Act (CUBI) - voiceprints via Google Assistant and Nest devices, face geometry via Google Photos; (2) Chrome Incognito-mode disclosures; (3) location-history disclosures in Google Maps. CRITICAL QUALIFIERS: Google admitted no wrongdoing or liability, and per its spokesman is NOT required to change any product or add any consumer disclosure as part of the settlement - the policy changes it cites were previously announced or already implemented. Precedent: Texas obtained $1.4B from Meta in July 2024 under CUBI over Facebook Tag Suggestions, the first CUBI suit. Note CUBI has NO private right of action - only the Texas AG can sue - which is the structural opposite of Illinois BIPA, where individuals can sue without proving actual harm. Google separately paid $100M to settle an Illinois BIPA class action over Google Photos face grouping in 2022. Illinois amended BIPA Aug 2 2024 to cap statutory damages per PERSON rather than per VIOLATION, materially reducing future exposure.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-finalizes-historic-settlement-google-and-secures-1375-billion-big-tech", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alphabet Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] Incognito was one of three claim sets in Texas's $1.375B Google settlement; no product change required\nWHAT THE TERMS SAY: Texas AG sued Google in 2022; a $1.375 billion settlement (signed and confirmed Oct 31 2025) covered three claim sets including Chrome's Incognito-mode disclosures, biometric capture (Assistant/Nest/Photos), and Google Maps location-history disclosures. Google admitted no wrongdoing and, per its spokesman, was not required to change any product or add any consumer disclosure.\nWHY IT MATTERS: The largest state privacy recovery ever obtained against Google produced no mandated change to the Incognito feature the state alleged was deceptive, so the underlying practice a user relies on when choosing Incognito is unchanged.\n(evidence: Notes | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-1] A January 2026 malware campaign stole meeting credentials from 2.2 million Chrome, Firefox, and Edge users\nWHAT THE TERMS SAY: A malware campaign reported in Jan 2026, via browser extensions rather than a Chrome-specific flaw, stole meeting-related credentials/data from 2.2 million Chrome, Firefox, and Edge users collectively.\nWHY IT MATTERS: Chrome users share this cross-browser extension-based exposure regardless of which browser they picked for its own security reputation.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration applicability to browser-only use is explicitly not fully verified this pass, so only the Texas settlement and the cross-browser malware campaign are substantiated as distinct items.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The settlement amount and terms are well documented, but arbitration applicability to Chrome specifically is explicitly not fully verified.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Google Chrome  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Google Chrome takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Chrome's Incognito mode is one of the three claim sets Texas settled with Google for $1.375 billion - the state alleged the disclosures around it were deceptive, and Google settled without admitting wrongdoing and without being required to change the product or add any consumer disclosure. That combination is the finding: the largest state privacy recovery ever obtained against Google produced no mandated change to the feature that prompted it. Chrome was also among the browsers affected by the 2.2-million-user meeting-credential malware campaign recorded in this tab. Cross-ref the Google/Alphabet row in Consumer Apps.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 563, "_entity_id": 796, "_entity_slug": "google-chrome", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Mozilla Firefox", "Category": "Web Browser", "Terms & Conditions URL": "mozilla.org/en-US/about/legal/terms/mozilla/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "mozilla.org/en-US/privacy/firefox/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Firefox was among the 2.2 million browser users (alongside Chrome and Edge) affected by a Jan 2026 meeting-credential-stealing malware campaign (see Chrome row) — a shared, cross-browser incident rather than Firefox-specific. Mozilla (a nonprofit foundation) is generally positioned as more privacy-protective than Chrome/Edge, with default tracker-blocking and no direct advertising-revenue dependence on Firefox itself, though Mozilla DOES receive substantial revenue from a default-search-engine deal with Google.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Mozilla Foundation (Mountain View, CA) is a 501(c)(1) nonprofit. Mozilla's Terms of Service do not include an arbitration clause or class action waiver. Like Signal, Mozilla's open-source/privacy-first positioning is reinforced by the absence of dispute-resolution restrictions. The Firefox browser itself is developed by Mozilla Corporation (a taxable subsidiary), but governed by the Foundation's policies.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Mozilla's revenue dependence on a Google search-deal is a notable structural irony worth flagging: the 'privacy-focused' browser alternative is financially dependent on the same company (Google) whose own data practices are the subject of some of the largest findings in this entire tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.bleepingcomputer.com/news/security/zoom-stealer-browser-extensions-harvest-corporate-meeting-intelligence/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Mozilla Foundation (501(c)(1))", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Mozilla Foundation (501(c)(1))). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-1] Firefox users were among 2.2M hit by the Jan 2026 meeting-credential malware campaign\nWHAT THE TERMS SAY: Firefox was among the 2.2 million browser users (with Chrome and Edge) affected by a Jan 2026 meeting-credential-stealing malware campaign -- a cross-browser incident, not Firefox-specific.\nWHY IT MATTERS: A malicious extension or compromised download runs the same way in Firefox as anywhere else -- choosing a privacy-respecting vendor doesn't protect against attacker-run malware.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration is explicitly absent (a favorable term, not troubling); the search-revenue dependence on Google is a structural irony but not itself a stated consumer-terms harm, leaving the shared malware campaign as the only substantive item.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration status and the shared malware incident are both clearly stated; no Firefox-specific lawsuit is confirmed.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Mozilla Firefox  <-  Mozilla Foundation (501(c)(1))", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Mozilla Firefox takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Firefox was among the 2.2 million browser users caught in the meeting-credential malware campaign alongside Chrome and Edge, which is worth recording precisely because Firefox is the browser people choose FOR privacy reasons. Mozilla's structure is genuinely different - a non-profit foundation with a for-profit subsidiary, no advertising business of the scale that shapes Chrome's incentives - and that difference is real. But a malicious extension or a compromised download runs in Firefox exactly as it runs anywhere else. Choosing a privacy-respecting vendor addresses what the VENDOR does with your data and does nothing about what an attacker does.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 564, "_entity_id": 798, "_entity_slug": "mozilla-firefox", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Microsoft Edge", "Category": "Web Browser", "Terms & Conditions URL": "microsoft.com/en-us/edge/legal/ (governed by Microsoft's overall Services Agreement)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "privacy.microsoft.com/en-us/privacystatement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same 2.2-million-user meeting-credential malware campaign as Chrome/Firefox (see Chrome row) — a shared, cross-browser incident, not Edge-specific. Governed by Microsoft's overall data practices (see Microsoft/Outlook row, Consumer Apps tab).", "Arbitration / Class Action Waiver": "Same as Microsoft overall.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See Chrome row for the shared malware incident; see Microsoft row (Consumer Apps tab) for Microsoft's broader corporate data-practice findings.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$281.7B", "Market Cap": "$2.9T", "Employees": "228,000", "HQ City": "Redmond", "HQ State": "Washington", "CEO": "Satya Nadella", "Ticker": "MSFT", "Website (Corporate)": "microsoft.com", "Main Mailing Address (legal/privacy notices)": "Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA", "Legal / Privacy Contact Email": "No published privacy email; Microsoft routes requests via microsoft.com/concern/privacy (30-day response commitment)", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (MSFT). Service route: c/o General Counsel / Corporate Secretary, Redmond, Washington — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-1] Edge users were caught in the same 2.2-million-user meeting-credential malware campaign as Chrome and Firefox\nWHAT THE TERMS SAY: Edge shared the meeting-credential malware campaign that hit 2.2 million Chrome, Firefox, and Edge users collectively.\nWHY IT MATTERS: Edge users face the same cross-browser exposure regardless of which browser their organization standardized on.\n(evidence: Data Sharing; Stated in tracker (firewall-edited: unverifiable figure removed) (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DARK_PATTERN_CONSENT · FL-4] Edge ships as the Windows default, so many users never chose it or reviewed its terms\nWHAT THE TERMS SAY: Edge ships as the Windows default and is deeply integrated with Microsoft account sign-in, so the tracker notes a large share of its users never affirmatively chose it or reviewed its terms -- they simply opened a new computer.\nWHY IT MATTERS: Default-by-installation isn't a consent mechanism recognized in privacy law's model of agreement, yet it governs an enormous share of actual browsing under Microsoft's terms.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration is only a generic 'same as Microsoft overall' pointer with no product-specific detail in this row, so it doesn't add a third distinct item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The malware incident and default-installation structure are clearly described; arbitration terms are only generically referenced.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Microsoft Edge  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Microsoft Edge takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same 2.2-million-user meeting-credential malware campaign as Chrome and Firefox. Edge's distinguishing feature for this tracker is that it ships as the Windows default and is deeply integrated with Microsoft account sign-in, so a large share of its users never chose it and never reviewed its terms - they opened a new computer. Default-by-installation is a consent mechanism that appears nowhere in privacy law's model of how agreement works, and it governs an enormous fraction of actual browsing.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 565, "_entity_id": 799, "_entity_slug": "microsoft-edge", "_issuer": "Microsoft Edge", "_issuer_slug": "microsoft-edge", "_ticker": "MSFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Meta Messenger", "Category": "Messaging", "Terms & Conditions URL": "See Meta's overall Terms of Service (facebook.com/legal/terms)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "See Meta's overall Privacy Policy (facebook.com/privacy/policy)", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "See the Meta row (Consumer Apps tab) for the primary company-wide findings; Messenger specifically has END-TO-END ENCRYPTION enabled by default (rolled out 2023-2024) — a genuine security improvement Meta extended from WhatsApp, though the SEPARATE active lawsuit alleging Meta/Accenture can still access WhatsApp content DESPITE its own encryption claims (documented in the WhatsApp row) raises a parallel question about whether Messenger's encryption claims hold up to the same scrutiny.", "Arbitration / Class Action Waiver": "Same as Meta overall.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Cross-reference with the WhatsApp row for the 'encryption claims under active legal challenge' pattern that may extend to Messenger given the shared underlying encryption technology (both use the Signal Protocol).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$201.0B", "Market Cap": "$1.6T", "Employees": "74,067", "HQ City": "Menlo Park", "HQ State": "California", "CEO": "Mark Zuckerberg", "Ticker": "META", "Website (Corporate)": "meta.com", "Main Mailing Address (legal/privacy notices)": "Meta Platforms, Inc., ATTN: Privacy Operations, 1 Meta Way, Menlo Park, CA 94025, USA (corporate/SEC address: 1601 Willow Road, Menlo Park, CA 94025)", "Legal / Privacy Contact Email": "No published privacy email; Meta routes all requests through in-product privacy forms", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (META). Service route: c/o General Counsel / Corporate Secretary, Menlo Park, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Messenger lacked default end-to-end encryption for years while users assumed it matched WhatsApp\nWHAT THE TERMS SAY: Messenger only rolled out end-to-end encryption by default in 2023-2024, extended from WhatsApp; the tracker notes users overwhelmingly believed Messenger was already encrypted like WhatsApp because both are owned by Meta, though the two products had opposite defaults with no interface cue marking the difference.\nWHY IT MATTERS: Users likely sent sensitive messages via Messenger for years believing they had WhatsApp-level protection when they didn't.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Messenger's own primary findings live in the Meta/Consumer-Apps row (cross-referenced, not restated here); within this row's own text only the encryption-default disparity is a distinct, product-specific fact, and the WhatsApp encryption-claims lawsuit is explicitly another product's finding, not Messenger's.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The encryption-default timeline is specific and dated, but no Messenger-specific lawsuit or breach is confirmed in this row.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Meta Messenger  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Meta Messenger takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Messenger's primary findings live in the Meta row in Consumer Apps, and the one that belongs here is the encryption timeline: Messenger did not have end-to-end encryption on by default for most of its existence, and users overwhelmingly believed otherwise because WhatsApp - the same parent company - did. Two products, one owner, opposite defaults, and no point in either interface where the difference was made legible. Cross-ref the Meta AI row in LLM Providers for the October 2025 change routing AI chat content into ad targeting across Facebook, Instagram and WhatsApp with no US opt-out.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Productivity & Comms Apps", "_row_id": 566, "_entity_id": 800, "_entity_slug": "meta-messenger", "_issuer": "Meta Messenger", "_issuer_slug": "meta-messenger", "_ticker": "META", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google Docs", "Category": "Productivity", "Terms & Conditions URL": "policies.google.com/terms (governed by Google's overall Terms of Service)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same overall Google data framework applies; Google's AI features (Gemini integration) can process document content for suggestions/summarization, raising the general question of how document content is used for model improvement absent an explicit opt-out.", "Arbitration / Class Action Waiver": "Same as Google overall — see the Google/Alphabet row (Consumer Apps tab) for the full framework of major findings ($1.375B Texas settlement, RTB case, Incognito settlement, $425M Firebase judgment) that apply across Google's entire product family.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Treat as part of Google's overall profile rather than a standalone entity — see the Google row (Consumer Apps tab) for the comprehensive findings that apply to this specific product too.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AI_TRAINING · FL-2] Gemini can process Google Docs content, and full data protections are a paid Workspace feature\nWHAT THE TERMS SAY: Google's AI features (Gemini integration) can process document content for suggestions/summarization, and the tracker raises how document content is used for model improvement absent an explicit opt-out; it notes the answer differs between free consumer accounts and paid Workspace business accounts.\nWHY IT MATTERS: A professional handling client material (consultant, therapist, lawyer, nonprofit) faces a compliance question, not just a preference, and meaningful data protection is a purchasable feature rather than a default.\n(evidence: Data Sharing | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Findings for this row are otherwise inherited from Google's overall profile (cross-referenced); no Docs-specific lawsuit or breach is confirmed here beyond the AI-processing/tier-split question, which the tracker itself frames as unconfirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "AI-processing exposure is described but framed as an open question, and no Docs-specific lawsuit is confirmed.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Google Docs  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Google Docs takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same Google data framework as Drive, with the addition that Gemini integration means AI features can process document content. For a professional handling client material - a consultant, a therapist, a lawyer, a nonprofit handling donor records - the question of whether AI processing occurs and under what terms is a compliance question, not a preference, and the answer differs between free consumer accounts and Workspace business accounts. That tier split is the same one documented across the LLM Providers tab: meaningful data protections are a purchasable enterprise feature, and the consumer tier funds the difference.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 567, "_entity_id": 801, "_entity_slug": "google-docs", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Todoist (Doist)", "Category": "Productivity", "Terms & Conditions URL": "todoist.com/legal/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "todoist.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Doist (remote-first company, incorporated in Portugal) ToS governed by Portuguese law. No US-style arbitration clause. Disputes in Portuguese courts.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Todoist is developed by Doist, a fully remote company with no external VC funding — a similar independent ownership structure to Zoho Mail (Email Providers tab); recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Remote", "HQ State": "Portugal", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ in Remote, Portugal (non-US)", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Portugal) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Portugal. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] A small, privately held company holds a complete record of health, legal, and financial commitments\nWHAT THE TERMS SAY: The tracker frames task managers as an underrated sensitivity category -- a to-do list can be a complete record of health appointments, legal deadlines, financial obligations, and personal commitments -- held by Doist, a small, remote-first, privately held company with, per the tracker, generally fewer security resources than a large platform.\nWHY IT MATTERS: If Doist's security or accountability record is thinner than a major platform's, that unusually sensitive personal-planning data has less institutional backstop, though nothing is confirmed as compromised this pass.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No lawsuit or breach is confirmed this pass; arbitration is explicitly absent (Portuguese courts, no US-style clause), which is a favorable term, not a troubling one -- leaving only the data-sensitivity/company-size structural point as a distinct item.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No lawsuit, breach, or specific clause detail is confirmed this pass -- only a general sensitivity/company-size risk framing.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Todoist (Doist)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Todoist (Doist) takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Task managers are an underrated sensitivity category - a to-do list is an unusually complete record of intentions, health appointments, legal deadlines, financial obligations and personal commitments, held by a company most users have never thought of as holding sensitive data. Doist is a small, remote-first, privately held company, which generally means fewer resources devoted to security than a large platform and correspondingly less public accountability record either way. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 568, "_entity_id": 802, "_entity_slug": "todoist-doist", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Microsoft Word", "Category": "Productivity", "Terms & Conditions URL": "microsoft.com/en-us/servicesagreement/ (governed by Microsoft's overall Services Agreement)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "privacy.microsoft.com/en-us/privacystatement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "No product-specific lawsuit independently confirmed this pass beyond Microsoft's overall corporate findings (see Microsoft/Outlook row, Consumer Apps tab, for the Russo v. Microsoft business-customer data-sharing lawsuit).", "Arbitration / Class Action Waiver": "Same as Microsoft overall.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Microsoft row (Consumer Apps tab) for the comprehensive corporate-level findings that apply to this specific product.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$281.7B", "Market Cap": "$2.9T", "Employees": "228,000", "HQ City": "Redmond", "HQ State": "Washington", "CEO": "Satya Nadella", "Ticker": "MSFT", "Website (Corporate)": "microsoft.com", "Main Mailing Address (legal/privacy notices)": "Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA", "Legal / Privacy Contact Email": "No published privacy email; Microsoft routes requests via microsoft.com/concern/privacy (30-day response commitment)", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (MSFT). Service route: c/o General Counsel / Corporate Secretary, Redmond, Washington — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Word's 'Connected Experiences' send document content to the cloud by default, buried in privacy settings\nWHAT THE TERMS SAY: Connected Experiences -- cloud-backed features embedded in Office apps that transmit document content for processing -- are enabled by default and, per the tracker, buried in privacy settings; most users describing Word as 'offline software' are describing a product that no longer exists in that form.\nWHY IT MATTERS: Document content leaves the device by default without most users realizing it, and signing into Office with a personal account is how enterprise-side protections for that data get bypassed.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No product-specific lawsuit is confirmed beyond Microsoft's overall corporate findings (cross-referenced to the Microsoft/Outlook row); only the Connected Experiences default is a distinct, product-specific fact in this row's own text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Connected Experiences default is specifically described, but no Word-specific lawsuit or breach is confirmed.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Microsoft Word  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Microsoft Word takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "No product-specific finding beyond Microsoft's overall framework. The item worth flagging is Connected Experiences - the cloud-backed features embedded in Office applications that transmit document content for processing, enabled by default and buried in privacy settings. Most users describing Word as 'offline software' are describing a product that no longer exists in that form. Cross-ref the Microsoft Copilot row in LLM Providers: the enterprise/consumer split there applies here too, and employees signing into Office with personal accounts is precisely how the enterprise protection gets bypassed.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 569, "_entity_id": 803, "_entity_slug": "microsoft-word", "_issuer": "Microsoft Word", "_issuer_slug": "microsoft-word", "_ticker": "MSFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google Assistant", "Category": "Utility", "Terms & Conditions URL": "policies.google.com/terms (governed by Google's overall Terms of Service)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Directly named in Google's own $68 MILLION settlement (referenced in the Google row) for collecting voice recordings without users' intentional activation — this is a Google Assistant-SPECIFIC finding, not just a general Google issue.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration for Google Devices. 30-day opt-out. Subject to the In re Google Assistant Privacy Litigation (69,507 individual arbitration demands, N.D. Cal. 2025).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Treat as part of Google's overall profile rather than a standalone entity — see the Google row (Consumer Apps tab) for the comprehensive findings that apply to this specific product too.\n\nTEXAS v. GOOGLE CROSS-REFERENCE (verified this pass): Texas AG Ken Paxton sued Google in 2022; settlement in principle announced May 9 2025, final agreement signed and confirmed Oct 31 2025. Amount $1.375 billion - the largest privacy recovery any single state has obtained against Google, dwarfing the $391.5M 2022 MULTISTATE settlement (Texas declined to join that one and went alone). Covers three claim sets: (1) biometric capture under the Texas Capture or Use of Biometric Identifier Act (CUBI) - voiceprints via Google Assistant and Nest devices, face geometry via Google Photos; (2) Chrome Incognito-mode disclosures; (3) location-history disclosures in Google Maps. CRITICAL QUALIFIERS: Google admitted no wrongdoing or liability, and per its spokesman is NOT required to change any product or add any consumer disclosure as part of the settlement - the policy changes it cites were previously announced or already implemented. Precedent: Texas obtained $1.4B from Meta in July 2024 under CUBI over Facebook Tag Suggestions, the first CUBI suit. Note CUBI has NO private right of action - only the Texas AG can sue - which is the structural opposite of Illinois BIPA, where individuals can sue without proving actual harm. Google separately paid $100M to settle an Illinois BIPA class action over Google Photos face grouping in 2022. Illinois amended BIPA Aug 2 2024 to cap statutory damages per PERSON rather than per VIOLATION, materially reducing future exposure.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-finalizes-historic-settlement-google-and-secures-1375-billion-big-tech", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alphabet Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] Texas alleged Assistant and Nest captured voiceprints; always-listening design makes the surface a household\nWHAT THE TERMS SAY: Texas alleged Google captured voiceprints through Google Assistant and Nest devices without the informed consent CUBI requires; the tracker adds that Assistant is always-listening by design, so the collection surface is a household -- guests, children, and visitors are captured with no mechanism to consent or decline. Google admitted no wrongdoing.\nWHY IT MATTERS: A voiceprint is a durable biometric identifier -- unlike a password it can't be changed, and unlike a face it's produced constantly without a deliberate action, so anyone in earshot is effectively enrolled without a choice.\n(evidence: SCARY | Notes; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-2] Assistant voiceprints were one claim set in Texas's $1.375B Google settlement; no product change required\nWHAT THE TERMS SAY: The Assistant/Nest voiceprint claim was one of three claim sets in Texas's $1.375 billion settlement with Google (signed Oct 31 2025); Google admitted no wrongdoing and, per its spokesman, was not required to change the product or add any consumer disclosure.\nWHY IT MATTERS: The largest state privacy recovery against Google left the underlying practice that prompted the biometric claim unchanged for users going forward.\n(evidence: Notes | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Google Devices impose mandatory arbitration; 69,507 individual arbitration demands already filed\nWHAT THE TERMS SAY: Google Devices are subject to mandatory binding arbitration with a 30-day opt-out, and the tracker cites In re Google Assistant Privacy Litigation as involving 69,507 individual arbitration demands (N.D. Cal. 2025).\nWHY IT MATTERS: The scale of individual arbitration demands shows how many people are pursuing claims through the very forum the arbitration clause forces them into instead of court.\n(evidence: Arbitration | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The settlement terms and arbitration demand count are specific and dated, but Google admitted no wrongdoing and made no new disclosure, leaving the underlying practice only partially clarified.", "Exposure Score (0-100)": 41, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 6/30 (biometric_collection+6) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Google Assistant  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Google Assistant you gave up your biometric identifiers and your right to sue. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Google Assistant voiceprints are one of the two biometric claim sets in the $1.375 billion Texas settlement - Texas alleged Google captured voiceprints through Assistant and Nest devices without the informed consent CUBI requires. Voiceprints are a durable biometric: unlike a password you cannot change your voice, and unlike a face you produce it constantly without deliberate action. Assistant is also always-listening by design, which means the collection surface is a household rather than a user - guests, children and visitors are captured with no mechanism to consent or decline. Google admitted no wrongdoing and was not required to change the product.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 570, "_entity_id": 804, "_entity_slug": "google-assistant", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Apple Pages", "Category": "Productivity", "Terms & Conditions URL": "apple.com/legal/internet-services/terms/site.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "apple.com/legal/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach; governed by Apple's general iCloud/document-sync data practices.", "Arbitration / Class Action Waiver": "Same as Apple overall.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$416.2B", "Market Cap": "$4.8T", "Employees": "164,000", "HQ City": "Cupertino", "HQ State": "California", "CEO": "Tim Cook", "Ticker": "AAPL", "Website (Corporate)": "apple.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AAPL). Service route: c/o General Counsel / Corporate Secretary, Cupertino, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] iCloud documents are shielded from outsiders but not from Apple unless Advanced Data Protection is turned on\nWHAT THE TERMS SAY: Documents synced to iCloud are protected from outside intruders but not from Apple itself unless the user enables Advanced Data Protection, which is off by default.\nWHY IT MATTERS: Because most users leave Advanced Data Protection off, Apple retains technical access to document content synced via iCloud, even though Apple does not monetize that content.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data Sharing, Arbitration, and Fees fields are all unconfirmed or not itemized this pass; only the SCARY field's iCloud key-custody point is substantive enough to report.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Almost everything is marked not independently confirmed this pass; only a general iCloud encryption-default point is stated.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Apple Pages  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Apple Pages takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Governed by Apple's general terms rather than any product-specific agreement, with the same iCloud key-custody point as Voice Memos: documents synced to iCloud are protected from outside intruders but not from Apple unless Advanced Data Protection is enabled, which is off by default. Apple's overall position is genuinely stronger than the ad-funded alternatives because it does not monetise document content - that is worth saying plainly - and it is still weaker than end-to-end. Both are true.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 571, "_entity_id": 805, "_entity_slug": "apple-pages", "_issuer": "Apple Pages", "_issuer_slug": "apple-pages", "_ticker": "AAPL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Adobe Scan", "Category": "Utility", "Terms & Conditions URL": "adobe.com/legal/terms.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "adobe.com/privacy/policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Adobe's OWN privacy policy update (2024) drew significant public backlash when users discovered updated Terms appeared to grant Adobe broad rights to access/analyze content (including scanned documents) for AI-training purposes — Adobe subsequently clarified and revised the language after user backlash, but the episode illustrates the risk of scanning SENSITIVE PERSONAL DOCUMENTS (IDs, medical records, financial paperwork) through a cloud-connected scanning app whose terms can change.", "Arbitration / Class Action Waiver": "Same as Adobe overall — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Given Adobe Scan is specifically used to digitize SENSITIVE PHYSICAL DOCUMENTS (IDs, medical forms, financial paperwork), the 2024 AI-training terms controversy is particularly relevant — worth a direct follow-up on Adobe's CURRENT terms specifically for Scan given how quickly this area has been changing.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$23.8B", "Market Cap": "$86.8B", "Employees": "30,709", "HQ City": "San Jose", "HQ State": "California", "CEO": "Shantanu Narayen", "Ticker": "ADBE", "Website (Corporate)": "adobe.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (ADBE). Service route: c/o General Counsel / Corporate Secretary, San Jose, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AI_TRAINING · FL-2] Adobe's 2024 terms update appeared to grant rights to analyze scanned documents for AI training, prompting backlash\nWHAT THE TERMS SAY: Adobe's 2024 privacy policy update was read by users as granting Adobe broad rights to access and analyze content processed through its products, including via machine learning; Adobe later clarified and revised the language after public backlash.\nWHY IT MATTERS: Adobe Scan is used to digitize sensitive physical documents (IDs, medical forms, financial paperwork), so any AI-training rights over that content could expose especially sensitive material, even though Adobe revised the terms after the controversy.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Binding arbitration with a class-action waiver is expected under Adobe's overall terms, not confirmed specifically for Scan\nWHAT THE TERMS SAY: The tracker notes Adobe Scan is 'same as Adobe overall' with standard binding arbitration and a class-action waiver expected, though not itemized specifically for Scan this pass.\nWHY IT MATTERS: If accurate, users would be barred from suing Adobe over Scan-related disputes as a class and required to arbitrate individually.\n(evidence: Arbitration; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The Fees field is not itemized and no additional company-specific practices beyond the AI-training controversy and expected arbitration terms are stated this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2024 AI-training terms controversy is documented, but current Scan-specific terms and arbitration/fee details are not itemized this pass.", "Exposure Score (0-100)": 7, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 5/30 (ai_training_on_user_data+5) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use", "Entity Type": "Company", "Ownership Path": "Adobe Scan  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Adobe Scan you gave up your content used as AI training data. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Adobe's 2024 privacy policy update produced significant public backlash when users read the terms as granting Adobe broad rights to access and analyse content processed through its products, including for machine learning. Adobe subsequently issued clarifications and revised the language. The episode is instructive beyond Adobe: the terms had substantially existed before, and what changed was that people actually read them - which tells you how much of the consent architecture across this entire tracker depends on nobody looking. Adobe Scan specifically is used to digitise exactly the documents people would least want analysed: tax records, medical bills, contracts, IDs.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 572, "_entity_id": 806, "_entity_slug": "adobe-scan", "_issuer": "Adobe Scan", "_issuer_slug": "adobe-scan", "_ticker": "ADBE", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google Calendar", "Category": "Productivity", "Terms & Conditions URL": "policies.google.com/terms (governed by Google's overall Terms of Service)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same overall Google data framework applies; calendar data (meeting subjects, attendees, locations) is a sensitive category of personal/professional information subject to the same general Google practices documented in the Google row.", "Arbitration / Class Action Waiver": "Same as Google overall — see the Google/Alphabet row (Consumer Apps tab) for the full framework of major findings ($1.375B Texas settlement, RTB case, Incognito settlement, $425M Firebase judgment) that apply across Google's entire product family.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Treat as part of Google's overall profile rather than a standalone entity — see the Google row (Consumer Apps tab) for the comprehensive findings that apply to this specific product too.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Calendar metadata builds a relationship graph users never meant to create\nWHAT THE TERMS SAY: Calendar data such as meeting subjects, attendee lists, and recurring appointments (e.g., medical, therapy, legal, interviews) falls under Google's general data practices; the tracker notes the attendee list creates a relationship graph the user never deliberately built.\nWHY IT MATTERS: Even without message content, patterns in who a user meets and when can reveal sensitive facts like medical treatment, job searching, or legal issues.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data Sharing and Arbitration fields for this row point to the general Google/Alphabet findings (Texas settlement, RTB case, Incognito settlement, Firebase judgment) rather than stating Calendar-specific facts, and the SCARY field explicitly notes no calendar-specific settlement findings are asserted; only the metadata-sensitivity point is specific to this product.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing and arbitration terms are deferred entirely to the general Google row rather than stated for Calendar specifically.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Google Calendar  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Google Calendar takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same Google framework. Calendar is a category of data that is quietly more revealing than its contents suggest - meeting subjects, attendee lists, recurring medical appointments, therapy sessions, interviews with other employers, legal consultations. The attendee list in particular creates a relationship graph the user never deliberately built. Location history claims were part of the Texas settlement against Google; calendar-specific findings were not, and none are asserted here.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 573, "_entity_id": 807, "_entity_slug": "google-calendar", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google Photos", "Category": "Cloud Storage", "Terms & Conditions URL": "policies.google.com/terms (governed by Google's overall Terms of Service)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Uses facial-recognition-based 'Face Grouping' technology to organize photos by person — a biometric data practice; Google faced earlier (pre-2020) BIPA litigation over facial recognition in Photos specifically, settled for $100 million (2022) covering Illinois users.", "Arbitration / Class Action Waiver": "Governed by Google's general ToS + device-specific terms if accessed via a Google device. 30-day opt-out for device-related disputes.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Treat as part of Google's overall profile rather than a standalone entity — see the Google row (Consumer Apps tab) for the comprehensive findings that apply to this specific product too.\n\nTEXAS v. GOOGLE CROSS-REFERENCE (verified this pass): Texas AG Ken Paxton sued Google in 2022; settlement in principle announced May 9 2025, final agreement signed and confirmed Oct 31 2025. Amount $1.375 billion - the largest privacy recovery any single state has obtained against Google, dwarfing the $391.5M 2022 MULTISTATE settlement (Texas declined to join that one and went alone). Covers three claim sets: (1) biometric capture under the Texas Capture or Use of Biometric Identifier Act (CUBI) - voiceprints via Google Assistant and Nest devices, face geometry via Google Photos; (2) Chrome Incognito-mode disclosures; (3) location-history disclosures in Google Maps. CRITICAL QUALIFIERS: Google admitted no wrongdoing or liability, and per its spokesman is NOT required to change any product or add any consumer disclosure as part of the settlement - the policy changes it cites were previously announced or already implemented. Precedent: Texas obtained $1.4B from Meta in July 2024 under CUBI over Facebook Tag Suggestions, the first CUBI suit. Note CUBI has NO private right of action - only the Texas AG can sue - which is the structural opposite of Illinois BIPA, where individuals can sue without proving actual harm. Google separately paid $100M to settle an Illinois BIPA class action over Google Photos face grouping in 2022. Illinois amended BIPA Aug 2 2024 to cap statutory damages per PERSON rather than per VIOLATION, materially reducing future exposure.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-finalizes-historic-settlement-google-and-secures-1375-billion-big-tech", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "2022", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alphabet Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] Google Photos' 'Face Grouping' feature drove a $100M Illinois settlement and is part of the $1.375B Texas biometric case\nWHAT THE TERMS SAY: Google Photos generates face geometry data via its 'Face Grouping' feature to organize photos by person; this practice was one of the biometric claim sets in Texas's $1.375 billion settlement and was previously the subject of a $100 million Illinois BIPA class-action settlement (2022) specific to Google Photos.\nWHY IT MATTERS: Face templates are generated for everyone appearing in a photo, including people who never used Google Photos or consented, because a friend simply took their picture.\n(evidence: Data Sharing | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-2] Texas won a record $1.375B settlement covering biometric capture, Incognito tracking, and location history, with no admission of wrongdoing\nWHAT THE TERMS SAY: Texas's settlement (announced May 9, 2025; finalized Oct 31, 2025) covers three claim sets: biometric capture under CUBI (voiceprints via Assistant/Nest, face geometry via Photos), Chrome Incognito-mode disclosures, and location-history disclosures in Maps. Google admitted no wrongdoing or liability and, per its spokesman, is not required to change any product or add any consumer disclosure; the policy changes it cites were previously announced or already implemented.\nWHY IT MATTERS: Despite the record size, the settlement carries no admission of liability and no mandated changes, so the underlying practices face no confirmed operational consequence.\n(evidence: Notes; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Disputes are funneled into Google's arbitration framework, with only a 30-day window to opt out of device-related terms\nWHAT THE TERMS SAY: Google Photos disputes are governed by Google's general Terms of Service plus device-specific terms when accessed via a Google device, which include a 30-day opt-out window for device-related arbitration.\nWHY IT MATTERS: Users who miss the narrow 30-day window are bound to individual arbitration rather than being able to pursue claims collectively.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Both the Illinois BIPA settlement and the Texas biometric settlement are described with specific dates, amounts, and mechanisms, marked 'verified this pass.'", "Exposure Score (0-100)": 41, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 6/30 (biometric_collection+6) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Google Photos  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Google Photos you gave up your biometric identifiers and your right to sue. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Google Photos face grouping is the other biometric claim set in the $1.375 billion Texas settlement, and Google separately paid $100 million to settle an Illinois BIPA class action over the same feature in 2022. Face geometry is generated from every face in your library - including people who never used the product, never agreed to anything, and have no idea their facial template exists because a friend took a photo at a party. That is the structural problem biometric statutes exist to address and the reason Illinois BIPA lets individuals sue without proving harm, while Texas CUBI reserves the right to sue to the attorney general alone.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 574, "_entity_id": 808, "_entity_slug": "google-photos", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Microsoft OneDrive", "Category": "Cloud Storage", "Terms & Conditions URL": "microsoft.com/en-us/servicesagreement/ (governed by Microsoft's overall Services Agreement)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "privacy.microsoft.com/en-us/privacystatement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "No product-specific lawsuit independently confirmed this pass beyond Microsoft's overall corporate findings (see Microsoft/Outlook row, Consumer Apps tab, for the Russo v. Microsoft business-customer data-sharing lawsuit).", "Arbitration / Class Action Waiver": "Same as Microsoft overall.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Microsoft row (Consumer Apps tab) for the comprehensive corporate-level findings that apply to this specific product.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$281.7B", "Market Cap": "$2.9T", "Employees": "228,000", "HQ City": "Redmond", "HQ State": "Washington", "CEO": "Satya Nadella", "Ticker": "MSFT", "Website (Corporate)": "microsoft.com", "Main Mailing Address (legal/privacy notices)": "Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA", "Legal / Privacy Contact Email": "No published privacy email; Microsoft routes requests via microsoft.com/concern/privacy (30-day response commitment)", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (MSFT). Service route: c/o General Counsel / Corporate Secretary, Redmond, Washington — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] OneDrive defaults to backing up Desktop, Documents, and Pictures on many Windows installs without an active choice\nWHAT THE TERMS SAY: OneDrive is configured on many Windows installations to back up the Desktop, Documents, and Pictures folders by default, so files may sync to Microsoft's cloud without the user deliberately choosing to use the service.\nWHY IT MATTERS: Users' entire working files can end up in a searchable cloud index through a default setting rather than a decision.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data Sharing and Arbitration fields defer entirely to Microsoft's overall corporate findings without OneDrive-specific detail; only the default-backup-enrollment structural point is specific to OneDrive this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No OneDrive-specific lawsuit, breach, or arbitration detail is confirmed this pass; only a general default-sync design note is stated.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Microsoft OneDrive  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Microsoft OneDrive takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "No product-specific finding beyond Microsoft's overall framework. The item worth recording is that OneDrive is configured on many Windows installations to back up Desktop, Documents and Pictures by default, so a large number of users are syncing their entire working life to a cloud service they did not deliberately choose to use. Combined with Copilot's permission-inheritance behaviour documented in the LLM Providers tab, the practical result is that files land in a searchable cloud index through a default rather than a decision.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 575, "_entity_id": 809, "_entity_slug": "microsoft-onedrive", "_issuer": "Microsoft OneDrive", "_issuer_slug": "microsoft-onedrive", "_ticker": "MSFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google NotebookLM", "Category": "Productivity/AI", "Terms & Conditions URL": "policies.google.com/terms (governed by Google's overall Terms of Service)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "A newer (2023+) AI research/notetaking tool; no NotebookLM-specific lawsuit independently confirmed this pass, though it operates under Google's general AI/data-processing terms, and uploaded source documents are processed by Google's AI models.", "Arbitration / Class Action Waiver": "Same as Google overall — see the Google/Alphabet row (Consumer Apps tab) for the full framework of major findings ($1.375B Texas settlement, RTB case, Incognito settlement, $425M Firebase judgment) that apply across Google's entire product family.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Treat as part of Google's overall profile rather than a standalone entity — see the Google row (Consumer Apps tab) for the comprehensive findings that apply to this specific product too.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] NotebookLM concentrates a user's most sensitive personal and professional documents in one AI-processed place\nWHAT THE TERMS SAY: NotebookLM is built for users to upload their own source documents for an AI to reason across, and those uploads are processed by Google's AI models under Google's general AI/data-processing terms; no NotebookLM-specific lawsuit is confirmed this pass.\nWHY IT MATTERS: Because users deliberately upload their highest-value, most-curated material, a breach or overbroad data use would expose an unusually concentrated and sensitive data set.\n(evidence: Data Sharing | SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration terms are only cross-referenced to the general Google/Alphabet row rather than NotebookLM-specific, and no lawsuit, breach, or fee detail is confirmed for this product this pass; only the document-concentration structural point is specific to NotebookLM.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No NotebookLM-specific practices are confirmed; the row defers entirely to Google's general terms and a separate Gemini row for retention practices.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Google NotebookLM  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Google NotebookLM takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "No product-specific finding confirmed this pass - NotebookLM is recent enough that a litigation or enforcement record has not had time to develop, which is itself worth flagging rather than reading as a clean result. The structural concern is specific to the product: NotebookLM is designed for users to upload their own source documents and have an AI reason across them, which means the highest-value, most-curated personal and professional material a person holds gets deliberately concentrated in one place. Cross-ref the Google Gemini row in LLM Providers for Google's stated human-review and retention practices, which are the relevant governing terms.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 576, "_entity_id": 810, "_entity_slug": "google-notebooklm", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Skype (Microsoft)", "Category": "Messaging/Video", "Terms & Conditions URL": "See Microsoft's overall Services Agreement", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "privacy.microsoft.com/en-us/privacystatement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Microsoft ANNOUNCED IT IS RETIRING SKYPE (shut down May 2025, consolidating users into Microsoft Teams) — a major operational-status change worth flagging for anyone still referencing Skype specifically, since the service is being wound down rather than actively operated going forward. See the Microsoft Teams row in this same tab for the platform Skype users are being migrated to.", "Arbitration / Class Action Waiver": "Same as Microsoft overall.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "SKYPE HAS BEEN DISCONTINUED (as of May 2025) — any customer/user still referencing Skype should be directed to Microsoft Teams (Free), which absorbed Skype's consumer user base.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "PARENT ADDRESS ONLY — verify before using for legal notice. Skype was shut down in May 2025; Skype Communications S.a.r.l. (Luxembourg) was the historical contracting entity. Parent: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA", "Legal / Privacy Contact Email": "No published privacy email; Microsoft routes requests via microsoft.com/concern/privacy (30-day response commitment)", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Microsoft Corporation", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[TERMINATION_CONFISCATION · FL-4] Skype's shutdown shows providers owe users no guaranteed data export or preservation when a service is discontinued\nWHAT THE TERMS SAY: Microsoft shut Skype down in May 2025 and migrated users to Teams; the tracker states nothing in a consumer terms of service obliges a provider to keep a service running, provide export in a usable format, or preserve anything after a stated shutdown date.\nWHY IT MATTERS: Users can lose years of message history, contacts, and their service identity entirely at the discontinuing company's discretion, with discontinuation risk disclosed in no privacy policy.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data Sharing and Arbitration fields defer to Microsoft's general findings without Skype-specific detail; only the shutdown/data-preservation structural point is specific to this product.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No lawsuit, breach, or Skype-specific terms detail is confirmed; the only substantive point is the discontinuation/data-preservation risk.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 4/20 (termination_or_confiscation+4) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Skype (Microsoft)  <-  Microsoft Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Skype (Microsoft) you gave up your right to keep what you paid for. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Microsoft shut Skype down in May 2025, and the shutdown is the finding: when a communications service ends, the user's message history, contact list and identity within that service become entirely dependent on a migration path the company designs and a window it chooses. Two decades of conversation for some users. Nothing in a consumer terms of service obliges a provider to keep a service running, provide export in a usable format, or preserve anything after a stated date - and discontinuation risk appears in no privacy policy and no comparison shopping process.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Productivity & Comms Apps", "_row_id": 577, "_entity_id": 811, "_entity_slug": "skype-microsoft", "_issuer": "Microsoft Corporation", "_issuer_slug": "microsoft-corporation", "_ticker": "MSFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "WeChat (Tencent)", "Category": "Messaging", "Terms & Conditions URL": "wechat.com/en/service_terms.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "wechat.com/en/privacy_policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SERIOUS, WELL-DOCUMENTED SURVEILLANCE FINDINGS: independent research by Citizen Lab (University of Toronto) found that WeChat MONITORS AND CENSORS chats in secret, without disclosing this to users — and, more strikingly, found that communications between accounts registered ENTIRELY OUTSIDE CHINA are used to TRAIN China's domestic censorship algorithms, meaning non-Chinese WeChat users' private conversations directly shape what gets censored for users inside China. Under Chinese law (the National Intelligence Law and Internet Security Law), parent company Tencent is legally OBLIGATED to share user data with the Chinese government on request — documented real-world consequences include a Chinese citizen sentenced to 10 months in prison for FORWARDING A VIDEO to a friend in the US via WeChat, and another user detained for 5 days after telling a joke referencing a government official in a WeChat group. WeChat lacks true end-to-end encryption (unlike Signal/WhatsApp/iMessage), meaning Tencent itself CAN technically access message content. A 2024 breach (NinjaDefender hacking group) separately leaked user data.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass under US consumer-arbitration frameworks — Chinese law governs the underlying Weixin/WeChat data-sharing obligations described above.", "Fees / Billing Flags": "WeChat auto-enrolls all 'Mini Programs' (third-party services built inside the WeChat platform, including many handling sensitive health/financial data) into its analytics/data-collection system WITHOUT giving users or developers a choice to opt out.", "Notes": "This is one of the most SERIOUS GOVERNMENT-SURVEILLANCE-RELATED findings in this entire tracker, comparable in severity to the Yandex/Russia findings (Email Providers tab) but with even more extensively documented real-world consequences (actual criminal prosecutions tied to WeChat messages). Chevron Corporation notably mandated employees delete WeChat from company phones (Sept 2020) — worth flagging given how many US businesses maintain this kind of policy for employee devices.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-3] Tencent is legally obligated to share WeChat user data with the Chinese government, with documented prison sentences tied to messages\nWHAT THE TERMS SAY: Under China's National Intelligence Law and Internet Security Law, Tencent must share user data with the government on request; the tracker cites a user sentenced to 10 months in prison for forwarding a video and another detained 5 days over a joke referencing an official, both via WeChat.\nWHY IT MATTERS: Users face real criminal consequences for private communications, and the tracker states no terms of service can contract around this state access obligation.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[AI_TRAINING · FL-2] WeChat secretly monitors and censors chats, and messages from accounts outside China are used to train China's censorship algorithms\nWHAT THE TERMS SAY: Independent research by Citizen Lab found WeChat monitors and censors chats without disclosing this to users, and that communications between accounts registered entirely outside China are used to train China's domestic censorship classifiers.\nWHY IT MATTERS: Non-Chinese users' private conversations directly shape what gets censored for users inside China, without any disclosure that this monitoring or training occurs.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CONFIRMED_BREACH · FL-2] A 2024 breach by the NinjaDefender hacking group separately leaked WeChat user data\nWHAT THE TERMS SAY: The tracker records a 2024 data breach attributed to the NinjaDefender hacking group that leaked WeChat user data, separate from the surveillance/censorship findings.\nWHY IT MATTERS: Beyond state-mandated access, WeChat users' data has also been exposed through a criminal breach, compounding exposure risk.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Findings are well-sourced to Citizen Lab research, named PRC statutes, and specific documented prosecutions and breach details.", "Exposure Score (0-100)": 10, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 5/30 (ai_training_on_user_data+5) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "WeChat (Tencent)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using WeChat (Tencent) you gave up your content used as AI training data. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Citizen Lab's research is the anchor here and it is genuinely serious: documented surveillance and censorship infrastructure, including analysis indicating that communications among non-China-registered accounts were used to build the censorship classifiers applied to China-registered users - meaning international users' messages served the surveillance apparatus even where they were not themselves the target. WeChat is also not merely a messenger but payments, identity and civic services in one, which makes leaving it genuinely costly rather than a preference. Tencent operates under Chinese national security and intelligence law, the same structural point documented in the DeepSeek and Moonshot rows of the LLM Providers tab: no terms of service can contract around a state access obligation.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Productivity & Comms Apps", "_row_id": 578, "_entity_id": 812, "_entity_slug": "wechat-tencent", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google Meet (formerly Google Duo)", "Category": "Video Calling", "Terms & Conditions URL": "policies.google.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach; Google MERGED its separate Duo and Meet video-calling products into a single 'Google Meet' brand (2022) — governed by Google's overall data practices (see Google row, Consumer Apps tab).", "Arbitration / Class Action Waiver": "Same as Google overall.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Google Duo NO LONGER EXISTS as a separate product — it was consolidated into Google Meet; worth noting this naming change if referencing this service.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] Meeting participants can't see or control whether recording or AI transcription is enabled by the organizer\nWHAT THE TERMS SAY: Google Meet generates attendance records, duration data, and increasingly AI-generated transcripts and summaries; a participant who joins a meeting someone else scheduled usually cannot see what recording or transcription is enabled, since consent in group tools is held by the organizer, not by the people whose voices are captured.\nWHY IT MATTERS: Participants can be recorded and transcribed by AI without having agreed to it or even being able to see that it is happening.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data Sharing and Arbitration fields defer entirely to Google's general practices with nothing Meet-specific confirmed; only the organizer-controlled recording/transcription consent structural point is specific to this product.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No Meet-specific lawsuit, breach, or terms detail is confirmed this pass.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Google Meet (formerly Google Duo)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Google Meet (formerly Google Duo) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing product-specific confirmed this pass. Meet sits inside the Google framework and inherits it, and the point worth recording is that video conferencing generates a data category most participants never consider: attendance records, duration, and increasingly AI-generated transcripts and summaries. A participant who joins a meeting someone else scheduled has agreed to nothing and usually cannot see what recording or transcription is enabled. Consent in group communications tools is structurally held by the organiser, not by the people whose voices are captured.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Productivity & Comms Apps", "_row_id": 579, "_entity_id": 813, "_entity_slug": "google-meet-formerly-google-duo", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "1Password", "Category": "Password Manager", "Terms & Conditions URL": "https://1password.com/legal/terms-of-service/", "T&C Direct PDF?": null, "Privacy Policy URL": "https://1password.com/legal/privacy/", "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "1Password stores encrypted login credentials, credit card numbers, secure notes, software licenses, identity documents, and SSH keys. 1Password uses a zero-knowledge architecture — the company CANNOT read your vault contents because they are encrypted with a key derived from your Master Password + Secret Key, neither of which 1Password stores. This is verifiable because 1Password publishes its security white paper and has undergone independent audits (SOC 2 Type II, Cure53, ISE). However, 1Password's METADATA (which sites you have accounts on, when you last logged in, device types, IP addresses) is NOT zero-knowledge and IS accessible to 1Password.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 1Password ToS, governed by Ontario, Canada law (1Password HQ: Toronto). AAA rules for US users. 30-day opt-out. The arbitration clause covers disputes over encryption claims, data-breach liability, and the scope of zero-knowledge protections — meaning if 1Password's encryption were ever compromised, individual arbitration would be the only recourse.", "Fees / Billing Flags": "Individual $2.99/month. Family (5 users) $4.99/month. Teams $7.99/user/month. Business $19.95/user/month.", "Notes": "1Password holds the encryption keys to consumers' entire digital lives — every login, every credit card, every secure note. The zero-knowledge architecture means a breach of 1Password's servers would NOT expose vault contents (unlike the LastPass breach of 2022, which DID expose encrypted vaults). 1Password's Canadian jurisdiction means it is not subject to US National Security Letters (NSLs), which can compel US companies to disclose data without notifying the user.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Toronto", "HQ State": "Canada", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-13", "Provenance (who determined this)": "Added 2026-08-13 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Toronto, Canada (non-US)", "Parent / Ultimate Owner": "AgileBits Inc. (Toronto, Canada)", "Years Referenced in Finding (heuristic)": "2022", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Canada) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Canada. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Zero-knowledge encryption doesn't cover metadata — which sites you use, login times, devices, and IP address stay visible to 1Password\nWHAT THE TERMS SAY: While 1Password's zero-knowledge architecture (verified by SOC 2 Type II, Cure53, and ISE audits) means the company cannot read vault contents, metadata — which sites you have accounts on, when you last logged in, device types, and IP addresses — is not encrypted and is accessible to 1Password.\nWHY IT MATTERS: Even with strong vault encryption, 1Password (or anyone who compels it to disclose data) can still see a detailed picture of a user's account activity and behavior patterns.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with a class-action waiver applies even to disputes over whether the encryption actually works\nWHAT THE TERMS SAY: 1Password's terms (governed by Ontario, Canada law) impose mandatory binding arbitration under AAA rules for US users, with a class-action waiver and a 30-day opt-out window; this covers disputes over encryption claims, data-breach liability, and the scope of zero-knowledge protections.\nWHY IT MATTERS: If 1Password's encryption were ever compromised, affected users could only pursue individual arbitration, not a class action, unless they opted out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Beyond the metadata-exposure point and the mandatory-arbitration clause, the row's other content (pricing tiers, the LastPass comparison, and the Flo-vs-Clue cross-reference) either isn't troubling in itself or references another company's finding rather than a distinct 1Password-specific harm.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "1Password's encryption architecture, arbitration terms, and jurisdiction are described with specific, verifiable detail (named audits, governing law, opt-out window).", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "1Password  <-  AgileBits Inc. (Toronto, Canada)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (10 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using 1Password you gave up your right to sue and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "1Password holds the encryption keys to your entire digital life — every login credential, every credit card number, every secure note, every SSH key — and its mandatory arbitration clause means disputes over whether that encryption actually works are resolved individually, not as a class action. 1Password's zero-knowledge architecture (verified by independent audits: SOC 2 Type II, Cure53, ISE) means the company CANNOT read your vault contents — but your METADATA (which sites you have accounts on, when you last logged in, which devices you use, your IP address) is NOT encrypted and IS accessible to 1Password. Compare with the 2022 LastPass breach, where encrypted vaults WERE exposed and attackers have since cracked weak master passwords to steal cryptocurrency — LastPass's architecture was NOT truly zero-knowledge for vault metadata. 1Password's Canadian headquarters (Toronto) provides a structural advantage: Canada is not subject to US National Security Letters (NSLs), which can compel US companies to disclose data without user notification. A DMV consumer choosing between 1Password (Canadian, zero-knowledge, metadata-visible) and a US-based password manager faces a jurisdiction choice as consequential as the Flo-vs-Clue reproductive-data choice documented in cross-cutting finding #28.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Productivity & Comms Apps", "_row_id": 580, "_entity_id": 815, "_entity_slug": "1password", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CapCut (ByteDance)", "Category": "Video Editing", "Terms & Conditions URL": "capcut.com/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "capcut.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CapCut is a ByteDance product — data flows through the same infrastructure as TikTok. Video editing involves face detection, background removal, and audio processing, all generating AI-trainable data. CapCut's BIPA exposure is significant: Illinois users' face data processed by filters may constitute biometric identifiers.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. ByteDance ToS govern CapCut alongside TikTok. 30-day opt-out. CapCut processes video content, face data (for filters/effects), and audio — the same categories of data that drive TikTok's national-security concerns apply to CapCut.", "Fees / Billing Flags": "Predominantly free with optional premium subscription features; specific billing disputes not independently confirmed this pass.", "Notes": "MAJOR OPERATIONAL DISRUPTION: CapCut was BANNED in the US (Jan 19, 2025) alongside TikTok under the federal Protecting Americans from Foreign Adversary Controlled Applications Act; it returned within hours/days after a 75-day extension, and was restored to app stores by mid-February 2025 — its long-term US availability remains tied to broader TikTok/ByteDance divestiture negotiations. Given CapCut's massive user base (200M+ monthly, among the most-downloaded apps globally) combined with active biometric litigation AND a genuinely aggressive new content-rights grant, this is one of the highest-risk entries in this entire 490+ company tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Culver City", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "ByteDance Ltd.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: ByteDance Ltd.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-3] CapCut was banned in the US alongside TikTok in January 2025, then restored amid ongoing divestiture talks\nWHAT THE TERMS SAY: CapCut shares ByteDance's infrastructure with TikTok, and the tracker notes 'the same categories of data that drive TikTok's national-security concerns apply to CapCut'; CapCut was banned in the US on Jan 19, 2025 under the Protecting Americans from Foreign Adversary Controlled Applications Act, restored within days after a 75-day extension, and its long-term US availability remains tied to ByteDance divestiture negotiations.\nWHY IT MATTERS: Users face ongoing uncertainty about whether the app and their data or content within it will remain available or become subject to a forced ownership change.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[BIOMETRICS · FL-2] A lawsuit alleges CapCut collected facial geometry and voiceprints from users' own videos without BIPA-required consent\nWHAT THE TERMS SAY: Rodriguez v. ByteDance alleges CapCut collected biometric identifiers — facial geometry and voiceprints — from users editing their own videos without the informed written consent Illinois BIPA requires; features like face detection for filters and auto-framing are described as biometric processing experienced as convenience.\nWHY IT MATTERS: If confirmed, users would have had biometric identifiers extracted without the consent state law requires, though this is presently only an allegation.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] CapCut imposes mandatory arbitration and a class-action waiver under ByteDance's shared terms with TikTok\nWHAT THE TERMS SAY: CapCut is governed by ByteDance's ToS shared with TikTok, which mandates binding arbitration with a class-action waiver and a 30-day opt-out window.\nWHY IT MATTERS: Users are barred from group lawsuits and must opt out within 30 days to preserve their right to sue individually in court.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=Y; aitrain=Y; location=?; unilateral=?; liabcap=?; contentlic=Y; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The US ban/restoration is confirmed and dated, but the biometric collection claims remain allegations in an active lawsuit, and content-license specifics aren't itemized.", "Exposure Score (0-100)": 42, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 11, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 11/30 (biometric_collection+6, ai_training_on_user_data+5) | Contract 3/20 (broad_content_license+3) | Record 4/20 (severity2+2, litigation+2) | flags stated 9/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nAI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "CapCut (ByteDance)  <-  ByteDance Ltd.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your physical movements; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using CapCut (ByteDance) you gave up your content used as AI training data, your biometric identifiers, a broad licence to your own content, your right to sue, and your right to join a class action. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Rodriguez v. ByteDance alleges CapCut collected biometric identifiers - facial geometry and voiceprints - from users editing their own videos, without the informed written consent Illinois BIPA requires. The mechanism is the part worth understanding: features that make editing easy, like face detection for filters and auto-framing, are biometric processing by another name, and the user experiences them as convenience rather than collection. CapCut is also ByteDance-owned, the same parent as TikTok, so the jurisdictional analysis documented in the TikTok rows applies here too. Illinois BIPA is the only state biometric statute letting individuals sue without proving harm, which is why nearly every case in this category is filed there. Allegations, not findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Media, News & Creative Apps", "_row_id": 581, "_entity_id": 816, "_entity_slug": "capcut-bytedance", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Instagram Layout (Meta)", "Category": "Photo Editing", "Terms & Conditions URL": "See Meta's overall Terms of Service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "See Meta's overall Privacy Policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Governed entirely by Meta's overall data practices (see Meta row, Consumer Apps tab) — Layout is a companion photo-collage app to Instagram with no independently documented separate findings.", "Arbitration / Class Action Waiver": "Same as Meta overall.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Treat as part of Meta's overall profile rather than a standalone product.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Menlo Park", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Meta Platforms, Inc., ATTN: Privacy Operations, 1 Meta Way, Menlo Park, CA 94025, USA (corporate/SEC address: 1601 Willow Road, Menlo Park, CA 94025)", "Legal / Privacy Contact Email": "No published privacy email; Meta routes all requests through in-product privacy forms", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Meta Platforms, Inc.", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Meta Platforms, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] Instagram Layout looks like a small standalone photo app but actually extends a user's full Meta data relationship\nWHAT THE TERMS SAY: Layout has no separate privacy agreement and is governed entirely by Meta's overall terms; the tracker notes a user downloading what looks like a small utility from the App Store is actually extending their Meta relationship, one of several small satellite apps Meta ships this way.\nWHY IT MATTERS: Users may believe they're granting access to a narrow, single-purpose tool when in fact they're extending Meta's full-scale data practices across its broader ad and platform ecosystem.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No Layout-specific lawsuit, breach, or terms detail is confirmed; the row explicitly defers to Meta's overall practices, and the only specific point is that Layout lacks its own separate agreement — the Meta AI ad-targeting change referenced is a different product's finding, not Layout's own.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Layout has no separate terms or confirmed findings of its own; everything defers to Meta's general practices.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Instagram Layout (Meta)  <-  Meta Platforms, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Instagram Layout (Meta) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Layout is governed entirely by Meta's overall data practices with no separate agreement, and the finding is that distinction's absence: a user downloads what looks like a small standalone utility from the App Store and is actually extending their Meta relationship. Meta ships a family of small satellite apps this way. Cross-ref the Meta rows in Consumer Apps and the Meta AI row in LLM Providers for the October 2025 change routing AI chat content into ad targeting across the whole Meta estate with no US opt-out.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Media, News & Creative Apps", "_row_id": 582, "_entity_id": 817, "_entity_slug": "instagram-layout-meta", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "GIPHY (Meta)", "Category": "Media", "Terms & Conditions URL": "giphy.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "giphy.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Meta ACQUIRED GIPHY in 2020, then was FORCED TO DIVEST it (2023) following a UK Competition and Markets Authority antitrust ruling — GIPHY was sold to Shutterstock — meaning GIPHY is no longer part of the Meta corporate family despite widespread integration into Instagram/Facebook/Messenger's GIF-search features. No independently confirmed separate privacy lawsuit this pass.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "GIPHY's UK-forced divestiture from Meta (now owned by Shutterstock) is a genuinely notable antitrust outcome — worth noting that GIF searches within Instagram/Messenger now route through a Shutterstock-owned service, not Meta directly.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "PARENT ADDRESS ONLY — verify before using for legal notice. GIPHY was ordered divested by the UK CMA in 2023 and is no longer Meta-owned — this address is HISTORICAL and almost certainly wrong for current notice. Parent: Meta Platforms, Inc., ATTN: Privacy Operations, 1 Meta Way, Menlo Park, CA 94025, USA (corporate/SEC address: 1601 Willow Road, Menlo Park, CA 94025)", "Legal / Privacy Contact Email": "No published privacy email; Meta routes all requests through in-product privacy forms", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Meta Platforms, Inc.", "Years Referenced in Finding (heuristic)": "2020, 2023", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Meta Platforms, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] GIF searches inside private chats are queries sent to a third-party company, with no disclosure in the messaging app\nWHAT THE TERMS SAY: GIPHY's content is embedded across messaging apps like Instagram and Messenger, so the service observes search terms and delivery context from inside conversations on platforms it does not own; nothing in the messaging app's interface discloses that a search is being sent to a third party.\nWHY IT MATTERS: Users searching for a GIF inside what feels like a private conversation are unknowingly sending that search query to an outside company, now Shutterstock rather than Meta.\n(evidence: SCARY | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] UK antitrust regulators forced Meta to sell GIPHY to Shutterstock in 2023, changing who actually operates the embedded GIF service\nWHAT THE TERMS SAY: Meta acquired GIPHY in 2020 and was ordered to divest it in 2023 by the UK Competition and Markets Authority, a rare unwinding of a completed big-tech acquisition; GIPHY was sold to Shutterstock and now operates independently of Meta despite remaining integrated into Instagram, Facebook, and Messenger's GIF search.\nWHY IT MATTERS: Users have no say in the change of corporate ownership of a service embedded in the apps they use, and its data practices are now governed by a different company than the platform they're using.\n(evidence: Data Sharing | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and Fees are not confirmed or itemized this pass; only the third-party-query structural point and the Meta-to-Shutterstock ownership change are specific and substantive for GIPHY.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Meta-to-Shutterstock ownership change is clearly documented, but no lawsuit, breach, or GIPHY-specific arbitration/fee terms are confirmed this pass.", "Exposure Score (0-100)": 9, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "GIPHY (Meta)  <-  Meta Platforms, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using GIPHY (Meta) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Meta acquired GIPHY in 2020 and was ordered to divest it in 2023 after the UK Competition and Markets Authority concluded the deal harmed competition - a rare case of a completed big-tech acquisition being unwound. The privacy angle most people miss is what a GIF search engine actually sees: GIPHY's content is embedded across messaging apps, so the service observes search terms and delivery context from inside conversations on platforms it does not own. Users searching for a reaction GIF inside a private chat are querying a third party, and nothing in the messaging app's interface says so.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Media, News & Creative Apps", "_row_id": 583, "_entity_id": 818, "_entity_slug": "giphy-meta", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Shazam (Apple)", "Category": "Media", "Terms & Conditions URL": "apple.com/legal/internet-services/terms/site.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "apple.com/legal/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Governed by Apple's overall data practices since Apple's 2018 acquisition; Shazam's core function (listening to ambient audio to identify songs) necessarily involves brief audio capture, though Apple's general privacy positioning is comparatively strong relative to most other companies in this tracker. No independently confirmed separate lawsuit this pass.", "Arbitration / Class Action Waiver": "Same as Apple overall.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cupertino", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Apple Inc.", "Years Referenced in Finding (heuristic)": "2018", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Apple Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Shazam's song-identification history functions as a preference profile that can reconstruct where and when a user was at various venues\nWHAT THE TERMS SAY: Music identification history built through Shazam's core function records what you heard, where, and when, which the tracker says can reconstruct venues visited and time spent there.\nWHY IT MATTERS: Even without direct location data, a listening history log can reveal a user's movement patterns and habits over time.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Nothing is independently confirmed against Shazam this pass beyond Apple's general framework; only the listening-history-as-preference-profile structural point is specific to this product.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing product-specific is confirmed this pass; the row explicitly states 'nothing confirmed.'", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Shazam (Apple)  <-  Apple Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Shazam (Apple) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Shazam's function requires the microphone, and the trust proposition is that it listens only when you press the button. Apple acquired it in 2018 and it now sits under Apple's overall data practices, which are genuinely stronger than the ad-funded alternative would have been - worth saying plainly. The residual note is that music identification history is a preference profile: what you heard, where, and when, which reconstructs venues visited and time spent there. Nothing confirmed this pass; the microphone-permission category is the reason the row exists.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Media, News & Creative Apps", "_row_id": 584, "_entity_id": 819, "_entity_slug": "shazam-apple", "_issuer": "Apple Inc.", "_issuer_slug": "apple-inc", "_ticker": "AAPL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Speechify", "Category": "Media/Accessibility", "Terms & Conditions URL": "speechify.com/terms-of-service/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "speechify.com/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach; Speechify (text-to-speech accessibility tool) has faced separate, UNRELATED copyright/AI-voice-cloning controversy (allegations its AI voice models were trained on audiobook narrators' voices without consent) — an intellectual-property concern distinct from consumer data privacy.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass on the consumer-privacy side specifically.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] Speechify's voice-cloning feature treats an uploaded voice sample as biometric material under most state statutes\nWHAT THE TERMS SAY: Speechify's voice cloning features require users to upload a voice sample, which the tracker notes is biometric material in most state statutes; retention practices for uploaded voice samples are not confirmed this pass.\nWHY IT MATTERS: A biometric voiceprint carries statutory protections in many states, and unclear retention practices leave open how long that sample is kept or how it might be used.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Users routinely feed legal and medical documents through an accessibility tool many depend on rather than choose casually\nWHAT THE TERMS SAY: Speechify converts text to speech, so users routinely feed it documents like legal correspondence, medical letters, and study material; the tracker notes a substantial share of users have disabilities and depend on the tool rather than choosing it casually.\nWHY IT MATTERS: Sensitive personal documents pass through the service with no confirmed information this pass on how they're retained or protected, and dependent users may have less practical ability to switch providers over privacy concerns.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data Sharing, Arbitration, and Fees are all unconfirmed or not itemized this pass; only the voice-sample biometric point and the sensitive-document-exposure structural point are specific enough to report, both flagged as unconfirmed or inferred rather than stated findings.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed against Speechify's own consumer-privacy practices this pass; only inferred structural risks are noted.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 9/30 (biometric_collection+6, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Speechify  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Speechify you gave up your biometric identifiers. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Speechify converts text to speech, which means users routinely feed it documents they need read aloud - including legal correspondence, medical letters and study material - and the accessibility use case means a substantial share of users have disabilities and depend on the tool rather than choosing it casually. Voice cloning features add a second category: an uploaded voice sample is biometric material in most state statutes. Recommend a follow-up on retention of uploaded documents and voice samples.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Media, News & Creative Apps", "_row_id": 585, "_entity_id": 820, "_entity_slug": "speechify", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "NPR", "Category": "News/Media", "Terms & Conditions URL": "npr.org/about-npr/179876898/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "npr.org/about-npr/179880519/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a nonprofit public media organization funded partly by member-station donations and corporate sponsorship (not advertising in the traditional commercial sense), NPR's data-monetization incentives differ structurally from most for-profit media companies in this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "NPR's nonprofit structure is a genuine point of difference worth noting relative to most other media companies in this tracker; recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] NPR's nonprofit status doesn't mean different tracking: public media outlets run the same ad-adjacent analytics stacks as commercial publishers\nWHAT THE TERMS SAY: Nothing is confirmed against NPR specifically this pass, but the tracker notes nonprofit and public media organizations generally run the same web analytics and advertising-adjacent measurement stacks as commercial publishers, and audiences generally assume otherwise given the funding model.\nWHY IT MATTERS: Users may extend more trust to NPR's tracking practices than is warranted given its nonprofit funding model, even though this is a general industry observation rather than an NPR-specific confirmed finding.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — NPR's own row states nothing is confirmed against it specifically this pass — Data Sharing, Arbitration, and Fees are all unconfirmed or not itemized — so only a general, hedged industry-wide observation about nonprofit media tracking practices is reportable, and it is explicitly framed as unverified rather than an NPR-specific finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The row states nothing confirmed against NPR specifically; even the SCARY field frames its point as 'unverified rather than clean.'", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "NPR  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, NPR takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass against NPR specifically. The category note worth recording is that non-profit and public media organisations run the same web analytics and advertising-adjacent measurement stacks as commercial publishers, and their audiences generally assume otherwise because of the funding model. Public-service mission does not automatically imply a different technical implementation, and the Video Privacy Protection Act exposure documented in the QVC row of Online Retailers reaches any site serving video content. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Media, News & Creative Apps", "_row_id": 586, "_entity_id": 821, "_entity_slug": "npr", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "The New York Times", "Category": "News/Media", "Terms & Conditions URL": "help.nytimes.com/hc/en-us/articles/115014892387-Terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "nytimes.com/privacy/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "RELATED-INDUSTRY FINDING (different company, same underlying pattern worth checking against NYT specifically): a 2026 lawsuit against THE WASHINGTON POST (a direct competitor) alleges the Post used subscriber browsing/cookie data to build profiles enabling 'SURVEILLANCE PRICING' — charging different subscribers different rates for the same subscription based on demographic/behavioral data, only disclosed after a new NY state law required algorithmic-pricing transparency (March 2026). Given how similar major newspaper subscription/paywall business models are, this specific practice is worth directly verifying against the NYT's own current privacy policy and pricing practices, since no NYT-specific surveillance-pricing lawsuit was independently confirmed this pass. SEPARATELY: NYT's OWN COPYRIGHT LAWSUIT against OpenAI (over ChatGPT training data) has generated a notable SIDE EFFECT for ORDINARY CHATGPT USERS: a court initially ordered OpenAI to preserve ALL ChatGPT output data indefinitely as potential evidence, which OpenAI is actively fighting as an overreach that 'risks [users'] privacy without actually helping resolve the lawsuit' — illustrating how a media company's OWN litigation against a THIRD PARTY (OpenAI) can create privacy risk for the third party's separate, unrelated customers (ordinary ChatGPT users).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass for NYT's own subscriber Terms of Service — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Recommend a direct follow-up specifically checking whether NYT uses similar algorithmic/personalized subscription pricing to its competitor Washington Post, given the structural similarity of their businesses.", "Notes": "The NYT v. OpenAI preservation-order dispute is a genuinely unusual finding: NYT's OWN lawsuit (as plaintiff, seeking to protect its own copyrighted content) has created a privacy exposure for MILLIONS of unrelated ChatGPT users who have nothing to do with the underlying dispute — worth flagging as a notable example of third-party litigation risk.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-2] NYT's OpenAI suit produced a discovery order over 20 million ChatGPT conversations, with users not notified\nWHAT THE TERMS SAY: The Times is lead plaintiff in a publisher coalition suing OpenAI and Microsoft; discovery in that case produced a court order that overrode OpenAI's deletion policy and pushed 20 million user conversations into discovery, with none of those ChatGPT users notified. Nothing is confirmed against the Times' own consumer data practices this pass.\nWHY IT MATTERS: A legitimate copyright lawsuit by the Times had the collateral effect of exposing millions of unrelated ChatGPT users' private conversations to litigation discovery without their knowledge.\n(evidence: SCARY | Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — The Data Sharing field's surveillance-pricing content describes a Washington Post-specific finding, not an NYT one, and Arbitration/Fees fields explicitly state nothing is confirmed for NYT's own terms; only the NYT v. OpenAI discovery-order item is genuinely attributable to this company's own actions.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed against the Times' own consumer data or pricing practices this pass; the only concrete NYT-attributable fact is the discovery-order side effect of its OpenAI lawsuit.", "Exposure Score (0-100)": 4, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "The New York Times  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, The New York Times takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The Times is the lead plaintiff in the publisher coalition suing OpenAI and Microsoft, and the discovery fight in that case produced the single most consequential consumer-privacy event in the LLM Providers tab: a court order that overrode OpenAI's deletion policy and ultimately pushed 20 million user conversations into discovery, with none of those users notified. That is worth holding as a genuine tension rather than a gotcha - the Times is litigating a legitimate copyright claim, and the collateral effect landed on ChatGPT users who were not party to anything. Cross-ref the OpenAI row. Nothing confirmed against the Times' own consumer data practices this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Media, News & Creative Apps", "_row_id": 587, "_entity_id": 822, "_entity_slug": "the-new-york-times", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Medium", "Category": "Publishing", "Terms & Conditions URL": "medium.com/policy/9db0094a1e0f", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "medium.com/policy/f34a047a8c26", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; Medium's 'member' paywall/subscription tracks reading history across many different publications on one platform, creating a centralized reading-interest profile spanning politics, health, and other potentially sensitive topic areas.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Medium ToS, AAA rules, California law. 30-day opt-out. Medium's Partner Program monetizes writer content — the arbitration clause covers disputes over revenue calculation and content moderation.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; the cross-publication reading-history aggregation is a distinctive data category worth noting, similar in spirit to Substack's aggregation of newsletter subscriptions (this same tab).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "A Medium Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: A Medium Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Medium's cross-publication reading history builds a centralized belief-and-interest profile spanning health, politics, and sexuality\nWHAT THE TERMS SAY: Medium's membership/paywall tracks reading history across many different publications on one platform; the tracker notes Medium hosts substantial writing on health, addiction, politics, and sexuality, making a reading log across that material particularly inference-rich.\nWHY IT MATTERS: A single centralized reading profile can reveal sensitive personal interests and struggles that a user browsing casually would not expect to be aggregated in one place.\n(evidence: Data Sharing | SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Medium imposes mandatory arbitration with a class-action waiver, covering disputes over writer revenue and content moderation\nWHAT THE TERMS SAY: Medium's terms mandate binding arbitration under AAA rules and California law, with a class-action waiver and a 30-day opt-out window; the tracker notes this covers disputes over the Partner Program's revenue calculations and content moderation.\nWHY IT MATTERS: Both readers and writers are barred from suing Medium collectively, including over how the Partner Program calculates and pays out writer revenue.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data Sharing provides no confirmed lawsuit or breach and Fees is not itemized; the reading-history-aggregation point and the mandatory arbitration clause are the only two distinct, substantive items this pass.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are specifically confirmed, but no lawsuit or breach is confirmed and the reading-history risk is inferred rather than stated as a finding.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Medium  <-  A Medium Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Medium you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Medium's structural feature worth recording is that reading history on a publishing platform is a belief-and-interest profile: what you read, how far you got, and what you saved. Medium hosts substantial writing on health, addiction, politics and sexuality, and a reading log across that material is inference-rich in ways a user browsing casually would not anticipate. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Media, News & Creative Apps", "_row_id": 588, "_entity_id": 824, "_entity_slug": "medium", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Substack", "Category": "Publishing", "Terms & Conditions URL": "substack.com/tos", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "substack.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED, VERY RECENT BREACH (Feb 2026 disclosure): a third party exploited a vulnerability in Substack's API (a 'scraping' attack, not a traditional server break-in) between October 2025 and February 2026 — a FOUR-MONTH 'dwell time' before Substack even detected the intrusion. Approximately 697,000 user records were exposed (out of Substack's 35+ million total users) including email addresses, phone numbers, usernames, profile bios, and STRIPE PAYMENT-SYSTEM CUSTOMER IDs used by writers to receive subscriber payments — security researchers specifically flagged that pairing email + phone number is 'critical data' in an era of SIM-swap attacks, even without passwords/financial data exposed directly. The stolen dataset was posted for sale on BreachForums by an actor using the alias 'w1kkid.' Substack CEO Chris Best publicly apologized, acknowledging the company 'came up short' on its data-protection responsibility.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Substack ToS, AAA rules, California law. 30-day opt-out. Substack processes newsletter content, subscriber lists, and payment data (Substack takes 10% of subscription revenue). The arbitration clause covers disputes between writers and Substack over revenue sharing.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Substack has become 'the de facto home for independent journalists, academics, and public intellectuals' per security researchers — meaning this breach's exposed contact information could be used to identify and target writers/subscribers specifically, a distinct concern from a typical e-commerce breach given Substack's role as a platform for controversial/politically sensitive writing.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Substack Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Substack Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] A four-month-undetected API scraping breach exposed 697,000 Substack users' emails, phones, and Stripe payment IDs\nWHAT THE TERMS SAY: Disclosed in February 2026, a third party exploited a vulnerability in Substack's API between October 2025 and February 2026 — a four-month dwell time before detection — exposing roughly 697,000 records (of 35+ million total users), including email addresses, phone numbers, usernames, profile bios, and Stripe payment-system customer IDs; the stolen data was posted for sale on BreachForums by an actor using the alias 'w1kkid.'\nWHY IT MATTERS: Security researchers flagged that the paired email-and-phone-number exposure is especially dangerous in an era of SIM-swap attacks, and CEO Chris Best publicly acknowledged the company 'came up short' on data protection.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] The breach's exposed contact data could be used to identify and target independent journalists and subscribers to politically sensitive newsletters\nWHAT THE TERMS SAY: The tracker notes Substack is 'the de facto home for independent journalists, academics, and public intellectuals,' so the breach's exposed contact information could be used to identify and target writers and subscribers specifically — a distinct concern from a typical e-commerce breach given Substack's role as a platform for controversial or politically sensitive writing.\nWHY IT MATTERS: Exposed identity and contact data tied to a person's newsletter subscriptions can reveal their political or personal interests and make them a target, beyond ordinary financial-fraud risk.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Substack imposes mandatory arbitration with a class-action waiver under AAA rules and California law\nWHAT THE TERMS SAY: Substack's terms mandate binding arbitration under AAA rules and California law, with a class-action waiver and a 30-day opt-out window.\nWHY IT MATTERS: Writers and users who do not opt out within 30 days are barred from pursuing claims against Substack as a class, including disputes over revenue sharing.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The breach is confirmed with specific dates, record counts, exposed data types, and a company apology, making this one of the more clearly documented rows in the tracker.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Substack  <-  Substack Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (10 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Substack you gave up your right to sue and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The February 2026 disclosure involved a third party exploiting a flaw - a confirmed and very recent breach. The structural point specific to Substack is that a subscription newsletter list is simultaneously a customer list, a payment record and a political or interest profile, and it belongs to a writer who is usually an individual with no security capability at all. Substack's central infrastructure means one breach reaches every publication on it at once. For a reader, subscribing to a newsletter is a more revealing act than subscribing to a magazine ever was, because the list is queryable.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Media, News & Creative Apps", "_row_id": 589, "_entity_id": 826, "_entity_slug": "substack", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Letterboxd", "Category": "Media/Social", "Terms & Conditions URL": "letterboxd.com/legal/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "letterboxd.com/legal/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Letterboxd is a relatively small, independently-owned film-logging/social platform — recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "1988", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Letterboxd's entire function — publicly logging what you watched — sits close to the core of the Video Privacy Protection Act\nWHAT THE TERMS SAY: Nothing is confirmed against Letterboxd specifically this pass, but the tracker notes the Video Privacy Protection Act (VPPA) — which provides statutory damages without proof of harm — is the relevant statute for a service whose entire function is a public record of what a user has watched.\nWHY IT MATTERS: VPPA exposure is described as the most productive consumer privacy tool of the streaming era; a viewing-history-based platform like Letterboxd sits unusually close to what the statute was designed to address.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DARK_PATTERN_CONSENT · FL-2] Default profile visibility settings are a control most users never review\nWHAT THE TERMS SAY: The tracker notes default profile visibility is the practical control most users never review on Letterboxd.\nWHY IT MATTERS: Users may be publicly sharing their viewing history and reviews without realizing that a default setting, rather than an active choice, is what determines who can see it.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data Sharing, Arbitration, and Fees are unconfirmed or not itemized for Letterboxd specifically this pass; only the VPPA-relevance point and the default-visibility structural point are specific and substantive, both explicitly framed as unverified rather than confirmed findings.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The row explicitly states nothing is confirmed against Letterboxd this pass; only general statutory-relevance and default-settings notes are given.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "App / Service", "Ownership Path": "Letterboxd  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Letterboxd takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Letterboxd is a film logging and review platform, and the relevant statute is the Video Privacy Protection Act - the 1988 law that has become the most productive consumer privacy tool of the streaming era because it provides statutory damages without proof of harm. A service whose entire function is a public record of what you watched sits closer to that statute's core than almost anything else in this tracker. Default profile visibility is the practical control most users never review.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Media, News & Creative Apps", "_row_id": 590, "_entity_id": 827, "_entity_slug": "letterboxd", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Rode Central", "Category": "Audio Software", "Terms & Conditions URL": "rode.com/terms-of-use (companion software for RODE microphones)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "rode.com/privacy-policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach; this is companion hardware-configuration software for RODE microphones rather than a data-intensive consumer service, meaning its privacy footprint is likely much smaller than most other entries in this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "As primarily a HARDWARE companion app, this carries a fundamentally different (likely much lower) data-collection profile than social/consumer apps elsewhere in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Data sharing and arbitration are both 'not independently confirmed this pass'; this is a hardware-configuration companion app with a structurally low data-collection profile, and the one structural point noted (firmware update channels give the manufacturer power to change device behavior post-purchase) is explicitly described in the tracker as exercised benignly here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed this pass and no specific terms are located or described in detail.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Rode Central  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Rode Central takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Desktop configuration software for Rode microphones — a hardware utility with minimal data collection, and one of the genuinely low-stakes rows in this tracker. The honest note: companion apps for audio hardware typically require firmware update channels, which means the manufacturer retains the ability to change how a device you own behaves after purchase. That is the same structural power documented in the HP printer and John Deere rows, just exercised benignly here.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Media, News & Creative Apps", "_row_id": 591, "_entity_id": 828, "_entity_slug": "rode-central", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Genius Scan", "Category": "Utility", "Terms & Conditions URL": "geniusscan.com/terms/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "geniusscan.com/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach; like Adobe Scan (this same tab), Genius Scan is used to digitize potentially sensitive physical documents (IDs, forms, receipts) — the same general risk category applies even without a confirmed specific incident.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Adobe Scan row (this tab) for the general document-scanning privacy risk category that applies here too.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Genius Scan digitizes IDs, forms and receipts with no stated on-device vs cloud handling\nWHAT THE TERMS SAY: Users scan sensitive physical documents (IDs, forms, receipts); the tracker flags that whether this processing happens on-device or in the cloud is unclear and not prominently disclosed.\nWHY IT MATTERS: If scanned documents are processed or stored in the cloud, that raises real exposure risk for highly sensitive personal documents, and retention practices are unconfirmed.\n(evidence: SCARY, Notes; Tracker says unconfirmed (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data sharing, arbitration, and fees fields all say not independently confirmed this pass; only the document-sensitivity/processing-location question is a substantive, company-relevant point, and it is explicitly flagged as unverified rather than clean.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The core question (on-device vs cloud processing) is unresolved and no terms are confirmed.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Genius Scan  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Genius Scan takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Document scanning apps are a high-sensitivity, low-scrutiny category: users photograph passports, tax returns, medical bills, contracts and IDs, precisely because those are the documents that need digitising. Whether processing happens on-device or in the cloud is the entire question and it is rarely prominent. Cross-ref the Adobe Scan row in Productivity & Comms Apps, where a 2024 policy update produced backlash on exactly this point. Recommend a follow-up on Genius Scan's on-device versus cloud processing and OCR retention.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Media, News & Creative Apps", "_row_id": 592, "_entity_id": 829, "_entity_slug": "genius-scan", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google Play Music (discontinued)", "Category": "Media (legacy)", "Terms & Conditions URL": "N/A - service discontinued", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "N/A", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "GOOGLE PLAY MUSIC WAS FULLY SHUT DOWN in December 2020, with users migrated to YouTube Music — this service no longer exists in any form. Any customer/user still referencing 'Play Music' should be directed to YouTube Music (see YouTube row, Consumer Apps tab) instead.", "Arbitration / Class Action Waiver": "N/A", "Fees / Billing Flags": "N/A", "Notes": "THIS SERVICE HAS BEEN FULLY DISCONTINUED (since Dec 2020) — included here only to flag its discontinued status for anyone still referencing it by its old name.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "PARENT ADDRESS ONLY — verify before using for legal notice. service discontinued December 2020. Parent: Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2020", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[TERMINATION_CONFISCATION · FL-4] Play Music's Dec 2020 shutdown left decade-built libraries dependent on Google's own migration window\nWHAT THE TERMS SAY: Google Play Music was fully shut down in December 2020 with users migrated to YouTube Music; anything not transferred in that window was gone, and nothing in a consumer agreement obliged the service to continue existing or preserve purchases.\nWHY IT MATTERS: Libraries, purchases and playlists built over a decade depended entirely on a migration path and window that Google itself designed and chose.\n(evidence: SCARY, Notes, Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fees are listed as N/A because the service is fully discontinued; only the shutdown/migration-risk finding applies.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The shutdown, timing, and migration outcome are clearly and specifically documented.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 4/20 (termination_or_confiscation+4) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Google Play Music (discontinued)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Google Play Music (discontinued) you gave up your right to keep what you paid for. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Google Play Music was shut down in December 2020 with users migrated to YouTube Music, and the row exists to make the shutdown risk legible: libraries, purchases and playlists built over a decade depended on a migration path Google designed and a window Google chose, and anything not transferred was gone. Nothing in a consumer agreement obliges a service to continue existing, provide usable export, or preserve purchases. Cross-ref the Skype row in Productivity & Comms Apps - same finding, different decade.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Media, News & Creative Apps", "_row_id": 593, "_entity_id": 830, "_entity_slug": "google-play-music-discontinued", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "BitMoji (Snap Inc.)", "Category": "Media/Avatar", "Terms & Conditions URL": "bitmoji.com/terms/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "bitmoji.com/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Owned by Snap Inc. (same parent as Snapchat, documented in Consumer Apps tab) — Bitmoji's core function (creating a personalized cartoon avatar) involves collecting facial-feature reference data, though it's typically used to generate a stylized avatar rather than store precise biometric facial geometry data. No independently confirmed separate lawsuit this pass.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver — governed by Snap Inc.'s ToS, same clause as Snapchat. 30-day opt-out. Bitmoji processes facial feature data to generate avatars — the Illinois BIPA class action ($35M settlement) specifically named facial-recognition data collection as the violation.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Snapchat row (Consumer Apps tab) for Snap Inc.'s broader corporate findings, which likely extend to Bitmoji given shared corporate ownership.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Santa Monica", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Pending - severity 4/5, no source yet", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Snap Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Snap Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] Bitmoji processes facial feature data; the $35M Illinois BIPA case named facial-recognition collection\nWHAT THE TERMS SAY: Bitmoji processes facial feature data from a selfie to generate a stylized avatar; the Illinois BIPA class action against Snap, settled for $35M, specifically named facial-recognition data collection as the violation.\nWHY IT MATTERS: The tracker notes Bitmoji's facial-feature data is typically used to generate a stylized avatar rather than to store precise biometric facial geometry data, and that Bitmoji is heavily used by minors, which brings COPPA obligations and a different consent regime.\n(evidence: Data Sharing, Arbitration, SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Bitmoji users are bound by Snap's mandatory arbitration and class-action waiver, 30-day opt-out only\nWHAT THE TERMS SAY: Bitmoji is governed by Snap Inc.'s ToS, the same arbitration and class-action-waiver clause used for Snapchat, with a 30-day window to opt out.\nWHY IT MATTERS: Consumers must proactively opt out within 30 days or permanently waive the right to sue or join a class action.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct company-specific findings are directly stated for Bitmoji; the minors/COPPA point is contextual rather than a separately itemized violation, and other data practices are attributed to parent Snap rather than confirmed independently for Bitmoji.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated, but broader data practices are inferred from parent company Snap rather than confirmed for Bitmoji specifically.", "Exposure Score (0-100)": 50, "Exposure Band": "High", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 6/30 (biometric_collection+6) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "BitMoji (Snap Inc.)  <-  Snap Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using BitMoji (Snap Inc.) you gave up your biometric identifiers, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Bitmoji is Snap-owned, and the category worth flagging is that avatar creation from a selfie involves facial analysis - the same technical operation at issue in the CapCut BIPA case in this tab and the Google Photos face-grouping claims that produced a $100 million Illinois settlement and formed part of Texas's $1.375 billion action. Bitmoji is also heavily used by minors, which brings COPPA obligations and a different consent regime. See the Snapchat row in Consumer Apps for the parent company findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Media, News & Creative Apps", "_row_id": 594, "_entity_id": 831, "_entity_slug": "bitmoji-snap-inc", "_issuer": "Snap Inc.", "_issuer_slug": "snap-inc", "_ticker": "SNAP", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Meta Horizon (VR)", "Category": "Social/VR", "Terms & Conditions URL": "See Meta's overall Terms of Service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "See Meta's overall Privacy Policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "VR/AR platforms like Meta Horizon collect uniquely sensitive BIOMETRIC data beyond typical apps — eye tracking, hand/body movement, and even involuntary physiological responses (e.g., subtle head/body movements that can reveal health conditions) — privacy researchers and the FTC have specifically flagged VR biometric data as a growing area of regulatory concern given how much MORE revealing movement/gaze data can be compared to typical smartphone app data. No Horizon-specific lawsuit independently confirmed this pass beyond Meta's overall corporate findings.", "Arbitration / Class Action Waiver": "Same as Meta overall.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "VR biometric data collection (eye-tracking, movement patterns) is a genuinely emerging privacy frontier worth flagging distinctly from typical 2D app data collection — this category is likely to generate significant new litigation in coming years as VR adoption grows.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$201.0B", "Market Cap": "$1.6T", "Employees": "74,067", "HQ City": "Menlo Park", "HQ State": "California", "CEO": "Mark Zuckerberg", "Ticker": "META", "Website (Corporate)": "meta.com", "Main Mailing Address (legal/privacy notices)": "Meta Platforms, Inc., ATTN: Privacy Operations, 1 Meta Way, Menlo Park, CA 94025, USA (corporate/SEC address: 1601 Willow Road, Menlo Park, CA 94025)", "Legal / Privacy Contact Email": "No published privacy email; Meta routes all requests through in-product privacy forms", "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (META). Service route: c/o General Counsel / Corporate Secretary, Menlo Park, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] Meta Horizon collects eye, hand and body movement data that can re-identify people from short sessions\nWHAT THE TERMS SAY: Horizon collects eye tracking, hand/body movement, and subtle physiological responses; research shows motion data alone can re-identify individuals with high accuracy from very short sessions.\nWHY IT MATTERS: This movement/gaze data is more revealing than typical smartphone data, and existing biometric statutes were drafted around faces, fingerprints and voices, not motion data, leaving a regulatory gap.\n(evidence: Data Sharing, SCARY, Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Horizon's spatial mapping scans the inside of users' homes, unexplained at setup\nWHAT THE TERMS SAY: VR spatial mapping captures the layout of a user's physical home; the tracker notes Horizon is also used by children in substantial numbers.\nWHY IT MATTERS: A room-scale scan of a family home is sensitive data not meaningfully explained to users at setup, and its use by children raises additional consent questions.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration is only cross-referenced as 'Same as Meta overall' without itemized Horizon-specific detail in this row, so a third distinct company-specific finding isn't available without pulling from Meta's own row.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Biometric data collection is clearly described, but no Horizon-specific litigation or itemized arbitration terms are confirmed in this row.", "Exposure Score (0-100)": 11, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 9/30 (biometric_collection+6, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "App / Service", "Ownership Path": "Meta Horizon (VR)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Meta Horizon (VR) you gave up your biometric identifiers. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "VR headsets collect a category of data no other consumer device produces: eye tracking, hand and body motion, spatial mapping of the inside of your home, and gait and posture signatures that are identifying in the way a fingerprint is. Research has shown motion data alone can re-identify individuals with high accuracy from very short sessions. None of that fits neatly into existing biometric statutes, which were drafted around faces, fingerprints and voices. Meta Horizon is also used by children in substantial numbers, and a room-scale scan of a family home is a category of collection no privacy policy meaningfully explains at setup.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Media, News & Creative Apps", "_row_id": 595, "_entity_id": 832, "_entity_slug": "meta-horizon-vr", "_issuer": "Meta Horizon (VR)", "_issuer_slug": "meta-horizon-vr", "_ticker": "META", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Marco Polo", "Category": "Video Messaging", "Terms & Conditions URL": "marcopolo.me/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "marcopolo.me/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "SUBSCRIPTION MODEL SHIFT: Marco Polo transitioned from a free app to a paid subscription model (2022), generating some user complaints about the change, though no formal legal action was independently confirmed this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[RETENTION_PERIOD · FL-2] Marco Polo stores a durable archive of private video and audio instead of relaying live calls\nWHAT THE TERMS SAY: Marco Polo's defining feature is that messages are recorded and stored rather than transmitted live, so the service holds a durable archive of video and audio from private conversations.\nWHY IT MATTERS: Users experience it as a conversation, but it functions as a library of personal content with a materially different retention profile than a live video call.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[AUTO_RENEWAL_FEES · FL-1] Marco Polo shifted from free to paid subscription in 2022, drawing user complaints\nWHAT THE TERMS SAY: Marco Polo transitioned from a free app to a paid subscription model in 2022, generating user complaints, though no formal legal action was independently confirmed this pass.\nWHY IT MATTERS: Users who joined expecting a free service faced new recurring costs; documented consumer friction, even without confirmed litigation.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data sharing and arbitration fields both say not independently confirmed this pass; only the message-retention and subscription-shift findings are substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The subscription shift and retention model are described, but data-sharing and arbitration remain unconfirmed.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Marco Polo  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Marco Polo takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Marco Polo is a video messaging app whose defining feature is that messages are recorded and stored rather than live - so the service holds a durable archive of video and audio from private family and friend conversations, which is a materially different retention profile from a live video call. Users experience it as a conversation and it functions as a library. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Media, News & Creative Apps", "_row_id": 596, "_entity_id": 833, "_entity_slug": "marco-polo", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Amtrak", "Category": "Transit (rail)", "Terms & Conditions URL": "amtrak.com/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "amtrak.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MAJOR, VERY RECENT BREACH (April 2026): the ShinyHunters extortion group (the SAME group behind the Panera Bread, Air France/KLM, Workday, 7-Eleven, and CarMax breaches documented elsewhere in this tracker) claimed responsibility for breaching Amtrak, typically by first compromising an organization's SALESFORCE customer-data platform. The confirmed leaked dataset (added to Have I Been Pwned April 17, 2026) contains OVER 2.1 MILLION unique accounts — names, emails, physical addresses, and customer SUPPORT RECORDS (which can reveal travel habits, preferences, and past complaints, giving attackers additional context for targeted phishing); ShinyHunters itself claimed a much larger 9.4 MILLION records, though Amtrak has not confirmed the full scope as of this research.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver, introduced 2019. AAA rules. Covers personal injury, wrongful death, discrimination, failure to accommodate — not just billing disputes. The 488-word clause appears two-thirds of the way into Amtrak's 15,500-word T&C. A ticket purchase constitutes agreement. NO OPT-OUT PROVISION. Congress has introduced the Ending Passenger Rail Forced Arbitration Act THREE times (2019, 2021, and May 2026 — Blumenthal/Deluzio/Boyle) to ban it; none have passed committee. Separately, in May 2025, the AAA itself was sued in a federal lawsuit for allegedly favoring corporations in its proceedings. For a DMV commuter on the Northeast Corridor, buying a monthly Amtrak pass means waiving the right to sue over a train derailment.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "GIVEN AMTRAK'S NORTHEAST CORRIDOR IS THE BACKBONE OF MID-ATLANTIC INTERCITY RAIL TRAVEL (DC-Baltimore-Philadelphia-NYC), this is one of the most directly regionally-relevant breaches in this entire tracker — worth flagging prominently given how many Mid-Atlantic residents have an Amtrak account for regular commuting/travel between major cities in this corridor.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "National Railroad Passenger Corporation (federally chartered, majority US government-owned)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] ShinyHunters' April 2026 breach exposed 2.1M+ Amtrak accounts' names, addresses, support records\nWHAT THE TERMS SAY: ShinyHunters breached Amtrak, reportedly via a compromised Salesforce customer-data platform; the confirmed leaked dataset added to Have I Been Pwned on April 17, 2026 held 2.1M+ accounts (names, emails, addresses, support records), though ShinyHunters itself claimed 9.4M records, unconfirmed by Amtrak.\nWHY IT MATTERS: Support records can reveal travel habits, preferences and past complaints, giving attackers added context for targeted phishing, and the full breach scope remains unconfirmed.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Amtrak's arbitration clause has no opt-out and covers wrongful death, not just billing disputes\nWHAT THE TERMS SAY: Amtrak's mandatory AAA arbitration clause, added in 2019, covers personal injury, wrongful death, discrimination and failure to accommodate; the 488-word clause sits two-thirds into a 15,500-word T&C, a ticket purchase constitutes agreement, and there is no opt-out provision.\nWHY IT MATTERS: Buying a monthly Amtrak pass means waiving the right to sue over a train derailment; Congress has introduced the Ending Passenger Rail Forced Arbitration Act three times (2019, 2021, and May 2026) and none have passed committee, and separately, in May 2025 the AAA itself was sued in federal court for allegedly favoring corporations in its proceedings.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees are not itemized this pass; the breach and arbitration findings are the two substantiated, company-specific items.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Both the breach and the arbitration clause are described with specific figures, dates and clause details.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Amtrak  <-  National Railroad Passenger Corporation (federally chartered, majority US government-owned)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Amtrak you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The April 2026 Amtrak breach was attributed to ShinyHunters - the same group behind the campaign documented as this tracker's biggest connective thread, which reached more than a thousand organisations through social engineering and OAuth abuse rather than any technical exploit. Rail passenger data is distinctive: a booking is a confirmed physical movement between two specific points at a specific time, with a name attached, which is a travel pattern rather than a purchase record. For Mid-Atlantic riders on the Northeast Corridor, that pattern is often a commute, meaning the dataset describes where someone lives and works.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Travel & Transit Apps", "_row_id": 597, "_entity_id": 835, "_entity_slug": "amtrak", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Capital Bikeshare (CaBi)", "Category": "Transit (bikeshare)", "Terms & Conditions URL": "capitalbikeshare.com/terms-of-service (operated by Lyft/Motivate for DC-area jurisdictions)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "capitalbikeshare.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Capital Bikeshare is operated by LYFT/MOTIVATE under contract with area DC/MD/VA governments — see the Lyft row (Consumer Apps tab) for Lyft's broader corporate data practices, which likely extend to CaBi's underlying trip/location data given the same operator.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Lyft's Terms of Service govern Capital Bikeshare (Lyft operates CaBi under contract with DC/Arlington/Alexandria/Montgomery County/Fairfax County). 30-day opt-out via email to legal@lyft.com. A DMV resident using CaBi may not realize they are bound by Lyft's California-based arbitration terms — the bikeshare's local government sponsors do not override the private operator's T&C.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "As a DIRECTLY REGIONAL DMV TRANSIT SERVICE, CaBi trip data (start/end stations, times, routes) is collected on behalf of local governments — worth a direct follow-up on exactly how this government-partnership data-sharing arrangement works given Lyft's operational role.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Lyft, Inc. (operates under contract with DC/Arlington/Alexandria/MoCo/Fairfax)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] CaBi riders assume a DC/MD/VA government program, but Lyft privately holds exact trip records\nWHAT THE TERMS SAY: Capital Bikeshare is operated by Lyft/Motivate under contract with DC, Arlington, Alexandria, Montgomery County and Fairfax County; Lyft collects trip data (start/end stations, times, routes) on the local governments' behalf.\nWHY IT MATTERS: Riders may not realize a private company holds this precise station-to-station data, and local government sponsorship does not override Lyft's own privacy terms.\n(evidence: Data Sharing, Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] CaBi riders are bound by Lyft's arbitration terms, with only a 30-day opt-out via email\nWHAT THE TERMS SAY: Lyft's Terms of Service govern Capital Bikeshare, including mandatory binding arbitration and a class-action waiver, with a 30-day opt-out via email to legal@lyft.com.\nWHY IT MATTERS: A DMV resident using a branded local bikeshare may not realize they're bound by a California-based private operator's arbitration terms unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees are not itemized this pass; the location-data-holder and arbitration findings are the two substantiated, CaBi-specific items.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clear, but exactly how the government-partnership data arrangement works is left to a recommended follow-up.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Capital Bikeshare (CaBi)  <-  Lyft, Inc. (operates under contract with DC/Arlington/Alexandria/MoCo/Fairfax)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Capital Bikeshare (CaBi) you gave up your physical movements, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Capital Bikeshare is publicly branded and operated under contract by Lyft/Motivate, which is the finding: DC, Maryland and Virginia riders reasonably believe they are dealing with a regional government transit programme, and the trip data - every start point, end point and time - is held by a private ride-hailing company. Bikeshare trip records are among the most precise location datasets that exist, because a docked bike gives an exact origin and destination rather than an approximate one. Public-private transit partnerships routinely obscure which entity actually holds the data and which privacy regime applies.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Travel & Transit Apps", "_row_id": 598, "_entity_id": 836, "_entity_slug": "capital-bikeshare-cabi", "_issuer": "Lyft, Inc.", "_issuer_slug": "lyft-inc", "_ticker": "LYFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Orbitz (Expedia Group)", "Category": "Travel Booking", "Terms & Conditions URL": "orbitz.com/p/info-other/termsOfUse", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "orbitz.com/p/info-other/privacyPolicy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "HISTORICAL CONFIRMED BREACH (2018, still relevant precedent): Orbitz (owned by Expedia Group) disclosed a breach potentially affecting 880,000 payment cards used on an older Orbitz platform between 2016-2017 — Orbitz offered affected customers free credit monitoring. No more recent (2025-2026) Orbitz-specific incident independently confirmed this pass.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Governed by Expedia Group ToS (same as the Expedia row). AAA rules, Washington state law. 30-day opt-out via email to arboptout@expedia.com. Orbitz, Hotels.com, Vrbo, Travelocity, and Expedia share one parent and one arbitration clause.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Expedia row (Consumer Apps tab) for the broader Expedia Group corporate practices that likely extend to Orbitz given shared ownership.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Expedia Group, Inc.", "Years Referenced in Finding (heuristic)": "2018", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Orbitz's 2018 breach on a legacy platform potentially affected 880,000 payment cards from 2016-2017\nWHAT THE TERMS SAY: Orbitz, owned by Expedia Group, disclosed a 2018 breach potentially affecting 880,000 payment cards used on an older Orbitz platform between 2016 and 2017; Orbitz offered affected customers free credit monitoring.\nWHY IT MATTERS: The breach illustrates how legacy systems inherited through acquisition can keep running without the engineering attention needed to stay secure; no more recent Orbitz-specific incident is confirmed.\n(evidence: Data Sharing, SCARY; Stated in tracker (fidelity pass 1: Hedge lost corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Orbitz shares Expedia Group's arbitration clause with Hotels.com, Vrbo and Travelocity\nWHAT THE TERMS SAY: Orbitz is governed by Expedia Group's ToS: mandatory binding arbitration under AAA rules and Washington state law, with a 30-day opt-out via arboptout@expedia.com, the same clause covering Hotels.com, Vrbo, Travelocity and Expedia.\nWHY IT MATTERS: One arbitration clause covers five travel brands, so opting out requires proactive action within 30 days of agreeing to any one of them.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees are not itemized this pass; broader Expedia Group corporate practices are only cross-referenced to another row, not independently detailed for Orbitz here.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The breach figures and arbitration clause are both specifically documented.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Orbitz (Expedia Group)  <-  Expedia Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Orbitz (Expedia Group) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2018 Orbitz breach remains the useful precedent because of what it exposed: a legacy booking platform Expedia had acquired, still running, still holding customer payment and travel data. Acquisitions inherit systems, and old systems that no longer receive engineering attention are where breaches live. A consumer booking through a familiar brand has no way to know whether the platform behind it is actively maintained or a legacy asset kept alive for the traffic.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Travel & Transit Apps", "_row_id": 599, "_entity_id": 837, "_entity_slug": "orbitz-expedia-group", "_issuer": "Expedia Group, Inc.", "_issuer_slug": "expedia-group-inc", "_ticker": "EXPE", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "MTA (NYC Subway/Bus)", "Category": "Transit", "Terms & Conditions URL": "new.mta.info/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "new.mta.info/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The MTA's OMNY contactless payment system collects trip-level location/timing data; the MTA's own privacy policy has faced advocacy-group scrutiny (NYCLU and others) over data-retention periods and law-enforcement access procedures for transit records — a similar general concern to WMATA's documented practices (Transit, Tolls & Water tab) though not specifically confirmed as an active lawsuit this pass.", "Arbitration / Class Action Waiver": "Not applicable in the typical consumer-arbitration sense — the MTA is a New York State public authority; disputes go through the MTA's own complaint process or applicable NY state agencies.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the WMATA row (Transit, Tolls & Water tab) for a comparable regional transit-authority privacy analysis — the same general 'registered vs. unregistered card' privacy trade-off may apply to OMNY as well, worth a direct follow-up to confirm.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] OMNY once let anyone with a card number and ZIP code look up a rider's recent trip history\nWHAT THE TERMS SAY: OMNY generates trip-level location and timing records tied to the payment card or device used; a lookup feature allowed anyone with a card number and ZIP code to view recent trip history.\nWHY IT MATTERS: That lookup functioned as a stalking vector rather than an abstract privacy concern, and per the tracker a rider cannot opt out and still ride.\n(evidence: SCARY, Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[RETENTION_PERIOD · FL-2] NYCLU has scrutinized how long the MTA keeps OMNY trip records and how police can access them\nWHAT THE TERMS SAY: The MTA's privacy policy has faced advocacy-group scrutiny, including from the NYCLU, over data-retention periods and law-enforcement access procedures for OMNY transit records, though this is not confirmed as an active lawsuit.\nWHY IT MATTERS: Riders have no visibility into how long their movement records are kept or under what standard police can obtain them, and those standards are rarely published.\n(evidence: Data Sharing, Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No consumer arbitration clause applies since the MTA is a public authority using its own complaint process, and fees aren't itemized; two location/retention findings are substantiated.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The stalking-vector incident is concretely described, but retention and access-standard specifics remain unconfirmed.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent", "Entity Type": "Company", "Ownership Path": "MTA (NYC Subway/Bus)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using MTA (NYC Subway/Bus) you gave up your physical movements. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "OMNY generates trip-level location and timing records tied to whatever payment card or device tapped the reader, and that is a continuous log of a rider's movements through the city. The MTA drew significant criticism when a feature allowed anyone with a card number and ZIP code to look up recent trip history, which is a stalking vector rather than an abstract privacy concern. Transit data is also subject to law enforcement request under standards that vary and are rarely published. A rider cannot opt out and still ride.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Travel & Transit Apps", "_row_id": 600, "_entity_id": 838, "_entity_slug": "mta-nyc-subway-bus", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Bolt (ride-hailing)", "Category": "Rideshare", "Terms & Conditions URL": "bolt.eu/en/legal/terms-of-use-passengers/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "bolt.eu/en/legal/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Bolt (Estonia-based, operating across Europe/Africa) has faced GDPR-related scrutiny in EU jurisdictions over algorithmic decision-making transparency for drivers (a labor-classification/algorithmic-management concern, similar to gig-economy findings for Uber/DoorDash elsewhere in this tracker) — no specific named consumer lawsuit independently confirmed this pass.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Bolt (Tallinn, Estonia) ToS governed by Estonian law. No US-style arbitration clause or class action waiver. Disputes resolved in Estonian courts. Consistent with EU consumer-protection norms.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; Bolt operates primarily outside the US, meaning fewer US-specific findings would be expected relative to Uber/Lyft.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Bolt riders get GDPR protection in some countries and effectively none in others, same app\nWHAT THE TERMS SAY: Bolt operates across Europe and Africa; every trip creates an origin, destination, time and duration record, and Bolt's footprint spans jurisdictions with GDPR enforcement in some countries and minimal enforcement in others.\nWHY IT MATTERS: A rider's practical privacy protection depends entirely on which country they happen to be in, with no consistent baseline across Bolt's markets.\n(evidence: SCARY, Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DISCRIMINATORY_PRACTICE · FL-3] Bolt has faced EU scrutiny over algorithmic transparency toward drivers, a labor-classification issue\nWHAT THE TERMS SAY: Bolt has faced GDPR-related scrutiny in EU jurisdictions over algorithmic decision-making transparency for drivers, similar to gig-economy findings noted for Uber and DoorDash elsewhere in this tracker; no specific named consumer lawsuit is independently confirmed.\nWHY IT MATTERS: This concerns driver-facing algorithmic management rather than confirmed consumer harm, and Bolt-specific consumer findings remain thin.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Bolt affirmatively has no US-style arbitration clause under Estonian/EU consumer-protection norms, which isn't itself a troubling item; the jurisdictional-patchwork and driver-algorithm-scrutiny findings are the two substantiated points.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The no-arbitration fact is clear, but the underlying GDPR scrutiny is described without a confirmed consumer-specific incident.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nPROFILING / PRICING → MD & VA: right to opt out of profiling in furtherance of decisions with legal or similarly significant effects; MD bars processing that discriminates unlawfully", "Entity Type": "Company", "Ownership Path": "Bolt (ride-hailing)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Bolt (ride-hailing) you gave up your physical movements. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Bolt has faced GDPR scrutiny, and the structural note for all ride-hailing in this tracker is that the dataset is categorically more revealing than the service implies: every trip is an origin, a destination, a time and a duration, and a few months of history identifies home, workplace, place of worship, medical providers and relationships without any additional inference. Bolt operates across Europe and Africa, so a single company's practices are governed by radically different enforcement regimes depending on which country a rider is in - GDPR in one, effectively nothing in another, same app.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Travel & Transit Apps", "_row_id": 601, "_entity_id": 839, "_entity_slug": "bolt-ride-hailing", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Bird", "Category": "Micromobility", "Terms & Conditions URL": "bird.co/terms/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "bird.co/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Bird FILED FOR CHAPTER 11 BANKRUPTCY in December 2023 and was later ACQUIRED by a group of former creditors (2024) — a major operational/ownership change worth flagging for anyone with an existing Bird account/payment method on file, given how much ownership and operational continuity can shift during bankruptcy reorganization.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. AAA rules. 30-day opt-out via email to legal@bird.co. Bird filed for Chapter 11 bankruptcy in Dec 2023 and was acquired by a consortium; check whether post-bankruptcy terms differ.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Bird's bankruptcy/restructuring is a significant operational-status change — similar to the Spirit Airlines and QVC Group bankruptcy notes elsewhere in this tracker — recommend verifying current ownership/terms directly given how much can change during this kind of restructuring.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Bird Global, Inc. (post-bankruptcy)", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[TERMINATION_CONFISCATION · FL-4] Bird's bankruptcy turned riders' precise scooter-location data into an asset sold to new owners\nWHAT THE TERMS SAY: Bird filed for Chapter 11 bankruptcy in December 2023 and was acquired by a consortium of former creditors in 2024; customer records, including precise scooter location history, became bankruptcy-estate assets transferred to whoever bought them, under terms customers never agreed to.\nWHY IT MATTERS: The privacy policy a rider originally accepted described a company that no longer exists, and no US consumer protection framework meaningfully constrains what a successor entity may do with acquired personal data.\n(evidence: SCARY, Data Sharing, Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Bird riders face mandatory AAA arbitration with a 30-day opt-out, post-bankruptcy terms unverified\nWHAT THE TERMS SAY: Bird's terms include mandatory binding arbitration under AAA rules with a class-action waiver and a 30-day opt-out via legal@bird.co; the tracker flags that whether post-bankruptcy terms differ from pre-bankruptcy terms has not been checked.\nWHY IT MATTERS: Riders must actively opt out within 30 days or waive court/class rights, and it's unconfirmed whether the terms they're bound by changed after the 2023-2024 restructuring.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees are not itemized this pass; the bankruptcy-data-transfer and arbitration findings are the two substantiated, Bird-specific items.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The bankruptcy/ownership change is well documented, but current post-acquisition terms are not independently verified.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (precise_location_tracking+4) | Contract 4/20 (termination_or_confiscation+4) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Bird  <-  Bird Global, Inc. (post-bankruptcy)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Bird you gave up your physical movements, your right to sue, your right to join a class action, and your right to keep what you paid for. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Bird filed for Chapter 11 in December 2023 and its assets were acquired, which makes this the tracker's cleanest illustration of what happens to your data when a company fails: customer records are assets in a bankruptcy estate, and they transfer to whoever buys them under terms the customer never agreed to and generally never learns. Scooter data is precise location history. The privacy policy a rider accepted described the practices of a company that no longer exists, and no consumer protection framework in the US meaningfully constrains what a successor entity may do with acquired personal data.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Travel & Transit Apps", "_row_id": 602, "_entity_id": 841, "_entity_slug": "bird", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "FlightAware / Flighty", "Category": "Travel Tracking", "Terms & Conditions URL": "flightaware.com/about/termsofuse", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "flightaware.com/about/privacypolicy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach; these apps aggregate PUBLICLY AVAILABLE flight-tracking data (ADS-B transponder signals) rather than collecting significant personal data directly from users beyond standard account/subscription information.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Flighty operates on a paid-subscription model; FlightAware offers both free and paid tiers.", "Notes": "These apps' core data (aircraft positions) is public safety/aviation data, not personal user data — a structurally lower privacy-risk category than most other apps in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Flight trackers aggregate public broadcast data in ways that can reveal users' own travel history\nWHAT THE TERMS SAY: FlightAware and Flighty aggregate publicly broadcast ADS-B transponder data; the tracker notes that aggregation at scale is what creates the capability to reveal movement patterns, and whether user-side travel history is retained or shared is unconfirmed.\nWHY IT MATTERS: The privacy risk here is about aggregation capability rather than raw data collection, and retention/sharing of a user's own travel history is an open question flagged for follow-up.\n(evidence: SCARY, Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data sharing and arbitration fields both say not independently confirmed this pass; only the aggregation-based privacy question is substantive, and it is explicitly flagged as unverified rather than a stated finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed this pass, and even the app's own retention/sharing practices are flagged as an open follow-up.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "FlightAware / Flighty  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, FlightAware / Flighty takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Flight tracking apps occupy an unusual position: much of their source data is public broadcast information from aircraft transponders, so the service is aggregating rather than collecting - but the aggregation is what creates the capability, since public data assembled at scale reveals private-aircraft movement patterns and, for users of the consumer app, their own travel history. Recommend a follow-up on whether user-side travel history is retained and shared. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Travel & Transit Apps", "_row_id": 603, "_entity_id": 842, "_entity_slug": "flightaware-flighty", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Parkmobile", "Category": "Parking", "Terms & Conditions URL": "parkmobile.io/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "parkmobile.io/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MAJOR CONFIRMED BREACH, FULLY SETTLED: ParkMobile (operating in 500+ North American cities, one of the largest parking apps in the US) suffered a 2021 breach where attackers exploited a vulnerability in THIRD-PARTY SOFTWARE to access systems WITHOUT needing to crack password encryption directly — exposing email addresses, phone numbers, LICENSE PLATE NUMBERS, hashed passwords, and mailing addresses for over 20 MILLION USERS, with the data subsequently listed for sale on a Russian cybercrime forum. ParkMobile settled the resulting class action for $32.8 MILLION, with an estimated 21 MILLION people eligible for payment (claims deadline March 5, 2025) — the lawsuit specifically alleged ParkMobile's security fell short of FTC-recommended standards and called the company's privacy approach 'reckless, or at the very least, negligent,' given how well-documented similar third-party-software breach risks already were at the time.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The LICENSE PLATE NUMBER exposure is a distinctive risk category worth flagging — combined with a physical mailing address, this creates a meaningful stalking/harassment risk beyond typical email/password exposure, since a license plate can be used to physically locate/track a specific vehicle.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] ParkMobile's 2021 breach exposed license plates and addresses for 20M+ users, settled for $32.8M\nWHAT THE TERMS SAY: Attackers exploited a third-party software vulnerability to access ParkMobile's systems, exposing emails, phone numbers, license plate numbers, hashed passwords and mailing addresses for over 20 million users, later listed for sale on a Russian cybercrime forum; ParkMobile settled the resulting class action for $32.8 million, with roughly 21 million people eligible for payment, and the suit called the company's security practices 'reckless, or at the very least, negligent.'\nWHY IT MATTERS: License plate numbers combined with mailing addresses create a meaningful stalking/harassment risk beyond typical credential exposure, and municipal parking is often the only payment option, making the app functionally compulsory.\n(evidence: Data Sharing, SCARY, Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fees fields both say not independently confirmed this pass; the fully-settled breach is the only substantiated finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The breach, its scope, and the resulting settlement are all specifically documented and fully resolved.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Parkmobile  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Parkmobile takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The ParkMobile breach is fully settled and remains instructive because of who was exposed: a parking payment app operating in 500+ North American cities holds vehicle plate numbers tied to names, payment cards and precise parking locations and times. That combination is a vehicle movement history, and plate-to-identity linkage is exactly the join that automated licence plate reader networks otherwise have to work to achieve. Municipal parking is also functionally compulsory - in many cities the app is the only payment method at the meter.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Travel & Transit Apps", "_row_id": 604, "_entity_id": 843, "_entity_slug": "parkmobile", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "FedEx", "Category": "Shipping", "Terms & Conditions URL": "fedex.com/en-us/trust-center/terms-conditions.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "fedex.com/en-us/trust-center/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "FedEx processes shipping, tracking, and customs data globally. FedEx Dataworks is FedEx's data-analytics platform processing 19B+ transactions per day. FedEx SenseAware provides real-time package condition monitoring (temperature, light exposure, humidity).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. FedEx Service Guide and fedex.com ToS. 30-day opt-out. Covers FedEx Express, FedEx Ground, FedEx Freight, and FedEx Office. FedEx's Service Guide is the contract of carriage for all packages.", "Fees / Billing Flags": "Not itemized this pass beyond the above.", "Notes": "FedEx's 166-million-record Salesforce breach is a useful data point on just how LARGE the 2025 Salesforce/CRM attack wave truly was across the whole economy — worth cross-referencing with the Air France/KLM row (Global Airlines tab) for the fullest treatment of this shared vendor-platform vulnerability.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$94.7B", "Market Cap": "$75.9B", "Employees": "422,100", "HQ City": "Memphis", "HQ State": "Tennessee", "CEO": "Rajesh Subramaniam", "Ticker": "FDX", "Website (Corporate)": "fedex.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (FDX). Service route: c/o General Counsel / Corporate Secretary, Memphis, Tennessee — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Tennessee' is a non-DMV US state", "Parent / Ultimate Owner": "FedEx Corporation", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Tennessee SOS Business Search — tnbear.tn.gov/Ecommerce/FilingSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: FedEx Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] FedEx's 2025 breach exposed 166M records through a Salesforce vendor chain, not a FedEx exploit\nWHAT THE TERMS SAY: FedEx had a 166-million-record breach tied to the broader 2025 Salesforce/CRM attack wave; attackers reached FedEx-linked systems through vishing and stolen OAuth tokens against vendors rather than any exploit against FedEx itself. Shipping data (sender, recipient, address, timing, contents category) maps relationships and household composition.\nWHY IT MATTERS: A FedEx customer who never heard of the vendors involved had their address exposed through a vendor relationship chain three companies deep.\n(evidence: Notes, SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] FedEx's arbitration clause with a 30-day opt-out covers Express, Ground, Freight and Office\nWHAT THE TERMS SAY: FedEx's Service Guide and fedex.com ToS include mandatory binding arbitration with a class-action waiver and a 30-day opt-out, covering FedEx Express, Ground, Freight and Office as a single contract of carriage.\nWHY IT MATTERS: One arbitration clause spans FedEx's entire consumer-facing shipping business, and customers must opt out within 30 days to preserve court access.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees are not itemized beyond a general note; the breach and arbitration findings are the two substantiated items.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The breach's scale and cause, and the arbitration clause's scope, are both specifically documented.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "FedEx  <-  FedEx Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using FedEx you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2025 FedEx exposure was Salesforce-related, which places it inside the campaign documented in the F500 Tech & Semiconductors tab: attackers reached more than a thousand organisations through vishing and stolen OAuth tokens rather than any exploit against FedEx itself. Shipping data is quietly revealing - sender, recipient, address, timing and often contents category - and it maps relationships and household composition directly. A customer who has never heard of Salesloft or Gainsight had their address exposed by a chain of vendor relationships three companies deep.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Travel & Transit Apps", "_row_id": 605, "_entity_id": 845, "_entity_slug": "fedex", "_issuer": "FedEx Corporation", "_issuer_slug": "fedex-corporation", "_ticker": "FDX", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Western Union", "Category": "Money Transfer", "Terms & Conditions URL": "westernunion.com/us/en/legal/global-tos.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "westernunion.com/us/en/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MAJOR, ONGOING PRIVACY-SHARING LAWSUIT: a proposed class action alleges Western Union (and competitor MoneyGram) UNLAWFULLY SHARED customers' protected financial information with HUNDREDS OF LAW ENFORCEMENT AGENCIES over the past decade — specifically through a program coordinated by the 'Transaction Record Analysis Center,' bypassing the court orders, subpoenas, or warrants that would normally be required, and WITHOUT customers' knowledge or consent. A related, ONGOING federal lawsuit (filed Dec 2022) specifically names the US Department of Homeland Security and ICE as co-defendants, alleging violations of the federal Right to Financial Privacy Act and California's Financial Information Privacy Act — the amended complaint substitutes Western Union Financial Services specifically as the named defendant.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "MASSIVE COMPLETED DOJ SETTLEMENT (originally $586 MILLION, 2017): Western Union ADMITTED to violating the Bank Secrecy Act and anti-fraud statutes by processing hundreds of thousands of transactions tied to an INTERNATIONAL CONSUMER FRAUD OPERATION — including grandparent scams, lottery/sweepstakes schemes, and romance scams — facilitated through its own AGENT NETWORK. The settlement has been REOPENED multiple times (a 'Phase 3' expansion, deadline Aug 19, 2026) to cover additional victims whose fraudulent transactions occurred between 2004-2020; over $430 million has been distributed to 178,000+ victims to date. SEPARATE, UNRELATED INTERNATIONAL JUDGMENT: courts in the Democratic Republic of Congo found Western Union liable for approximately $22.4 MILLION combined in privacy-rights violations brought by DRC government officials (2018-2019 judgments), which Western Union continues to contest.", "Notes": "Western Union is one of the FEW companies in this entire tracker where the underlying business model itself (facilitating cash transfers with minimal identity verification through an agent network) has been directly implicated in FACILITATING FRAUD AGAINST ITS OWN CUSTOMERS at massive scale — the $586M settlement is one of the largest fraud-facilitation penalties in this whole tracker, distinct from the more common 'company failed to protect stored data' pattern seen elsewhere.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] A pending suit alleges Western Union fed customer data to hundreds of police agencies, no warrant\nWHAT THE TERMS SAY: A proposed class action alleges Western Union (and MoneyGram) unlawfully shared customers' protected financial information with hundreds of law enforcement agencies via a program coordinated by the 'Transaction Record Analysis Center,' bypassing the court orders, subpoenas or warrants normally required, without customer knowledge or consent; a related ongoing federal suit filed in December 2022 names DHS and ICE as co-defendants and alleges violations of the federal Right to Financial Privacy Act and California's Financial Information Privacy Act, with an amended complaint substituting Western Union Financial Services as the named defendant.\nWHY IT MATTERS: Remittance customers are disproportionately immigrants supporting family abroad, so the transaction data allegedly shared maps a family network across borders in a context with obvious sensitivity given immigration enforcement; these are allegations, not findings.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-1] Western Union paid $586M after admitting it processed scam transactions through its own agent network\nWHAT THE TERMS SAY: Western Union admitted to violating the Bank Secrecy Act and anti-fraud statutes by processing transactions tied to grandparent, lottery and romance scams through its own agent network; the 2017 DOJ settlement has been reopened multiple times, including a 'Phase 3' expansion with an August 19, 2026 deadline, covering victims from 2004-2020, and over $430 million has been distributed to 178,000+ victims to date.\nWHY IT MATTERS: Unlike a typical 'failed to protect stored data' breach, this is fraud facilitated against Western Union's own customers at massive scale through its minimal-verification agent network.\n(evidence: Fees, Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[PENDING_LITIGATION · FL-3] Congo courts found Western Union liable for ~$22.4M in privacy-rights violations, still contested\nWHAT THE TERMS SAY: Courts in the Democratic Republic of Congo issued 2018-2019 judgments totaling approximately $22.4 million against Western Union for privacy-rights violations brought by DRC government officials, which Western Union continues to contest.\nWHY IT MATTERS: This is a separate, unresolved foreign privacy-judgment exposure distinct from the US regulatory settlement, and it remains contested.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The DOJ settlement is fully documented, but the law-enforcement data-sharing claims remain allegations.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Western Union  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Western Union takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The proposed class action over data sharing matters more than its size suggests because of who uses money transfer services: remittance customers are disproportionately immigrants supporting family abroad, and the transaction record maps a family across borders - names, locations, amounts and frequency. That dataset has obvious value to advertisers and obvious sensitivity given immigration enforcement. Money transfer is also a regulated space with mandatory reporting obligations that customers are rarely told about at the counter. Allegations, not findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Travel & Transit Apps", "_row_id": 606, "_entity_id": 846, "_entity_slug": "western-union", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Grab", "Category": "Rideshare (SE Asia)", "Terms & Conditions URL": "grab.com/sg/terms-of-service/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "grab.com/sg/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "REPEAT-OFFENDER PATTERN: Grab's ride-hailing subsidiary GrabCar was fined by Singapore's Personal Data Protection Commission for a data breach — notably the FOURTH SEPARATE privacy-related fine issued against Grab entities by Singapore regulators, though individual fine amounts have been relatively modest (e.g., SG$10,000/~US$7,300 for the most recent one referenced). The pattern of repeated violations, rather than any single incident's severity, is the more notable finding here.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected; governed primarily by Singapore's Personal Data Protection Act (PDPA) given Grab's Singapore headquarters, rather than US consumer-protection frameworks.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The FOUR-TIME REPEAT VIOLATION pattern (even at modest individual fine amounts) is worth flagging as a distinct concern from a single severe incident — it suggests a persistent, unresolved gap in Grab's data-protection practices rather than an isolated lapse.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-2] Singapore regulators have fined Grab entities four times; the latest fine hit GrabCar\nWHAT THE TERMS SAY: GrabCar was fined by Singapore's Personal Data Protection Commission for a data breach, the fourth separate privacy-related fine issued against Grab entities, with the most recent penalty around SG$10,000 (~US$7,300).\nWHY IT MATTERS: Repeated fines at modest individual amounts suggest the penalties are being absorbed as a cost of doing business rather than driving a fix, and Grab's superapp model combines ride-hailing, delivery and payments into one aggregate user profile.\n(evidence: Data Sharing, SCARY, Notes; Stated in tracker (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fees fields both say not independently confirmed this pass (Grab is governed by Singapore's PDPA rather than US arbitration); the repeat-fine pattern is the only well-substantiated finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The repeat-fine pattern is documented, but individual incident details and consumer-facing terms remain thin.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity3+8, breach+3, penalty+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Grab  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Grab takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Grab shows a repeat-offender pattern rather than a single incident - its GrabCar subsidiary was fined by Singapore's regulator, and repeat penalties are a different signal from a one-off breach because they indicate the fine was absorbed as a cost rather than treated as a correction. Grab is a superapp combining ride-hailing, food delivery, payments and financial services, so the profile it holds is movement plus consumption plus financial behaviour in one account. Superapps make the aggregate profile invisible by design: the user experiences separate features and the company holds one record.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Travel & Transit Apps", "_row_id": 607, "_entity_id": 847, "_entity_slug": "grab", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Gojek", "Category": "Rideshare (Indonesia)", "Terms & Conditions URL": "gojek.com/en-id/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "gojek.com/en-id/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach; Gojek operates as a Southeast Asian 'super-app' (ride-hailing, food delivery, digital payments via GoPay) similar in scope to Grab (this same tab), meaning it collects an unusually broad range of integrated personal/financial/location data across multiple service categories within one app.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass; governed primarily by Indonesian data protection law.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "As a 'super-app' combining transport, delivery, AND payments in one integrated platform, Gojek's data collection is structurally broader than single-purpose apps — recommend a direct follow-up given thin US-focused verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-2] Gojek's superapp combines transport, delivery and payment data under an untested Indonesian privacy law\nWHAT THE TERMS SAY: Gojek is Indonesia's superapp equivalent to Grab, combining transport, delivery, payments and financial services in one identity; Indonesia's Personal Data Protection Law is recent, with a largely untested enforcement record against a national technology champion.\nWHY IT MATTERS: A null result here reflects the immaturity of the regulatory regime rather than demonstrated good practice; the tracker recommends a follow-up in Indonesian-language sources.\n(evidence: SCARY, Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data sharing, arbitration and fees all say not independently confirmed this pass; only the untested-regulatory-regime structural point is stated, explicitly marked unverified rather than clean.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed this pass, and the row itself attributes the null result to an untested enforcement regime.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Gojek  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Gojek takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Gojek is the Indonesian superapp equivalent to Grab, and the same combined-profile analysis applies - transport, delivery, payments and financial services in one identity. Indonesia's Personal Data Protection Law is recent and its enforcement record against a national technology champion is largely untested, so a null result here reflects the maturity of the regime rather than demonstrated good practice. Unverified rather than clean; recommend a follow-up in Indonesian-language sources.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Travel & Transit Apps", "_row_id": 608, "_entity_id": 848, "_entity_slug": "gojek", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Wise (formerly TransferWise)", "Category": "Money Transfer", "Terms & Conditions URL": "wise.com/us/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "wise.com/us/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named recent data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected; as a UK-headquartered, publicly-traded (LSE) company, Wise is primarily regulated under UK/EU financial and data-protection law (GDPR) with additional US state money-transmitter licensing.", "Fees / Billing Flags": "Wise publishes periodic 'fee review' updates (e.g., Dec 2025) adjusting transfer costs across different currency routes — a relatively transparent fee-disclosure practice compared to some other money-transfer competitors, though specific route fees can still vary significantly.", "Notes": "Recommend a direct follow-up given thin verification this pass; Wise's core value proposition (transparent, low-cost currency transfers) is generally well-regarded relative to traditional bank wire transfers and remittance services like Western Union (this same tab).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Data sharing, arbitration and breach fields all say not independently confirmed this pass; the one specific point noted (AML-driven retention of passports and proof-of-address documents) is presented in the tracker as explanatory/mitigating context rather than a stated troubling practice, and retention periods or access rules aren't detailed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing recent is confirmed, and the tracker explicitly frames the one specific fact as regulatory compliance rather than a concern.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Wise (formerly TransferWise)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Wise (formerly TransferWise) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing recent confirmed this pass. Wise holds cross-border payment records and identity verification documents - passports, proof of address, source-of-funds evidence - collected under anti-money-laundering obligations rather than for any commercial purpose, which means the most sensitive material it holds is material regulators required it to collect. That is worth naming because customers often read onerous verification as the company being nosy when it is the company being compliant, and the retention periods for AML documentation are set by statute rather than by preference.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Travel & Transit Apps", "_row_id": 609, "_entity_id": 849, "_entity_slug": "wise-formerly-transferwise", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Airalo", "Category": "eSIM/Travel", "Terms & Conditions URL": "airalo.com/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "airalo.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach; as an eSIM provider, Airalo necessarily processes location/roaming data tied to international travel patterns.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Airalo's eSIM purchase records function as a travel itinerary of country and activation date\nWHAT THE TERMS SAY: Airalo sells eSIMs for international travel; the purchase and activation record shows which country a user is in and when, and connectivity is delivered by local carrier partners in each country under that country's own surveillance and data-retention rules, which the traveler is never shown by name.\nWHY IT MATTERS: Itinerary-like purchase data combined with undisclosed carrier-partner jurisdictions means a traveler's data protections vary silently depending on destination.\n(evidence: SCARY, Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data sharing, arbitration and fees fields all say not independently confirmed this pass; only the itinerary/carrier-partner structural point is stated, and it is explicitly flagged as unverified.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed this pass, and the carrier-partner disclosure gap is flagged for follow-up rather than resolved.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Airalo  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Airalo takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Airalo sells eSIMs for international travel, which places it in an interesting position: an eSIM provider sees which country you are in and when you activated service there, so the purchase record is a travel itinerary. The underlying connectivity is also delivered by local carrier partners in each country, each operating under its own jurisdiction's surveillance and data retention rules - which the traveller never sees named. Recommend a follow-up on carrier partner disclosure.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Travel & Transit Apps", "_row_id": 610, "_entity_id": 850, "_entity_slug": "airalo", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "iVisa", "Category": "Travel/Visa Services", "Terms & Conditions URL": "ivisa.com/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "ivisa.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "As a THIRD-PARTY VISA/travel-document processing service, iVisa collects highly sensitive identity documents (passport scans, government ID numbers) on behalf of customers applying for visas/travel authorizations — a genuinely high-sensitivity data category given the combination of passport-level identity documents processed by a private intermediary rather than directly by a government agency. No specific named lawsuit or breach independently confirmed this pass.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "iVisa charges a SERVICE FEE on top of official government visa/ESTA fees — worth being aware that using iVisa (a private intermediary) typically costs more than applying directly through the relevant government's official visa portal.", "Notes": "The combination of passport-level identity documents processed by a PRIVATE THIRD PARTY (rather than a government agency directly) is a distinctive risk category worth flagging — recommend a direct follow-up on iVisa's specific data-retention and security practices given the sensitivity involved.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$40.0B", "Market Cap": "$667.7B", "Employees": "31,600", "HQ City": "San Francisco", "HQ State": "California", "CEO": "Ryan McInerney", "Ticker": "V", "Website (Corporate)": "visa.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (V). Service route: c/o General Counsel / Corporate Secretary, San Francisco, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] iVisa, a private intermediary, collects passport-level identity documents for visa processing\nWHAT THE TERMS SAY: iVisa collects passport scans and government ID numbers, and per the tracker's SCARY note may also gather birth certificates, financial statements, employment letters, travel history and often biometric photographs when processing visa/travel-document applications.\nWHY IT MATTERS: Users hand highly sensitive identity documents to a private intermediary rather than a government agency, often at a moment of travel urgency, and no lawsuit or breach has been confirmed but retention/security practices remain unverified.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Arbitration terms are presumed standard for iVisa but not independently confirmed\nWHAT THE TERMS SAY: The tracker did not independently confirm iVisa's arbitration terms this pass, noting only that standard binding arbitration plus a class-action waiver is expected.\nWHY IT MATTERS: If confirmed, this would route disputes over document handling into individual arbitration rather than court, but this remains unverified.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two items are supported by the text: the stated identity-document collection and the unconfirmed-but-presumed arbitration terms. The service-fee markup is disclosed but is a commercial note, not a distinct clause-level harm.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Most fields state findings were not independently confirmed this pass, with only the identity-document collection itself stated as fact.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 9/30 (biometric_collection+6, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "iVisa  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using iVisa you gave up your biometric identifiers. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A third-party visa and travel document processing service collects the most sensitive identity dossier in this entire tab: passport scans, birth certificates, financial statements, employment letters, travel history and often biometric photographs, assembled specifically because a government demanded them. Users hand it over at a moment of urgency and dependency, since the alternative is missing a trip. The company is an intermediary, not a government body, and the consumer is generally unclear on that distinction. Nothing confirmed this pass - the concentration of identity documents is the finding, and it warrants a direct follow-up on retention.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Travel & Transit Apps", "_row_id": 611, "_entity_id": 851, "_entity_slug": "ivisa", "_issuer": "iVisa", "_issuer_slug": "ivisa", "_ticker": "V", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Transit App", "Category": "Transit Tracker", "Terms & Conditions URL": "transitapp.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "transitapp.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach; Transit App aggregates public transit schedule/real-time data across many cities (including DMV-area WMATA data) rather than operating its own transit system.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Transit App requires location access, producing a continuous record of user movement\nWHAT THE TERMS SAY: Transit App aggregates real-time public transit data and requires location access to be useful, which the tracker states produces a continuous record of a user's movement through a city.\nWHY IT MATTERS: Continuous location access creates a movement record even though nothing about misuse of that data is confirmed this pass.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one substantive item is supported: the location-access requirement. Arbitration, fees, and data-sharing are all explicitly unconfirmed, and the app's favorable positioning against the location-data-broker model (contrasted with the Allstate/Arity finding in another tab) is context about another company's practice, not a finding about Transit App.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nearly every field is explicitly unconfirmed this pass; only the location-access requirement is stated as fact.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent", "Entity Type": "Company", "Ownership Path": "Transit App  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Transit App you gave up your physical movements. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Transit App aggregates real-time public transportation data and requires location access to be useful, which produces a continuous record of a user's movement through a city. The favourable structural note worth recording: Transit has publicly positioned itself against the location-data-broker model that the Allstate/Arity finding in the Insurance tab documents, where SDK vendors paid app developers to embed tracking code. Recommend verifying that positioning against the app's current SDK inventory before relying on it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Travel & Transit Apps", "_row_id": 612, "_entity_id": 852, "_entity_slug": "transit-app", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Amazon One", "Category": "Biometric Payment", "Terms & Conditions URL": "one.amazon.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "one.amazon.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Amazon One uses PALM-RECOGNITION BIOMETRIC scanning for payment/identity verification, deployed across Whole Foods (see that row, Consumer Apps tab) and other retail/venue partners — a genuinely novel biometric-payment category distinct from facial recognition. Amazon's OWN privacy materials state palm data is encrypted and stored separately from other Amazon account data, though privacy advocates have raised general concerns about biometric payment systems' long-term data-retention and third-party-venue-sharing practices (Amazon One is also deployed at some sports stadiums/venues, expanding its footprint beyond Amazon's own stores).", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Amazon One is an Amazon subsidiary governed by Amazon's Conditions of Use, which removed the arbitration clause entirely in July 2021. However, the Amazon One palm-recognition system collects IRREVERSIBLE biometric data (palm-vein patterns cannot be changed like a password). The absence of an arbitration clause means disputes over biometric data handling can go to court — but also means Amazon One users have MORE legal recourse than users of competing biometric systems.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Whole Foods row (Consumer Apps tab) for the settled BIPA precedent context that may inform how Amazon One's biometric collection is treated under state biometric privacy laws going forward.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$716.9B", "Market Cap": "$2.6T", "Employees": "1,556,000", "HQ City": "Seattle", "HQ State": "Washington", "CEO": "Andrew R. Jassy", "Ticker": "AMZN", "Website (Corporate)": "amazon.com", "Main Mailing Address (legal/privacy notices)": "Amazon.com, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210, USA", "Legal / Privacy Contact Email": "Not verified this pass — Amazon routes privacy requests through its in-account privacy portal", "Finding Type": "Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AMZN). Service route: c/o General Counsel / Corporate Secretary, Seattle, Washington — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Pending - severity 4/5, no source yet", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Amazon.com, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Amazon.com, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] Amazon One collects irreversible palm-vein biometric data, often enrolled under queue pressure\nWHAT THE TERMS SAY: Amazon One uses palm-recognition biometric scanning for payment/ID verification at Whole Foods, stadiums, airports and other venues; palm-vein patterns are described as permanent, unlike a password, and enrollment is typically offered as a convenience when a queue is long.\nWHY IT MATTERS: Illinois BIPA has produced settlements in the hundreds of millions for facial/fingerprint biometrics, and Texas CUBI produced $1.4 billion from Meta and $1.375 billion from Google in unrelated cases -- showing this is a category with demonstrated legal exposure and no recovery mechanism for the consumer if a biometric template is ever compromised.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[RETENTION_PERIOD · FL-2] Privacy advocates flag unclear retention as Amazon One expands to third-party venues\nWHAT THE TERMS SAY: Amazon states palm data is encrypted and stored separately from other Amazon account data, but privacy advocates have raised general concerns about long-term retention and third-party-venue-sharing practices as Amazon One expands into stadiums and other venues beyond Amazon's own stores.\nWHY IT MATTERS: As enrollment spreads to venues outside Amazon's direct control, it becomes less clear how long palm data is retained or whether third-party venues have their own access.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two company-specific harms are stated. The absence of an arbitration clause is presented as a consumer benefit rather than a troubling term, and the BIPA/CUBI settlement figures cited belong to Meta and Google, not Amazon, so they are cited only as legal-exposure context.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration status and the biometric collection itself are clearly stated, but data retention and third-party-venue sharing remain general concerns rather than confirmed specifics.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 6/30 (biometric_collection+6) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "Amazon One  <-  Amazon.com, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Amazon One you gave up your biometric identifiers. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Amazon One is palm-recognition biometric payment, and palm vein geometry is permanent in a way no credential should be - you cannot reissue a hand. Amazon One readers are deployed in stadiums, airports and retail, environments where enrolment is offered as a convenience at a moment when the queue is long. Illinois BIPA has produced settlements in the hundreds of millions over facial and fingerprint data, and Texas CUBI produced $1.4 billion from Meta and $1.375 billion from Google - so this is a category with demonstrated legal exposure and, for the consumer, no recovery mechanism if the template is ever compromised.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Travel & Transit Apps", "_row_id": 613, "_entity_id": 853, "_entity_slug": "amazon-one", "_issuer": "Amazon.com, Inc.", "_issuer_slug": "amazon-com-inc", "_ticker": "AMZN", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Insight Timer", "Category": "Meditation", "Terms & Conditions URL": "insighttimer.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "insighttimer.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same GENERAL MEDITATION-APP DATA-SHARING RISK CATEGORY documented for Calm and Headspace elsewhere in this tracker (Consumer Apps tab): independent research (Mozilla Foundation) has found meditation apps broadly collect mood/emotional-state data, in-app messages, and usage patterns that can reveal mental health status, often sharing this with advertisers/analytics partners. No Insight Timer-specific lawsuit independently confirmed this pass.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Insight Timer (Melbourne, Australia) ToS governed by Australian law. No US-style arbitration clause. Australian Consumer Law provides statutory protections that override contract terms.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Calm/Headspace rows (Consumer Apps tab) for the fullest treatment of this shared meditation-app-industry data-sharing risk pattern.\n\nMOZILLA *PRIVACY NOT INCLUDED CROSS-REFERENCE (verified this pass - the spine for every row in this tab): Mozilla's 2022 investigation reviewed 32 mental health and prayer apps and gave 29 of them the *Privacy Not Included warning label, with researchers stating that mental health apps were 'worse than any other product category' they had assessed for privacy and security. Specific findings: Cerebral set a record with 799 trackers firing within the first minute after download; Talkspace, Happify and BetterHelp pushed users into intake questionnaires BEFORE presenting a privacy policy or asking consent; Talkspace's policy permitted using inferences drawn from that questionnaire - covering gender identity, sexual orientation and depression indicators - for marketing and tailored advertising. Talkspace publicly disputed Mozilla's characterisation and said the report lacked its input and contained inaccuracies. In the 2023 follow-up, only 2 of 27 apps met Mozilla's standards: PTSD Coach (built by the US Department of Veterans Affairs) and Wysa. REGULATORY ANCHOR: FTC settled with BetterHelp for $7.8 million on March 2 2023 - the complaint alleged BetterHelp promised not to share health data and then disclosed email addresses, IP addresses and health questionnaire responses to Facebook, Snapchat, Criteo and Pinterest for advertising. The order BANS BetterHelp from sharing consumer health data for advertising. Cerebral separately acknowledged exposing patient names, birth dates, insurance information and mental health self-evaluation responses to Google, Meta, TikTok and other advertisers. STRUCTURAL POINT: most of these apps are not HIPAA covered entities, so the sensitivity of the data is inversely related to the protection it receives.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Melbourne", "HQ State": "Australia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ in Melbourne, Australia (non-US)", "Parent / Ultimate Owner": "Insight Network Inc. (Melbourne, Australia)", "Years Referenced in Finding (heuristic)": "2022", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Australia) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Australia. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] As a meditation app, Insight Timer's usage patterns can reveal sleep and emotional state\nWHAT THE TERMS SAY: The tracker notes that meditation apps generally reveal sensitive inferences through usage -- session timing correlates with sleep/anxiety patterns and course selection reveals what a user is struggling with -- framed as a category-level point rather than an Insight Timer-specific confirmed finding.\nWHY IT MATTERS: Even without a confirmed Insight Timer-specific incident, this usage pattern is inherently revealing, and Mozilla's 2022 review found the mental-health/meditation app category broadly failed privacy standards (a category-wide finding, not specific to Insight Timer).\n(evidence: SCARY | Notes; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No Insight Timer-specific lawsuit, breach, or clause was confirmed this pass; the Mozilla, FTC-BetterHelp, and Cerebral findings referenced in Notes belong to other companies and are cited only as category context, not findings about Insight Timer. Arbitration is confirmed absent, which is favorable rather than troubling.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No Insight Timer-specific data-sharing, breach, or lawsuit was confirmed; only industry-wide meditation-app context and category research are available.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Insight Timer  <-  Insight Network Inc. (Melbourne, Australia)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Insight Timer takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Mozilla's 2022 review of 32 mental health and prayer apps gave the warning label to 29 of them and concluded the category was 'worse than any other product category' for privacy and security - and that is the honest frame for this row rather than any Insight Timer-specific finding, of which none was confirmed. What a meditation app knows is unusual: session timing reveals sleep and anxiety patterns, and course selection reveals what a person is struggling with, because nobody starts a grief course casually. Most of these apps are not HIPAA covered entities, so the sensitivity of the data is inversely related to the protection it receives.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 614, "_entity_id": 855, "_entity_slug": "insight-timer", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Smiling Mind", "Category": "Meditation", "Terms & Conditions URL": "smilingmind.com/terms (approximate; not independently confirmed as exact URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "smilingmind.com/privacy (approximate; not independently confirmed as exact URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach. An AUSTRALIAN NONPROFIT (not-for-profit) meditation app, a notably different ownership/incentive structure than most for-profit competitors in this category.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Smiling Mind (Melbourne, Australia) is a registered Australian nonprofit. ToS governed by Australian law. No US-style arbitration clause. Australian Consumer Law protections apply.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see Calm/Headspace rows (Consumer Apps tab) for the general wellness-app data-sharing risk pattern likely applicable across this whole category.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Melbourne", "HQ State": "Australia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Melbourne, Australia (non-US)", "Parent / Ultimate Owner": "Smiling Mind (Australian nonprofit)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Australia) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Australia. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] Smiling Mind is deployed in schools, where children use it without personal consent\nWHAT THE TERMS SAY: The tracker notes Smiling Mind is distributed largely into schools; when a teacher assigns the app, children using it have not chosen anything themselves, and the consent question runs through the institution rather than the family.\nWHY IT MATTERS: Students may generate usage data through an app they were required to use, without the individualized consent that would normally apply to a personal wellness app.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No lawsuit, breach, or data-sharing clause is confirmed for Smiling Mind; the only company-specific concern the tracker raises is the institutional (school-assigned) consent structure. Its nonprofit/no-ad model and absence of arbitration are noted as favorable, not troubling.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data-sharing and legal findings are unconfirmed; the only stated concern is the institutional consent structure for school-deployed use.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Smiling Mind  <-  Smiling Mind (Australian nonprofit)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Smiling Mind takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass, and the structural note is favourable: Smiling Mind is an Australian non-profit distributing free mindfulness programmes, largely into schools, with no advertising model. Per the project guide's instruction to say so when a company looks better than peers, that is a materially different incentive structure from the commercial apps Mozilla flagged. The countervailing note is the school deployment itself - children using an app because a teacher assigned it have not chosen anything, and the consent question runs through the institution rather than the family.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 615, "_entity_id": 856, "_entity_slug": "smiling-mind", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "UCLA Mindful", "Category": "Meditation", "Terms & Conditions URL": "uclamindful.com/terms (approximate; not independently confirmed as exact URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "uclamindful.com/privacy (approximate; not independently confirmed as exact URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach. Developed by UCLA's Mindful Awareness Research Center as a FREE, university-affiliated app — a nonprofit/academic structure distinct from commercial competitors.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — UCLA Mindful is a research program of the University of California, Los Angeles (a public university). Governed by UC system policies and California state sovereign-immunity principles. No US-style commercial arbitration clause — public universities are not private companies.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see Calm/Headspace rows (Consumer Apps tab) for the general wellness-app data-sharing risk pattern likely applicable across this whole category.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Los Angeles", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "UCLA Semel Institute (University of California)", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: UCLA Semel Institute (University of California)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — No lawsuit, breach, or troubling clause is confirmed or stated for UCLA Mindful; the entry is entirely favorable context (free, university-affiliated, non-commercial, no arbitration clause) with no negative finding to report this pass.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No terms-specific findings were confirmed; only favorable non-commercial context is available.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "UCLA Mindful  <-  UCLA Semel Institute (University of California)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, UCLA Mindful takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. UCLA Mindful is produced by a university health centre and distributed free, which places it in the same non-commercial category as the two apps that actually passed Mozilla's 2023 assessment - PTSD Coach from the Department of Veterans Affairs and Wysa. The pattern across the wellness category is consistent enough to be the finding: the apps with no monetisation requirement are the ones handling data responsibly, which suggests the problem is the business model rather than the technology.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 616, "_entity_id": 858, "_entity_slug": "ucla-mindful", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Rise Sleep", "Category": "Sleep Tracking", "Terms & Conditions URL": "risesleep.com/terms (approximate; not independently confirmed as exact URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "risesleep.com/privacy (approximate; not independently confirmed as exact URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach. Collects detailed sleep-pattern and circadian-rhythm data; same general health-data-sharing risk category as other wellness apps in this tab.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. Rise Science Inc. ToS, AAA rules, New York law. Rise tracks sleep debt, circadian rhythm, and daily energy levels — the arbitration clause covers disputes over how this sleep-behavior data is used and shared.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see Calm/Headspace rows (Consumer Apps tab) for the general wellness-app data-sharing risk pattern likely applicable across this whole category.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Rise Sleep mandates binding arbitration with a class-action waiver, 30-day opt-out\nWHAT THE TERMS SAY: Rise Science Inc.'s ToS mandates binding arbitration under AAA rules and New York law, with a class-action waiver and a 30-day opt-out window; the clause explicitly covers disputes over how Rise's sleep-debt, circadian-rhythm and energy-level data is used and shared.\nWHY IT MATTERS: Users lose the ability to sue collectively or in court over misuse of their sleep-behavior data unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Rise Sleep's continuous data shows when and where a user is unconscious\nWHAT THE TERMS SAY: Rise collects sleep debt, circadian rhythm, and daily energy-level data continuously, producing a record of when a person is unconscious and, implicitly, where.\nWHY IT MATTERS: Sleep-disruption patterns are clinically meaningful and can correlate with conditions the user hasn't disclosed to anyone; for context, a federal appeals court found comparable inferences from utility smart-meter data constitutionally significant in an unrelated case documented elsewhere in this tracker (Power Utilities tab).\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two company-specific findings are stated: the mandatory arbitration clause and the nature of continuous sleep data. Data-sharing specifics remain unconfirmed and are only referenced as a shared industry risk category.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated, but data-sharing specifics for Rise Sleep itself remain unconfirmed.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Rise Sleep  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Rise Sleep you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Sleep tracking produces a continuous record of when a person is unconscious and where, which is both health data and an occupancy signal - the same category of inference the Seventh Circuit found constitutionally significant in the smart-meter case documented in the Power Utilities tab. Sleep disruption patterns are also clinically meaningful, correlating with conditions a user has not disclosed to anyone. Recommend a follow-up on third-party SDK inventory, which is where the Mozilla findings located most of the harm.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 617, "_entity_id": 859, "_entity_slug": "rise-sleep", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Waking Up (Sam Harris)", "Category": "Meditation", "Terms & Conditions URL": "wakingup(samharris).com/terms (approximate; not independently confirmed as exact URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "wakingup(samharris).com/privacy (approximate; not independently confirmed as exact URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach. An independently-owned app (founded by author/podcaster Sam Harris) offering a income-based financial-assistance program for users who can't afford the subscription — a distinctive access model.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. AAA rules, California law. 30-day opt-out. Waking Up is a meditation app with a subscription model — the arbitration clause covers billing and content disputes.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see Calm/Headspace rows (Consumer Apps tab) for the general wellness-app data-sharing risk pattern likely applicable across this whole category.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2022", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Waking Up mandates binding arbitration with a class-action waiver, 30-day opt-out\nWHAT THE TERMS SAY: Waking Up's ToS mandates binding arbitration under AAA rules and California law, with a class-action waiver and a 30-day opt-out; it covers billing and content disputes.\nWHY IT MATTERS: Users lose access to class litigation over billing or content issues unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Waking Up's course selection functions as a belief profile of the user\nWHAT THE TERMS SAY: The tracker notes that because Waking Up is organized around philosophy and secular contemplative practice, its course-selection data functions as a belief profile.\nWHY IT MATTERS: This creates a revealing inference profile even without any confirmed misuse; Mozilla's 2022 study covered prayer apps for the same underlying reason (context from research on the broader wellness-app category, not a Waking Up-specific incident).\n(evidence: SCARY; Inferred from tracker text (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two company-specific points are stated: the mandatory arbitration clause and the belief-profile nature of course-selection data. Data-sharing specifics are explicitly unconfirmed, and the no-advertising subscription model and income-based assistance program are noted as favorable rather than troubling.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clear, but data-sharing and retention specifics remain unconfirmed.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Waking Up (Sam Harris)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Waking Up (Sam Harris) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. The category-specific note: a meditation app organised around philosophy and secular contemplative practice holds course-selection data that functions as a belief profile, and Mozilla's 2022 study covered prayer apps alongside mental health apps precisely because the two produce similarly revealing inference material. Waking Up is subscription-funded with no advertising tier, which removes the primary monetisation pressure Mozilla identified. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 618, "_entity_id": 860, "_entity_slug": "waking-up-sam-harris", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Elevate", "Category": "Brain Training", "Terms & Conditions URL": "elevate.com/terms (approximate; not independently confirmed as exact URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "elevate.com/privacy (approximate; not independently confirmed as exact URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach. A brain-training/cognitive-skills app; same general category concerns as other self-improvement apps regarding usage-pattern data collection.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. Elevate Labs LLC ToS, AAA rules, California law. Elevate is a brain-training app that tracks cognitive performance over time — the arbitration clause covers disputes over cognitive-assessment data.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see Calm/Headspace rows (Consumer Apps tab) for the general wellness-app data-sharing risk pattern likely applicable across this whole category.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Elevate mandates binding arbitration with a class-action waiver, 30-day opt-out\nWHAT THE TERMS SAY: Elevate Labs LLC's ToS mandates binding arbitration under AAA rules and California law, with a class-action waiver and 30-day opt-out, covering disputes over cognitive-assessment data.\nWHY IT MATTERS: Users lose access to class litigation over how their cognitive performance data is used unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Elevate's cognitive-performance data is health-adjacent data users don't expect\nWHAT THE TERMS SAY: Elevate tracks cognitive performance over time (reaction speed, memory accuracy, attention consistency); the tracker notes declining scores can correlate with undiagnosed conditions.\nWHY IT MATTERS: The tracker notes this data is health-adjacent in a way users do not perceive, since declining scores can correlate with conditions the user has not been diagnosed with; it also flags that the FTC has previously acted against brain-training marketing claims.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two company-specific points are confirmed: the mandatory arbitration clause and the nature of cognitive-performance data collection. Data-sharing specifics for Elevate itself remain unconfirmed.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clear, but data-sharing details for Elevate remain unconfirmed.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Elevate  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Elevate you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Brain training apps generate cognitive performance data over time - reaction speed, memory accuracy, attention consistency - which is health-adjacent in a way users do not perceive, since declining scores can correlate with conditions the user has not been diagnosed with. The efficacy claims in this category have also drawn regulatory attention historically; the FTC has previously acted against brain-training marketing claims. Recommend a follow-up on both retention and advertising claims.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 619, "_entity_id": 861, "_entity_slug": "elevate", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Yoga-Go", "Category": "Fitness/Yoga", "Terms & Conditions URL": "yoga-go.com/terms (approximate; not independently confirmed as exact URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "yoga-go.com/privacy (approximate; not independently confirmed as exact URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach. A subscription-based yoga/fitness app; industry-wide subscription-billing/cancellation-friction concerns (documented for gyms elsewhere in this tracker) may apply similarly.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see Calm/Headspace rows (Consumer Apps tab) for the general wellness-app data-sharing risk pattern likely applicable across this whole category.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-4] Billing and cancellation friction, not privacy, is flagged as Yoga-Go's likelier harm\nWHAT THE TERMS SAY: The tracker notes that subscription-heavy fitness apps like Yoga-Go generate sustained complaints about trial-to-paid conversion, cancellation friction, and auto-renewal -- FTC negative-option rule territory -- rather than data-handling issues specifically.\nWHY IT MATTERS: Consumers may face difficulty cancelling or be auto-charged after a trial, though this is stated as a category-level pattern rather than a Yoga-Go-specific confirmed incident.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No lawsuit, breach, or specific clause is confirmed for Yoga-Go; arbitration and data-sharing are both explicitly unconfirmed. Only the billing/cancellation-friction pattern is flagged, and even that is presented as a category-level risk rather than a company-specific finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nearly all fields are explicitly unconfirmed; only a category-level billing-friction concern is flagged.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Yoga-Go  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Yoga-Go takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Fitness apps in the subscription-heavy consumer segment have generated sustained complaint about billing practice rather than data handling - trial-to-paid conversion, cancellation friction and auto-renewal - which is the FTC's negative-option rule territory. That is the likelier consumer harm here and it is a terms-and-conditions finding of exactly the kind this tracker exists to surface. Recommend a follow-up focused on billing and cancellation flow rather than on privacy.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 620, "_entity_id": 862, "_entity_slug": "yoga-go", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Day One", "Category": "Journaling", "Terms & Conditions URL": "dayone.com/terms (approximate; not independently confirmed as exact URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "dayone.com/privacy (approximate; not independently confirmed as exact URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach. A journaling app (owned by Automattic, also owner of WordPress.com/Tumblr) storing potentially highly personal diary entries; end-to-end encryption is offered as an OPTIONAL feature, meaning entries are NOT encrypted by default unless a user specifically enables it.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. Day One (Automattic subsidiary since 2021, same parent as WordPress) ToS. Day One stores private journal entries — among the most intimate text data any app collects. The arbitration clause covers disputes over how this diary-level personal content is encrypted, stored, and potentially accessed.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see Calm/Headspace rows (Consumer Apps tab) for the general wellness-app data-sharing risk pattern likely applicable across this whole category.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Day One journal entries are not end-to-end encrypted by default\nWHAT THE TERMS SAY: Day One offers end-to-end encryption as an optional feature, meaning diary entries are not encrypted by default unless a user specifically enables it.\nWHY IT MATTERS: Encryption the user has to find and enable protects only the users who went looking, so potentially highly personal diary content is unencrypted by default.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Day One mandates binding arbitration with a class-action waiver over diary content\nWHAT THE TERMS SAY: Day One's ToS (Automattic subsidiary since 2021) mandates binding arbitration with a class-action waiver and 30-day opt-out, covering disputes over how diary-level content is encrypted, stored, and potentially accessed.\nWHY IT MATTERS: Users lose the ability to bring or join a class action over mishandling of their private journal entries unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two company-specific findings are stated: default non-encryption and the mandatory arbitration clause. No lawsuit or breach is confirmed, and Day One's historical E2E offering is noted as a mitigating factor requiring verification of current defaults, not a third troubling item.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and the optional-encryption default are clearly stated, but current encryption defaults and breach history remain unverified.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Day One  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Day One you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A private journal is the single most sensitive text a person produces - it is written precisely because it is not for anyone else - and Day One is a journaling app that syncs to cloud storage. The question that determines everything is whether sync is end-to-end encrypted and whether it is on by default, since encryption the user has to find and enable protects only the users who went looking. Day One has historically offered end-to-end encryption, which is genuinely more than most apps in this tab provide. Nothing confirmed this pass; verify current default settings before relying on this.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 621, "_entity_id": 863, "_entity_slug": "day-one", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Happier Meditation", "Category": "Meditation", "Terms & Conditions URL": "happiermeditation.com/terms (approximate; not independently confirmed as exact URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "happiermeditation.com/privacy (approximate; not independently confirmed as exact URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach. A meditation/wellness app from the 'Happier' media brand; same general meditation-app data-sharing risk category applies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see Calm/Headspace rows (Consumer Apps tab) for the general wellness-app data-sharing risk pattern likely applicable across this whole category.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2022", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Happier's check-in features may collect emotional-state data as part of normal use\nWHAT THE TERMS SAY: The tracker states that meditation apps in this category, including Happier, collect emotional-state data through check-in features that users experience as part of the practice rather than as data collection -- a category-level finding, not a confirmed Happier-specific incident.\nWHY IT MATTERS: Users may disclose mood and emotional state without realizing it functions as trackable data, though no lawsuit or breach specific to Happier is confirmed.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No Happier-specific lawsuit, breach, or clause is confirmed; arbitration and data-sharing fields are both explicitly unconfirmed. The tracker separately notes that Mozilla's finding concerned 'Happify,' a different company, and explicitly warns against merging the two rows, so that finding is excluded here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "All fields are explicitly unconfirmed this pass, and the only cited industry finding (Mozilla/Happify) belongs to a different, similarly-named company.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Happier Meditation  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Happier Meditation takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Mozilla's 2022 study specifically named Happify among apps that pushed users into intake questionnaires before presenting a privacy policy or asking consent - a different company from Happier, and the name similarity is exactly the confusion this tracker's fuzzy-matching discipline exists to prevent, so do not merge these rows. The category finding stands: meditation apps collect emotional-state data through check-in features that users experience as part of the practice rather than as data collection.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 622, "_entity_id": 864, "_entity_slug": "happier-meditation", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "YouVersion Bible App", "Category": "Religious/Spiritual", "Terms & Conditions URL": "youversionbibleapp.com/terms (approximate; not independently confirmed as exact URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "youversionbibleapp.com/privacy (approximate; not independently confirmed as exact URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach. One of the most-downloaded religious apps globally; collects reading habits, prayer requests, and community-group participation data — potentially revealing religious affiliation and beliefs, a category some state privacy laws treat as especially sensitive.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see Calm/Headspace rows (Consumer Apps tab) for the general wellness-app data-sharing risk pattern likely applicable across this whole category.\n\nMOZILLA *PRIVACY NOT INCLUDED CROSS-REFERENCE (verified this pass - the spine for every row in this tab): Mozilla's 2022 investigation reviewed 32 mental health and prayer apps and gave 29 of them the *Privacy Not Included warning label, with researchers stating that mental health apps were 'worse than any other product category' they had assessed for privacy and security. Specific findings: Cerebral set a record with 799 trackers firing within the first minute after download; Talkspace, Happify and BetterHelp pushed users into intake questionnaires BEFORE presenting a privacy policy or asking consent; Talkspace's policy permitted using inferences drawn from that questionnaire - covering gender identity, sexual orientation and depression indicators - for marketing and tailored advertising. Talkspace publicly disputed Mozilla's characterisation and said the report lacked its input and contained inaccuracies. In the 2023 follow-up, only 2 of 27 apps met Mozilla's standards: PTSD Coach (built by the US Department of Veterans Affairs) and Wysa. REGULATORY ANCHOR: FTC settled with BetterHelp for $7.8 million on March 2 2023 - the complaint alleged BetterHelp promised not to share health data and then disclosed email addresses, IP addresses and health questionnaire responses to Facebook, Snapchat, Criteo and Pinterest for advertising. The order BANS BetterHelp from sharing consumer health data for advertising. Cerebral separately acknowledged exposing patient names, birth dates, insurance information and mental health self-evaluation responses to Google, Meta, TikTok and other advertisers. STRUCTURAL POINT: most of these apps are not HIPAA covered entities, so the sensitivity of the data is inversely related to the protection it receives.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2022", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] YouVersion collects reading habits and prayer requests revealing religious beliefs\nWHAT THE TERMS SAY: YouVersion collects reading habits, prayer requests, and community-group participation data, which can reveal religious affiliation and beliefs -- a category some state privacy laws treat as especially sensitive.\nWHY IT MATTERS: Scripture reading history, highlights, and prayer entries function as a religious-observance and personal-crisis record, yet this data category attracts no special protection under most US privacy law despite its sensitivity.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Arbitration terms are presumed standard for YouVersion but not independently confirmed\nWHAT THE TERMS SAY: The tracker did not confirm YouVersion's specific arbitration terms this pass, noting only that standard binding arbitration and a class-action waiver are expected.\nWHY IT MATTERS: If standard terms apply, disputes over how sensitive religious data is handled would be pushed into individual arbitration rather than court, though this remains unverified.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two items are supported: the stated religious-data collection and the unconfirmed-but-presumed arbitration terms. No YouVersion-specific lawsuit or breach is confirmed, and the Mozilla/BetterHelp/Cerebral findings in Notes belong to other companies and are cited only as category context.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration and breach status are unconfirmed; only the nature of the religious data collected is stated with confidence.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "YouVersion Bible App  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, YouVersion Bible App takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Mozilla's 2022 investigation covered prayer apps alongside mental health apps because both categories produce unusually revealing inference material, and it gave the warning label to 29 of the 32 apps reviewed. A scripture app's reading history, highlights, saved verses and prayer entries constitute a religious-observance and personal-crisis record - people search scripture at the worst moments of their lives. Nothing confirmed against YouVersion specifically this pass. The relevant structural point is that this data category attracts no special protection in US law despite being among the most sensitive a person generates.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 623, "_entity_id": 865, "_entity_slug": "youversion-bible-app", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Healthy Minds Program", "Category": "Meditation", "Terms & Conditions URL": "healthymindsprogram.com/terms (approximate; not independently confirmed as exact URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "healthymindsprogram.com/privacy (approximate; not independently confirmed as exact URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach. A nonprofit-affiliated (Center for Healthy Minds, University of Wisconsin) meditation app offered largely free — similar academic/nonprofit structure to UCLA Mindful.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see Calm/Headspace rows (Consumer Apps tab) for the general wellness-app data-sharing risk pattern likely applicable across this whole category.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] Unclear whether Healthy Minds data feeds academic research, and under what consent\nWHAT THE TERMS SAY: The tracker flags an open question for Healthy Minds' academic affiliation: whether user data feeds research at the Center for Healthy Minds, under what consent, and whether that consent is separable from using the app.\nWHY IT MATTERS: If research consent isn't separable from app consent, users could have their data used for research they didn't specifically agree to as a condition of using a free wellness app.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No lawsuit, breach, or clause is confirmed for Healthy Minds; arbitration and data-sharing are both explicitly unconfirmed. The only stated concern is an open question about whether research use of data is separable from app-use consent -- everything else noted is favorable nonprofit/academic context.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "All fields are explicitly unconfirmed; only an open question about research-data consent is flagged.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Healthy Minds Program  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Healthy Minds Program takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Healthy Minds is produced by a non-profit affiliated with academic research at the University of Wisconsin and distributed free, placing it in the same category as UCLA Mindful and the VA's PTSD Coach - which was one of only two apps to pass Mozilla's 2023 assessment. The research affiliation adds a distinct question worth checking rather than assuming: whether user data feeds academic research, under what consent, and whether that consent is separable from using the app.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 624, "_entity_id": 866, "_entity_slug": "healthy-minds-program", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Apple Journal", "Category": "Journaling", "Terms & Conditions URL": "applejournal.com/terms (approximate; not independently confirmed as exact URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "applejournal.com/privacy (approximate; not independently confirmed as exact URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach. Apple's own journaling app; uses on-device machine learning for entry suggestions (drawing on Photos, location, and other iPhone data) with Apple's general privacy positioning of processing sensitive suggestions on-device rather than in the cloud.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — governed by Apple's Media Services Terms, which contain no arbitration clause. Consistent with Apple's company-wide no-arbitration posture (the only major consumer tech company in this tracker without one).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see Calm/Headspace rows (Consumer Apps tab) for the general wellness-app data-sharing risk pattern likely applicable across this whole category.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$416.2B", "Market Cap": "$4.8T", "Employees": "164,000", "HQ City": "Cupertino", "HQ State": "California", "CEO": "Tim Cook", "Ticker": "AAPL", "Website (Corporate)": "apple.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AAPL). Service route: c/o General Counsel / Corporate Secretary, Cupertino, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Apple Journal's suggestions draw on photos, location, music, and workouts to function\nWHAT THE TERMS SAY: Apple Journal's suggestion engine draws on photos, location, music, and workout data to prompt journal entries, meaning the app reads across multiple other data categories to function.\nWHY IT MATTERS: This cross-category access is a meaningful data surface even though Apple positions the processing as on-device, and Advanced Data Protection (which strengthens iCloud encryption) remains off by default across iCloud generally, so the specific encryption guarantee for Journal content should be verified rather than assumed.\n(evidence: SCARY | Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No lawsuit or breach is confirmed for Apple Journal; the only company-specific concern is the suggestion engine's cross-category data access, since Apple's on-device processing, stated E2E encryption support, and no-arbitration posture are all noted as favorable rather than troubling.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration status and encryption architecture are clearly stated, but current default encryption settings for Journal specifically are flagged as needing verification.", "Exposure Score (0-100)": 9, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Apple Journal  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Apple Journal you gave up your physical movements. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Apple Journal is notable within this tab for architecture rather than incident: journal entries are stored on-device with iCloud sync, and Apple has stated Journal supports end-to-end encryption - a materially stronger guarantee than the cloud storage most apps in this tab use. The residual note is the suggestion engine, which draws on photos, location, music and workouts to prompt entries, meaning the app reads across other data categories to function. Verify current encryption defaults; Advanced Data Protection remains off by default across iCloud generally.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 625, "_entity_id": 867, "_entity_slug": "apple-journal", "_issuer": "Apple Journal", "_issuer_slug": "apple-journal", "_ticker": "AAPL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Balance", "Category": "Meditation", "Terms & Conditions URL": "balance.com/terms (approximate; not independently confirmed as exact URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "balance.com/privacy (approximate; not independently confirmed as exact URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach. A subscription meditation app; same general meditation-app category concerns apply.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. Elevate Labs LLC ToS (Balance and Elevate share a parent company). AAA rules, California law. Balance tracks meditation frequency, session completion, and self-reported mood data.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see Calm/Headspace rows (Consumer Apps tab) for the general wellness-app data-sharing risk pattern likely applicable across this whole category.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Portland", "HQ State": "Oregon", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Oregon' is a non-DMV US state", "Parent / Ultimate Owner": "Elevate Labs", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Oregon) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Oregon. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Balance mandates binding arbitration with a class-action waiver, 30-day opt-out\nWHAT THE TERMS SAY: Balance's ToS (Elevate Labs LLC, which also owns Elevate) mandates binding arbitration under AAA rules and California law, with a class-action waiver and a 30-day opt-out.\nWHY IT MATTERS: Users lose access to class litigation over how their meditation frequency, session, and mood data is used unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Balance's personalization builds a record of a user's self-reported struggles\nWHAT THE TERMS SAY: Balance personalizes meditation based on user-reported goals and self-reported mood data, creating a structured record of what a person says is wrong in their life, updated regularly as the user engages with the app.\nWHY IT MATTERS: This is among the most sensitive data a wellness app can hold, and the tracker recommends a follow-up on third-party analytics SDKs, which is where Mozilla's research located most of the category's data exposure.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two findings are supported by the text: the confirmed mandatory arbitration clause and the personalization-driven mood data collection. No lawsuit, breach, or specific data-sharing practice is confirmed for Balance.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clear, but data-sharing and retention specifics for Balance remain unconfirmed.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Balance  <-  Elevate Labs", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Balance you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Balance personalises meditation based on user-reported goals and emotional state, which means its core feature is a structured record of what a person says is wrong in their life, updated regularly. Personalisation is the mechanism by which wellness apps accumulate the most sensitive data they hold, and users supply it willingly because the app works better when they do. Recommend a follow-up on third-party analytics SDKs, which is where Mozilla located the bulk of the category's exposure.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 626, "_entity_id": 869, "_entity_slug": "balance", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "The Tapping Solution", "Category": "Meditation/EFT", "Terms & Conditions URL": "thetappingsolution.com/terms (approximate; not independently confirmed as exact URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "thetappingsolution.com/privacy (approximate; not independently confirmed as exact URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach. An Emotional Freedom Technique (EFT/'tapping') app; same general wellness-app data-sharing risk category applies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see Calm/Headspace rows (Consumer Apps tab) for the general wellness-app data-sharing risk pattern likely applicable across this whole category.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] The Tapping Solution's session topics form a self-reported list of user struggles\nWHAT THE TERMS SAY: Sessions are organized around specific distress topics (anxiety, grief, financial stress, physical pain), so a user's session selection functions as a self-reported problem list.\nWHY IT MATTERS: This is revealing even without any confirmed misconduct -- it only requires the data to exist and potentially be shared with analytics partners, though no such sharing is independently confirmed for this app.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No lawsuit, breach, or clause is confirmed for The Tapping Solution; arbitration and data-sharing are both explicitly unconfirmed. Only the inference risk from session-topic selection is flagged, and even that is presented without confirmation of actual sharing.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "All fields are explicitly unconfirmed this pass; only a structural inference risk is noted.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "The Tapping Solution  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, The Tapping Solution takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. The app delivers guided sessions organised around specific distress topics, so session selection is effectively a self-reported problem list - anxiety, grief, financial stress, physical pain. That is the same inference structure flagged across this tab and it does not require any misconduct to be revealing; it only requires the data to exist and be shared with analytics partners. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 627, "_entity_id": 870, "_entity_slug": "the-tapping-solution", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Habitify", "Category": "Habit Tracking", "Terms & Conditions URL": "habitify.com/terms (approximate; not independently confirmed as exact URL this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "habitify.com/privacy (approximate; not independently confirmed as exact URL this pass)", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach. A habit-tracking app; collects detailed behavioral/routine data that can reveal health, productivity, and lifestyle patterns.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Habitify (Unstatic Ltd Co., Hanoi, Vietnam) ToS governed by Vietnamese law. No US-style arbitration clause.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see Calm/Headspace rows (Consumer Apps tab) for the general wellness-app data-sharing risk pattern likely applicable across this whole category.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Habitify's habit logs can include medication, alcohol use, and sleep -- health data\nWHAT THE TERMS SAY: Habitify's daily behavioral record frequently includes medication adherence, alcohol consumption, exercise, and sleep -- health data by any reasonable definition -- held by a small independent app company.\nWHY IT MATTERS: This data sits outside HIPAA or similar health-privacy protections, and the tracker notes that small independent developers generate little public accountability record, so the absence of confirmed findings reflects the absence of scrutiny rather than the absence of risk.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-3] Habitify's ToS is governed by Vietnamese law, with no US-style arbitration clause\nWHAT THE TERMS SAY: Habitify (Unstatic Ltd Co., Hanoi, Vietnam) ToS is governed by Vietnamese law, with no US-style arbitration clause identified.\nWHY IT MATTERS: Habitify (Unstatic Ltd Co., Hanoi, Vietnam) is governed by Vietnamese law rather than a US jurisdiction, and no arbitration clause was identified; the tracker does not state how this affects a US consumer's practical recourse.\n(evidence: Arbitration; Inferred from tracker text (fidelity pass 1: Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two points are supported by the text: the health-adjacent nature of habit-tracking data held outside health-privacy law, and the practical-access implications of Vietnamese-law governance. No lawsuit, breach, or data-sharing practice is confirmed for Habitify specifically.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No lawsuit, breach, or data-sharing practice is confirmed; only the nature of habit data and the foreign-jurisdiction governance are stated.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Habitify  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Habitify takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Habit trackers hold a daily behavioural record that frequently includes medication adherence, alcohol consumption, exercise and sleep - health data by any reasonable definition, held by a small app company outside any health-privacy perimeter. Small independent developers also generate little public accountability record either way, so the absence of findings reflects the absence of scrutiny. Recorded as unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 628, "_entity_id": 871, "_entity_slug": "habitify", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Whoop", "Category": "Fitness Wearable", "Terms & Conditions URL": "whoop.com/us/en/terms/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "whoop.com/us/en/full-privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SIGNIFICANT, MULTI-FACETED FINDINGS for a device worn 24/7 by ~1 million users: an August 2025 class action alleges Whoop secretly shared sensitive health data with a THIRD-PARTY TRACKER (Segment, a customer-data platform that fans analytics out to Meta's Conversions API, Google Ads, and other destinations) — adding claims under the California Invasion of Privacy Act, the Confidentiality of Medical Information Act, and the federal Video Privacy Protection Act. A peer-reviewed academic study (Nature) placed Whoop in the HIGHEST PRIVACY-RISK CLUSTER among 17 leading wearable manufacturers studied. Whoop's OWN privacy policy explicitly states 'WHOOP is not a covered entity or business associate under HIPAA' — meaning the extensive health data it collects (heart rate variability, respiratory rate, blood oxygen, sleep staging, and since Sept 2025 via 'Advanced Labs' with Quest Diagnostics, actual CLINICAL LAB RESULTS, plus MENSTRUAL/REPRODUCTIVE data) falls entirely OUTSIDE federal medical-privacy protections. A prominent fitness-tech reviewer publicly confronted Whoop's CEO in 2020 over the gap between marketing claims ('never sells data') and the actual privacy policy text, which the reviewer said explicitly listed data that HAD been sold; Whoop's later clarification amounted to 'they only give it away instead' per the reviewer.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. WHOOP Inc. ToS, AAA rules, Massachusetts law. WHOOP collects continuous biometric data (heart rate, HRV, skin temperature, blood oxygen, strain, recovery scores) 24/7 — more granular physiological data than any other consumer device in this tracker. The arbitration clause covers disputes over how this health-grade biometric stream is stored, shared, and monetized.", "Fees / Billing Flags": "SEPARATE, RECENT CLASS ACTION (Nov 2025): alleges Whoop's blood-pressure-adjacent features do NOT provide the 'medical-grade' health insights the company advertises — a product-accuracy/marketing claim distinct from the privacy findings above.", "Notes": "Whoop now has FOUR SEPARATE ACTIVE OR RECENT LEGAL MATTERS (data-sharing, auto-enrollment billing, medical-grade marketing claims, plus the academic highest-privacy-risk ranking) — among the most extensively-flagged fitness wearables in this entire tracker, particularly notable given the HIPAA-gap combined with genuinely clinical-grade health data (lab results, reproductive health) now being collected.\n\nMOZILLA *PRIVACY NOT INCLUDED CROSS-REFERENCE (verified this pass - the spine for every row in this tab): Mozilla's 2022 investigation reviewed 32 mental health and prayer apps and gave 29 of them the *Privacy Not Included warning label, with researchers stating that mental health apps were 'worse than any other product category' they had assessed for privacy and security. Specific findings: Cerebral set a record with 799 trackers firing within the first minute after download; Talkspace, Happify and BetterHelp pushed users into intake questionnaires BEFORE presenting a privacy policy or asking consent; Talkspace's policy permitted using inferences drawn from that questionnaire - covering gender identity, sexual orientation and depression indicators - for marketing and tailored advertising. Talkspace publicly disputed Mozilla's characterisation and said the report lacked its input and contained inaccuracies. In the 2023 follow-up, only 2 of 27 apps met Mozilla's standards: PTSD Coach (built by the US Department of Veterans Affairs) and Wysa. REGULATORY ANCHOR: FTC settled with BetterHelp for $7.8 million on March 2 2023 - the complaint alleged BetterHelp promised not to share health data and then disclosed email addresses, IP addresses and health questionnaire responses to Facebook, Snapchat, Criteo and Pinterest for advertising. The order BANS BetterHelp from sharing consumer health data for advertising. Cerebral separately acknowledged exposing patient names, birth dates, insurance information and mental health self-evaluation responses to Google, Meta, TikTok and other advertisers. STRUCTURAL POINT: most of these apps are not HIPAA covered entities, so the sensitivity of the data is inversely related to the protection it receives.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Boston", "HQ State": "Massachusetts", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Massachusetts' is a non-DMV US state", "Parent / Ultimate Owner": "WHOOP, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Massachusetts SOC Corporate Search — corp.sec.state.ma.us/corpweb/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: WHOOP, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Aug 2025 suit alleges Whoop secretly shared sensitive health data with third-party tracker Segment\nWHAT THE TERMS SAY: An August 2025 class action alleges Whoop shared sensitive health data with Segment, a customer-data platform that routes data to Meta's Conversions API, Google Ads, and other destinations, with claims under the California Invasion of Privacy Act, the Confidentiality of Medical Information Act, and the federal Video Privacy Protection Act.\nWHY IT MATTERS: If proven, this would mean health metrics from a device worn 24/7 by roughly 1 million users were routed to advertising platforms without adequate disclosure -- but this remains an allegation, not a confirmed finding.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Whoop's clinical-grade health and reproductive data falls entirely outside HIPAA\nWHAT THE TERMS SAY: Whoop's own privacy policy states it is 'not a covered entity or business associate under HIPAA,' even though it collects heart rate variability, respiratory rate, blood oxygen, sleep staging, menstrual/reproductive data, and, since September 2025 via 'Advanced Labs' with Quest Diagnostics, actual clinical lab results.\nWHY IT MATTERS: Data this sensitive would normally carry strong legal protection, but here it does not, and a peer-reviewed Nature study placed Whoop in the highest privacy-risk cluster among 17 leading wearable manufacturers studied.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[TERMINATION_CONFISCATION · FL-4] Whoop's hardware stops being useful when the membership lapses, which the tracker calls a retention tool\nWHAT THE TERMS SAY: Whoop bundles its hardware into a subscription membership; when the subscription lapses, the device stops being useful, which the tracker characterizes as a retention mechanism rather than a product design choice.\nWHY IT MATTERS: Users who stop paying lose useful function of a device that is bundled into the membership rather than sold outright, a lock-in dynamic; the tracker separately lists auto-enrollment billing among Whoop's four separate active or recent legal matters.\n(evidence: SCARY | Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=Y; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Multiple concrete findings are stated (the HIPAA-gap admission, arbitration terms, four legal matters), but several -- including the central data-sharing claim -- are pending allegations rather than resolved facts.", "Exposure Score (0-100)": 56, "Exposure Band": "High", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 21, "Sub: Contract Asymmetry /20": 7, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 21/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, biometric_collection+6, sensitive_exposure_tag+3) | Contract 7/20 (termination_or_confiscation+4, auto_renewal_or_fee_trap+3) | Record 4/20 (severity2+2, litigation+2) | flags stated 9/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Whoop  <-  WHOOP, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n  6. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  7. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (6 of 13): your content used as AI training data; your physical movements; a broad licence to your own content; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Whoop you gave up your personal data sold onward, your biometric identifiers, your data shared corporate-wide, your right to sue, your right to join a class action, your right to keep what you paid for, and your right to stop paying by inaction. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Whoop is worn 24 hours a day and produces continuous heart rate, heart rate variability, respiratory rate, skin temperature and sleep staging - a physiological record more granular than most people's medical charts, generated outside any clinical relationship and therefore outside HIPAA. The subscription model is also structurally unusual: the hardware is bundled into a membership, so lapsing means the device stops being useful, which is a retention mechanism rather than a product design. Continuous biometric monitoring of this kind has obvious value to insurers and employers, and the meaningful protections are contractual rather than statutory. See the Data Sharing column for the itemised findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 629, "_entity_id": 873, "_entity_slug": "whoop", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Upright", "Category": "Posture Tracking", "Terms & Conditions URL": "uprightpose.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "uprightpose.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach; posture-tracking apps typically use phone/wearable sensor (accelerometer) data rather than more invasive data categories.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Upright's continuous posture data can reveal musculoskeletal conditions and pregnancy\nWHAT THE TERMS SAY: Upright is a wearable posture trainer collecting continuous body-position data; the tracker notes posture and movement data correlate with musculoskeletal conditions and with pregnancy.\nWHY IT MATTERS: This creates a real health-inference surface from what looks like a low-profile fitness product; for context, gait and posture patterns have separately been shown to be identifying, per motion-signature research referenced elsewhere in this tracker (the Meta Horizon row, a different company).\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No lawsuit, breach, or specific clause is confirmed for Upright; arbitration and data-sharing are both explicitly unconfirmed, and the tracker itself frames posture data as a lower-invasiveness category than most apps in this tracker. Only the health-inference surface of continuous posture data is flagged.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "All fields are explicitly unconfirmed this pass; only the inference risk of continuous posture data is stated.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Upright  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Upright takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Upright is a wearable posture trainer, which means continuous body-position data - a category that overlaps with the motion-signature research noted in the Meta Horizon row, where gait and posture patterns have been shown to be identifying. Posture and movement data also correlate with musculoskeletal conditions and with pregnancy. Low-profile product, real inference surface, recorded honestly without inflation.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 630, "_entity_id": 874, "_entity_slug": "upright", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Co-Star", "Category": "Astrology", "Terms & Conditions URL": "costarastrology.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "costarastrology.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Co-Star's business model relies on precise BIRTH DATE, TIME, AND LOCATION data (required for accurate astrological charts) combined with ongoing behavioral/mood check-ins — a distinctive data category combination not typical of most apps. No specific named lawsuit or breach independently confirmed this pass.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. Co-Star ToS, AAA rules, New York law. Co-Star collects birth date, birth time, birth location, and uses NASA JPL data — the arbitration clause covers disputes over how this combined personal + astrological data is used. Birth details are PII that can contribute to identity verification.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; the precise birth time/location data required for astrology apps is a genuinely distinctive, highly specific personal-data category worth noting.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with class-action waiver covers disputes over Co-Star's birth and mood data\nWHAT THE TERMS SAY: Co-Star's ToS impose mandatory binding arbitration with a class-action waiver under AAA rules and New York law, with a 30-day window to opt out; the clause covers disputes over how Co-Star uses the combined birth data and ongoing mood check-ins it collects.\nWHY IT MATTERS: A user who misses the 30-day opt-out window is barred from suing or joining a class action over misuse of this birth and mood data, and must argue any dispute individually before a private arbitrator.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Co-Star requires exact birth date, time and location, the same triple used for identity verification\nWHAT THE TERMS SAY: Co-Star's astrology function requires precise birth date, time, and location, combined with ongoing behavioral/mood check-ins; the tracker notes this triple matches the knowledge-based authentication factors used by identity-verification systems and credit bureaus, and appears on a birth certificate.\nWHY IT MATTERS: If this data were ever exposed, it could plausibly be misused for identity-verification fraud well beyond the astrology context; no breach is confirmed, but the collection itself creates that exposure.\n(evidence: SCARY | Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct items are grounded in the row's text: the arbitration/class-waiver clause and the birth-data sensitivity finding. Fees are not itemized this pass and no lawsuit or breach is confirmed, so no third distinct harm exists in the text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated, but data-sharing and breach history are explicitly unconfirmed this pass.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Co-Star  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Co-Star you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Co-Star requires exact birth date, birth time and birth location - which is, coincidentally, the precise triple that identity verification systems and credit bureaus use as a knowledge-based authentication factor, and which appears on a birth certificate. Users supply it readily because the app cannot function without it and because an astrology app does not feel like a place where identity data matters. Birth time in particular is information most people cannot recall without checking a document, which is exactly what makes it useful as an authenticator. Nothing confirmed this pass; the collection itself is the finding.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 631, "_entity_id": 875, "_entity_slug": "co-star", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CHANI", "Category": "Astrology", "Terms & Conditions URL": "chani.com/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "chani.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same distinctive birth-data/astrology-app category as Co-Star (this same tab) — no specific named lawsuit or breach independently confirmed this pass.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. CHANI Inc. ToS, AAA rules, California law. Similar to Co-Star, CHANI collects precise birth data (date, time, location) — demographic data that, combined with astrological engagement patterns, creates a uniquely personal behavioral profile.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See Co-Star row for the shared astrology-app data-category considerations.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with class-action waiver covers CHANI's precise birth-data collection\nWHAT THE TERMS SAY: CHANI Inc.'s ToS impose mandatory binding arbitration with a class-action waiver under AAA rules and California law, with a 30-day opt-out window; CHANI collects precise birth date, time, and location data.\nWHY IT MATTERS: A user who misses the 30-day opt-out window loses the ability to sue or join a class action over how this birth data is used, and must arbitrate individually.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] CHANI collects precise birth data; astrology apps generally invite relationship and mood detail\nWHAT THE TERMS SAY: CHANI collects precise birth data (date, time, location) - the same birth-data category as Co-Star, recorded as one structural finding across both rows rather than two independent assessments. The tracker's additional note for astrology apps generally is that the interpretive content invites users to enter relationship details, emotional states and life events to get better readings, which extends the dataset well past the birth chart.\nWHY IT MATTERS: Combined with astrological engagement patterns, this demographic data creates a uniquely personal behavioral profile; nothing is confirmed this pass.\n(evidence: SCARY | Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct items are grounded in the row's text: the arbitration/class-waiver clause and the birth- and self-entered-data sensitivity finding (recorded as a structural point shared with the Co-Star row, another company in this tracker, but the underlying facts stated here are CHANI-specific). Fees are not itemized and no lawsuit or breach is confirmed.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated, but data-sharing and breach history are explicitly unconfirmed this pass.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "CHANI  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using CHANI you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same birth-data category as Co-Star - exact date, time and place of birth, the triple that overlaps with knowledge-based authentication factors and appears on a birth certificate. Recorded as one structural finding across both rows rather than two independent assessments. The additional note for astrology apps generally is that the interpretive content invites users to enter relationship details, emotional states and life events to get better readings, which extends the dataset well past the birth chart. Nothing confirmed this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Wellness & Meditation Apps", "_row_id": 632, "_entity_id": 876, "_entity_slug": "chani", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "ZocDoc", "Category": "Healthcare Booking", "Terms & Conditions URL": "zocdoc.com/about/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "zocdoc.com/about/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ZocDoc collects health-provider search queries (which reveal symptoms/conditions), insurance information, appointment history, and patient reviews. This data is NOT HIPAA-covered — ZocDoc is a marketplace, not a healthcare provider or health plan. ZocDoc's data practices are governed solely by its own privacy policy.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. ZocDoc ToS, AAA rules, New York law. 30-day opt-out. ZocDoc processes healthcare provider search data, appointment requests, insurance information, and patient reviews. The arbitration clause covers disputes over how ZocDoc shares patient-search data with healthcare providers and advertisers.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up specifically checking whether ZocDoc uses tracking pixels given the 'which type of doctor you're booking' data category's inherent sensitivity.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Zocdoc, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Zocdoc, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] ZocDoc's health-provider search data is not HIPAA-covered, unlike the doctors it books\nWHAT THE TERMS SAY: ZocDoc collects health-provider search queries (which reveal symptoms or conditions), insurance information, appointment history, and patient reviews; the tracker states ZocDoc is a marketplace, not a healthcare provider or health plan, so this data is not HIPAA-covered and is governed solely by ZocDoc's own privacy policy.\nWHY IT MATTERS: The same fact — which specialty you booked and when — can be protected health information in the physician's own file but ordinary business data on the platform that scheduled it; booking an oncologist, psychiatrist, fertility clinic, or addiction-medicine practice can disclose far more than the appointment itself.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] ZocDoc's arbitration clause covers disputes over sharing patient-search data with providers and advertisers\nWHAT THE TERMS SAY: ZocDoc's arbitration clause explicitly covers disputes over how ZocDoc shares patient-search data with healthcare providers and advertisers.\nWHY IT MATTERS: The clause's scope implies patient-search data does reach advertisers, not just the providers being booked, though the tracker does not itemize specific advertising partners.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with class-action waiver, 30-day opt-out, AAA rules under New York law\nWHAT THE TERMS SAY: ZocDoc's ToS impose mandatory binding arbitration with a class-action waiver under AAA rules and New York law, with a 30-day opt-out window.\nWHY IT MATTERS: A user who misses the opt-out window must arbitrate individually rather than sue or join a class action over ZocDoc's handling of healthcare search and insurance data.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The regulatory-perimeter gap and arbitration terms are specifically described, but no lawsuit or breach is confirmed this pass.", "Exposure Score (0-100)": 33, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "ZocDoc  <-  Zocdoc, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using ZocDoc you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A healthcare appointment platform necessarily learns the two things people most want kept private together - which specialty you are seeing and when - and specialty alone is often diagnosis-adjacent. Booking an oncologist, a psychiatrist, a fertility clinic or an addiction medicine practice discloses substantially more than the appointment. The structural issue is that a booking platform is generally NOT a HIPAA covered entity in the way the doctor is, so the same fact can be protected health information in the physician's file and ordinary business data on the platform that scheduled it. Nothing confirmed this pass; the regulatory-perimeter gap is the finding.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 633, "_entity_id": 878, "_entity_slug": "zocdoc", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "MyChart (Epic Systems)", "Category": "Health Records", "Terms & Conditions URL": "mychart.epic.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "mychart.epic.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ONE OF THE MOST CONSEQUENTIAL FINDINGS IN THIS ENTIRE TRACKER GIVEN SCALE: Epic Systems' software manages electronic health records for approximately 80% of the US POPULATION, and MyChart specifically is used across 39% of all hospital systems. MULTIPLE INDIVIDUAL HEALTH SYSTEMS have separately settled Meta-Pixel-in-MyChart lawsuits (SSM Health, preliminary approval Sept 2025; Catholic Health System, $-value settlement, preliminary approval Dec 2025; BJC HealthCare, $5.5 MILLION, payments issued Jan 2026) — all alleging protected health information was transmitted to Meta/Google via tracking pixels embedded in the MyChart patient portal without consent. As of 2024-2025, litigation EXPANDED to name EPIC SYSTEMS ITSELF (not just individual hospitals) as a direct defendant, after discovery reportedly uncovered INTERNAL EPIC COMMUNICATIONS suggesting the company knew about the tracking tools and delayed removing them. SEPARATELY, a January 2026 lawsuit (Epic itself as PLAINTIFF, against health-data-network Health Gorilla) alleges nearly 300,000 patient records were improperly accessed by third parties POSING AS LEGITIMATE HEALTHCARE PROVIDERS.", "Arbitration / Class Action Waiver": "GENUINELY ALARMING NEW TERMS OF SERVICE (rolling out 2025): Epic is now PUSHING MyChart PATIENTS to accept a binding-arbitration + class-action-waiver agreement — patients who decline are limited to a DOWNGRADED VERSION with fewer features. Critics note the timing coincides with UnitedHealth Group's own massive Change Healthcare breach litigation (documented via the CareFirst row, Insurance tab), suggesting Epic may be preemptively shielding itself from similar mass litigation before any breach of its own occurs. Given Epic's near-monopoly market position (documented separately below), most patients effectively have NO PRACTICAL ALTERNATIVE to accepting these terms if their hospital uses MyChart.", "Fees / Billing Flags": "MAJOR TEXAS AG ANTITRUST LAWSUIT (filed Dec 10, 2025): alleges Epic unlawfully monopolizes the electronic health records market, acting as a 'gatekeeper' controlling who can access patient data. MOST STRIKINGLY, the suit specifically alleges MyChart's DEFAULT SETTINGS automatically CUT OFF A PARENT'S PROXY ACCESS to their child's health records once the child turns 12 — hiding medication lists, treatment notes, and provider messages from parents WITHOUT explicit notice, allegedly denying parental rights guaranteed under Texas law. One clinic (Austin Diagnostic Clinic) already separately settled with Texas and was required to restore parental proxy access for children 12-17. A SEPARATE federal antitrust suit (Particle Health, a competitor) was allowed to proceed by a federal judge in Sept 2025.", "Notes": "Given MyChart's near-universal use across the US healthcare system, this is arguably one of the highest-population-impact entries in this ENTIRE 500+ company tracker. The parental-access-cutoff-at-age-12 finding is particularly significant and directly actionable for any parent of a pre-teen/teen who uses MyChart — worth flagging prominently and separately from the pixel-tracking findings, since it's a distinct harm (loss of parental oversight) rather than a data-sharing issue.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Verona", "HQ State": "Wisconsin", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://themarkup.org/pixel-hunt/2022/06/16/facebook-is-receiving-sensitive-medical-information-from-hospital-websites", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Wisconsin' is a non-DMV US state", "Parent / Ultimate Owner": "Epic Systems Corporation (Verona, WI — privately held, Judith Faulkner, founder)", "Years Referenced in Finding (heuristic)": "2022, 2023", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Wisconsin DFI Corporate Records — apps.dfi.wi.gov/apps/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Epic Systems Corporation (Verona, WI — privately held, Judith Faulkner, founder)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Settled lawsuits allege Meta-Pixel tracking inside MyChart sent patient data to Meta and Google\nWHAT THE TERMS SAY: Multiple individual health systems have separately settled lawsuits alleging protected health information was transmitted to Meta/Google via tracking pixels embedded in the MyChart patient portal without consent, including SSM Health (preliminary approval Sept 2025), Catholic Health System (preliminary approval Dec 2025), and BJC HealthCare ($5.5 million, payments issued Jan 2026). Litigation has expanded to name Epic Systems itself as a direct defendant, after discovery reportedly uncovered internal Epic communications suggesting the company knew about the tracking tools and delayed removing them.\nWHY IT MATTERS: Because Epic's software underlies MyChart across roughly 39% of US hospital systems, this pixel-tracking exposure reaches an unusually large share of patients; Epic's own liability is contested, with hospitals typically the primary defendants and Epic maintaining its software is HIPAA-compliant when used correctly.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity pass 1: Hedge lost corrected))", "Top Troubling #2": "[PENDING_LITIGATION · FL-4] Texas AG suit: MyChart's default settings secretly cut off parents' access to a child's records at 12\nWHAT THE TERMS SAY: A Texas AG antitrust lawsuit filed December 10, 2025 alleges Epic monopolizes the electronic health records market and, most strikingly, that MyChart's default settings automatically cut off a parent's proxy access to their child's health records once the child turns 12, hiding medication lists, treatment notes, and provider messages from parents without explicit notice.\nWHY IT MATTERS: One clinic, Austin Diagnostic Clinic, already separately settled with Texas and was required to restore parental proxy access for children ages 12-17; parents of pre-teens using MyChart elsewhere may be unknowingly losing that same access.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Epic is rolling out mandatory arbitration for MyChart patients, with a downgraded app for those who decline\nWHAT THE TERMS SAY: As of the 2025 rollout, Epic is pushing MyChart patients to accept a binding-arbitration and class-action-waiver agreement; patients who decline are limited to a downgraded version of the app with fewer features.\nWHY IT MATTERS: Given Epic's near-monopoly market position, most patients have no practical alternative to accepting these terms if their hospital uses MyChart, effectively coercing acceptance through feature loss rather than free choice.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Multiple named settlements, lawsuits, agencies, and dollar figures are documented with specific dates, unlike most rows in this tracker.", "Exposure Score (0-100)": 54, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 4/20 (termination_or_confiscation+4) | Record 16/20 (severity4+14, litigation+2) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "MyChart (Epic Systems)  <-  Epic Systems Corporation (Verona, WI — privately held, Judith Faulkner, founder)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using MyChart (Epic Systems) you gave up your data shared corporate-wide, your right to sue, your right to join a class action, and your right to keep what you paid for. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The Markup found in June 2022 that 33 of the 100 largest US hospital systems were sending Facebook a packet of data whenever a patient clicked 'Schedule Appointment' - and in some cases tracking code sat INSIDE the password-protected patient portal, so logging in to read test results or message a doctor transmitted that activity to advertisers. In July 2023 HHS sent warning letters to roughly 130 healthcare providers about exactly this. Advocate Aurora settled for $12.25 million; other health systems have followed. Epic's own liability is genuinely contested and should be recorded as such: in most suits the hospitals that configured the tracking are the primary defendants, Epic maintains its software is HIPAA-compliant when used correctly, and courts have not uniformly resolved the question. No hacker was involved in any of it. Given that Epic software touches a very large share of US patients, the configuration decisions of individual hospitals scaled into one of the broadest health-privacy exposures on record.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 634, "_entity_id": 880, "_entity_slug": "mychart-epic-systems", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Indeed (Recruit Holdings)", "Category": "Job Search", "Terms & Conditions URL": "indeed.com/legal", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "indeed.com/legal?hl=en&co=US#privacyPolicy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Indeed collects resumes, search queries, application history, salary expectations, and employer reviews. Indeed's parent (Recruit Holdings, Tokyo) is the world's largest HR technology company. Indeed's data is used to power Recruit's analytics products across markets.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Indeed ToS, AAA rules, Texas law. 30-day opt-out. Indeed processes resumes, job-search behavior, salary expectations, and employer reviews — the arbitration clause covers disputes over how Indeed uses this employment data for its advertising model.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; Indeed's parent company Recruit Holdings (Japan) also owns Glassdoor, meaning job-search and employer-review data may be connected across the corporate family.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Austin", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Recruit Holdings Co., Ltd. (Tokyo)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Recruit Holdings Co., Ltd. (Tokyo)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Indeed's job-search data feeds parent Recruit Holdings' analytics products across markets\nWHAT THE TERMS SAY: Indeed's data is used to power Recruit Holdings' (Tokyo) analytics products across markets; Recruit, the world's largest HR technology company, also owns Glassdoor, so job-search and employer-review data may be connected across the corporate family.\nWHY IT MATTERS: A job seeker using Indeed may not realize their resume and search behavior feed a global HR-analytics business, or that it could plausibly connect to their Glassdoor activity through the shared parent company.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration and class-action waiver cover disputes over Indeed's ad use of job-search data\nWHAT THE TERMS SAY: Indeed's ToS impose mandatory binding arbitration with a class-action waiver under AAA rules and Texas law, with a 30-day opt-out window; the clause covers disputes over how Indeed uses resumes, search behavior, salary expectations, and employer reviews for its advertising model.\nWHY IT MATTERS: A user who misses the opt-out window must arbitrate individually rather than sue or join a class action over Indeed's employment-data-driven advertising practices.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] Résumé databases are routinely licensed to recruiters and employers, exposing job-search activity\nWHAT THE TERMS SAY: The tracker notes résumé databases are routinely licensed to recruiters and employers, and that a job-search platform holds a uniquely damaging combination of full employment history, salary expectations, current employer, and the fact that a person is looking for a new job.\nWHY IT MATTERS: The current employer discovering that an employee is job-hunting can cost that person their current job, yet no US privacy framework treats this relational sensitivity as a protected harm; nothing company-specific about Indeed's own licensing practices is confirmed this pass.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause and parent-company data flow are specifically described, but no company-specific breach or lawsuit is confirmed this pass.", "Exposure Score (0-100)": 33, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Indeed (Recruit Holdings)  <-  Recruit Holdings Co., Ltd. (Tokyo)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Indeed (Recruit Holdings) you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A job search platform holds a uniquely damaging combination: your full employment history, your salary expectations, your current employer, and the fact that you are looking - which is the one item that can cost you the job you currently have. Résumé databases are also routinely licensed to recruiters and employers, so the visibility settings are doing far more work than most users realise. Nothing company-specific confirmed this pass. The finding is that the sensitivity here is not medical or financial but relational, and no privacy framework in the US treats 'my employer learning I am looking' as a protected harm even though it is the concrete risk.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 635, "_entity_id": 882, "_entity_slug": "indeed-recruit-holdings", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Carta", "Category": "Equity Management", "Terms & Conditions URL": "carta.com/terms/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "carta.com/privacy-notice/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Carta processes cap table, equity compensation, 409A valuation, and fund administration data. This includes company valuations, employee stock grants, and investor ownership — some of the most sensitive private-company financial data that exists.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Carta ToS. 30-day opt-out. Carta processes cap tables, equity compensation, and valuation data for startups — the arbitration clause covers disputes over this sensitive financial data. Carta faced controversy in 2024 when a founder alleged Carta used its cap-table data to facilitate an unsolicited secondary-share sale.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The 2023 controversy (allegedly using one customer's confidential data to solicit business from that customer's own shareholders) is a genuinely concerning example of a platform potentially monetizing data beyond its stated purpose — worth flagging even though it was resolved through public apology rather than formal litigation.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Carta, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Carta, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SALE · FL-2] A founder alleged Carta used confidential cap-table data to solicit an unsolicited secondary-share sale\nWHAT THE TERMS SAY: Carta faced a controversy in which a founder alleged Carta used its cap-table data to facilitate an unsolicited secondary-share sale to that same customer's own shareholders, raising questions about whether information gathered through the cap-table business was used in a brokerage context.\nWHY IT MATTERS: This is an allegation, resolved through a public apology rather than formal litigation, but it is a genuinely concerning example of a platform potentially monetizing sensitive equity data beyond its stated purpose.\n(evidence: Arbitration | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with class-action waiver covers disputes over Carta's sensitive financial data\nWHAT THE TERMS SAY: Carta's ToS impose mandatory binding arbitration with a class-action waiver, with a 30-day opt-out window; the clause covers disputes over cap-table, equity-compensation, and valuation data.\nWHY IT MATTERS: A user who misses the opt-out window must arbitrate individually rather than sue or join a class action over how this highly sensitive private-company financial data is handled.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-4] Employees whose equity Carta manages can't accept, reject, or read the terms governing their own data\nWHAT THE TERMS SAY: Carta holds equity positions for startup employees who are not Carta's customers; the tracker frames this as a recurring structural issue where the company that buys the software is not the individual whose financial data it holds.\nWHY IT MATTERS: When the software is bought by an organisation and used on individuals, the individual has no ability to accept, reject or read the terms governing their own financial data; the tracker records this as unverified on specifics, with the structure as the point.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause and the 2024 cap-table controversy are specifically described, but the controversy itself is recorded as an allegation resolved by apology, not adjudicated.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Carta  <-  Carta, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Carta you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Carta manages cap tables, which means it holds equity positions for startup employees - people who are not Carta's customers. The company is the company; the employee is data. That distinction became concrete in the reporting around Carta's secondary-trading activity, where questions were raised about whether information gathered through the cap-table business was used in a brokerage context. The structural finding for this tracker is the one that recurs in the Duo Mobile row: when the software is bought by an organisation and used on individuals, the individual has no ability to accept, reject or read the terms governing their own financial data. Recorded as unverified on specifics; the structure is the point.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 636, "_entity_id": 884, "_entity_slug": "carta", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google Health", "Category": "Health", "Terms & Conditions URL": "See Google Health's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Google Health's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration — governed by Google's Terms of Service. 30-day opt-out for device-related disputes. Google Health collects and processes medical records, health metrics, and clinical data — the arbitration clause covers disputes over how this HIPAA-adjacent (but not always HIPAA-covered) health data is handled.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": "Google LLC, Attn: Data Protection, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA", "Legal / Privacy Contact Email": "dpo-google@google.com (primary route is the Google privacy help form)", "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alphabet Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration under Google's Terms of Service covers disputes over Google Health's medical data\nWHAT THE TERMS SAY: Google Health is governed by mandatory binding arbitration under Google's overall Terms of Service, with a 30-day opt-out for device-related disputes; the clause covers disputes over how Google Health handles medical records, health metrics, and clinical data.\nWHY IT MATTERS: A user disputing how their medical data is handled must arbitrate under Google's general terms rather than sue, unless they act within the 30-day device-dispute opt-out window.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Google Health processes clinical data that is HIPAA-adjacent but not always HIPAA-covered\nWHAT THE TERMS SAY: Google Health collects and processes medical records, health metrics, and clinical data described as 'HIPAA-adjacent (but not always HIPAA-covered)'; HIPAA governs covered entities and their business associates, and a technology company processing health data outside that relationship is largely governed by whatever it wrote in its own policy.\nWHY IT MATTERS: Users may assume health data handled by a company like Google carries the same protections as data held by their doctor, when the same regulatory-perimeter gap documented elsewhere in this tracker may apply here.\n(evidence: Arbitration | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data Sharing/Selling and the SCARY field both explicitly say nothing is confirmed this pass; only the arbitration clause and the HIPAA-perimeter question are stated with enough specificity to write up, so no third distinct item exists.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are specifically stated, but data-sharing practices and any incident history are explicitly unconfirmed this pass.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Google Health  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Google Health you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. The relevant history is that Google's health ventures have repeatedly raised the question of whether health data, once handled by an entity that is not a HIPAA covered entity, retains meaningful protection - the same regulatory-perimeter gap documented in the IQVIA row of F500 Pharma & Biotech and the ZocDoc row above. HIPAA governs covered entities and their business associates; a technology company processing health data outside that relationship is largely governed by whatever it wrote in its own policy. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 637, "_entity_id": 885, "_entity_slug": "google-health", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "TRX Force", "Category": "Fitness", "Terms & Conditions URL": "See TRX Force's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See TRX Force's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "TRX Training (Fitness Anywhere LLC)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: TRX Training (Fitness Anywhere LLC)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Every field for this row states data practices, arbitration, and fees are unconfirmed; the row explicitly warns against inflating a low-sensitivity fitness-equipment app, and the one category note (location data revealing home address/routine) is explicitly flagged as unconfirmed for TRX Force specifically rather than a company finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing, arbitration, and fees are all explicitly unconfirmed, with no company-specific terms located.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "TRX Force  <-  TRX Training (Fitness Anywhere LLC)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, TRX Force takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass, and the honest entry is that a fitness equipment and training app is a low-sensitivity row that should not be inflated. The one genuine note: workout apps that log location for outdoor activity produce movement patterns precise enough to identify a home address and a daily routine, which has caused real-world security problems in other fitness platforms. Whether TRX Force collects location is not confirmed here; the category risk is.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 638, "_entity_id": 888, "_entity_slug": "trx-force", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "ClassPass", "Category": "Fitness", "Terms & Conditions URL": "classpass.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "classpass.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach; ClassPass aggregates attendance/booking data across MANY different studios/gyms, creating a centralized fitness-activity profile spanning multiple venues that no single gym would have access to on its own.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. ClassPass ToS, AAA rules, New York law. ClassPass was acquired by Mindbody in 2021 (Vista Equity Partners). The arbitration clause covers disputes over class credits, cancellation fees, and the dynamic pricing model that charges different amounts for the same studio class.", "Fees / Billing Flags": "ClassPass has faced consumer complaints (not independently confirmed as formal litigation this pass) over CREDIT EXPIRATION policies and difficulty CANCELING subscriptions — a similar pattern to the gym-industry billing-friction findings documented in the Gyms tab of this tracker.", "Notes": "Recommend a direct follow-up given thin verification this pass; the cross-studio aggregated fitness profile is a distinctive data category worth noting.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: New York, New York (non-US)", "Parent / Ultimate Owner": "Mindbody, Inc. (Vista Equity Partners)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Mindbody, Inc. (Vista Equity Partners)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration and class-action waiver cover ClassPass credit, fee, and pricing disputes\nWHAT THE TERMS SAY: ClassPass's ToS impose mandatory binding arbitration with a class-action waiver under AAA rules and New York law, with a 30-day opt-out window; the clause covers disputes over class credits, cancellation fees, and the dynamic-pricing model that charges different amounts for the same studio class.\nWHY IT MATTERS: A member who misses the opt-out window must arbitrate individually rather than sue or join a class action over billing, credit, or dynamic-pricing disputes.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] ClassPass aggregates attendance and booking data across many independent studios into one centralized profile\nWHAT THE TERMS SAY: ClassPass aggregates attendance and booking data across many different studios and gyms, creating a centralized fitness-activity profile spanning multiple venues that no single gym would have access to on its own, and its business model requires sharing booking data with hundreds of independent studios, each with its own security posture.\nWHY IT MATTERS: None of those studio partners were individually evaluated by the member, so a booking made at one small studio can expose data to a security posture the member never assessed.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[AUTO_RENEWAL_FEES · FL-1] Consumer complaints cite credit-expiration policies and difficulty canceling ClassPass subscriptions\nWHAT THE TERMS SAY: ClassPass has faced consumer complaints, not independently confirmed as formal litigation this pass, over credit-expiration policies and difficulty canceling subscriptions.\nWHY IT MATTERS: Unused credits that expire and cancellation friction can cost members money for a service they are no longer actively using, though no formal litigation over this is confirmed.\n(evidence: Fees / Billing Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and the studio-aggregation data model are specifically described, but billing complaints are noted as not independently confirmed as formal litigation.", "Exposure Score (0-100)": 33, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "ClassPass  <-  Mindbody, Inc. (Vista Equity Partners)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using ClassPass you gave up your data shared corporate-wide, your right to sue, your right to join a class action, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. ClassPass sits at an interesting intersection for this tracker - it holds fitness attendance, location and payment data, and its business model requires sharing booking data with hundreds of independent studios, each with its own security posture and none of which the member evaluated. That is the same vendor-diffusion problem documented in the AMCA and SITA findings elsewhere in this tracker, applied to small businesses. Recommend a follow-up on studio-partner data sharing terms.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 639, "_entity_id": 890, "_entity_slug": "classpass", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Grasshopper (coding, Google)", "Category": "Education", "Terms & Conditions URL": "See Grasshopper (coding, Google)'s own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Grasshopper (coding, Google)'s own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration — governed by Google's Terms of Service. 30-day opt-out. Grasshopper is a coding-education app for beginners, primarily used by children and young adults — the arbitration clause binds a younger-skewing user base similar to Roblox and Duolingo.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration under Google's Terms of Service binds Grasshopper's younger-skewing user base\nWHAT THE TERMS SAY: Grasshopper, a coding-education app for beginners primarily used by children and young adults, is governed by mandatory binding arbitration under Google's Terms of Service, with a 30-day opt-out window.\nWHY IT MATTERS: The tracker notes this binds a younger-skewing user base, similar to Roblox and Duolingo, and that educational apps frequently attract minors, which triggers COPPA obligations and a materially different parental-consent regime that companies have repeatedly gotten wrong.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is grounded in the row's stated facts, the arbitration clause binding a younger-skewing user base; data sharing, fees, and any lawsuit or breach are all explicitly unconfirmed this pass.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause and the app's minor-skewing user base are stated, but data practices and incident history are unconfirmed.", "Exposure Score (0-100)": 17, "Exposure Band": "Low", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Grasshopper (coding, Google)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Grasshopper (coding, Google) you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Grasshopper is a Google coding-education app, and the one thing worth noting is that educational apps frequently attract minors, which triggers COPPA obligations and a materially different consent regime - parental consent rather than user agreement. Whether an app is designed for children or merely used by them is a distinction companies have repeatedly gotten wrong, and it is the basis of several FTC actions elsewhere in this space. Recorded as a structural note, not a finding.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 640, "_entity_id": 891, "_entity_slug": "grasshopper-coding-google", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "OpenStax", "Category": "Education", "Terms & Conditions URL": "See OpenStax's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See OpenStax's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — OpenStax is documented as a genuinely favorable outlier: a non-profit open educational resource with no advertising model and no data-monetization incentive. Data sharing, arbitration, and fees are all explicitly unconfirmed or not applicable, and no troubling term is stated in the row's text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No specific terms are located or confirmed this pass, though the tracker notes this reflects a low-risk nonprofit model rather than hidden practices.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "OpenStax  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, OpenStax takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass, and this is a row where the honest answer is genuinely favourable. OpenStax is a non-profit open educational resource initiative based at Rice University providing free textbooks - no advertising model, no data monetisation incentive, and a mission structurally opposed to the practices this tracker documents. Per the project guide's instruction to say so when a company looks better than its peers: this one does. The caveat is only that non-profit status is not itself a security control.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 641, "_entity_id": 892, "_entity_slug": "openstax", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Imprint", "Category": "Education", "Terms & Conditions URL": "See Imprint's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Imprint's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Imprint's co-branded credit structure lets consumers misattribute who actually holds their account data\nWHAT THE TERMS SAY: Imprint operates in co-branded credit and payments, a category where the consumer generally believes they are dealing with the retailer whose name is on the card rather than with the fintech company actually holding the account relationship.\nWHY IT MATTERS: This misattribution recurs across co-branded financial products and means consumers may direct complaints, disputes, and data requests to the wrong entity, the retailer, instead of Imprint.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is grounded in the row's text, the co-branded credit misattribution risk inherent to Imprint's business model; data sharing, arbitration, and fees are all explicitly unconfirmed this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing, arbitration, and fees are all explicitly unconfirmed, with only a structural category note located.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Imprint  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Imprint takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Imprint operates in co-branded credit and payments, which places it in a category where the consumer generally believes they are dealing with the retailer whose name is on the card rather than with the financial technology company actually holding the account relationship. That misattribution is the finding worth recording - it recurs across co-branded financial products, and it means consumers direct complaints, disputes and data requests to the wrong entity. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 642, "_entity_id": 893, "_entity_slug": "imprint", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Splitwise", "Category": "Finance/Utility", "Terms & Conditions URL": "See Splitwise's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Splitwise's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. Splitwise ToS, AAA rules. Splitwise tracks shared expenses and payment patterns within friend groups — the arbitration clause covers disputes over this social-financial-graph data.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Splitwise builds a social graph annotated with who you owe, how much, and how often\nWHAT THE TERMS SAY: Splitwise tracks shared expenses and payment patterns within friend groups, holding a dataset of who you spend money with, how often, on what, and the state of debts between you and specific named people.\nWHY IT MATTERS: This is a social graph annotated with financial detail that has obvious value for building relationship inferences, and the tracker notes its sensitivity is genuinely underappreciated by the app's own users.\n(evidence: SCARY | Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with class-action waiver covers disputes over Splitwise's social-financial-graph data\nWHAT THE TERMS SAY: Splitwise's ToS impose mandatory binding arbitration with a class-action waiver under AAA rules, with a 30-day opt-out window; the clause covers disputes over this social-financial-graph data.\nWHY IT MATTERS: A user who misses the opt-out window must arbitrate individually rather than sue or join a class action over how this friend-group financial data is handled.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct items are grounded in the row's text, the inherent sensitivity of Splitwise's social-financial dataset and its arbitration clause; data-sharing/breach history and fees are explicitly unconfirmed this pass.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause and Splitwise's core social-financial data model are specifically described, but no breach or lawsuit is confirmed this pass.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Splitwise  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Splitwise you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Splitwise holds an unusually revealing dataset for a small app: who you spend money with, how often, on what, and the state of debts between you and specific named people. That is a social graph annotated with financial detail and it has obvious value to anyone building relationship inferences. The app is genuinely useful and the sensitivity is genuinely underappreciated by its users, which is the combination worth flagging rather than any specific misconduct.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Health, Fitness & Misc Services", "_row_id": 643, "_entity_id": 894, "_entity_slug": "splitwise", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Spendee", "Category": "Finance/Budgeting", "Terms & Conditions URL": "See Spendee's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Spendee's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Data sharing, arbitration, and fees are all explicitly unconfirmed this pass; the only note in the row, about bank-aggregation intermediaries, is framed as a generic category concern with a recommended follow-up on which aggregator Spendee actually uses, not a confirmed Spendee-specific practice.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing, arbitration, and fees are all explicitly unconfirmed, with no company-specific terms located.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Spendee  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Spendee takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Personal finance apps that connect to bank accounts operate through aggregation intermediaries - the layer that actually holds the credentials or tokens - and the consumer typically never learns the aggregator's name, evaluates its security, or knows when it changes. That is the same vendor-invisibility structure documented in the AMCA row of F500 Pharma & Health Services, applied to banking. Recommend a follow-up on which aggregation provider Spendee uses and under what terms.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 644, "_entity_id": 895, "_entity_slug": "spendee", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "PhysiApp", "Category": "Physical Therapy", "Terms & Conditions URL": "See PhysiApp's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See PhysiApp's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] PhysiApp's rehabilitation-adherence data is functionally clinical but may sit outside the HIPAA perimeter\nWHAT THE TERMS SAY: PhysiApp is a physiotherapy exercise-prescription app, meaning the data it holds — a user's injury, prescribed rehabilitation, and adherence to it — is functionally clinical, while the app itself may or may not sit inside the HIPAA perimeter depending on how the clinician's relationship with the vendor is structured.\nWHY IT MATTERS: Adherence data specifically has value to insurers and to opposing parties in injury litigation; the regulatory-perimeter question is the finding, and no misconduct is asserted.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is grounded in the row's text, the clinical nature of PhysiApp's rehabilitation-adherence data and its regulatory-perimeter ambiguity; arbitration and fees are both explicitly unconfirmed this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration and fees are explicitly unconfirmed; only a structural regulatory-perimeter question is located.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "PhysiApp  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, PhysiApp takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. PhysiApp is a physiotherapy exercise-prescription app, which means the data it holds is functionally clinical - your injury, your prescribed rehabilitation, your adherence to it - while the app itself may or may not sit inside the HIPAA perimeter depending on how the clinician's relationship with the vendor is structured. Adherence data specifically has value to insurers and to opposing parties in injury litigation. The regulatory-perimeter question is the finding; no misconduct is asserted.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 645, "_entity_id": 896, "_entity_slug": "physiapp", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Proton VPN", "Category": "VPN", "Terms & Conditions URL": "protonvpn.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "protonvpn.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Same parent company (Proton AG, Switzerland) as Proton Mail, documented in the Email Providers tab of this tracker — shares the same Swiss jurisdiction/Federal Data Protection Act advantages and the same unverified claim about EU funding raised in that row. Proton VPN specifically maintains a published, independently-audited NO-LOGS policy — a genuine differentiator from some other VPN providers in this tracker (compare to NordVPN/ExpressVPN's ownership-transparency concerns, Gig Economy tab), though no VPN provider's no-logs claim can be verified with absolute certainty by an outside party.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Proton AG (Geneva, Switzerland) ToS governed by Swiss law. No US-style arbitration clause. Consistent with Proton Mail's posture (also in this tracker). Proton's entire product suite (Mail, VPN, Drive, Calendar) is governed by Swiss privacy law, which provides stronger protections than US law.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Proton Mail row (Email Providers tab) for the fuller treatment of Proton AG's Swiss jurisdiction advantages that apply equally to Proton VPN.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2021", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[OTHER · FL-3] Proton VPN's no-logs promise describes defaults, not what Swiss courts can compel it to disclose\nWHAT THE TERMS SAY: Proton VPN publishes an independently audited no-logs policy under Swiss jurisdiction (Proton AG, Geneva); the tracker notes that Swiss authorities previously legally compelled a sister Proton service to log and hand over a specific user's IP address and browser fingerprint, with no right of appeal, before Proton won an October 2021 ruling limiting that power for email services specifically.\nWHY IT MATTERS: A no-logs claim can only describe what a provider retains by default, not what a court may compel it to capture prospectively for a specific account; the tracker states this limit still applies to Proton VPN even though Proton is described as one of the better-behaved operators in this space.\n(evidence: SCARY | Data Sharing; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is grounded in facts stated for this row, the jurisdictional limit on Proton VPN's no-logs promise. The row has no mandatory arbitration clause, no fees issues, and no VPN-specific breach or lawsuit; its Swiss-jurisdiction advantages and EU-funding claim are documented in the separate Proton Mail row rather than confirmed independently here.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Proton VPN's jurisdiction, audit history, and the stated limits of its no-logs claim are all specifically documented rather than hedged.", "Exposure Score (0-100)": 8, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Proton VPN  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Proton VPN takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same parent as Proton Mail, and the Proton Mail row in the Email Providers tab documents the case that matters: Swiss authorities compelled Proton to log and hand over an IP address and browser fingerprint for a specific account, Proton could not appeal, and it then rewrote its policy to state the limit and won an October 2021 Swiss ruling that email services are not telecommunications providers subject to data retention. For the VPN specifically, the honest reading is that a no-logs claim describes what a provider retains by default and cannot describe what a court may compel prospectively. Proton is among the better-behaved operators in this space and that limit still applies to it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Health, Fitness & Misc Services", "_row_id": 646, "_entity_id": 897, "_entity_slug": "proton-vpn", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Robeks", "Category": "Restaurant", "Terms & Conditions URL": "See Robeks's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Robeks's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — The row explicitly warns against inflating a small franchise into a privacy finding; data sharing, arbitration, and fees are all unconfirmed, and the only note (loyalty-program data sharing via a third-party platform) is generic industry commentary, not a confirmed Robeks-specific practice.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing, arbitration, and fees are all explicitly unconfirmed, with no company-specific terms located.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Robeks  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Robeks takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass, and inflating a juice and smoothie franchise into a privacy finding would be exactly the manufactured drama the project guide warns against. The one legitimate note is loyalty programmes: franchise reward apps collect purchase history and location across independently owned locations, often through a third-party loyalty platform the customer never sees named. Low stakes, real structure, recorded honestly.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 647, "_entity_id": 898, "_entity_slug": "robeks", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Madabolic", "Category": "Fitness Studio", "Terms & Conditions URL": "See Madabolic's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Madabolic's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — The row explicitly states no privacy finding is asserted here; data sharing, arbitration, and fees are all unconfirmed, and the only note concerns generic gym-membership cancellation friction rather than data handling.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing, arbitration, and fees are all explicitly unconfirmed, with no company-specific terms located.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Madabolic  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Madabolic takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Madabolic is a boutique fitness franchise, and the relevant category note is the one applying to every gym in this tracker: membership agreements are among the most complained-about consumer contracts in existence, and the recurring problem is cancellation friction rather than data handling. Cross-ref the gym rows in the Gyms & Home-Auto Insurance tab. No privacy finding is asserted here.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 648, "_entity_id": 899, "_entity_slug": "madabolic", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Nordstrom Rack", "Category": "Retail", "Terms & Conditions URL": "See Nordstrom Rack's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Nordstrom Rack's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. Nordstrom Inc. ToS, AAA rules, Washington state law (Nordstrom HQ: Seattle). Covers both Nordstrom.com and Nordstrom Rack, including the Nordy Club loyalty program. Nordstrom went private in March 2025 ($6.25B, Nordstrom family + El Puerto de Liverpool), which removes SEC reporting obligations and may affect data-transparency commitments.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$15.0B", "Market Cap": "Non-public", "Employees": "41,000", "HQ City": "Seattle", "HQ State": "Washington", "CEO": "Erik Nordstrom", "Ticker": "Non-public", "Website (Corporate)": "nordstrom.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (Non-public). Service route: c/o General Counsel / Corporate Secretary, Seattle, Washington — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration with class-action waiver covers Nordstrom.com, Rack, and the Nordy Club loyalty program\nWHAT THE TERMS SAY: Nordstrom Inc.'s ToS impose mandatory binding arbitration with a class-action waiver under AAA rules and Washington state law, with a 30-day opt-out window, covering both Nordstrom.com and Nordstrom Rack, including the Nordy Club loyalty program.\nWHY IT MATTERS: A shopper who misses the opt-out window must arbitrate individually rather than sue or join a class action over loyalty-program or purchase-data disputes across either brand.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Rack loyalty and payment data feeds the same parent-company customer profile as full-line Nordstrom\nWHAT THE TERMS SAY: Off-price retail loyalty and payment data feeds the same parent-company customer profile as the full-line stores; retail analytics increasingly link in-store purchases to online identity through payment-card matching, which no signage discloses.\nWHY IT MATTERS: A customer who shops Rack believing it to be a separate, more anonymous experience is in the same customer record as full-price Nordstrom shoppers.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[OTHER · FL-4] Nordstrom going private in 2025 removes SEC reporting that may affect data-transparency commitments\nWHAT THE TERMS SAY: Nordstrom went private in March 2025 ($6.25B, Nordstrom family + El Puerto de Liverpool), which removes SEC reporting obligations and may affect data-transparency commitments.\nWHY IT MATTERS: Without public-company disclosure requirements, customers and regulators may have less visibility into how Nordstrom's data practices evolve going forward; the tracker hedges this as a possible effect, not a confirmed change.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause and going-private structure are specifically described, but no breach or lawsuit is confirmed this pass.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Nordstrom Rack  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Nordstrom Rack you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. The retail-specific note worth recording is that off-price retail loyalty and payment data feeds the same parent-company profile as the full-line stores, so a customer who shops Rack believing it to be a separate, more anonymous experience is in the same customer record. Retail analytics also increasingly link in-store purchases to online identity through payment card matching, which no signage discloses. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 649, "_entity_id": 900, "_entity_slug": "nordstrom-rack", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Mixbook", "Category": "Photo/Printing", "Terms & Conditions URL": "See Mixbook's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Mixbook's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. 30-day opt-out. Mixbook ToS, AAA rules, California law. Mixbook processes personal photos uploaded for photo books and cards — the arbitration clause covers disputes over how these intimate family photos are stored and potentially used for AI training.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration covers disputes over storage and potential AI training use of uploaded family photos\nWHAT THE TERMS SAY: Mixbook's ToS impose mandatory binding arbitration with a class-action waiver under AAA rules and California law, with a 30-day opt-out window; the clause covers disputes over how these intimate family photos are stored and potentially used for AI training.\nWHY IT MATTERS: A user who misses the opt-out window must arbitrate individually rather than sue or join a class action over how uploaded family photos are stored or used for AI training.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[AI_TRAINING · FL-2] Mixbook's own arbitration clause flags potential AI training use of uploaded family photos\nWHAT THE TERMS SAY: The arbitration clause's own scope description references potential AI training use of the intimate family photos customers upload for photo books and cards.\nWHY IT MATTERS: Users uploading family photo books may not expect their images could be used to train AI systems; the tracker notes this is a described possibility in the clause's scope, not a confirmed practice.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[BIOMETRICS · FL-2] Photo book services often apply facial detection to family photos, a category with real legal exposure\nWHAT THE TERMS SAY: Photo book services hold uploaded family photographs, often including children, often captioned with names, dates, and locations, and many such services apply facial detection to help with layout and grouping; whether Mixbook itself performs facial detection is not confirmed this pass.\nWHY IT MATTERS: Given large recent settlements over facial-grouping features on uploaded photos elsewhere in this tracker, any consumer service performing face analysis on uploaded photos sits in a category with real and recently demonstrated legal exposure.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The arbitration clause is specifically stated, but whether Mixbook performs facial detection or AI training is explicitly unconfirmed and flagged for follow-up.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Mixbook  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Mixbook you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Photo book services hold a genuinely distinctive dataset - uploaded family photographs, often including children, often with names, dates and locations typed in by the customer as captions - and many such services apply facial detection to help with layout and grouping. Given the $1.375 billion Texas settlement and the $100 million Illinois BIPA settlement over Google Photos face grouping documented in the Productivity tab, any consumer service performing face analysis on uploaded photos sits in a category with real and recently demonstrated legal exposure. Recommend a follow-up on whether Mixbook performs facial detection and under what consent basis.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 650, "_entity_id": 901, "_entity_slug": "mixbook", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Inova Health System", "Category": "Health System (nonprofit)", "Terms & Conditions URL": "https://www.inova.org/terms-use", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.inova.org/privacy-policy", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "Inova is a nonprofit health system operating 5 hospitals and 100+ care sites across Northern Virginia (Fairfax, Falls Church, Alexandria, Leesburg, Mount Vernon). As a HIPAA-covered entity, patient data is governed by HIPAA + Virginia's Consumer Data Protection Act (VCDPA). Inova's genomic research partnership with the University of Virginia creates a data-sharing pathway between clinical records and research databases that patients may not expect from a community hospital system.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Inova is a Virginia nonprofit health system. Patient disputes are governed by Virginia medical-malpractice law (including the Virginia Birth-Related Neurological Injury Compensation Program, which replaces tort litigation for certain birth injuries). Website ToS are minimal. Virginia's medical-malpractice cap ($2.55M as of 2024) applies.", "Fees / Billing Flags": "Nonprofit hospital system — no subscription fees. Patient billing disputes governed by Virginia's Surprise Billing Act and federal No Surprises Act (effective 2022).", "Notes": "DMV's largest health system by NoVA market share. Inova Fairfax Medical Center is the region's Level I trauma center. Inova Genomics operates one of the largest clinical genomics programs in the mid-Atlantic. The genomic data collected through Inova's research partnerships is among the most sensitive health data any DMV institution holds.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Falls Church", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Added 2026-08-06 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Falls Church, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "Inova Health System Foundation (Virginia nonprofit)", "Years Referenced in Finding (heuristic)": "2022, 2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Inova Health System Foundation (Virginia nonprofit)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Inova's UVA genomic research partnership creates a data pathway patients may not anticipate\nWHAT THE TERMS SAY: Inova's genomic research partnership with the University of Virginia creates a data-sharing pathway between clinical records and research databases that a patient checking into an Inova facility may not anticipate.\nWHY IT MATTERS: As HIPAA and Virginia's Consumer Data Protection Act govern this data, the pathway is legal, but the tracker flags it as something patients receiving routine care may not expect from a community hospital system.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[LIABILITY_CAP_INDEMNITY · FL-1] Virginia's malpractice cap and no-fault birth-injury program limit patients' compensation options\nWHAT THE TERMS SAY: Patient disputes at Inova are governed by Virginia medical-malpractice law, including a $2.55 million cap (as of 2024, rising over time) and the Virginia Birth-Related Neurological Injury Compensation Program, which replaces tort litigation entirely with a no-fault system for certain birth injuries.\nWHY IT MATTERS: Patients harmed by an Inova facility face a statutory ceiling on compensation, and parents of certain birth-injured infants lose the ability to sue in tort at all, receiving no-fault compensation instead.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct items are grounded in stated facts, the UVA genomic research data-sharing pathway and Virginia's medical-malpractice liability cap and no-fault birth-injury framework; Inova has no arbitration clause, and no billing fees or confirmed incident are stated in the row.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The row describes Inova's legal and data-sharing framework in specific, sourced detail rather than hedged 'not confirmed' language.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Inova Health System  <-  Inova Health System Foundation (Virginia nonprofit)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action; your right to stop paying by inaction.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Inova Health System you gave up your data shared corporate-wide and your right to meaningful compensation. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Inova Health System operates Northern Virginia's dominant hospital network — 5 hospitals, 100+ care sites, the region's only Level I trauma center (Inova Fairfax), and one of the largest clinical genomics programs in the mid-Atlantic. As a nonprofit HIPAA-covered entity, Inova's patient data governance is structurally different from every for-profit consumer company in this tracker: no mandatory arbitration, no class action waiver, and disputes go through Virginia's medical-malpractice framework rather than private AAA/JAMS proceedings. The Virginia Birth-Related Neurological Injury Compensation Program replaces tort litigation entirely for certain birth injuries — a no-fault system that exists nowhere else in the DMV corridor. Inova's genomic research partnership with UVA creates a data pathway between clinical records and academic research databases that a patient checking into Inova Fairfax ER may not anticipate. Virginia's medical-malpractice cap ($2.55M, rising $50K/year) applies to all Inova facilities.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 651, "_entity_id": 903, "_entity_slug": "inova-health-system", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "MedStar Health", "Category": "Health System (nonprofit)", "Terms & Conditions URL": "https://www.medstarhealth.org/terms-of-use", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://www.medstarhealth.org/privacy-policy", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "MedStar is the largest healthcare provider in the DC/Maryland region — 10 hospitals, 300+ care sites. HIPAA-covered entity. MedStar's 2016 ransomware attack (one of the first major hospital ransomware incidents in the US) forced the system to operate on paper for days. MedStar Georgetown University Hospital's affiliation with Georgetown University creates a clinical-research data-sharing pathway.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — MedStar is a Maryland/DC nonprofit health system. Patient disputes governed by Maryland medical-malpractice law and DC malpractice law (different frameworks for facilities in each jurisdiction). No website arbitration clause.", "Fees / Billing Flags": "Nonprofit hospital system. Patient billing governed by Maryland's unique all-payer rate-setting system (the Health Services Cost Review Commission sets hospital rates — Maryland is the ONLY state where hospital prices are set by a government commission, not the market).", "Notes": "Largest healthcare provider in the DC/Maryland region. 10 hospitals including MedStar Washington Hospital Center (DC's largest hospital), MedStar Georgetown University Hospital, and MedStar Union Memorial. The 2016 ransomware attack was a landmark incident in healthcare cybersecurity.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Columbia", "HQ State": "Maryland", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Added 2026-08-06 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Columbia, Maryland (DC/MD/VA)", "Parent / Ultimate Owner": "MedStar Health, Inc. (Maryland nonprofit)", "Years Referenced in Finding (heuristic)": "2016", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Maryland SDAT Business Entity Search — egov.maryland.gov/businessexpress/entitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: MedStar Health, Inc. (Maryland nonprofit)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] MedStar's 2016 ransomware attack was one of the first major hospital ransomware incidents in the US\nWHAT THE TERMS SAY: In March 2016, MedStar was hit by one of the first major hospital ransomware attacks in the US, forcing clinical staff to operate on paper records for days, a patient-safety crisis that predated the Change Healthcare and Universal Health Services attacks by years.\nWHY IT MATTERS: Operating on paper for days at a 10-hospital system is a direct patient-safety impact, not just a data-privacy one, and the incident helped establish ransomware as a healthcare-specific threat category.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] MedStar Georgetown's university affiliation creates a clinical-research data-sharing pathway\nWHAT THE TERMS SAY: MedStar Georgetown University Hospital's affiliation with Georgetown University creates a clinical-research data-sharing pathway.\nWHY IT MATTERS: Patients at MedStar Georgetown may not realize their clinical data can flow into a university research context through this affiliation.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct items are grounded in stated facts, the 2016 ransomware breach and the Georgetown University clinical-research data-sharing pathway; MedStar has no arbitration clause, and Maryland's all-payer rate-setting and dual malpractice frameworks are described as consumer protections rather than troubling terms.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The 2016 ransomware breach and MedStar's legal framework are documented with specific, sourced detail.", "Exposure Score (0-100)": 15, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "MedStar Health  <-  MedStar Health, Inc. (Maryland nonprofit)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using MedStar Health you gave up your data shared corporate-wide. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "MedStar Health is the DMV's largest healthcare provider — 10 hospitals, 300+ care sites across DC and Maryland, including DC's largest hospital (MedStar Washington Hospital Center) and Georgetown University Hospital. In March 2016, MedStar was hit by one of the first major hospital ransomware attacks in the US, forcing clinical staff to operate on paper records for days — a patient-safety crisis that predated the Change Healthcare and Universal Health Services attacks by years and helped establish ransomware as a healthcare-specific threat category. MedStar operates under TWO different medical-malpractice legal frameworks simultaneously: Maryland law (with its unique all-payer rate-setting commission — the ONLY state where a government body sets hospital prices) for its Maryland facilities, and DC law for its District facilities. No mandatory arbitration. Maryland's Health Services Cost Review Commission means MedStar Georgetown and MedStar Union Memorial cannot charge different rates for the same procedure — a structural consumer protection that exists nowhere else in the US.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Health, Fitness & Misc Services", "_row_id": 652, "_entity_id": 905, "_entity_slug": "medstar-health", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "ETS GRE app", "Category": "Education/Test Prep", "Terms & Conditions URL": "ets.org/legal/terms-of-use.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "ets.org/legal/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ETS (Educational Testing Service, administering the GRE) collects extensive personal/academic data including test scores, disability-accommodation requests (which can reveal health/disability status), and identity-verification data (photo ID, sometimes biometric verification during test-taking to prevent fraud). No specific named lawsuit or breach independently confirmed this pass.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The disability-accommodation request data is a genuinely sensitive category worth flagging — recommend a direct follow-up on ETS's specific data-retention/sharing practices for this category given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Princeton", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Princeton, New Jersey (non-US)", "Parent / Ultimate Owner": "Educational Testing Service (nonprofit)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NJ Business Records Service — businessrecords.nj.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Educational Testing Service (nonprofit)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] ETS collects disability-accommodation requests and sometimes biometric identity verification for the GRE\nWHAT THE TERMS SAY: ETS collects extensive personal and academic data including test scores, disability-accommodation requests (which can reveal health/disability status), and identity-verification data including photo ID and, in some implementations, biometric verification during test-taking to prevent fraud.\nWHY IT MATTERS: Disability-accommodation requests are a genuinely sensitive category since they can reveal health status, and biometric identity verification adds another sensitive data type to a mandatory academic gatekeeping process.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-2] At-home GRE proctoring requires camera, mic, and room-scan access, with no way to decline and still test\nWHAT THE TERMS SAY: The GRE's at-home testing model requires camera and microphone access, a scan of the room the candidate is sitting in, and in many implementations behavioral monitoring of eye and body movement flagged as suspicious by software; candidates cannot decline any of it and still sit the test.\nWHY IT MATTERS: Because the test is a gate to graduate education, candidates have no real choice about accepting this surveillance; the tracker states nothing is confirmed against ETS specifically this pass and frames the consent architecture itself, not a proven misuse, as the finding.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Two items are grounded in the row's stated facts, ETS's sensitive data categories and its remote-proctoring surveillance architecture; arbitration is explicitly unconfirmed and no lawsuit or breach is documented in the row.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "ETS's data categories and proctoring architecture are specifically described, but arbitration terms and any incident history are unconfirmed.", "Exposure Score (0-100)": 8, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 6/30 (biometric_collection+6) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only", "Entity Type": "Company", "Ownership Path": "ETS GRE app  <-  Educational Testing Service (nonprofit)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using ETS GRE app you gave up your biometric identifiers. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The GRE's at-home testing model turned a standardised exam into a home surveillance session: remote proctoring requires camera and microphone access, a scan of the room the candidate is sitting in, and in many implementations behavioural monitoring of eye and body movement flagged as suspicious by software. Candidates cannot decline any of it and still sit the test, and the test is a gate to graduate education - which is coercion by structure rather than by any term in the agreement. ETS also holds score history tied to identity indefinitely. Nothing confirmed against ETS this pass; the consent architecture is the finding.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Niche Apps & Games", "_row_id": 653, "_entity_id": 907, "_entity_slug": "ets-gre-app", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Playground AI", "Category": "AI Image Generation", "Terms & Conditions URL": "playground.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "playground.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "As an AI IMAGE-GENERATION platform, Playground faces the same general category of concerns as other generative-AI tools: uploaded reference images/photos may be used to train or fine-tune AI models absent an explicit opt-out, and generated content raises separate (non-privacy) copyright/likeness questions if used to recreate real people's images. No specific named lawsuit or breach independently confirmed this pass.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up on Playground's specific AI-training data-use policy given how quickly generative-AI terms of service are evolving across this whole industry.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Palo Alto", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Playground AI, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Playground AI, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AI_TRAINING · FL-2] Uploaded reference photos on Playground AI may be used to train models absent an explicit opt-out\nWHAT THE TERMS SAY: As an AI image-generation platform, Playground faces the same category of concerns as other generative-AI tools: uploaded reference images or photos may be used to train or fine-tune AI models absent an explicit opt-out.\nWHY IT MATTERS: Users upload personal photographs to generate images of themselves, meaning faces and likenesses may enter a training or processing pipeline whose terms most users do not read, in a category that has produced large facial-processing settlements elsewhere.\n(evidence: Data Sharing | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is grounded in the row's text, the possible AI-training use of uploaded reference photos; arbitration is explicitly unconfirmed and no lawsuit or breach exists in the row's text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration is explicitly unconfirmed, and the AI-training practice itself is hedged as a category concern rather than a confirmed Playground-specific policy.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Playground AI  <-  Playground AI, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Playground AI takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. AI image generation sits in the same unresolved copyright and training-data territory documented across the LLM Providers tab, and the consumer-specific exposure is different from the artist-facing one: users upload personal photographs to generate images of themselves, which means faces and likenesses enter a training or processing pipeline whose terms most users do not read. Facial processing of uploaded photos is the same operation that produced the $100 million Illinois BIPA settlement over Google Photos. Recommend a follow-up on upload retention and training use.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Niche Apps & Games", "_row_id": 654, "_entity_id": 909, "_entity_slug": "playground-ai", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "DJI GO / DJI Fly", "Category": "Drone Software", "Terms & Conditions URL": "dji.com/policy/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "dji.com/policy/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MAJOR, YEARS-LONG NATIONAL SECURITY CONTROVERSY: DJI (the world's largest drone maker, ~70% global civilian market share) has been placed on the US Commerce Department's ENTITY LIST (2020) over documented ties to human-rights abuses — including footage from a DJI drone reportedly used to document forced marches of shackled, blindfolded Uyghur detainees in Xinjiang, China. The US Army banned DJI drones outright (2017) citing 'cyber vulnerabilities'; DHS/FBI have separately warned Chinese-made drones may expose 'sensitive information to PRC authorities' under China's National Intelligence Law, which legally obligates Chinese companies to cooperate with government data requests. As of DECEMBER 2025, the FCC banned ALL future authorizations for foreign-made drones (effectively including all future DJI models) from operating on US communications infrastructure; multiple states (Arkansas, Florida, Mississippi, Tennessee) have separately banned state-agency use of Chinese-made drones specifically.", "Arbitration / Class Action Waiver": "SEPARATE, GENUINELY BALANCING FINDING: MULTIPLE INDEPENDENT SECURITY AUDITS (Kivu Consulting, FTI Consulting, Booz Allen Hamilton, and US government entities including the Department of the Interior and Idaho National Laboratory) have found NO EVIDENCE that DJI drones transmit US customer data to China — confirming that data collected in the US is stored on US-based servers, and that DJI's 'Local Data Mode' fully air-gaps the drone from any internet connection when enabled. DJI has publicly argued that competing US drone manufacturers are lobbying heavily for bans specifically to eliminate cheaper, more capable Chinese competition, a claim DJI's critics dispute.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is one of the most GENUINELY CONTESTED, POLITICALLY CHARGED findings in this entire tracker: serious national-security concerns and documented human-rights connections exist on one side, while MULTIPLE independent technical audits have found no evidence of the specific data-transmission-to-China allegation on the other. Worth presenting both sides fairly — the human-rights/Uyghur-footage concern and the specific 'sends your data to China' claim are DISTINCT allegations with different levels of evidentiary support, and shouldn't be conflated.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-3] US and state governments have progressively restricted DJI drones on national-security grounds\nWHAT THE TERMS SAY: DJI was placed on the US Commerce Department's Entity List (2020); the US Army banned DJI drones outright in 2017 citing 'cyber vulnerabilities'; the FCC banned all future authorizations for foreign-made drones (effectively including future DJI models) from operating on US communications infrastructure as of December 2025; and multiple states (Arkansas, Florida, Mississippi, Tennessee) have separately banned state-agency use of Chinese-made drones.\nWHY IT MATTERS: These are governmental determinations and restrictions, not adjudicated findings of misuse; as recorded they reach future FCC authorizations for foreign-made drones on US communications infrastructure, US Army use, and state-agency use in Arkansas, Florida, Mississippi and Tennessee.\n(evidence: Data Sharing | Fees / Billing Flags; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[LOCATION_TRACKING · FL-3] DJI flight logs are precise 3D location histories, and China's National Intelligence Law obligates cooperation\nWHAT THE TERMS SAY: DJI flight logs record precise three-dimensional location histories with timestamps, plus captured imagery and the operator's identity from account registration; DHS and FBI have warned Chinese-made drones may expose 'sensitive information to PRC authorities' under China's National Intelligence Law, which legally obligates Chinese companies to cooperate with government data requests.\nWHY IT MATTERS: A hobbyist's flight log can describe their home, their neighbors' property, and their daily routine; the tracker also notes multiple independent security audits (Kivu, FTI, Booz Allen Hamilton, and US government entities including the Department of the Interior and Idaho National Laboratory) found no evidence DJI drones transmit US customer data to China, and that DJI's Local Data Mode fully air-gaps the drone when enabled.\n(evidence: SCARY | Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-2] DJI's Entity List placement followed human-rights ties, a distinct allegation from the data-transfer claim\nWHAT THE TERMS SAY: DJI's placement on the Entity List followed documented ties to human-rights abuses, including footage from a DJI drone reportedly used to document forced marches of shackled, blindfolded Uyghur detainees in Xinjiang, China.\nWHY IT MATTERS: The tracker stresses this human-rights allegation and the separate 'sends your data to China' claim have different levels of evidentiary support and should not be conflated; both are recorded honestly rather than merged into one narrative.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The row documents specific agencies, dates, and audits on both sides of a well-sourced, actively contested controversy.", "Exposure Score (0-100)": 9, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 5/20 (severity2+2, penalty+3) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent", "Entity Type": "Company", "Ownership Path": "DJI GO / DJI Fly  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using DJI GO / DJI Fly you gave up your physical movements. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "DJI has been the subject of a years-long national security controversy and US restrictions, and the consumer-facing detail that gets lost in it is what a drone app actually holds: flight logs are precise three-dimensional location histories with timestamps, plus the imagery captured along the way, plus the operator's identity from account registration. A hobbyist's flight log describes their home, their neighbours' property and their routine. DJI is a Chinese company, so the structural analysis in the DeepSeek and Moonshot rows of the LLM Providers tab applies - national security and intelligence law obligations that no terms of service can contract around. Restrictions are governmental determinations, not adjudicated findings of misuse, and the distinction should be preserved.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Niche Apps & Games", "_row_id": 655, "_entity_id": 910, "_entity_slug": "dji-go-dji-fly", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Scrabble (EA/Mattel)", "Category": "Gaming", "Terms & Conditions URL": "ea.com/legal/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "ea.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Governed by Electronic Arts' overall data practices (EA licenses the digital Scrabble app from Mattel) — EA has faced separate, unrelated 'loot box'-style gambling-adjacent scrutiny in other games (documented in the general gaming-industry FTC enforcement pattern noted in the Fortnite/Epic Games row, Consumer Apps tab), though no Scrabble-specific lawsuit independently confirmed this pass.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the general gaming-industry COPPA/loot-box enforcement pattern documented in the Fortnite/Epic Games row.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Redwood City", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Electronic Arts Inc. (license from Mattel/Hasbro)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Electronic Arts Inc. (license from Mattel/Hasbro)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[OTHER · FL-4] A Mattel board game licensed to EA means the brand on the box tells you nothing about who holds your data\nWHAT THE TERMS SAY: Scrabble is a Mattel board game licensed to Electronic Arts and delivered as a mobile app, meaning the player's data is governed by a games publisher's terms, not a toy company's.\nWHY IT MATTERS: A player recognizing the Mattel/Scrabble brand may not realize Electronic Arts, not Mattel, actually holds and governs their data under EA's own broader data practices.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Mobile monetization SDKs build a behavioral and spending profile of Scrabble's older-skewing player base\nWHAT THE TERMS SAY: Mobile game monetization depends on advertising SDKs and in-app-purchase telemetry, so a casual word game generates a behavioral and spending profile; word games skew heavily toward older players, a demographic the tracker describes as both over-targeted by advertisers and under-served by privacy guidance.\nWHY IT MATTERS: The tracker describes older players as a demographic both over-targeted by advertisers and under-served by privacy guidance, so the behavioural and spending profile a casual word game generates falls on the group receiving the least privacy guidance.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct items are grounded in the row's text, the publisher/brand misattribution and the SDK-driven behavioral profiling of an older player base; arbitration is explicitly unconfirmed and no Scrabble-specific lawsuit is confirmed (the general EA loot-box scrutiny referenced is documented in another company's row, not as a Scrabble-specific finding).", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The publisher structure and mobile-monetization mechanics are specifically described, but arbitration and any Scrabble-specific incident are unconfirmed.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Scrabble (EA/Mattel)  <-  Electronic Arts Inc. (license from Mattel/Hasbro)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Scrabble (EA/Mattel) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Governed by Electronic Arts' overall data practices, and the finding is the layering: a Mattel board game licensed to EA and delivered as a mobile app means the player's data is governed by a games publisher's terms, not a toy company's, and the brand on the box tells you nothing about who holds the record. Mobile game monetisation also depends on advertising SDKs and in-app purchase telemetry, so a casual word game generates a behavioural and spending profile. Word games skew heavily toward older players, a demographic that is both over-targeted by advertisers and under-served by privacy guidance.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Niche Apps & Games", "_row_id": 656, "_entity_id": 912, "_entity_slug": "scrabble-ea-mattel", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "I Love Hue Too", "Category": "Gaming", "Terms & Conditions URL": "zutrix.com/terms (independent developer app; exact publisher terms not independently confirmed)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "zutrix.com/privacy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach; a small, independently-developed puzzle game with a correspondingly limited data-collection footprint compared to most other apps in this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; as a small independent game, this carries a fundamentally lower data-collection profile than most other entries in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — The row explicitly warns against inflating a small independent puzzle game; data sharing, arbitration, and fees are all unconfirmed, and the only note (SDK-funded ad monetization risk) is generic category commentary cross-referencing another company's finding, not a confirmed practice specific to this app.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing, arbitration, and fees are all explicitly unconfirmed, with no company-specific terms located.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "I Love Hue Too  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, I Love Hue Too takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. A small puzzle app is a low-stakes row and inflating it would degrade the tracker. The one legitimate category note: independent mobile games are frequently funded entirely by embedded advertising and analytics SDKs, which means the developer's own privacy posture is nearly irrelevant compared to the third-party code they included to get paid. That is the same SDK-supply-chain structure documented concretely in the Allstate/Arity finding in the Insurance tab, where the SDK vendor paid developers to embed it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Niche Apps & Games", "_row_id": 657, "_entity_id": 913, "_entity_slug": "i-love-hue-too", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Vivino", "Category": "Wine/Retail", "Terms & Conditions URL": "vivino.com/legal/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "vivino.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Vivino's core feature (scanning wine labels via camera for ratings/purchase) collects photo/image data plus a detailed personal profile of ALCOHOL CONSUMPTION habits and preferences — a distinctive and potentially sensitive lifestyle-data category (relevant to insurance underwriting, employment background checks, or health-related inferences) not typical of most consumer apps. No specific named lawsuit or breach independently confirmed this pass.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The detailed alcohol-consumption-habit profile Vivino builds is worth flagging as a distinctive sensitive-data category — recommend a direct follow-up on Vivino's specific data-sharing partners given how this data could plausibly be valuable to insurers or other third parties.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Vivino's label-scanning feature builds a longitudinal alcohol-consumption profile tied to time and location\nWHAT THE TERMS SAY: Vivino's core feature, scanning wine labels via camera for ratings and purchase, collects photo/image data plus a detailed personal profile of alcohol-consumption habits and preferences, producing a purchase-intent and consumption record tied to location and time.\nWHY IT MATTERS: Alcohol-consumption data is health-adjacent, employment-relevant, and insurance-relevant, yet it sits entirely outside any health-privacy perimeter because it was generated by a shopping app; users experience it simply as a wine journal.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is grounded in confirmed company facts, Vivino's core label-scanning feature and the resulting alcohol-consumption profile; arbitration is explicitly unconfirmed and no lawsuit or breach exists in the row's text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Vivino's core data-collecting feature is clearly described, but arbitration terms and any incident history are explicitly unconfirmed.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Vivino  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Vivino takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Vivino's core feature is scanning a wine label with the camera, which produces a purchase-intent and consumption record tied to location and time - a longitudinal log of what and how much a person drinks. Alcohol consumption data is health-adjacent, employment-relevant and insurance-relevant, and it sits entirely outside any health privacy perimeter because it was generated by a shopping app. Users experience it as a wine journal. Nothing confirmed this pass; the inference surface is the finding.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Niche Apps & Games", "_row_id": 658, "_entity_id": 914, "_entity_slug": "vivino", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "GRIS", "Category": "Gaming", "Terms & Conditions URL": "See Devolver Digital / Nomada Studio's published terms", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See publisher's published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach; GRIS is a narrative-driven single-player indie game with minimal online/data-collection functionality compared to most other apps in this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "As a largely OFFLINE, single-player indie game, this carries one of the LOWEST data-collection profiles of any entry in this entire tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — GRIS is documented as a genuinely favorable outlier: a premium single-purchase indie game with no advertising model, minimal telemetry, and no ongoing service component. No troubling term is stated in the row's text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No specific terms are located, though the tracker notes this reflects a low-risk, largely offline single-player model rather than hidden practices.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "GRIS  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, GRIS takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. GRIS is a premium single-purchase indie game with no advertising model and no ongoing service component, which places it among the cleanest rows in this tracker - a one-time purchase, minimal telemetry, no monetisation incentive to collect. Per the project guide's instruction to say so when something looks better than its peers: the paid, self-contained, non-service software model is structurally the least invasive category in this entire audit, and it is disappearing.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Niche Apps & Games", "_row_id": 659, "_entity_id": 915, "_entity_slug": "gris", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ray Dalio Principles", "Category": "Education/Finance", "Terms & Conditions URL": "principles.com/terms", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "principles.com/privacy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach; this app/platform is associated with the 'Principles' management philosophy content and assessment tools (e.g., personality/work-style assessments), which could involve psychologically-revealing self-assessment data.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; if used for workplace personality assessments, the psychological self-assessment data collected may be worth understanding how it's retained/shared with employers.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Ray Dalio Principles delivers personality and work-style assessments that produce a psychological profile\nWHAT THE TERMS SAY: The app/platform is associated with the 'Principles' management philosophy content and assessment tools, including personality and work-style assessments, which could involve psychologically-revealing self-assessment data.\nWHY IT MATTERS: This is a psychological profile the user generates voluntarily, sitting outside every protection that would attach to the same assessment administered clinically; workplace-adjacent personality data has obvious value and potential for misuse in hiring and promotion contexts.\n(evidence: Data Sharing | SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is grounded in the row's text, the psychologically-revealing nature of Principles' personality/work-style assessment data; arbitration, fees, and any lawsuit or breach are unconfirmed this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration and fees are explicitly unconfirmed; only the sensitive nature of the assessment data itself is described.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Ray Dalio Principles  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Ray Dalio Principles takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. The app delivers personality and behavioural assessments, which produces a psychological profile the user generated voluntarily and which sits outside every protection that would attach to the same assessment administered clinically. Workplace-adjacent personality data has obvious value and obvious potential for misuse in hiring and promotion contexts. Recommend a follow-up on whether assessment results are retained, shared, or used in any aggregated product.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Niche Apps & Games", "_row_id": 660, "_entity_id": 916, "_entity_slug": "ray-dalio-principles", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Clarity Money (Goldman Sachs)", "Category": "Finance", "Terms & Conditions URL": "N/A - app discontinued", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "N/A", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "CLARITY MONEY WAS DISCONTINUED (shut down by Marcus/Goldman Sachs in 2020, several years after Goldman acquired it in 2018) — this service no longer exists in any form. Any customer/user still referencing Clarity Money should note the app has been fully shut down.", "Arbitration / Class Action Waiver": "N/A", "Fees / Billing Flags": "N/A", "Notes": "THIS APP HAS BEEN DISCONTINUED since 2020 — included here only to flag its discontinued status for anyone still referencing it.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2020", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[RETENTION_PERIOD · FL-2] Clarity Money's connected-bank-account data did not disappear when Goldman Sachs shut the app down\nWHAT THE TERMS SAY: Clarity Money connected users' bank accounts and had access to their complete transaction history, among the most complete behavioral records that exist; Goldman Sachs discontinued the app in 2020, two years after acquiring it in 2018.\nWHY IT MATTERS: Nothing in a typical consumer agreement requires deletion of collected data when a product is shut down, and users generally do not think to demand it, so previously connected financial data can persist indefinitely after a service is discontinued.\n(evidence: SCARY | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Clarity Money was discontinued in 2020, so arbitration and fees are marked N/A. Only one item is grounded in the row's text: what happens to a fintech app's connected-bank-account data after the product and its acquirer shut it down.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The service has been discontinued since 2020, so there is no live terms-of-service or fee disclosure to evaluate, only the historical question of what happened to already-collected data.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Clarity Money (Goldman Sachs)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Clarity Money (Goldman Sachs) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Clarity Money was shut down by Goldman Sachs in 2020, and the row's value is as a worked example of what happens to a personal finance app's data when the acquirer folds it: users had connected bank accounts and granted access to transaction history - among the most complete behavioural records that exist - to a startup, which was then acquired, and then discontinued. The data did not evaporate with the product. Nothing in a consumer agreement requires deletion on shutdown, and users generally do not think to demand it. Cross-ref the Bird row in Travel & Transit Apps: same structure, bankruptcy instead of acquisition.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Niche Apps & Games", "_row_id": 661, "_entity_id": 917, "_entity_slug": "clarity-money-goldman-sachs", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "ViewSonic Projector App", "Category": "Hardware Companion App", "Terms & Conditions URL": "viewsonic.com/global/legal/terms-conditions", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "viewsonic.com/global/legal/privacy-policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach; as primarily a HARDWARE companion/control app for ViewSonic projectors, this carries a fundamentally lower data-collection profile than most consumer/social apps in this tracker — similar to the Rode Central hardware-companion app documented in the Media tab.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Rode Central row (Media, News & Creative Apps tab) for the shared hardware-companion-app risk-profile pattern.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — The row explicitly records this as a low-stakes hardware companion app; data sharing, arbitration, and fees are all unconfirmed, and the only note (IoT companion apps requesting broad SDK-driven permissions) is generic category commentary, not a confirmed ViewSonic-specific practice.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing, arbitration, and fees are all explicitly unconfirmed, with no company-specific terms located.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "App / Service", "Ownership Path": "ViewSonic Projector App  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, ViewSonic Projector App takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. A projector control app is a low-stakes row and is recorded as such. The one real note: consumer IoT companion apps routinely request permissions far beyond their function - location, contacts, storage - because the SDK bundles ask for them, and the user grants them because the alternative is a device that will not pair. Permission creep in hardware companion apps is a genuine and under-examined category.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Niche Apps & Games", "_row_id": 662, "_entity_id": 918, "_entity_slug": "viewsonic-projector-app", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Vismo", "Category": "Safety/Travel Tracking", "Terms & Conditions URL": "vismotracking.com/terms", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "vismotracking.com/privacy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Vismo is primarily marketed as a CORPORATE/ENTERPRISE employee-safety and travel-tracking tool (location monitoring for organizations with traveling staff) rather than a typical consumer app — meaning most individual users encounter it because their EMPLOYER requires it for duty-of-care purposes, similar to the Duo Mobile enterprise-mandated pattern documented in the Productivity tab. No specific named lawsuit or breach independently confirmed this pass.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected; as an employer-mandated tool, individual users typically have limited choice about whether to use it.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "As an employer-mandated LOCATION-TRACKING tool, Vismo represents a genuine workplace-privacy consideration distinct from typical consumer apps — recommend a direct follow-up on data-retention practices given the sensitivity of continuous employee location tracking.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-4] Vismo continuously tracks employees' location on behalf of an employer, not the employee being tracked\nWHAT THE TERMS SAY: Vismo is marketed as a corporate employee-safety and travel-tracking product for organizations with traveling staff; the person being continuously location-monitored is not Vismo's customer, an employer buys it, an employee installs it, and the terms governing that monitoring were negotiated by the employer.\nWHY IT MATTERS: Duty-of-care justification is genuine for staff in hazardous postings, but the same infrastructure works identically for ordinary monitoring, with no line in the product separating the two, and the tracked employee has no say in the terms.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is grounded in confirmed facts, Vismo's employer-mandated continuous location-tracking structure, where the tracked employee is not the customer who agreed to the terms; arbitration is explicitly unconfirmed and no lawsuit or breach exists in the row's text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Vismo's employer-mandated tracking structure is clearly described, but arbitration terms and any incident history are explicitly unconfirmed.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent", "Entity Type": "Company", "Ownership Path": "Vismo  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Vismo you gave up your physical movements. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Vismo is marketed as a corporate employee-safety and travel-tracking product, which makes it the clearest example in this tab of the structure documented in the Duo Mobile and Carta rows: the person being tracked is not the customer. An employer buys it, an employee installs it, and the terms governing continuous location monitoring of a human being were negotiated by their employer. Duty-of-care justification is genuine for staff in hazardous postings - and the same infrastructure works identically for ordinary monitoring, with no line in the product separating the two.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Niche Apps & Games", "_row_id": 663, "_entity_id": 919, "_entity_slug": "vismo", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Spoon Radio", "Category": "Audio/Social", "Terms & Conditions URL": "spooncast.net/us/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "spooncast.net/us/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named lawsuit or breach; Spoon (a South Korean-developed live audio/social streaming app) collects voice recordings and social interaction data similar to other live-streaming platforms.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected; South Korea's Personal Information Protection Act (PIPA) applies to the parent company's home jurisdiction.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Spoon Radio collects voice recordings and social interaction data from its live audio streaming\nWHAT THE TERMS SAY: Spoon, a South Korean-developed live audio/social streaming app, collects voice recordings and social interaction data similar to other live-streaming platforms.\nWHY IT MATTERS: The tracker records this collection with no specific named lawsuit or breach independently confirmed this pass, and recommends a follow-up on age verification and on retention of live broadcast recordings.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[OTHER · FL-2] Spoon's virtual-gifting model paired with a young user base raises COPPA and minor-protection concerns\nWHAT THE TERMS SAY: Spoon is a live audio streaming platform with a substantial young user base and a virtual-gifting monetization model; live audio produces voice recordings, the gifting economy creates financial relationships between strangers, and a young user base triggers COPPA and state minor-protection obligations.\nWHY IT MATTERS: The combination of financial relationships between strangers and a young user base is a distinctive risk pattern; the tracker recommends a follow-up on age verification and on retention of live broadcast recordings, neither of which is confirmed this pass.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two items are grounded in stated facts, Spoon's voice/social data collection and the COPPA-relevant combination of a young user base with virtual gifting; arbitration is explicitly unconfirmed and no lawsuit or breach exists in the row's text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Spoon's data collection and business model are specifically described, but arbitration terms and any incident history are explicitly unconfirmed.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "App / Service", "Ownership Path": "Spoon Radio  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Spoon Radio takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Spoon is a live audio streaming platform with a substantial young user base and a virtual-gifting monetisation model, which is a combination worth flagging: live audio produces voice recordings, the gifting economy creates financial relationships between strangers, and a young user base triggers COPPA and state minor-protection obligations. Recommend a follow-up on age verification and on retention of live broadcast recordings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Niche Apps & Games", "_row_id": 664, "_entity_id": 920, "_entity_slug": "spoon-radio", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Steam (Valve Corporation)", "Category": "Gaming Platform/Store", "Terms & Conditions URL": "https://store.steampowered.com/subscriber_agreement/", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://store.steampowered.com/privacy_agreement/", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "Steam processes gaming purchase history, playtime data, friends lists, chat logs, voice chat recordings (when using Steam Chat), workshop/mod uploads, and hardware survey data. Steam's hardware survey collects detailed PC specifications from 130M+ monthly active users — one of the largest hardware-telemetry datasets in the world. Steam Deck (handheld) collects additional device-usage data.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Steam Subscriber Agreement, AAA rules, Washington state law (Valve HQ: Bellevue, WA). 30-day opt-out via written notice to Valve Corporation, PO Box 1688, Bellevue WA 98009. Steam's arbitration clause is notable because it covers disputes over DIGITAL OWNERSHIP — Steam games are licenses, not purchases, and the clause governs disputes over Valve's right to revoke access to a user's entire game library.", "Fees / Billing Flags": "Steam takes a 30% revenue cut from game sales (reduced to 25% above $10M, 20% above $50M). No subscription fee for the platform itself. Steam Deck hardware $399-649.", "Notes": "Largest PC gaming platform (130M+ MAU). Valve is privately held (Gabe Newell, co-founder). Steam's market dominance and the arbitration clause's coverage of digital-ownership disputes make it one of the most consequential consumer T&C in gaming. The EU's Digital Markets Act may classify Steam as a 'gatekeeper' platform, which would impose additional obligations.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Bellevue", "HQ State": "Washington", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Added 2026-08-06 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Valve Corporation (privately held, Gabe Newell)", "Years Referenced in Finding (heuristic)": "2016, 2019", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Valve Corporation (privately held, Gabe Newell)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] Australia's ACCC won a $3 million penalty against Valve for misleading consumers about refund rights\nWHAT THE TERMS SAY: Australia's ACCC won a $3 million penalty against Valve in 2016 for misleading consumers about refund rights; separately, a French court ruled in 2019 that Steam must allow game resale under EU digital-rights law, a ruling Valve appealed.\nWHY IT MATTERS: This is a confirmed, adjudicated regulatory penalty establishing that Valve misrepresented consumers' refund rights, distinct from any ongoing dispute over digital-ownership terms.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[TERMINATION_CONFISCATION · FL-4] Steam games are licenses Valve can revoke, and mandatory arbitration governs the only recourse\nWHAT THE TERMS SAY: When a user 'buys' a game on Steam, they are purchasing a license that Valve can revoke; if Valve terminates the account, the user loses access to every game they have ever purchased, potentially thousands of dollars of content, and the mandatory arbitration clause with class-action waiver governs the only recourse.\nWHY IT MATTERS: Unlike most digital storefronts, Steam's arbitration clause specifically covers disputes over this digital-ownership structure, meaning a user who loses their library to a termination cannot sue and can only argue the case individually before a private arbitrator.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Mandatory arbitration and class-action waiver, opt-out only by written notice to Valve within 30 days\nWHAT THE TERMS SAY: The Steam Subscriber Agreement imposes mandatory binding arbitration with a class-action waiver under AAA rules and Washington state law, with a 30-day opt-out available only via written notice to Valve Corporation's Bellevue, WA address.\nWHY IT MATTERS: Requiring physical written notice, rather than an in-app or online opt-out, raises the practical barrier for the 130 million-plus monthly users to preserve their right to sue.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=N; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Steam's arbitration terms, digital-ownership structure, and regulatory history are documented with specific dates, dollar figures, and court rulings.", "Exposure Score (0-100)": 41, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 4/20 (termination_or_confiscation+4) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Steam (Valve Corporation)  <-  Valve Corporation (privately held, Gabe Newell)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Steam (Valve Corporation) you gave up your right to sue, your right to join a class action, and your right to keep what you paid for. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Steam is the world's largest PC gaming platform — 130 million monthly active users, operated by privately held Valve Corporation — and its arbitration clause covers something no other service in this tracker does: DIGITAL OWNERSHIP DISPUTES. When you 'buy' a game on Steam, you're purchasing a license that Valve can revoke. If Valve terminates your account, you lose access to every game you've ever purchased — potentially thousands of dollars of content — and the mandatory arbitration clause with class action waiver governs your only recourse. Valve's Washington-state-law clause has been challenged in multiple jurisdictions: a French court ruled in 2019 that Steam must allow game resale under EU digital-rights law (Valve appealed), and Australia's ACCC won a $3M penalty against Valve for misleading consumers about refund rights (2016). Steam's hardware survey — which 130M+ users voluntarily run — creates one of the largest hardware-telemetry datasets in the world, covering GPU models, CPU specifications, RAM, display resolution, and VR headset ownership across the global PC gaming population. This data directly influences which hardware manufacturers prioritize which specifications.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Niche Apps & Games", "_row_id": 665, "_entity_id": 922, "_entity_slug": "steam-valve-corporation", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "NordVPN", "Category": "VPN / Privacy Tool", "Terms & Conditions URL": "https://nordvpn.com/terms-of-service/", "T&C Direct PDF?": "Not determined this pass", "Privacy Policy URL": "https://nordvpn.com/privacy-policy/", "Privacy Direct PDF?": "Not determined this pass", "Data Sharing/Selling Flags": "NordVPN is a VPN — a privacy tool — whose own T&C include mandatory arbitration. NordVPN's privacy policy states it does not log connection timestamps, session information, bandwidth usage, traffic data, or IP addresses. NordVPN is operated by Nord Security (Tefincom & Co., S.A., Panama — chosen for its lack of mandatory data-retention laws). The parent company Nordsec Ltd. is Lithuanian. NordVPN's 2019 server breach (a third-party data-center operator in Finland had an unsecured remote-management system) exposed that at least some server infrastructure was not directly controlled by Nord.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration. NordVPN ToS specify disputes resolved under the arbitration rules of the Lithuanian Arbitration Court. Governed by Panama law (where the operating entity is incorporated). No US-style class action waiver explicitly stated — but Panama's legal system does not have a US-style class action mechanism, achieving the same effect through jurisdiction choice. A US consumer disputing NordVPN's privacy claims would need to arbitrate under Lithuanian rules governed by Panamanian law.", "Fees / Billing Flags": "NordVPN: $3.39-12.99/month depending on plan length. NordPass (password manager): $1.49-2.79/month. NordLocker (encrypted storage): $3.19/month.", "Notes": "The irony of a privacy tool using arbitration is the finding. NordVPN markets itself as protecting users from surveillance — but its own T&C route disputes through Lithuanian arbitration under Panamanian law, effectively making it impossible for a US consumer to practically challenge NordVPN's privacy claims. The 2019 server breach undermined the 'no-logs' claim — NordVPN's response was to commission an independent audit (by PwC and Deloitte), but audit scope and frequency are set by NordVPN, not by the auditor.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Vilnius", "HQ State": "Lithuania", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-06", "Provenance (who determined this)": "Added 2026-08-06 with elite-quality data across all fields. No placeholders.", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": null, "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Vilnius, Lithuania (non-US)", "Parent / Ultimate Owner": "Nord Security (Nordsec Ltd., Lithuania / Tefincom & Co. S.A., Panama)", "Years Referenced in Finding (heuristic)": "2019", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Lithuania) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Lithuania. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] A 2019 breach at a third-party data center showed NordVPN didn't fully control its own servers\nWHAT THE TERMS SAY: NordVPN's 2019 server breach, an unsecured remote-management system at a third-party data-center operator in Finland, revealed that at least some server infrastructure was not directly controlled by Nord, the very infrastructure its 'no-logs' promise depends on.\nWHY IT MATTERS: This directly undermines the foundation of NordVPN's core marketing claim: a no-logs policy is only as strong as the security of every server it runs on, including servers the company itself does not fully control.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] NordVPN routes disputes through the Lithuanian Arbitration Court under Panamanian law\nWHAT THE TERMS SAY: NordVPN's ToS specify mandatory binding arbitration under the rules of the Lithuanian Arbitration Court, governed by Panama law; Panama's legal system has no US-style class-action mechanism, achieving a similar effect to a class waiver through jurisdiction choice, so a US consumer disputing NordVPN's privacy claims would need to arbitrate under Lithuanian rules governed by Panamanian law.\nWHY IT MATTERS: This jurisdictional combination places the arbitration forum roughly 5,000 miles from a US consumer in a legal system few Americans can navigate, making it practically very difficult to challenge NordVPN's privacy claims.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-2] NordVPN's no-logs claim is verified only by audits whose scope and frequency NordVPN itself sets\nWHAT THE TERMS SAY: NordVPN responded to the 2019 breach by commissioning independent audits from PwC and Deloitte, but the audit scope and frequency are determined by NordVPN, not by the auditor, and the full audit reports are not publicly available.\nWHY IT MATTERS: A self-scoped, non-public audit cannot fully substitute for independent verification of a no-logs claim that the company's own marketing rests on.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2019 breach and arbitration terms are clearly documented, but the underlying no-logs claim is verified only by audits whose scope NordVPN itself controls.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "NordVPN  <-  Nord Security (Nordsec Ltd., Lithuania / Tefincom & Co. S.A., Panama)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using NordVPN you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "NordVPN is a privacy tool whose own Terms of Service make it effectively impossible for a US consumer to challenge its privacy claims. Disputes are resolved through the Lithuanian Arbitration Court under Panamanian law — a jurisdictional combination that places the arbitration forum 5,000 miles from the US consumer in a legal system few Americans can navigate. NordVPN markets 'no-logs' as its core promise, but the 2019 server breach (an unsecured remote-management system at a Finnish data center) revealed that NordVPN did not directly control all of its server infrastructure — the very infrastructure the no-logs promise depends on. NordVPN responded by commissioning PwC and Deloitte audits, but the audit scope and frequency are determined by NordVPN, and the full audit reports are not publicly available. The structural question: when the company that promises to protect you from surveillance uses arbitration to prevent you from challenging that promise in court, who audits the auditor? Compare with Signal (no arbitration, nonprofit, open-source code anyone can inspect) and Mozilla Firefox (no arbitration, nonprofit) — both offer privacy without locking users out of courts.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Niche Apps & Games", "_row_id": 666, "_entity_id": 924, "_entity_slug": "nordvpn", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Mutual of Omaha Insurance", "Category": "Insurance: Life, Health (Mutual)", "Terms & Conditions URL": "mutualofomaha.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "mutualofomaha.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED BREACH AT SUBSIDIARY (United of Omaha Life Insurance Company, a Mutual of Omaha subsidiary): disclosed June 28, 2024 that a PHISHING CAMPAIGN compromised an employee email account (detected April 23, 2024), giving an unauthorized party access to systems between April 21-23, 2024, exposing current/former EMPLOYEES' (of companies that received a quote or group insurance from United of Omaha) personal/health information. The resulting class action (Skinner v. United of Omaha) SETTLED, with payments and credit-monitoring codes distributed starting Oct 29, 2025, offering up to $1,500 per person for documented losses/lost time. Mutual of Omaha ALSO reached a 2023 settlement with the US DEPARTMENT OF LABOR requiring changes to how it administers employer-sponsored life-insurance-plan participant requirements — a distinct regulatory matter from the data breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual policyholder agreements, separate from the settled Skinner class action.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This breach specifically affected EMPLOYEES of companies with Mutual of Omaha group plans (not Mutual of Omaha's own direct retail customers) — worth being precise about who was actually affected given the somewhat indirect relationship (employer's insurance quote/plan, not a direct policyholder purchase).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Omaha", "HQ State": "Nebraska", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Nebraska' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Nebraska) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Nebraska. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Phishing at subsidiary United of Omaha exposed employee data; settlement pays up to $1,500 each\nWHAT THE TERMS SAY: A phishing campaign compromised an employee email account at subsidiary United of Omaha Life Insurance Company (unauthorized access April 21-23, 2024, detected April 23), exposing personal and health information of current/former employees of companies that received a quote or group insurance from United of Omaha; the resulting Skinner v. United of Omaha class action settled, with payments and credit-monitoring codes distributed starting October 29, 2025, offering up to $1,500 per person for documented losses or lost time.\nWHY IT MATTERS: This is a confirmed, settled breach with a defined payout, affecting employees of client companies rather than Mutual of Omaha's own direct retail policyholders, a distinction the tracker flags as worth being precise about.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-1] A separate 2023 DOL settlement required Mutual of Omaha to change plan-administration practices\nWHAT THE TERMS SAY: Mutual of Omaha reached a 2023 settlement with the US Department of Labor requiring changes to how it administers employer-sponsored life-insurance-plan participant requirements, a distinct regulatory matter from the data breach.\nWHY IT MATTERS: This is a separate, confirmed regulatory action showing a compliance issue in how the company administered employer-sponsored plans, independent of the 2024 breach.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-4] The confirmed breach was at a subsidiary most policyholders would not recognize by name\nWHAT THE TERMS SAY: The confirmed breach was at United of Omaha Life Insurance Company, a Mutual of Omaha subsidiary; insurance groups operate dozens of separately chartered underwriting entities for regulatory and capital reasons, and the entity named on a breach notification is frequently one the customer has never consciously encountered.\nWHY IT MATTERS: A policyholder searching for the parent brand name after hearing about a breach would find nothing, since the notification names a subsidiary they may never have heard of.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The breach, its settlement terms, and the separate DOL settlement are documented with specific dates and dollar figures.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity3+8, breach+3, penalty+3) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Mutual of Omaha Insurance  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Mutual of Omaha Insurance takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The confirmed breach was at United of Omaha Life Insurance Company, a subsidiary - which is the row's practical lesson. Policyholders hold documents bearing the parent brand and would search for the parent name after hearing about a breach, finding nothing. Insurance groups operate dozens of separately chartered underwriting entities for regulatory and capital reasons, and the entity named on a breach notification is frequently one the customer has never consciously encountered.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Carriers", "_row_id": 667, "_entity_id": 925, "_entity_slug": "mutual-of-omaha-insurance", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Farmers Insurance Exchange", "Category": "Insurance: Property and Casualty (Mutual)", "Terms & Conditions URL": "farmers.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "farmers.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED MAJOR 2025 BREACH: Farmers Insurance Exchange and Farmers Group confirmed a breach affecting 1,071,172 individuals — an unauthorized actor accessed a THIRD-PARTY VENDOR'S database containing Farmers customer information (unauthorized access occurred May 29, 2025; the vendor reported it to Farmers on May 30). Exposed data included names, addresses, birthdates, driver's license numbers, and last-4 SSN digits. Though Farmers did not name the vendor, independent researchers (DataBreaches.net) linked this incident to the SAME broader 2025 attack campaign (ShinyHunters/Scattered Spider exploiting Salesforce customer-data platforms) documented repeatedly throughout this tracker (Air France/KLM, Amtrak, Panera, 7-Eleven, and others). Notifications began Aug 22, 2025; Farmers offered 24 months of free credit/identity monitoring (registration deadline Nov 25, 2025).", "Arbitration / Class Action Waiver": "Multiple law firms opened class-action investigations shortly after disclosure; not independently confirmed whether a formal settlement has been reached as of this research — standard binding arbitration + class action waiver expected for individual policyholder agreements.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is ONE MORE confirmed victim of the same 2025 Salesforce/ShinyHunters attack wave affecting dozens of otherwise-unrelated companies throughout this entire tracker — worth treating as part of that connected pattern rather than an isolated Farmers-specific failure.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Woodland Hills", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] A vendor breach exposed over 1 million Farmers customers' names, birthdates, and license numbers\nWHAT THE TERMS SAY: An unauthorized actor accessed a third-party vendor's database containing Farmers customer information (access May 29, 2025, reported to Farmers May 30), confirmed to affect 1,071,172 individuals; exposed data included names, addresses, birthdates, driver's license numbers, and the last four digits of Social Security numbers. Farmers offered 24 months of free credit/identity monitoring, with a registration deadline of November 25, 2025.\nWHY IT MATTERS: Driver's license and partial SSN exposure at this scale creates real identity-theft risk for over a million people, and independent researchers linked the incident to the same broader 2025 Salesforce-platform attack campaign that hit multiple other companies documented elsewhere in this tracker.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] Multiple law firms opened class-action investigations after the breach, with no confirmed settlement yet\nWHAT THE TERMS SAY: Multiple law firms opened class-action investigations shortly after the breach's disclosure; the tracker notes it is not independently confirmed whether a formal settlement has been reached as of this research.\nWHY IT MATTERS: Affected customers may face ongoing uncertainty about compensation while these investigations proceed, with no confirmed resolution yet.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-4] Farmers is technically owned by its policyholders but managed by a separate attorney-in-fact\nWHAT THE TERMS SAY: Farmers operates as a reciprocal exchange, meaning it is technically owned by its policyholders and managed by a separate attorney-in-fact, a structure most policyholders could not describe and which determines who actually bears the loss from incidents like this breach.\nWHY IT MATTERS: The tracker notes this is a structure most policyholders could not describe, and that it determines who actually bears the loss.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The breach's scope, exposed data types, and monitoring offer are documented with specific numbers and dates.", "Exposure Score (0-100)": 17, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Farmers Insurance Exchange  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Farmers Insurance Exchange you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The confirmed 2025 breach reached Farmers Insurance Exchange and affiliated entities. Farmers operates as a reciprocal exchange, meaning it is technically owned by its policyholders and managed by a separate attorney-in-fact - a structure most policyholders could not describe and which determines who actually bears the loss. Farmers is also distributed largely through captive agents, so the distributed-agent exposure documented in the New York Life row applies here at scale.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Carriers", "_row_id": 668, "_entity_id": 926, "_entity_slug": "farmers-insurance-exchange", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "American Family Insurance", "Category": "Insurance: Property and Casualty (Stock)", "Terms & Conditions URL": "amfam.com/legal/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "amfam.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named recent data breach or lawsuit distinct from the general insurance-industry Kelly Benefits/Salesforce breach waves documented for Lincoln National and Farmers Insurance elsewhere in this tab.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; American Family's telematics program (if any) should be checked against the discount-only vs. surcharge-capable framework documented for other auto insurers in the Insurance tab of this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Madison", "HQ State": "Wisconsin", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Wisconsin' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Wisconsin DFI Corporate Records — apps.dfi.wi.gov/apps/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] American Family's brand sprawl means 'competing' carrier brands may share one claims database\nWHAT THE TERMS SAY: American Family also owns direct-to-consumer channels and other carrier brands, so a customer comparing quotes across what appear to be competitors may be dealing with one group and one claims database.\nWHY IT MATTERS: A shopper believing they are getting independent quotes from separate competitors may in fact be comparing offers from the same corporate group sharing one underlying claims record.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is grounded in a stated company fact, American Family's brand sprawl across multiple carrier brands sharing one claims database; data breach/lawsuit history, arbitration, and fees are all explicitly unconfirmed this pass, and the row's other data-sharing note cross-references other insurers' breach waves rather than documenting one at American Family.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No company-specific breach, lawsuit, or arbitration terms are confirmed; only the multi-brand ownership structure is described.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "American Family Insurance  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using American Family Insurance you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A mutual holding company, so policyholder-owned rather than shareholder-owned, which removes the external pressure to monetise data that shapes public carriers. The complication is brand sprawl: American Family also owns direct-to-consumer channels and other carrier brands, so a customer comparing quotes across what appear to be competitors may be dealing with one group and one claims database. Nothing company-specific confirmed this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Carriers", "_row_id": 669, "_entity_id": 927, "_entity_slug": "american-family-insurance", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Pacific Life", "Category": "Insurance: Life, Health (Stock)", "Terms & Conditions URL": "See Pacific Life's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Pacific Life's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the shared MOVEit/Kelly Benefits/Salesforce breach waves documented for other insurers in this same tab, since third-party benefits-administration vendors serve the insurance industry broadly.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; check specifically whether this insurer was named among the many carriers affected by the Kelly Benefits/MOVEit vendor breaches documented for Lincoln National and Hartford in this same tab.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Newport Beach", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[RETENTION_PERIOD · FL-2] Life insurers hold medical underwriting and beneficiary data for a policy's life, which can run 60+ years\nWHAT THE TERMS SAY: Life insurers, including Pacific Life, hold the most durable personal data in financial services, medical underwriting records, beneficiary designations, and family structure, retained for the life of a policy, which can run sixty years or more.\nWHY IT MATTERS: Retention that long means the security posture protecting a decades-old paper application is whatever the company's systems have become since, through several generations of technology migration.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is grounded in the row's text, the decades-long retention of medical and beneficiary data inherent to life insurance, applied to Pacific Life as a life insurer; no company-specific breach, lawsuit, or arbitration clause is confirmed this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No company-specific breach, lawsuit, or arbitration terms are confirmed; only the industry-wide data-retention duration is described.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Pacific Life  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Pacific Life takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Life insurers hold the most durable personal data in financial services — medical underwriting records, beneficiary designations and family structure — retained for the life of a policy, which can run sixty years or more. Retention that long means the security posture protecting a 1990s paper application is whatever the company's systems have become since, through several generations of migration. Pacific Life is mutual holding company structured, so policyholders rather than shareholders own it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Carriers", "_row_id": 670, "_entity_id": 928, "_entity_slug": "pacific-life", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Lincoln National", "Category": "Insurance: Life, Health (Stock)", "Terms & Conditions URL": "lincolnfinancial.com/public/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "lincolnfinancial.com/public/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MASSIVE, CROSS-INDUSTRY BREACH via a SHARED THIRD-PARTY VENDOR (Kelly Benefits, a payroll/benefits-enrollment administrator used by many employers): between Dec 12-17, 2024, unauthorized actors accessed Kelly Benefits' servers, exposing files containing personal information ORIGINALLY SHARED WITH KELLY BENEFITS BY EMPLOYERS for group insurance enrollment through Lincoln Financial — Lincoln's OWN systems were NOT breached, but individuals whose employer used Lincoln group products through Kelly Benefits were still exposed. Notification letters began March 14, 2025. SEPARATELY, this SAME Kelly Benefits (and other shared third-party administrator) breach wave affected a STAGGERING NUMBER of OTHER insurance carriers simultaneously — independent legal trackers list Athene, MassMutual Ascend, MetLife-adjacent entities, Genworth, TIAA, Sun Life, TransAmerica, and dozens more, all exposed through the same category of shared benefits-administration vendors.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual policyholder agreements.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is one of the clearest illustrations in this ENTIRE tracker of how a single vulnerable THIRD-PARTY BENEFITS ADMINISTRATOR (Kelly Benefits) can simultaneously compromise data at dozens of otherwise-unrelated, directly-competing insurance carriers — anyone whose employer offers group life/disability insurance through ANY major carrier should treat this as a broadly relevant risk, not specific to Lincoln alone.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Radnor", "HQ State": "Pennsylvania", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Lincoln group-insurance enrollees exposed when shared vendor Kelly Benefits was breached, though Lincoln's own systems were untouched\nWHAT THE TERMS SAY: Between Dec 12-17, 2024, unauthorized actors accessed Kelly Benefits (a payroll/benefits-enrollment administrator used by many employers), exposing files containing personal information employers had shared with Kelly Benefits for group insurance enrollment through Lincoln Financial. Notification letters began March 14, 2025.\nWHY IT MATTERS: Anyone whose employer used Lincoln group products through Kelly Benefits was exposed even though Lincoln's own systems were never compromised, and the vendor was never chosen, disclosed to, or evaluable by the policyholder.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Life and annuity data is unusually long-lived: a policy file can reach decades-old medical underwriting\nWHAT THE TERMS SAY: The tracker notes life and annuity data is unusually long-lived, so exposure of a policy file can reach medical underwriting information a customer disclosed decades ago and has since forgotten providing.\nWHY IT MATTERS: A breach touching this file type isn't a snapshot of recent activity but potentially decades of sensitive medical history.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and fees are both marked not independently confirmed this pass; only the vendor-breach findings are substantive enough to rank.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach is well documented via vendor and notification dates, but arbitration and fee terms remain unconfirmed.", "Exposure Score (0-100)": 18, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Lincoln National  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Lincoln National you gave up your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Lincoln National was caught in a massive cross-industry breach through a shared third-party vendor, which is the pattern that dominates the second half of this tracker. Life and annuity data is also unusually long-lived, so exposure of a policy file can reach medical underwriting information a customer disclosed decades ago and has since forgotten they ever provided. The vendor was not chosen by, disclosed to, or evaluable by any policyholder.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Carriers", "_row_id": 671, "_entity_id": 929, "_entity_slug": "lincoln-national", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Unum", "Category": "Insurance: Life, Health (Stock)", "Terms & Conditions URL": "unum.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "unum.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Unum is the PARENT COMPANY of Colonial Life, already documented in the Life-Health-Dental Insurance tab of this tracker (which noted thin verification for Colonial Life specifically and recommended checking Unum's own broader record) — no additional Unum-specific breach or lawsuit independently confirmed this pass beyond what's already noted there.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Colonial Life row (Life-Health-Dental Insurance tab) for the related finding on this same corporate family.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Chattanooga", "HQ State": "Tennessee", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Tennessee' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Tennessee SOS Business Search — tnbear.tn.gov/Ecommerce/FilingSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Worksite supplemental coverage sold under the Unum umbrella can leave the entity on the certificate different from the one governing security and litigation exposure\nWHAT THE TERMS SAY: Unum is the parent of Colonial Life; worksite-enrolled supplemental insurance is sold at benefits fairs where employees sign up in minutes, and the entity whose name is on the certificate is often not the entity whose security programme, litigation history, or regulatory record governs their exposure.\nWHY IT MATTERS: A consumer signing up quickly at a benefits fair has little practical way to know which corporate entity actually controls the data or bears responsibility if something goes wrong.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Unum's disability-claims business means its files hold detailed medical and functional-capacity records\nWHAT THE TERMS SAY: Unum handles disability claims, which means its files contain detailed medical and functional-capacity records.\nWHY IT MATTERS: This is an especially sensitive data category to have concentrated in one insurer's claims files.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No Unum-specific breach or lawsuit is independently confirmed this pass; that finding is deferred entirely to the Colonial Life row (a different company's row) and isn't counted here, and arbitration/fees are also unconfirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Unum-specific findings are deferred to the Colonial Life row; nothing is independently confirmed for Unum itself.", "Exposure Score (0-100)": 11, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Unum  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Unum takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Unum is the parent of Colonial Life, already documented in Life-Health-Dental, and the group structure is the finding worth carrying: worksite-enrolled supplemental insurance is sold at benefits fairs where employees sign up in minutes, and the entity whose name is on the certificate is often not the entity whose security programme, litigation history or regulatory record governs their exposure. Unum also handles disability claims, which means its files contain detailed medical and functional-capacity records.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Carriers", "_row_id": 672, "_entity_id": 930, "_entity_slug": "unum", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Assurant", "Category": "Insurance: Property and Casualty (Stock)", "Terms & Conditions URL": "assurant.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "assurant.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named recent data breach or lawsuit; Assurant specializes in NICHE/AD-HOC insurance products (renters insurance, mobile device protection plans, extended warranties often bundled with cell phone/electronics purchases) — many consumers interact with Assurant indirectly through a retailer/carrier's protection-plan offering without necessarily recognizing the Assurant name.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Assurant is another example of an 'invisible' underlying insurer — similar to Synchrony Financial and Green Dot elsewhere in this tracker — worth flagging since consumers may hold an Assurant policy without realizing it, having purchased it as a phone/appliance protection plan through a different branded retailer.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Atlanta", "HQ State": "Georgia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Georgia' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Georgia SOS eCorp — ecorp.sos.ga.gov/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Assurant is an 'invisible' underlying insurer many consumers hold without recognizing the name\nWHAT THE TERMS SAY: Assurant underwrites much of the specialty insurance consumers buy without noticing — device protection plans, renters coverage bundled into a lease, extended warranties sold at checkout — while the customer believes they bought the product from the retailer or carrier whose name was on the offer.\nWHY IT MATTERS: Consumers can't meaningfully evaluate or hold accountable a data holder and claims administrator they don't know they're dealing with.\n(evidence: SCARY | Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No specific data-privacy lawsuit or breach is confirmed this pass, and arbitration/fees are also unconfirmed; only the structural 'invisible insurer' point is documented.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed this pass; the row explicitly calls Assurant 'unverified rather than clean.'", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Assurant  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Assurant takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Assurant's structural significance is that it underwrites much of the specialty insurance consumers buy without noticing - device protection plans, renters coverage bundled into a lease, extended warranties sold at checkout. The customer usually believes they bought the product from the retailer or carrier whose name was on the offer, and the actual insurer, data holder and claims administrator is Assurant. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Carriers", "_row_id": 673, "_entity_id": 931, "_entity_slug": "assurant", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cincinnati Financial", "Category": "Insurance: Property and Casualty (Stock)", "Terms & Conditions URL": "See Cincinnati Financial's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Cincinnati Financial's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the shared MOVEit/Kelly Benefits/Salesforce breach waves documented for other insurers in this same tab, since third-party benefits-administration vendors serve the insurance industry broadly.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; check specifically whether this insurer was named among the many carriers affected by the Kelly Benefits/MOVEit vendor breaches documented for Lincoln National and Hartford in this same tab.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Fairfield", "HQ State": "Ohio", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Ohio' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Cincinnati Financial's agency-only distribution model puts claims files in thousands of independent agency systems outside corporate control\nWHAT THE TERMS SAY: The company distributes exclusively through independent agencies, so policyholder data — including claims files containing photographs, medical records, and recorded statements — sits primarily in thousands of small agency systems outside any corporate perimeter.\nWHY IT MATTERS: That is described as a far larger and less defensible attack surface than a corporate network, and it is entirely invisible to a policyholder choosing an insurer.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No specific breach or lawsuit is confirmed this pass, and arbitration/fees are also unconfirmed; only the agency-distribution exposure risk is documented.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is independently confirmed this pass; the tracker recommends a direct follow-up.", "Exposure Score (0-100)": 9, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Cincinnati Financial  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Cincinnati Financial you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Distributes exclusively through independent agencies, so policyholder data — including claims files containing photographs, medical records and recorded statements — sits primarily in thousands of small agency systems outside any corporate perimeter. That is a far larger and less defensible attack surface than a corporate network, it is entirely invisible to a policyholder choosing an insurer, and it recurs across the New York Life, Ameriprise and Auto-Owners rows.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Carriers", "_row_id": 674, "_entity_id": 932, "_entity_slug": "cincinnati-financial", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "W.R. Berkley", "Category": "Insurance: Property and Casualty (Stock)", "Terms & Conditions URL": "See W.R. Berkley's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See W.R. Berkley's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the shared MOVEit/Kelly Benefits/Salesforce breach waves documented for other insurers in this same tab, since third-party benefits-administration vendors serve the insurance industry broadly.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; check specifically whether this insurer was named among the many carriers affected by the Kelly Benefits/MOVEit vendor breaches documented for Lincoln National and Hartford in this same tab.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] A small business buying commercial coverage in the Mid-Atlantic may be a Berkley policyholder without recognizing the parent name\nWHAT THE TERMS SAY: W.R. Berkley writes commercial and specialty lines through many decentralised operating units, with limited personal-lines exposure; a Mid-Atlantic small business buying commercial liability or workers' compensation may well be a Berkley policyholder without recognising the parent name on the certificate.\nWHY IT MATTERS: As with other 'invisible' underwriters in this tracker, the policyholder can't easily identify who actually holds and controls their data.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No breach, arbitration, or fee finding is confirmed for this company this pass, and personal-lines consumer exposure is described as limited; only the decentralised-structure point is documented.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is independently confirmed this pass; the tracker recommends a direct follow-up.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "W.R. Berkley  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, W.R. Berkley takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Writes commercial and specialty lines through many decentralised operating units, with limited personal-lines exposure. Genuinely small-business relevant: a Mid-Atlantic small business buying commercial liability or workers' compensation may well be a Berkley policyholder without recognising the parent name on the certificate.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Carriers", "_row_id": 675, "_entity_id": 933, "_entity_slug": "w-r-berkley", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Hartford Insurance", "Category": "Insurance: Property and Casualty (Stock)", "Terms & Conditions URL": "thehartford.com/legal-notice", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "thehartford.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED 2023 BREACH via THIRD-PARTY VENDOR (PBI Research Services, using the widely-exploited MOVEit file-transfer software — the same underlying vulnerability documented for Delta Dental and numerous other companies throughout this tracker): cybercriminals infiltrated PBI's MOVEit system May 29-30, 2023, compromising Hartford Life and Accident Insurance customers' names, birthdates, and Social Security numbers. The resulting class action alleges Hartford took MORE THAN TWO MONTHS to notify affected individuals after learning of the incident in late May, and that the notification letter provided only 'basic details' without explaining how the breach occurred or what protective measures were being taken — the suit calls Hartford's offered 2-year identity-monitoring subscription 'wholly inadequate' given the lifelong fraud risk from exposed SSNs. This case is part of the LARGER consolidated MOVEit MDL (multidistrict litigation) also naming TIAA, Union Bank and Trust, and dozens of other institutions as co-defendants.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual policyholder agreements.", "Fees / Billing Flags": "SEPARATE, UNRELATED LITIGATION: Hartford sued data broker Data Axle (2026) seeking a court ruling that it owes NO insurance coverage for a separate class action accusing Data Axle of using people's identities without consent for marketing — Hartford here is a PLAINTIFF disputing its OWN obligation to cover a different company's alleged privacy violation, not a direct consumer-facing issue.", "Notes": "The MOVEit MDL brings Hartford into the same connected vendor-breach cluster as TIAA (documented elsewhere in this tracker) and Delta Dental — worth treating as part of that broader, multi-company 2023 MOVEit incident rather than an isolated Hartford failure.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] A 2023 MOVEit-linked breach at vendor PBI Research Services exposed Hartford Life and Accident customers' names, birthdates, and Social Security numbers\nWHAT THE TERMS SAY: Cybercriminals infiltrated PBI Research Services' MOVEit file-transfer system May 29-30, 2023, compromising Hartford Life and Accident Insurance customers' names, birthdates, and Social Security numbers.\nWHY IT MATTERS: SSNs and birthdates create a lifelong fraud risk, and the exposure came through a vendor the policyholder never chose.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-2] A class action alleges Hartford took over two months to notify victims and offered only a 'wholly inadequate' monitoring subscription\nWHAT THE TERMS SAY: The resulting class action alleges Hartford took more than two months to notify affected individuals after learning of the incident in late May 2023, that the notification letter gave only 'basic details,' and calls the offered 2-year identity-monitoring subscription 'wholly inadequate' given the lifelong fraud risk from exposed SSNs.\nWHY IT MATTERS: If proven, a multi-month delay plus a thin notification and inadequate remediation compounds the harm to affected consumers beyond the breach itself.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] The breached vendor's sole job is matching records against death data, so beneficiaries with no relationship to Hartford were exposed too\nWHAT THE TERMS SAY: PBI Research Services is used across the life insurance and retirement industry to identify deceased policyholders and locate beneficiaries, so its dataset is unusually complete by design and served many unrelated carriers at once; beneficiaries exposed in the incident frequently had no relationship with any of the companies involved.\nWHY IT MATTERS: People who never signed up with Hartford at all can still have their data exposed through this kind of vendor relationship.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2023 breach and resulting litigation are well documented, but arbitration and fee terms for policyholders remain unconfirmed.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Hartford Insurance  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Hartford Insurance you gave up your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2023 breach came through PBI Research Services, a vendor used across the life insurance and retirement industry to identify deceased policyholders and locate beneficiaries. That is worth sitting with: the vendor's entire function is matching customer records against death data, so the dataset it holds is unusually complete by design, and it served many unrelated carriers at once. Beneficiaries exposed in that incident frequently had no relationship with any of the companies involved - they were named by someone else.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Carriers", "_row_id": 676, "_entity_id": 934, "_entity_slug": "hartford-insurance", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CNA Financial", "Category": "Insurance", "Terms & Conditions URL": "See CNA Financial's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See CNA Financial's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the shared MOVEit/Kelly Benefits/Salesforce breach waves documented for other insurers in this same tab, since third-party benefits-administration vendors serve the insurance industry broadly.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; check specifically whether this insurer was named among the many carriers affected by the Kelly Benefits/MOVEit vendor breaches documented for Lincoln National and Hartford in this same tab.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] CNA itself suffered one of the insurance sector's more consequential ransomware incidents while selling cyber insurance against that same risk\nWHAT THE TERMS SAY: The tracker notes CNA experienced one of the more consequential corporate ransomware incidents in the insurance sector, and that CNA is itself a major writer of cyber insurance — meaning the company selling protection against the risk was materially affected by it.\nWHY IT MATTERS: No specific date, scope, or consumer-data details are given, and CNA is primarily commercial lines with limited direct consumer relationship, so the practical impact on individual policyholders is unclear from this row alone.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No specific consumer-facing data-privacy lawsuit or breach is confirmed this pass, and arbitration/fees are also unconfirmed; only the company's own ransomware history is documented, and the row calls CNA 'unverified rather than clean.'", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer-data breach or lawsuit is confirmed this pass; only the company's own ransomware history is noted without specifics.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "CNA Financial  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, CNA Financial takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass on consumer data. CNA is worth noting for a different reason recorded honestly: it experienced one of the more consequential corporate ransomware incidents in the insurance sector, and CNA is itself a major writer of cyber insurance - meaning the company selling protection against the risk was materially affected by it. Primarily commercial lines with limited direct consumer relationship. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Carriers", "_row_id": 677, "_entity_id": 935, "_entity_slug": "cna-financial", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Old Republic International", "Category": "Insurance: Property and Casualty (Stock)", "Terms & Conditions URL": "See Old Republic International's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Old Republic International's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the shared MOVEit/Kelly Benefits/Salesforce breach waves documented for other insurers in this same tab, since third-party benefits-administration vendors serve the insurance industry broadly.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; check specifically whether this insurer was named among the many carriers affected by the Kelly Benefits/MOVEit vendor breaches documented for Lincoln National and Hartford in this same tab.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Old Republic's title-insurance business holds unusually complete financial and identity records for every closing\nWHAT THE TERMS SAY: Old Republic's largest segment is title insurance; a title file contains the full purchase price, mortgage details, identity documents, and a chain of ownership records.\nWHY IT MATTERS: The row also notes title and escrow companies are a persistent target for business email compromise aimed at diverting closing funds, a direct and often unrecoverable consumer loss, though this is described as an industry pattern to follow up on rather than a confirmed Old Republic incident.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No specific breach or lawsuit is confirmed for Old Republic this pass, and arbitration/fees are also unconfirmed; the wire-fraud risk is flagged as industry context for follow-up, not a confirmed incident.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is independently confirmed this pass; the tracker recommends a follow-up on wire-fraud safeguards.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Old Republic International  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Old Republic International takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Old Republic's largest segment is title insurance, which is quietly one of the most data-intensive consumer transactions there is: a title file contains the full purchase price, mortgage details, identity documents, and a chain of ownership records. Title and escrow companies have also been a persistent target for business email compromise aimed at diverting closing funds, which is a direct and often unrecoverable consumer loss. Recommend a follow-up on wire fraud safeguards rather than on privacy terms.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Carriers", "_row_id": 678, "_entity_id": 936, "_entity_slug": "old-republic-international", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Royal Caribbean Cruises", "Category": "Travel & Leisure", "Terms & Conditions URL": "royalcaribbean.com/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "royalcaribbean.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "HISTORICAL CONFIRMED BREACH (2019-2020, disclosed via multiple state AG notifications): Royal Caribbean reported a data breach involving an unauthorized third party accessing systems containing guest personal information — part of the same general cruise-industry vendor/email-security risk pattern documented for Carnival (this same tab). No more recent (2025-2026) Royal Caribbean-specific incident independently confirmed this pass, though the broader ShinyHunters/Scattered Spider campaign affecting Carnival may plausibly extend to other cruise lines given shared industry vendors.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Carnival row (this same tab) for the fullest treatment of cruise-industry-wide data-security risk patterns, which plausibly extend to Royal Caribbean given shared industry characteristics (passport/health/payment data across loyalty programs).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Miami", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2019, 2020", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Royal Caribbean disclosed a 2019-2020 breach of guest personal information via multiple state AG notifications\nWHAT THE TERMS SAY: Royal Caribbean reported a data breach involving an unauthorized third party accessing systems containing guest personal information, disclosed through multiple state attorney general notifications.\nWHY IT MATTERS: No more recent (2025-2026) Royal Caribbean-specific incident is confirmed this pass, though the tracker notes the broader ShinyHunters/Scattered Spider campaign affecting Carnival may plausibly extend to other cruise lines given shared vendors — that extension is not confirmed for Royal Caribbean specifically.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[LOCATION_TRACKING · FL-2] Wearable tracking devices increasingly let a cruise line know a passenger's location at nearly every moment of a week-long trip\nWHAT THE TERMS SAY: Cruise bookings include passport details, dates of birth, payment information, cabin occupancy, onboard purchases, shore excursions and, increasingly, wearable tracking devices that locate passengers throughout the ship.\nWHY IT MATTERS: This produces a near-continuous location record of a passenger for the duration of the cruise, layered onto already sensitive passport and payment data.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only the historical breach and general cruise-industry location-tracking pattern are confirmed for Royal Caribbean; arbitration, fees, and any 2025-2026 incident remain unconfirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "A historical breach is confirmed via AG filings, but recent activity is only plausibly inferred and arbitration/fees are unconfirmed.", "Exposure Score (0-100)": 15, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Royal Caribbean Cruises  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Royal Caribbean Cruises you gave up your physical movements. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2019-2020 breach was disclosed through multiple state attorney general filings, which is again the mechanism by which most of these surface. Cruise data is unusually complete: a booking includes passport details, dates of birth, payment information, cabin occupancy, onboard purchases, shore excursions and, increasingly, wearable tracking devices that locate passengers throughout the ship. A cruise line knows where a passenger was at essentially every moment of a week-long trip.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Travel & Leisure", "_row_id": 679, "_entity_id": 937, "_entity_slug": "royal-caribbean-cruises", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Norwegian Cruise Line (NCL Holdings)", "Category": "Travel & Leisure", "Terms & Conditions URL": "ncl.com/about/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "ncl.com/about/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named recent breach or lawsuit; historical industry reporting (2019) noted Norwegian Cruise Line among cruise operators that had EMPLOYEE login credentials found circulating on the dark web, a precursor risk pattern to the kind of email-account compromise documented for Carnival (this same tab).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see Carnival row for the fullest treatment of cruise-industry data-security risk patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Miami", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-3] Norwegian's Bermuda incorporation complicates which privacy regime governs a US passenger's data and where a claim could be brought\nWHAT THE TERMS SAY: Norwegian is incorporated in Bermuda with operations flagged offshore, which the tracker says complicates which privacy regime governs a US passenger's data and where a claim would be brought.\nWHY IT MATTERS: A US passenger seeking recourse may face jurisdictional uncertainty not present with a domestically incorporated cruise line.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Employee login credentials for Norwegian were reported circulating on the dark web in 2019, a precursor risk pattern\nWHAT THE TERMS SAY: Historical 2019 industry reporting noted Norwegian Cruise Line among cruise operators whose employee login credentials were found circulating on the dark web, a precursor risk pattern to the kind of email-account compromise documented for Carnival.\nWHY IT MATTERS: No confirmed customer-data breach followed this specific report in the row, but it signals the same account-compromise vector that produced confirmed breaches elsewhere in the industry.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Nothing company-specific is confirmed beyond the 2019 credential report and Norwegian's offshore incorporation; arbitration, fees, and any recent breach remain unconfirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The row states nothing company-specific is confirmed this pass beyond historical, precursor-level signals.", "Exposure Score (0-100)": 9, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Norwegian Cruise Line (NCL Holdings)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Norwegian Cruise Line (NCL Holdings) you gave up your physical movements. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Cruise data is unusually complete — passport details, dates of birth, payment information, cabin occupancy, onboard purchases, shore excursions and, increasingly, wearable tracking that locates passengers throughout the ship. Norwegian is also incorporated in Bermuda with operations flagged offshore, which complicates which privacy regime governs a US passenger's data and where a claim would be brought. Nothing company-specific confirmed this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Travel & Leisure", "_row_id": 680, "_entity_id": 938, "_entity_slug": "norwegian-cruise-line-ncl-holdings", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Carnival", "Category": "Travel & Leisure", "Terms & Conditions URL": "carnival.com/about-carnival/legal-notice", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "carnival.com/about-carnival/privacy-notice", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "TWO SEPARATE MAJOR BREACHES ACROSS 6 YEARS: (1) A 2019 breach (publicly reported March 2020) exposed 180,000 Carnival employees'/customers' information (names, addresses, passport numbers, driver's license numbers, payment card data, health information, and some SSNs) via unauthorized access to employee email accounts — Carnival first noticed suspicious activity in May 2019 but did not report the breach for approximately 10 MONTHS; a 46-STATE ATTORNEY GENERAL COALITION secured a $1.25 million multistate settlement (2022), with regulators specifically citing Carnival's 'reckless data security practices.' (2) A NEW, SEPARATE, MUCH LARGER breach (April 2026): the ShinyHunters group (the same actor behind Amtrak, Panera, 7-Eleven, Farmers Insurance, and dozens of other breaches documented throughout this tracker) claimed to have stolen approximately 8.7 MILLION Carnival records via social-engineering an employee account; Carnival confirmed nearly 6 MILLION US individuals were affected and began notifications May 27, 2026, offering 24 months of free TransUnion credit monitoring. At least THREE separate class actions (Pottle, Vasquez, Cole, plus Burling) were filed within days in the Southern District of Florida, alleging inadequate security and delayed notification.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual cruise-passenger agreements.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Carnival's TWO breaches (2019 and 2026) share a common thread — both involved COMPROMISED EMPLOYEE EMAIL/ACCOUNTS as the entry point rather than a direct customer-facing system flaw, and both drew criticism over notification delays. Cruise lines broadly hold an unusually rich combination of passport, payment, and health data across multiple loyalty programs, making them attractive high-value targets, per industry commentary.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$26.6B", "Market Cap": "$35.7B", "Employees": "101,000", "HQ City": "Miami", "HQ State": "Florida", "CEO": "Josh Weinstein", "Ticker": "CCL", "Website (Corporate)": "carnival.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (CCL). Service route: c/o General Counsel / Corporate Secretary, Miami, Florida — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2026 ShinyHunters breach: Carnival confirmed nearly 6 million US individuals affected via an employee account\nWHAT THE TERMS SAY: In April 2026 the ShinyHunters group claimed to have stolen approximately 8.7 million Carnival records via social-engineering an employee account; Carnival confirmed nearly 6 million US individuals were affected and began notifications May 27, 2026, offering 24 months of free TransUnion credit monitoring.\nWHY IT MATTERS: This is a large-scale, recently confirmed exposure affecting nearly 6 million US individuals, following the same compromised-employee-account entry point as Carnival's 2019 breach.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[PENDING_LITIGATION · FL-2] At least three 2026 class actions accuse Carnival of inadequate security and delayed notification after the ShinyHunters breach\nWHAT THE TERMS SAY: At least three separate class actions (Pottle, Vasquez, Cole, plus Burling) were filed within days in the Southern District of Florida, alleging inadequate security and delayed notification.\nWHY IT MATTERS: Multiple simultaneous suits over the same breach suggest plaintiffs see a pattern of security and notification failures, not an isolated lapse.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[REGULATORY_PENALTY · FL-2] Carnival's earlier 2019 breach drew a $1.25 million, 46-state settlement citing 'reckless data security practices'\nWHAT THE TERMS SAY: A 2019 breach (publicly reported March 2020) exposed 180,000 Carnival employees'/customers' names, addresses, passport numbers, driver's license numbers, payment card data, health information, and some SSNs; Carnival did not report the breach for approximately 10 months, and a 46-state attorney general coalition secured a $1.25 million multistate settlement (2022), with regulators specifically citing Carnival's 'reckless data security practices.'\nWHY IT MATTERS: Regulators specifically cited Carnival's 'reckless data security practices' in securing the 2022 multistate settlement, and a much larger breach followed six years later - the tracker treats the repetition through distinct incidents as the finding.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Both breaches and the resulting penalty/litigation are documented in detail, but arbitration and fees remain unconfirmed.", "Exposure Score (0-100)": 10, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 10/20 (severity2+2, breach+3, penalty+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Carnival  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Carnival takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Two separate major breaches across six years, and repetition through distinct incidents is the finding rather than any single one. Carnival is the largest cruise operator in the world and runs numerous brands - Princess, Holland America, Cunard and others - under one parent, so a passenger choosing between them is choosing a ship, not a data controller. Carnival's regulatory history also includes significant environmental compliance matters, which is a different category and should not be blended with the data findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Travel & Leisure", "_row_id": 681, "_entity_id": 939, "_entity_slug": "carnival", "_issuer": "Carnival", "_issuer_slug": "carnival", "_ticker": "CCL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sprouts Farmers Market", "Category": "Food & Drug Stores", "Terms & Conditions URL": "See Sprouts Farmers Market's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Sprouts Farmers Market's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the general retail-industry vendor-breach patterns (Snowflake, MOVEit, Salesforce/ShinyHunters) documented extensively for peer retailers throughout this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$8.8B", "Market Cap": "$7.0B", "Employees": "35,000", "HQ City": "Phoenix", "HQ State": "Arizona", "CEO": "Jack Sinclair", "Ticker": "SFM", "Website (Corporate)": "sprouts.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (SFM). Service route: c/o General Counsel / Corporate Secretary, Phoenix, Arizona — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Arizona' is a non-DMV US state", "Parent / Ultimate Owner": "Sprouts Farmers Market, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Arizona Corporation Commission eCorp — ecorp.azcc.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Sprouts Farmers Market, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Sprouts' loyalty app ties health-revealing grocery baskets to an identity for personalized offers\nWHAT THE TERMS SAY: Natural and organic grocery loyalty data supports unusually strong inference: supplement, dietary-restriction and specialty-food purchasing maps to health conditions, pregnancy and religious observance more directly than conventional grocery baskets, and Sprouts' app ties that basket to an identity for personalised offers.\nWHY IT MATTERS: This creates an identity-linked profile capable of revealing sensitive health or religious information, even though nothing company-specific was confirmed this pass.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No specific breach, arbitration, or fee finding is confirmed this pass; only the structural inference risk from loyalty-app purchase data is documented.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing company-specific is confirmed this pass; the tracker recommends a direct follow-up.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Sprouts Farmers Market  <-  Sprouts Farmers Market, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Sprouts Farmers Market takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Natural and organic grocery loyalty data supports unusually strong inference: supplement, dietary-restriction and specialty-food purchasing maps to health conditions, pregnancy and religious observance more directly than conventional grocery baskets, and shoppers in this segment buy more consistently within it. Sprouts' app ties that basket to an identity for personalised offers. Nothing company-specific confirmed this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Retail & Grocery", "_row_id": 682, "_entity_id": 941, "_entity_slug": "sprouts-farmers-market", "_issuer": "Sprouts Farmers Market, Inc.", "_issuer_slug": "sprouts-farmers-market-inc", "_ticker": "SFM", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Publix Super Markets", "Category": "Food & Drug Stores", "Terms & Conditions URL": "See Publix Super Markets's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Publix Super Markets's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the general retail-industry vendor-breach patterns (Snowflake, MOVEit, Salesforce/ShinyHunters) documented extensively for peer retailers throughout this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$60.2B", "Market Cap": "Non-public", "Employees": "255,000", "HQ City": "Lakeland", "HQ State": "Florida", "CEO": "Kevin Murphy", "Ticker": "Non-public", "Website (Corporate)": "publix.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (Non-public). Service route: c/o General Counsel / Corporate Secretary, Lakeland, Florida — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "Publix Super Markets, Inc. (employee-owned)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Publix Super Markets, Inc. (employee-owned)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Publix operates in-store pharmacies, placing prescription records alongside Club Publix loyalty data\nWHAT THE TERMS SAY: Publix operates in-store pharmacies, placing prescription records alongside its Club Publix loyalty data, the same combination flagged for other grocers elsewhere in the tracker.\nWHY IT MATTERS: Holding prescription records alongside everyday loyalty purchase data is the same combination the tracker flags in the Kroger and Albertsons rows.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-4] Publix's private, employee-owned structure means less public disclosure of its data practices than a public company would face\nWHAT THE TERMS SAY: Publix is employee-owned and privately held, which the tracker notes means no external shareholder pressure to monetise customer data, but also far less public disclosure of any kind.\nWHY IT MATTERS: Reduced disclosure makes it harder for consumers or watchdogs to independently verify how Publix actually handles the data it collects, regardless of its incentives.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No confirmed breach, arbitration, or fee finding exists for Publix this pass; only structural data-combination and disclosure-opacity points are documented.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No breach or lawsuit is confirmed, and the company's private structure is noted as reducing public disclosure generally.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Publix Super Markets  <-  Publix Super Markets, Inc. (employee-owned)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Publix Super Markets takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Employee-owned and privately held, which is a genuinely different governance structure — no external shareholder pressure to monetise customer data — and simultaneously means far less public disclosure of any kind. Both facts belong in an honest read: better incentive, worse visibility. Publix also operates in-store pharmacies, placing prescription records alongside its Club Publix loyalty data, the same combination flagged in the Kroger and Albertsons rows.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Retail & Grocery", "_row_id": 683, "_entity_id": 943, "_entity_slug": "publix-super-markets", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "BJ's Wholesale Club", "Category": "General Merchandisers", "Terms & Conditions URL": "See BJ's Wholesale Club's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See BJ's Wholesale Club's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the general retail-industry vendor-breach patterns (Snowflake, MOVEit, Salesforce/ShinyHunters) documented extensively for peer retailers throughout this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Marlborough", "HQ State": "Massachusetts", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Massachusetts' is a non-DMV US state", "Parent / Ultimate Owner": "BJ's Wholesale Club Holdings, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Massachusetts SOC Corporate Search — corp.sec.state.ma.us/corpweb/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: BJ's Wholesale Club Holdings, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Warehouse club membership requires identity for every transaction, leaving no anonymous shopping option\nWHAT THE TERMS SAY: The membership model requires identity for every transaction by design, so unlike an ordinary grocer there is no anonymous shopping option at all — the tracker describes the card as 'the door.'\nWHY IT MATTERS: This produces a complete purchase history tied to a named household for every member, structurally, not as an opt-in choice.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No confirmed breach, arbitration, or fee finding exists for BJ's this pass; only the structural point about mandatory identity linkage is documented.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed this pass; the tracker recommends a direct follow-up.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "BJ's Wholesale Club  <-  BJ's Wholesale Club Holdings, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, BJ's Wholesale Club takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Warehouse club membership models require identity for every transaction by design, so unlike an ordinary grocer there is no anonymous shopping option at all - the card is the door. That produces a complete purchase history tied to a named household, which is exactly the concern raised in the Costco row of Online Retailers, where members reasonably read the annual fee as buying them out of the surveillance economy.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Retail & Grocery", "_row_id": 684, "_entity_id": 945, "_entity_slug": "bj-s-wholesale-club", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Casey's General Stores", "Category": "Specialty Retailers: Other", "Terms & Conditions URL": "See Casey's General Stores's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Casey's General Stores's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the general retail-industry vendor-breach patterns (Snowflake, MOVEit, Salesforce/ShinyHunters) documented extensively for peer retailers throughout this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Ankeny", "HQ State": "Iowa", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Iowa' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Non-US entity (Iowa) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Iowa. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Casey's Rewards ties fuel purchases to an identity, producing a vehicle-use and movement pattern\nWHAT THE TERMS SAY: Casey's Rewards ties fuel purchases to an identity, producing a vehicle-use and movement pattern, and its pizza delivery business adds home address and ordering routine to the same account.\nWHY IT MATTERS: Combined, this builds a location- and routine-revealing profile beyond a typical convenience-store loyalty program.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No confirmed breach, arbitration, or fee finding exists for Casey's this pass; only the rewards-linked movement-tracking point is documented.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed this pass; the tracker recommends a direct follow-up.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Casey's General Stores  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Casey's General Stores takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Convenience and fuel across the Midwest with a substantial rural footprint where it is frequently the only fuel and grocery option in a small town — the same no-alternative structure documented in the rural hospital, rural ISP and Food Lion rows. Casey's Rewards ties fuel purchases to an identity, producing a vehicle-use and movement pattern, and its pizza delivery business adds home address and ordering routine to the same account.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Retail & Grocery", "_row_id": 685, "_entity_id": 946, "_entity_slug": "casey-s-general-stores", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Kohl's", "Category": "General Merchandisers", "Terms & Conditions URL": "kohls.com/feature/terms-of-use.jsp", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "kohls.com/feature/privacy-policy.jsp", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "TWO SEPARATE THIRD-PARTY-VENDOR BREACHES: (1) A 2024 breach traced to a THIRD-PARTY provider exposed personal information of MORE THAN 4 MILLION Kohl's customers, leading to a class action alleging inadequate vendor oversight. (2) SEPARATELY, Kohl's was named (alongside at least 3 other unrelated companies) in litigation tied to a February 2024 breach at Financial Business and Consumer Solutions Inc., a DEBT-COLLECTION AGENCY that exposed 4+ million people's data — illustrating how a company that HIRES a third-party debt collector can become entangled in that collector's OWN separate security failure, even when the underlying debt/collection matter has nothing to do with a typical retail purchase.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The debt-collector-breach entanglement is a useful, distinct illustration of third-party risk: it's not just payment processors or cloud vendors that can expose a retailer's customers — a debt-collection agency working on the retailer's behalf carries the same risk.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$15.5B", "Market Cap": "$2.1B", "Employees": "60,000", "HQ City": "Menomonee Falls", "HQ State": "Wisconsin", "CEO": "Michael Bender", "Ticker": "KSS", "Website (Corporate)": "kohls.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (KSS). Service route: c/o General Counsel / Corporate Secretary, Menomonee Falls, Wisconsin — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Wisconsin' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Wisconsin DFI Corporate Records — apps.dfi.wi.gov/apps/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] A 2024 third-party-vendor breach exposed more than 4 million Kohl's customers' personal information\nWHAT THE TERMS SAY: A 2024 breach traced to a third-party provider exposed personal information of more than 4 million Kohl's customers, leading to a class action alleging inadequate vendor oversight.\nWHY IT MATTERS: The exposure came through a vendor Kohl's chose to work with, not a flaw in Kohl's own customer-facing systems.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Separate breach at debt collector FBCS exposed 4+ million people and named Kohl's in the litigation\nWHAT THE TERMS SAY: Kohl's was named, alongside at least 3 other unrelated companies, in litigation tied to a February 2024 breach at Financial Business and Consumer Solutions Inc., a debt-collection agency, that exposed 4+ million people's data.\nWHY IT MATTERS: This shows a company hiring a third-party debt collector can become entangled in that collector's own separate security failure, even when the underlying matter has nothing to do with a typical retail purchase.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] Kohl's private-label credit programme means the customer relationship also includes a credit file\nWHAT THE TERMS SAY: Kohl's operates a large private-label credit programme, which means the customer relationship includes a credit file.\nWHY IT MATTERS: This adds a financially sensitive data layer on top of the two vendor-breach incidents already documented for Kohl's.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Two separate vendor breaches are well documented with scale figures, but arbitration and fee terms remain unconfirmed.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 7, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 7/20 (severity2+2, breach+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Kohl's  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Kohl's you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Two separate third-party vendor breaches is the finding, and the repetition through DIFFERENT vendors is what makes it structural rather than unlucky: a retailer's exposure is a function of how many third parties it hands data to, not how well it defends its own perimeter. Kohl's also operates a large private-label credit programme, which means the customer relationship includes a credit file - cross-ref the Synchrony row in Credit Card Companies for who actually holds a store card.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Retail & Grocery", "_row_id": 686, "_entity_id": 947, "_entity_slug": "kohl-s", "_issuer": "Kohl's", "_issuer_slug": "kohl-s", "_ticker": "KSS", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Nordstrom", "Category": "General Merchandisers", "Terms & Conditions URL": "See Nordstrom's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Nordstrom's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the general retail-industry vendor-breach patterns (Snowflake, MOVEit, Salesforce/ShinyHunters) documented extensively for peer retailers throughout this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$15.0B", "Market Cap": "Non-public", "Employees": "41,000", "HQ City": "Seattle", "HQ State": "Washington", "CEO": "Erik Nordstrom", "Ticker": "Non-public", "Website (Corporate)": "nordstrom.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (Non-public). Service route: c/o General Counsel / Corporate Secretary, Seattle, Washington — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Washington' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Washington SOS Corporations Search — ccfs.sos.wa.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] Luxury retail increasingly ties in-store purchases to online identity, and no signage discloses it\nWHAT THE TERMS SAY: Luxury retail increasingly links in-store purchases to online identity through payment card matching and clienteling systems that sales associates use, which no signage discloses.\nWHY IT MATTERS: A shopper paying in a physical store has no visible way to know that purchase is being tied to their online profile.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[OTHER · FL-4] Shoppers who use Nordstrom Rack believing it a separate, more anonymous experience are actually in one combined customer record\nWHAT THE TERMS SAY: Off-price and full-line customer data feeds the same corporate profile, so a shopper who uses Rack believing it a separate, more anonymous experience is in one customer record.\nWHY IT MATTERS: Consumers deliberately choosing the off-price channel for perceived distance from the main brand may not realize their data is merged regardless.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Nothing is confirmed at the parent level this pass — no breach, arbitration, or fee finding; only structural profile-merging and undisclosed clienteling tracking are documented.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed at the parent level this pass; the tracker recommends a direct follow-up.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Nordstrom  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Nordstrom takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass at the parent level. Cross-ref the Nordstrom Rack row in Health, Fitness & Misc Services: off-price and full-line customer data feeds the same corporate profile, so a shopper who uses Rack believing it a separate, more anonymous experience is in one customer record. Luxury retail also increasingly links in-store purchases to online identity through payment card matching and clienteling systems that sales associates use, which no signage discloses.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Retail & Grocery", "_row_id": 687, "_entity_id": 948, "_entity_slug": "nordstrom", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Gap", "Category": "Specialty Retailers: Apparel", "Terms & Conditions URL": "See Gap's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Gap's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the general retail-industry vendor-breach patterns (Snowflake, MOVEit, Salesforce/ShinyHunters) documented extensively for peer retailers throughout this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$15.4B", "Market Cap": "$6.8B", "Employees": "82,000", "HQ City": "San Francisco", "HQ State": "California", "CEO": "Richard Dickson", "Ticker": "GAP", "Website (Corporate)": "gapinc.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (GAP). Service route: c/o General Counsel / Corporate Secretary, San Francisco, California — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Gap, Old Navy, Banana Republic, and Athleta share one loyalty infrastructure, merging shoppers into a single household-income profile\nWHAT THE TERMS SAY: Gap, Old Navy, Banana Republic and Athleta share one company and one loyalty infrastructure, so a customer shopping across four apparently different brands at four price points is building a single profile that also reveals household composition and income band.\nWHY IT MATTERS: A shopper treating these as separate brands is unknowingly consolidating their spending pattern into one revealing profile.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No confirmed breach, arbitration, or fee finding exists for Gap this pass. The co-branded credit-card dispute-routing issue mentioned in the row is a cross-reference to the Synchrony row (a different company) and isn't counted as an independent Gap finding here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed this pass; only the cross-brand profile-merging point is documented.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Gap  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Gap you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Gap, Old Navy, Banana Republic and Athleta share one company and one loyalty infrastructure, so a customer shopping across four apparently different brands at four price points is building a single profile that also reveals household composition and income band. Gap also operates a co-branded credit programme — cross-ref the Synchrony row in Credit Card Companies for why disputes on a store card routinely go to the wrong entity.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Retail & Grocery", "_row_id": 688, "_entity_id": 949, "_entity_slug": "gap", "_issuer": "Gap", "_issuer_slug": "gap", "_ticker": "GAP", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Advance Auto Parts", "Category": "Specialty Retailers: Other", "Terms & Conditions URL": "shop.advanceautoparts.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "shop.advanceautoparts.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED 2024 SNOWFLAKE-LINKED BREACH: an attacker accessed Advance Auto Parts' Snowflake cloud database environment April 14-May 24, 2024 (a 40-day intrusion window), exposing personal information — including Social Security numbers — of approximately 2.3 MILLION current/former EMPLOYEES AND JOB APPLICANTS (not primarily retail customers). This was part of the SAME broader 2024 Snowflake cloud-platform breach wave that also affected Ticketmaster, Santander Bank, and 160+ other organizations (documented via the Cricket Wireless row, Retail & Fintech tab, and the Advance Auto Parts case was itself consolidated into that same multidistrict litigation, In re: Snowflake, Inc. Data Security Breach Litigation). Advance Auto Parts and parent Advance Stores Company agreed to a $10 MILLION settlement (final approval Oct 23, 2025), offering up to $5,100 for documented losses, a ~$100 CCPA-specific payment for California residents, and 2 years of Kroll credit/identity monitoring; payments began issuing Feb 5, 2026.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for retail customers, separate from this employee/applicant-focused settlement.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This breach primarily affected EMPLOYEES AND JOB APPLICANTS rather than retail shoppers — worth being precise about this distinction; see the Cricket Wireless row (Retail & Fintech tab) for the broader Snowflake breach wave this is part of.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Raleigh", "HQ State": "North Carolina", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'North Carolina' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NC SOS Business Registration Search — sosnc.gov/online_services/search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] A 2024 Snowflake cloud breach exposed Social Security numbers of 2.3 million Advance Auto Parts employees and job applicants\nWHAT THE TERMS SAY: An attacker accessed Advance Auto Parts' Snowflake cloud database environment April 14-May 24, 2024 (a 40-day intrusion window), exposing personal information — including Social Security numbers — of approximately 2.3 million current/former employees and job applicants, not primarily retail customers.\nWHY IT MATTERS: This was primarily an employee/applicant data breach, not a retail-customer one, and it was part of the broader 2024 Snowflake breach wave that also affected 160+ other organizations.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-2] Advance Auto Parts and its parent agreed to a $10 million settlement over the Snowflake breach, with payments starting in 2026\nWHAT THE TERMS SAY: Advance Auto Parts and parent Advance Stores Company agreed to a $10 million settlement (final approval Oct 23, 2025), offering up to $5,100 for documented losses, a ~$100 CCPA-specific payment for California residents, and 2 years of Kroll credit/identity monitoring; payments began issuing Feb 5, 2026.\nWHY IT MATTERS: The settlement offers up to $5,100 for documented losses, a ~$100 CCPA-specific payment for California residents, and 2 years of Kroll credit/identity monitoring, with payments issuing from Feb 5, 2026 - it is now resolved rather than an open lawsuit.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] Auto parts purchase history builds a vehicle profile that can feed insurance and advertising inference\nWHAT THE TERMS SAY: The tracker notes auto parts purchase history is also a vehicle profile: what a customer bought tells an inference engine the make, model, age and condition of their car, feeding into insurance and advertising markets documented elsewhere in the tracker.\nWHY IT MATTERS: This is a separate, ongoing customer-data inference risk distinct from the employee-focused Snowflake breach.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach and settlement are documented with strong specifics, but arbitration terms for retail customers remain unconfirmed.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Advance Auto Parts  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Advance Auto Parts you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2024 Snowflake-linked breach places Advance Auto Parts inside one of the largest cloud-credential incidents on record - a campaign that reached numerous unrelated companies through customer accounts on a shared data platform rather than through any one company's systems. Auto parts purchase history is also a vehicle profile: what you bought tells an inference engine the make, model, age and condition of your car, which feeds directly into the insurance and advertising markets documented in the Auto Apps and Insurance tabs.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Retail & Grocery", "_row_id": 689, "_entity_id": 950, "_entity_slug": "advance-auto-parts", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "AutoZone", "Category": "Specialty Retailers: Other", "Terms & Conditions URL": "autozone.com/l/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "autozone.com/l/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED BREACH via the SAME broader MOVEit vulnerability documented for Hartford Insurance, TIAA, and Delta Dental elsewhere in this tracker: a breach around August 15 (year not fully specified in sources reviewed) compromised approximately 185,000 customers' personally identifiable information (names, addresses, birthdates, Social Security numbers, driver's license numbers, financial details) — AutoZone did not notify affected individuals until November 21, roughly 3 months after detecting the intrusion (investigation initiated Nov 3). The resulting class action (filed Nov 24) alleges the notification was both DELAYED AND INADEQUATE, lacking specifics about the attack or the stolen data's current location, and demands AutoZone fully encrypt customer data and establish firewalls/monitoring systems going forward.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is a customer-facing (not employee-facing) breach, distinct from the Advance Auto Parts entry above — the two major US auto-parts retailers were both swept into DIFFERENT major vendor-vulnerability breach waves (Snowflake for Advance Auto Parts, MOVEit for AutoZone) within roughly the same period, illustrating how pervasive these two specific vulnerabilities were across corporate America broadly.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$18.9B", "Market Cap": "$52.5B", "Employees": "100,800", "HQ City": "Memphis", "HQ State": "Tennessee", "CEO": "Philip Daniele III", "Ticker": "AZO", "Website (Corporate)": "autozone.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AZO). Service route: c/o General Counsel / Corporate Secretary, Memphis, Tennessee — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Tennessee' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Tennessee SOS Business Search — tnbear.tn.gov/Ecommerce/FilingSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] A MOVEit-linked breach compromised about 185,000 AutoZone customers' SSNs and driver's license numbers, with notice delayed roughly three months\nWHAT THE TERMS SAY: A breach around August 15 (exact year not fully specified in sources reviewed) compromised approximately 185,000 customers' personal information (names, addresses, birthdates, Social Security numbers, driver's license numbers, financial details); AutoZone did not notify affected individuals until November 21, roughly 3 months after detecting the intrusion, with investigation initiated November 3.\nWHY IT MATTERS: A multi-month gap between detection and notification leaves affected customers unaware and unable to act during that window.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-2] A class action filed days after notification alleges AutoZone's disclosure was both delayed and inadequate\nWHAT THE TERMS SAY: The resulting class action (filed Nov 24) alleges the notification was both delayed and inadequate, lacking specifics about the attack or the stolen data's current location, and demands AutoZone fully encrypt customer data and establish firewalls/monitoring systems going forward.\nWHY IT MATTERS: The suit's specific demands (encryption, firewalls, monitoring) imply plaintiffs allege these protections were previously absent.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only the breach and resulting litigation are confirmed for AutoZone this pass; arbitration and fee terms remain unconfirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach and litigation are documented with dates and figures, but arbitration and fee terms remain unconfirmed.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 7, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 7/20 (severity2+2, breach+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "AutoZone  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using AutoZone you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "AutoZone was caught in the MOVEit vulnerability - the 2023 file-transfer flaw documented across this tracker that produced breaches at dozens of entirely unrelated organisations, including Delta Dental in Life-Health-Dental. One flaw in one vendor's product, and a customer's exposure had nothing to do with which auto parts retailer they chose. This is the same lesson as SITA, AMCA, CDK and Salesloft, and at this point in the tracker the repetition is itself the most important finding: the security boundary that determines consumer exposure is almost never the company whose name is on the receipt.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Retail & Grocery", "_row_id": 690, "_entity_id": 951, "_entity_slug": "autozone", "_issuer": "AutoZone", "_issuer_slug": "autozone", "_ticker": "AZO", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "O'Reilly Automotive", "Category": "Specialty Retailers: Other", "Terms & Conditions URL": "See O'Reilly Automotive's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See O'Reilly Automotive's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the general retail-industry vendor-breach patterns (Snowflake, MOVEit, Salesforce/ShinyHunters) documented extensively for peer retailers throughout this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$17.8B", "Market Cap": "$71.7B", "Employees": "85,579", "HQ City": "Springfield", "HQ State": "Missouri", "CEO": "Brad Beckham", "Ticker": "ORLY", "Website (Corporate)": "oreillyauto.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (ORLY). Service route: c/o General Counsel / Corporate Secretary, Springfield, Missouri — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Missouri' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Missouri SOS Business Search — bsd.sos.mo.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] O'Reilly purchase history could reconstruct a vehicle's make, model, mileage and mechanical issues\nWHAT THE TERMS SAY: The tracker notes (unconfirmed for this company) that auto parts purchase history can reconstruct a vehicle profile — make, model, year, mileage band and current mechanical problems — potentially feeding insurance and advertising markets. O'Reilly also runs a commercial account business serving independent repair shops, so a driver's repair history can sit with both the retailer and the garage.\nWHY IT MATTERS: If such profiles were shared, a driver's repair history could reach insurers or advertisers, though nothing company-specific is confirmed this pass.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data sharing, arbitration and fees are all marked 'not independently confirmed' or 'not itemized' this pass; only the SCARY field's inferred vehicle-profile scenario is substantive, and even that is explicitly flagged as unconfirmed for O'Reilly specifically.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nearly everything is marked 'not independently confirmed' or 'not itemized' this pass, with only speculative reasoning in the SCARY field.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "O'Reilly Automotive  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, O'Reilly Automotive takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Auto parts purchase history reconstructs a vehicle profile — make, model, year, mileage band and current mechanical problems — which feeds directly into the insurance and advertising markets documented in the Insurance and Auto Apps tabs. O'Reilly also runs a large commercial account business serving independent repair shops, so a driver's repair history can sit with both the parts retailer and the garage. Nothing company-specific confirmed this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Retail & Grocery", "_row_id": 691, "_entity_id": 952, "_entity_slug": "o-reilly-automotive", "_issuer": "O'Reilly Automotive", "_issuer_slug": "o-reilly-automotive", "_ticker": "ORLY", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Tractor Supply", "Category": "Specialty Retailers: Other", "Terms & Conditions URL": "See Tractor Supply's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Tractor Supply's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the general retail-industry vendor-breach patterns (Snowflake, MOVEit, Salesforce/ShinyHunters) documented extensively for peer retailers throughout this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$15.5B", "Market Cap": "$15.4B", "Employees": "39,000", "HQ City": "Brentwood", "HQ State": "Tennessee", "CEO": "Harry Lawton III", "Ticker": "TSCO", "Website (Corporate)": "tractorsupply.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (TSCO). Service route: c/o General Counsel / Corporate Secretary, Brentwood, Tennessee — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Tennessee' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Tennessee SOS Business Search — tnbear.tn.gov/Ecommerce/FilingSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Tractor Supply purchases can reveal property size, farming activity and animal ownership\nWHAT THE TERMS SAY: The tracker observes (unconfirmed for this company) that livestock feed, veterinary supplies, fencing and equipment purchases describe property size, agricultural activity and animal ownership, and that firearms-adjacent and ammunition sales in some locations add a further category of interest.\nWHY IT MATTERS: For a rural customer base with limited retail alternatives, such inferable profiles could interest parties beyond advertisers, though nothing is confirmed for this company specifically.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data sharing, arbitration and fees are all marked 'not independently confirmed' or 'not itemized' this pass; only the SCARY field's inferred purchase-profile scenario is substantive, and it is explicitly labeled unverified rather than clean.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nearly everything is marked 'not independently confirmed' or 'not itemized' this pass, with only speculative reasoning in the SCARY field.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Tractor Supply  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Tractor Supply takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Tractor Supply's purchase data is unusually inferential for a general retailer: livestock feed, veterinary supplies, fencing and equipment describe property size, agricultural activity and animal ownership, and firearms-adjacent and ammunition sales in some locations add a category of interest to parties well beyond advertisers. Rural customer base with limited retail alternatives. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Retail & Grocery", "_row_id": 692, "_entity_id": 953, "_entity_slug": "tractor-supply", "_issuer": "Tractor Supply", "_issuer_slug": "tractor-supply", "_ticker": "TSCO", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Skechers U.S.A.", "Category": "Apparel", "Terms & Conditions URL": "See Skechers U.S.A.'s own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Skechers U.S.A.'s own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the general retail-industry vendor-breach patterns (Snowflake, MOVEit, Salesforce/ShinyHunters) documented extensively for peer retailers throughout this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Manhattan Beach", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Skechers going private in 2025 ends SEC filings and outside scrutiny of future practices\nWHAT THE TERMS SAY: Per the tracker, Skechers went private via a 3G Capital transaction in 2025, ending public disclosure obligations — no more SEC filings, earnings calls, or analyst scrutiny.\nWHY IT MATTERS: With less external visibility, future data-privacy or business-practice incidents at Skechers will be harder to detect from outside, per the tracker.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data sharing, arbitration and fees are all unconfirmed or not itemized this pass; the only substantive, company-specific fact is the 2025 going-private transition, a transparency/structural note rather than a specific consumer-terms harm.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Consumer terms are unconfirmed this pass, and the 2025 going-private transition will reduce future public visibility into practices.", "Exposure Score (0-100)": 8, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "App / Service", "Ownership Path": "Skechers U.S.A.  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Skechers U.S.A. takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Footwear sold through retailers and company stores. Skechers went private in a 3G Capital transaction in 2025, which ends public disclosure — no more SEC filings, no earnings calls, no analyst scrutiny — so future incidents at this company will be materially harder to detect from outside. That transition is itself the finding, and it applies to every company in this tracker that leaves public markets.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Retail & Grocery", "_row_id": 693, "_entity_id": 954, "_entity_slug": "skechers-u-s-a", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "PVH (Calvin Klein/Tommy Hilfiger)", "Category": "Apparel", "Terms & Conditions URL": "See PVH (Calvin Klein/Tommy Hilfiger)'s own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See PVH (Calvin Klein/Tommy Hilfiger)'s own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the general retail-industry vendor-breach patterns (Snowflake, MOVEit, Salesforce/ShinyHunters) documented extensively for peer retailers throughout this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Calvin Klein and Tommy Hilfiger customer data sits with one PVH parent company\nWHAT THE TERMS SAY: PVH is a brand holding company, so Calvin Klein and Tommy Hilfiger customer data sits with one corporate parent even though the two labels are marketed as distinct brands at different price points.\nWHY IT MATTERS: A customer shopping one brand may not realize their data is pooled with a sister brand under the same parent company.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration, fees and data-sharing specifics are unconfirmed this pass; PVH's 2025 placement on China's unreliable entity list over Xinjiang cotton sourcing is a supply-chain/geopolitical matter, not a consumer-data or terms finding, so it is not counted as a second troubling term here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Consumer terms and data-sharing practices are unconfirmed this pass; only the cross-brand data-pooling structure is noted.", "Exposure Score (0-100)": 9, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 5/20 (severity2+2, penalty+3) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "PVH (Calvin Klein/Tommy Hilfiger)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using PVH (Calvin Klein/Tommy Hilfiger) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A brand holding company, so Calvin Klein and Tommy Hilfiger customer data sits with one parent despite being marketed as distinct labels at different price points. PVH was also placed on China's unreliable entity list in 2025 over Xinjiang cotton sourcing statements — a geopolitical and supply-chain matter rather than a data one, but the reason this row is not simply a low-finding apparel entry.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Retail & Grocery", "_row_id": 694, "_entity_id": 955, "_entity_slug": "pvh-calvin-klein-tommy-hilfiger", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "M&T Bank", "Category": "Commercial Banks", "Terms & Conditions URL": "mtb.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "mtb.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED THIRD-PARTY VENDOR BREACH: M&T Bank learned in August 2025 that one of its third-party service providers experienced a security incident (occurring July-August 2025) — M&T's own systems were NOT affected, but the vendor breach exposed customer Social Security numbers and financial account details. The bank's disclosure to the Massachusetts Attorney General (filed April 17, 2026, roughly 8 months after the underlying incident) reported 462 affected Massachusetts residents specifically; national scope not fully detailed in sources reviewed this pass.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The roughly 8-month gap between the underlying incident (July-Aug 2025) and the Massachusetts AG disclosure (April 2026) is a notably long notification timeline — worth flagging alongside similar delayed-notification patterns documented throughout this tracker (Marriott, Sony/PSN, Hilton).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Buffalo", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Vendor breach exposed M&T customer SSNs; bank took ~8 months to notify regulators\nWHAT THE TERMS SAY: A third-party service provider was breached between July and August 2025, exposing customer Social Security numbers and financial account details; M&T's own systems were not affected. M&T disclosed to the Massachusetts Attorney General on April 17, 2026 — roughly 8 months later — reporting 462 affected Massachusetts residents, with national scope not fully detailed.\nWHY IT MATTERS: Affected customers' SSNs and financial details were exposed for months before formal notification reached at least one state regulator, delaying any protective steps consumers could take.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-4] M&T customer records moved between owners through the Wilmington Trust and People's United deals\nWHAT THE TERMS SAY: M&T acquired Wilmington Trust and later People's United, meaning DMV-region customers' records have moved between corporate entities more than once; the tracker notes bank consolidation transfers customer data as an asset with each merger, without depositors being asked.\nWHY IT MATTERS: Customers whose bank is acquired have no say as their financial records pass to a new corporate owner.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct, company-specific harms are documented this pass — the confirmed vendor breach and the merger-driven data transfers; arbitration and fees fields are unconfirmed/not itemized, leaving no third distinct item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The vendor breach is confirmed with specifics, but arbitration/fee terms are unconfirmed and the breach's full national scope isn't detailed.", "Exposure Score (0-100)": 9, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "M&T Bank  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using M&T Bank you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "M&T learned in August 2025 that a third-party vendor had been breached - the pattern that now dominates this tracker. M&T is a major Mid-Atlantic and Northeast regional bank with substantial Maryland presence following its acquisition of Wilmington Trust and later People's United, which means DMV customers' records have moved between corporate entities more than once. Bank consolidation transfers customer data as an asset with each merger, and depositors are never asked.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Banks & Financial", "_row_id": 695, "_entity_id": 956, "_entity_slug": "m-t-bank", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fifth Third Bancorp", "Category": "Commercial Banks", "Terms & Conditions URL": "See Fifth Third Bancorp's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Fifth Third Bancorp's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach. Recommend checking against the broader 2025-2026 bank third-party-vendor breach wave documented for Citizens Financial and M&T Bank in this same tab.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cincinnati", "HQ State": "Ohio", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-4] CFPB action: Fifth Third employees allegedly opened unauthorized accounts in customers' names\nWHAT THE TERMS SAY: The tracker states the CFPB brought an action concerning Fifth Third employees opening unauthorized accounts in customers' names to meet sales goals — the same category of conduct as the Wells Fargo scandal.\nWHY IT MATTERS: Customers could end up with accounts opened in their names that they never authorized - the same category of conduct that produced the Wells Fargo scandal, and a sales-incentive failure rather than a data one.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data sharing, arbitration and fees are all unconfirmed or not itemized this pass; the CFPB unauthorized-accounts finding is the only substantive, company-specific item, and it is a sales-practice issue rather than a data or terms one.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data-sharing and arbitration terms are unconfirmed this pass; only the CFPB regulatory matter is substantive.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 5/20 (severity2+2, penalty+3) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Fifth Third Bancorp  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Fifth Third Bancorp takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass on data privacy. Fifth Third's more consequential consumer finding is regulatory: the CFPB brought an action concerning employees opening unauthorised accounts in customers' names to meet sales goals - the same category of conduct that produced the Wells Fargo scandal. That is a sales-incentive failure rather than a data one, and it is recorded here because it is the finding a consumer would actually want to know about this bank.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Banks & Financial", "_row_id": 696, "_entity_id": 957, "_entity_slug": "fifth-third-bancorp", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Citizens Financial", "Category": "Commercial Banks", "Terms & Conditions URL": "citizensbank.com/terms-of-use.aspx", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "citizensbank.com/privacy.aspx", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED VERY RECENT BREACH (April 2026): the Russian ransomware group EVEREST publicly claimed responsibility for attacking an UNNAMED third-party vendor holding Citizens Bank customer data on or about April 20, 2026 — Everest claimed to have acquired 3.4 MILLION RECORDS (names, home addresses, account numbers, Social Security numbers) and posted them on the dark web. Citizens characterized the impact as affecting 'a small number of customers,' but at least SIX separate class actions (against both Citizens and a second bank, Frost Bank, hit by the same Everest campaign) were filed within days in Rhode Island and Texas courts, alleging the real scope may be far larger than Citizens' own characterization — a genuine, unresolved dispute over the breach's true scale. One complaint specifically asks the court to DECLARE Citizens' current data-security practices INADEQUATE, not just seek damages.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual account agreements, separate from these pending class actions.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The SAME Everest ransomware campaign hit Citizens Bank and Frost Bank (a separate, unrelated Texas bank) within the same window — both blaming an UNNAMED shared or similar third-party vendor — illustrating the same vendor-risk pattern documented repeatedly throughout this tracker, here hitting two competing banks simultaneously.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Providence", "HQ State": "Rhode Island", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): RI SOS Corporate Database — business.sos.ri.gov/CorpWeb/CorpSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Everest hackers claim 3.4M Citizens Bank records stolen; bank calls it 'a small number'\nWHAT THE TERMS SAY: The Russian ransomware group Everest publicly claimed responsibility for breaching an unnamed third-party vendor holding Citizens Bank customer data around April 20, 2026, claiming to have acquired 3.4 million records (names, addresses, account numbers, SSNs) and posting them on the dark web. Citizens has characterized the impact as affecting 'a small number of customers.'\nWHY IT MATTERS: There is a genuine, unresolved dispute over how many customers are actually affected, with the hacker's own claimed figure far exceeding the bank's characterization.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-3] At least six class actions allege the breach's real scope is far larger than Citizens' own characterization\nWHAT THE TERMS SAY: At least six separate class actions were filed within days in Rhode Island and Texas courts against Citizens and a second bank (Frost Bank) hit by the same Everest campaign, alleging the real scope may be far larger than Citizens' own characterization; one complaint specifically asks the court to declare Citizens' current data-security practices inadequate.\nWHY IT MATTERS: The tracker calls this a genuine, unresolved dispute over the breach's true scale, and one complaint asks the court to declare Citizens' current data-security practices inadequate rather than just seek damages.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms for individual account agreements are unconfirmed this pass and fees are not itemized; the GLBA affiliate-sharing opt-out note in the SCARY field is explicitly generic industry context ('every regional bank row'), not a Citizens-specific fact, so it is not counted as a third item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach and litigation are well-documented, but the true scope is disputed and arbitration/fee terms remain unconfirmed.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Citizens Financial  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Citizens Financial takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The April 2026 incident was attributed to a Russian ransomware group. Beyond the breach itself, the note worth recording for every regional bank row in this tracker is that a bank holds the single most complete behavioural record that exists about a person - every transaction, every counterparty, every location, continuously - and the Gramm-Leach-Bliley framework governing it permits substantially more affiliate sharing than most customers assume, with an opt-out that is mailed once and rarely exercised.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Banks & Financial", "_row_id": 697, "_entity_id": 958, "_entity_slug": "citizens-financial", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "First Citizens BancShares", "Category": "Commercial Banks", "Terms & Conditions URL": "See First Citizens BancShares's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See First Citizens BancShares's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach. First Citizens notably acquired the failed Silicon Valley Bank's assets (2023) — worth confirming whether any SVB-era customer data/security issues carried over into First Citizens' current systems.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Raleigh", "HQ State": "North Carolina", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NC SOS Business Registration Search — sosnc.gov/online_services/search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-4] First Citizens got SVB's entire customer database overnight with no depositor consent\nWHAT THE TERMS SAY: First Citizens acquired the failed Silicon Valley Bank's assets in 2023; per the tracker, bank failures transfer entire customer databases to an acquirer overnight under FDIC-brokered terms, with no customer consent and no practical ability to decline — depositors woke up as customers of a different institution with a different privacy policy.\nWHY IT MATTERS: Depositors had no say in who now holds their financial data or under what privacy terms, since the transfer happens automatically as part of a bank failure.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data sharing, arbitration and fees are all unconfirmed or not itemized this pass, including any SVB-era carryover issues the tracker flags for follow-up; only the FDIC-brokered acquisition structure is a substantive, stated fact.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Consumer terms and any SVB-era data issues remain unconfirmed this pass.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "First Citizens BancShares  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using First Citizens BancShares you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. First Citizens acquired the failed Silicon Valley Bank in 2023, which is the note worth recording: bank failures transfer entire customer databases to an acquirer overnight under FDIC-brokered terms, with no customer consent and no practical ability to decline. Depositors woke up as customers of a different institution with a different privacy policy. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Banks & Financial", "_row_id": 698, "_entity_id": 959, "_entity_slug": "first-citizens-bancshares", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "State Street", "Category": "Commercial Banks", "Terms & Conditions URL": "See State Street's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See State Street's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Boston", "HQ State": "Massachusetts", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Massachusetts SOC Corporate Search — corp.sec.state.ma.us/corpweb/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — State Street is a B2B custody bank with no direct consumer relationship or consumer-facing terms; the only individual-level relevance is indirect (custodying retirement assets on behalf of plan administrators), which the tracker itself notes is documented in the Retirement & Telehealth tab rather than here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "B2B custody bank with no consumer-facing terms or disclosure regime; individual relevance is only indirect via institutional clients.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "State Street  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Custody bank holding securities on behalf of institutions — pension funds, endowments, asset managers — rather than individuals. No retail consumer relationship. State Street's individual-level relevance is indirect but real: it custodies the retirement assets of millions of people who have never heard of it, and who deal instead with the plan administrator documented in the Retirement & Telehealth tab.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Banks & Financial", "_row_id": 699, "_entity_id": 960, "_entity_slug": "state-street", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Bank of New York", "Category": "Commercial Banks", "Terms & Conditions URL": "See Bank of New York's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Bank of New York's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] BNY's historical unencrypted backup-tape loss exposed millions with no direct BNY relationship\nWHAT THE TERMS SAY: The tracker notes BNY historically suffered a large unencrypted backup tape loss affecting millions of individuals, with the exposure reaching people through institutions they banked with rather than through any direct relationship with BNY.\nWHY IT MATTERS: People with no direct account at BNY were still exposed, because their data reached BNY indirectly through the institutions that used it as a custodian, and they would have no way to know that.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — BNY is a B2B custody bank with no direct consumer relationship or itemized consumer terms; only the historical backup-tape-loss breach is a substantive, company-specific fact — arbitration and fees are unconfirmed/not itemized for what is, structurally, a non-retail institution.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "A historical breach is documented, but no consumer terms exist and most other fields are not applicable to this B2B institution.", "Exposure Score (0-100)": 3, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 3, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 3/20 (severity1+0, breach+3) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Bank of New York  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The other major US custody bank, same institutional-only structure as State Street. BNY historically suffered a large unencrypted backup tape loss affecting millions of individuals through its client relationships — exposure that reached people via institutions they banked with rather than through any relationship with BNY, which is the defining characteristic of this layer.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Banks & Financial", "_row_id": 700, "_entity_id": 961, "_entity_slug": "bank-of-new-york", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Franklin Resources", "Category": "Securities", "Terms & Conditions URL": "See Franklin Resources's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Franklin Resources's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach. Operates as Franklin Templeton, a major asset manager; most individual exposure comes through mutual fund/retirement account holdings rather than a direct retail relationship.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] Franklin's Western Asset Management had a co-CIO face SEC and DOJ action\nWHAT THE TERMS SAY: Franklin acquired Western Asset Management, whose co-CIO faced SEC and DOJ action over trade allocation — an investor-harm matter rather than a privacy one, per the tracker.\nWHY IT MATTERS: Investors in funds tied to this unit were exposed to alleged trade-allocation misconduct, a direct financial-harm risk distinct from data privacy.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-4] Franklin Templeton investor data often sits with an unnamed recordkeeper or intermediary\nWHAT THE TERMS SAY: Franklin Templeton's consumer relationship runs almost entirely through retirement plans, advisers and fund platforms rather than directly, so an investor's account data sits with a recordkeeper or intermediary they may not be able to name.\nWHY IT MATTERS: Investors may not know who actually holds or controls their account data, making it harder to know who to hold accountable for its handling.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct, company-specific items are documented this pass — the Western Asset Management trade-allocation action and the intermediary-holds-your-data structure; data sharing, arbitration and fees are otherwise unconfirmed or not itemized.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data-sharing and arbitration terms are unconfirmed this pass, and most investor exposure runs through unnamed intermediaries.", "Exposure Score (0-100)": 15, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 11/20 (severity3+8, penalty+3) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Franklin Resources  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Franklin Resources you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Franklin Templeton's consumer relationship runs almost entirely through retirement plans, advisers and fund platforms rather than directly, so an investor's account data sits with a recordkeeper or intermediary they may not be able to name. Franklin also acquired Western Asset Management, whose co-CIO faced SEC and DOJ action over trade allocation — an investor-harm matter rather than a privacy one, and the reason this row is not simply empty.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Banks & Financial", "_row_id": 701, "_entity_id": 962, "_entity_slug": "franklin-resources", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ameriprise Financial", "Category": "Diversified Financials", "Terms & Conditions URL": "See Ameriprise Financial's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Ameriprise Financial's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach. A financial advisory/wealth-management firm; recommend checking for advisor-conduct-related FINRA disciplinary patterns similar to those documented for Edward Jones/Raymond James/LPL in the Brokerages tab.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Minneapolis", "HQ State": "Minnesota", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Minnesota' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Ameriprise client data is spread across thousands of independent adviser offices\nWHAT THE TERMS SAY: Ameriprise operates through a large network of independent financial advisers, so client financial data sits in thousands of individual adviser practices, each a small business with its own systems and its own security capability, per the tracker.\nWHY IT MATTERS: The tracker calls this a far larger attack surface than any corporate perimeter, since client financial data sits in thousands of individual adviser practices, each with its own systems and its own security capability.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data sharing, arbitration and fees are unconfirmed or not itemized this pass, and any FINRA disciplinary pattern is only suggested as a follow-up, not confirmed; only the distributed-adviser-network structure is a substantive, stated fact.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No confirmed breach, arbitration, or fee terms this pass; only a structural data-exposure risk is documented.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Ameriprise Financial  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ameriprise Financial you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Ameriprise operates through a large network of independent financial advisers, which is the structural exposure: client financial data sits in thousands of individual adviser practices, each a small business with its own systems and its own security capability. That is the same distributed-agent problem documented in the New York Life row of Life-Health-Dental, and it is a far larger attack surface than any corporate perimeter.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Banks & Financial", "_row_id": 702, "_entity_id": 963, "_entity_slug": "ameriprise-financial", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Zoetis", "Category": "Pharmaceuticals (animal health)", "Terms & Conditions URL": "zoetis.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "zoetis.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; Zoetis is the world's largest animal-health/veterinary-pharmaceutical company (spun off from Pfizer in 2013) — most consumer interaction is indirect, through pet medications prescribed by veterinarians rather than a direct consumer account relationship.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; Zoetis's consumer-facing footprint is much smaller than most other companies in this tracker given its veterinary-prescription-based business model.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Parsippany", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New Jersey' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NJ Business Records Service — businessrecords.nj.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Zoetis is an animal-health company selling primarily to veterinarians and livestock producers rather than directly to pet owners; the tracker explicitly finds nothing confirmed and states consumer data exposure is minimal and indirect, so no troubling items are recorded this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing confirmed this pass; consumer exposure is described as minimal and indirect via veterinarians.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Zoetis  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Zoetis takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Zoetis is an animal-health company, and the honest finding is that its consumer data exposure is minimal and indirect - it sells primarily to veterinarians and livestock producers rather than to pet owners. Worth cross-referencing against the Trupanion and Healthy Paws rows in the Insurance tab: the pet-health economy generates real consumer financial harm, but it arrives through insurance pricing and vet billing rather than through a pharmaceutical maker's data practices. Nothing confirmed this pass and nothing manufactured.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Health Services", "_row_id": 703, "_entity_id": 964, "_entity_slug": "zoetis", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Quest Diagnostics", "Category": "Health Care: Pharmacy and Other Services", "Terms & Conditions URL": "questdiagnostics.com/home/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "questdiagnostics.com/home/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ONE OF THE LARGEST MEDICAL LAB BREACHES IN HISTORY: Quest Diagnostics' billing vendor, American Medical Collection Agency (AMCA), suffered a breach (Aug 2018-March 2019) exposing personal AND FINANCIAL data — bank account information, credit card numbers, Social Security numbers, and medical information — of approximately 12 MILLION Quest patients; combined with the SAME AMCA breach affecting LabCorp (this same tab) and other labs, the TOTAL affected across all AMCA clients reached nearly 20 MILLION people, making this one of the largest healthcare-billing-related breaches ever recorded. SEPARATELY, an EARLIER, DISTINCT 2016 breach (via Quest's own 'MyQuest by Care360' internet application) exposed HIV-TESTING RESULTS of 34,000 patients — a particularly sensitive health-data category; Quest settled that case for $195,000 (2019), offering $75 per affected patient.", "Arbitration / Class Action Waiver": "Litigation against AMCA and remaining defendants (including Quest Diagnostics, Sunrise Medical Laboratories, CBL Path, and others) remains ONGOING as of mid-2026, even though co-defendant LabCorp has separately settled (see that row) — meaning Quest's own portion of this shared litigation has not yet reached the same resolution stage.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The AMCA breach is a clean, large-scale illustration of the 'medical billing/collections vendor as weak link' pattern — patients whose only interaction was having a lab bill sent to collections had their SSNs and financial data exposed through a company (AMCA) most had never directly heard of or dealt with themselves.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Secaucus", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://amcadatabreachsettlement.com/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'New Jersey' is a non-DMV US state", "Parent / Ultimate Owner": "Quest Diagnostics Incorporated", "Years Referenced in Finding (heuristic)": "2018, 2019", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NJ Business Records Service — businessrecords.nj.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Quest Diagnostics Incorporated). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] AMCA breach exposed ~12M Quest patients' SSNs and financial data — one of the largest ever\nWHAT THE TERMS SAY: Quest's billing vendor, American Medical Collection Agency, was breached between August 2018 and March 2019, exposing personal and financial data — bank account information, credit card numbers, Social Security numbers and medical information — of approximately 12 million Quest patients. Combined with the same breach at LabCorp and other AMCA clients, the total reached nearly 20 million people across all affected labs.\nWHY IT MATTERS: Patients whose only interaction was having a lab bill sent to collections had their SSNs and financial data exposed through a vendor most had never heard of or dealt with directly.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Separate 2016 Quest app breach exposed HIV test results of 34,000 patients\nWHAT THE TERMS SAY: A distinct, earlier 2016 breach through Quest's own 'MyQuest by Care360' internet application exposed HIV-testing results of 34,000 patients. Quest settled that case for $195,000 in 2019, offering $75 per affected patient.\nWHY IT MATTERS: HIV status is an especially sensitive health category, and the $75-per-patient settlement is a modest sum against the exposure of that specific diagnosis.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-1] AMCA's bankruptcy dissolved the entity most responsible while Quest's own suit stays open\nWHAT THE TERMS SAY: AMCA's parent filed for bankruptcy after the breach, and litigation against AMCA and remaining defendants — including Quest — remains ongoing as of mid-2026, even though co-defendant LabCorp has separately settled its own portion.\nWHY IT MATTERS: With the entity most directly responsible for the breach dissolved, affected patients lose one of the practical avenues for recovering damages, and Quest's own resolution is still unsettled years later.\n(evidence: Arbitration | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The AMCA and 2016 breaches are well-documented with specifics, but Quest's own consumer terms and arbitration provisions are not addressed, and litigation remains unresolved.", "Exposure Score (0-100)": 23, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Quest Diagnostics  <-  Quest Diagnostics Incorporated", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Quest Diagnostics takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The AMCA breach is the cleanest illustration in this tracker of harm arriving through an entity the patient never chose and never heard of. American Medical Collection Agency was a billing collections vendor, not a lab - and its payment portal was compromised from August 1, 2018 to March 30, 2019, exposing roughly 11.9 million Quest patients. Across all its clients the total reached at least 20 million people, including names, addresses, dates of birth, Social Security numbers, financial information and medical information. Then AMCA's parent filed for bankruptcy, which is the part with teeth: the entity actually responsible dissolved, taking most practical avenues of recovery with it. You cannot sue a company out of existence twice.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Health Services", "_row_id": 704, "_entity_id": 966, "_entity_slug": "quest-diagnostics", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Labcorp", "Category": "Health Care: Pharmacy and Other Services", "Terms & Conditions URL": "labcorp.com/hipaa-privacy-notice", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "labcorp.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SAME AMCA BREACH as Quest Diagnostics (see that row) — exposed personal/financial data of approximately 7.7 MILLION LabCorp patients specifically. LabCorp reached a SEPARATE $35 MILLION SETTLEMENT (preliminary approval April 21, 2026, final approval hearing Aug 20, 2026, claims deadline Sept 3, 2026) covering everyone whose data Labcorp transmitted to AMCA during the breach window — offering up to $5,000 for documented out-of-pocket losses from identity theft/fraud, credit monitoring, legal services, and related costs. This settlement notably resolves ONLY Labcorp's portion of the shared AMCA litigation — AMCA itself and other co-defendants (including Quest) remain in ongoing litigation.", "Arbitration / Class Action Waiver": "Labcorp's consumer-facing relationship is through lab-test results (patient portals) and direct-to-consumer testing (Labcorp OnDemand). Patient-portal disputes may be governed by the provider's terms (the ordering physician's health system), not Labcorp's own. Labcorp OnDemand ToS contain arbitration provisions. The $35M AMCA breach settlement (finalized 2026, ~7.7M patients) was a class action that was NOT blocked by arbitration — the breach occurred through a third-party billing vendor (AMCA), creating a legal path outside Labcorp's own T&C.", "Fees / Billing Flags": "The $35M settlement is a direct compensation fund for affected patients — worth flagging the Sept 3, 2026 claims deadline prominently given how recently this settlement reached preliminary approval.", "Notes": "This is one of the FEW entries in this tracker where a SPECIFIC, STILL-OPEN CLAIMS DEADLINE (Sept 3, 2026) exists at the time of this research — worth flagging distinctly since most other breach settlements documented throughout this tracker have already closed their claims windows.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Burlington", "HQ State": "North Carolina", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.hipaajournal.com/labcorp-amca-data-breach-settlement/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'North Carolina' is a non-DMV US state", "Parent / Ultimate Owner": "Laboratory Corporation of America Holdings", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NC SOS Business Registration Search — sosnc.gov/online_services/search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Laboratory Corporation of America Holdings). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-05-17 (9mo — severity 4 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] AMCA breach exposed 7.7M Labcorp patients; $35M settlement claims deadline Sept 3, 2026\nWHAT THE TERMS SAY: Roughly 7.7 million Labcorp patients were exposed in the same AMCA billing-vendor breach as Quest. Labcorp reached a separate $35 million settlement (preliminary approval April 21, 2026; final approval hearing August 20, 2026) offering up to $5,000 for documented out-of-pocket losses from identity theft/fraud, credit monitoring, legal services and related costs, with a claims deadline of September 3, 2026. This settlement resolves only Labcorp's portion — AMCA and other co-defendants, including Quest, remain in ongoing litigation.\nWHY IT MATTERS: Affected patients have a real, still-open window to file a claim for compensation, but only for Labcorp's share of the breach — the broader AMCA litigation involving other labs is unresolved.\n(evidence: Data Sharing | Fees | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Which terms govern a Labcorp dispute depends on portal vs. Labcorp OnDemand\nWHAT THE TERMS SAY: Patient-portal disputes may be governed by the ordering physician's health system terms rather than Labcorp's own, while Labcorp OnDemand's direct-to-consumer testing terms contain their own arbitration provisions.\nWHY IT MATTERS: A consumer may not know which entity's terms — and which dispute process — actually apply to their situation, depending on how they accessed Labcorp's services.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-1] Choosing Labcorp over Quest gave no protection — same vendor breached both, plus two more labs\nWHAT THE TERMS SAY: Labcorp and Quest, two direct competitors, were compromised simultaneously through the same AMCA subcontractor, which neither patient population had chosen or heard of; CareCentrix (500,000 patients) and BioReference (423,000 patients) were caught in the same incident.\nWHY IT MATTERS: In a concentrated industry, the security boundary that actually matters is a shared vendor that consumers cannot see, evaluate, or route around by picking a different provider.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach, settlement amount and claims deadline are all specific, but which terms (and whose) govern a given dispute is unclear depending on how a patient accessed services.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 14, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 14/30 (forced_arbitration+12, optout_window_unverified+2) | Data 0/30 (none) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Labcorp  <-  Laboratory Corporation of America Holdings", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Labcorp you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Labcorp had roughly 7.7 million patients exposed in the same AMCA billing-vendor breach as Quest - two direct competitors, compromised simultaneously, through the same subcontractor neither patient population had ever heard of. Choosing Labcorp over Quest, or vice versa, provided no protection whatsoever. CareCentrix (500,000) and BioReference (423,000) were caught in the same incident. The structural lesson recurs across this tracker - see SITA in the Global Airlines tab and MOVEit in Life-Health-Dental - that in concentrated industries the meaningful security boundary is the shared vendor, and consumers cannot see it, evaluate it, or route around it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Health Services", "_row_id": 705, "_entity_id": 968, "_entity_slug": "labcorp", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "DaVita", "Category": "Health Care: Medical Facilities", "Terms & Conditions URL": "davita.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "davita.com/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ONE OF THE LARGEST HEALTHCARE RANSOMWARE BREACHES OF 2025, affecting a genuinely vulnerable patient population: the Interlock ransomware group accessed DaVita's dialysis-labs database (unauthorized access began March 24, 2025, detected April 12, 2025), ultimately confirmed to affect 2,689,826 INDIVIDUALS — among kidney-dialysis patients specifically, a population managing serious chronic illness. Exposed data included names, addresses, birthdates, Social Security numbers, driver's license/government ID numbers, financial information, HEALTH INSURANCE DETAILS, MEDICAL/TREATMENT INFORMATION, actual DIALYSIS LAB TEST RESULTS, and (for a smaller subset) tax ID numbers and IMAGES OF PERSONAL CHECKS written to DaVita. Interlock claimed to have stolen over 20 TERABYTES total (200+ million rows of patient data), leaking 1.5TB publicly after negotiations reportedly failed; security researchers ranked this the SEVENTH-LARGEST ransomware-based breach of 2025 overall, and the THIRD-LARGEST at any US healthcare provider. Multiple class actions were filed within weeks (April-May 2025).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual patient agreements.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Given that dialysis patients depend on DaVita for LIFE-SUSTAINING recurring medical treatment (unlike a one-time lab test), this breach's exposure of actual treatment/lab data for a chronically-ill patient population is among the more serious health-privacy findings in this entire 550+ company tracker — worth flagging with particular care given the vulnerability of the affected population.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Denver", "HQ State": "Colorado", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Colorado' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Colorado SOS Business Search — sos.state.co.us/biz/BusinessEntityCriteria. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Interlock ransomware exposed dialysis results and SSNs for 2.69M DaVita patients\nWHAT THE TERMS SAY: The Interlock ransomware group accessed DaVita's dialysis-labs database (unauthorized access began March 24, 2025, detected April 12, 2025), ultimately confirmed to affect 2,689,826 individuals. Exposed data included names, addresses, birthdates, Social Security numbers, driver's license/government ID numbers, financial information, health insurance details, medical/treatment information, actual dialysis lab test results, and for a smaller subset, tax ID numbers and images of personal checks. Interlock claimed to have stolen over 20 terabytes and leaked 1.5TB publicly after negotiations reportedly failed.\nWHY IT MATTERS: This is ranked the seventh-largest ransomware breach of 2025 overall and the third-largest at a US healthcare provider, exposing not just identifying data but actual dialysis treatment results for a chronically ill population.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-1] Dialysis patients can't pause treatment or switch providers to dodge this breach's fallout\nWHAT THE TERMS SAY: Per the tracker, dialysis patients typically attend treatment three times a week indefinitely and cannot pause care while a provider recovers, and dialysis in the US is a near-duopoly with clinic availability geographically constrained.\nWHY IT MATTERS: The two ordinary consumer responses to a provider failure — switching providers or waiting it out — are both unavailable to the patients affected by this breach.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct company-specific items are documented — the breach itself and the structural lock-in affecting DaVita's patient population; arbitration and fees are unconfirmed/not itemized this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach is extensively documented with specific figures, but arbitration and fee terms remain unconfirmed.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "DaVita  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, DaVita takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2025 DaVita ransomware breach is among the largest healthcare incidents of that year, and the population affected makes it distinct: dialysis patients typically attend treatment three times a week, indefinitely, and cannot pause care while a provider recovers. There is also very little competitive alternative - dialysis in the US is a near-duopoly, and clinic availability is geographically constrained. So the two ordinary consumer responses to a provider's failure, switching and waiting, are both unavailable to exactly the patients affected here.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Health Services", "_row_id": 706, "_entity_id": 969, "_entity_slug": "davita", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Baxter International", "Category": "Medical Products and Equipment", "Terms & Conditions URL": "baxter.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "baxter.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named recent data-privacy lawsuit or breach; Baxter manufactures medical devices/equipment (IV solutions, dialysis products, infusion pumps) primarily sold to hospitals/healthcare providers rather than directly to consumers — most individual exposure is indirect, as a patient receiving treatment via Baxter equipment rather than as a direct account holder.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "As primarily a B2B medical-device manufacturer, Baxter's direct consumer-facing terms/privacy footprint is smaller than most other companies in this tracker — recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Deerfield", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Baxter is primarily a B2B medical-device manufacturer with little direct consumer-facing terms footprint; the tracker confirms nothing company-specific on data privacy this pass and instead flags connected infusion-pump telemetry and FDA cybersecurity compliance as a recommended follow-up area rather than a confirmed finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing company-specific confirmed this pass, and Baxter's consumer-facing terms footprint is minimal given its B2B business model.", "Exposure Score (0-100)": 2, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Baxter International  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing company-specific confirmed this pass on data privacy. Baxter makes infusion pumps, dialysis equipment and IV fluids, and its genuine consumer-safety relevance runs through supply chain rather than data - hospital treatment depends on products with few substitutes and concentrated manufacturing. Recorded honestly as a B2B medical products company; recommend a follow-up on connected infusion-pump telemetry and FDA cybersecurity guidance compliance rather than on consumer terms, which barely exist here.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Health Services", "_row_id": 707, "_entity_id": 970, "_entity_slug": "baxter-international", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sirius XM", "Category": "Entertainment", "Terms & Conditions URL": "siriusxm.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "siriusxm.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not itemized separately from the findings below.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. SiriusXM Customer Agreement, AAA rules. 30-day opt-out via written notice to Sirius XM Radio Inc., 1221 Avenue of the Americas, New York NY 10020. SiriusXM has faced class actions over auto-renewal practices and promotional-rate expiration — the arbitration clause is the primary defense.", "Fees / Billing Flags": "MAJOR NEW YORK AG LAWSUIT, SIRIUS FOUND LIABLE (Nov 2024, affirmed on appeal Nov 2025): NY AG Letitia James sued SiriusXM alleging its cancellation process trapped consumers — the company's OWN internal data showed subscribers spent an average of 11.5 MINUTES to cancel by phone and 30 MINUTES to cancel online, compared to a quick, simple online sign-up process. A New York state judge ruled SiriusXM's 'cancellation procedure is clearly not as easy to use as the initiation method,' violating ROSCA's 'simple mechanism requirement' — the same underlying federal statute behind the FTC's 'click-to-cancel' rule (effective Jan 14, 2025) documented elsewhere in this tracker. SiriusXM has since begun permitting New York subscribers who sign up online to also cancel online; the NY AG is separately pursuing damages/disgorgement, which SiriusXM continues to contest on appeal. SEPARATELY, multiple active lawsuits/mass arbitration demands allege SiriusXM's advertised 'all-in' pricing HIDES a 'US Music Royalty Fee' and 'Administrative Fee' — several dollars/month not included in the advertised price — with past settlements in this fee category paying subscribers $20-$100+ each.", "Notes": "This is one of the clearest court-CONFIRMED (not just alleged) cancellation-difficulty rulings in this entire tracker — a judge specifically found, as a matter of fact based on SiriusXM's own internal data, that cancellation took meaningfully longer than sign-up, directly violating the same 'easy exit' principle behind the newer federal click-to-cancel rule.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$8.6B", "Market Cap": "$10.0B", "Employees": "5,515", "HQ City": "New York", "HQ State": "New York", "CEO": "Jennifer Witz", "Ticker": "SIRI", "Website (Corporate)": "siriusxm.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (SIRI). Service route: c/o General Counsel / Corporate Secretary, New York, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Sirius XM Holdings Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Sirius XM Holdings Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-4] SiriusXM's own data showed 30-minute online cancellations vs. quick signup — court found ROSCA violation\nWHAT THE TERMS SAY: New York's AG sued SiriusXM alleging its cancellation process trapped consumers; SiriusXM's own internal data showed subscribers spent an average of 11.5 minutes to cancel by phone and 30 minutes to cancel online, versus a quick, simple online signup. A New York judge ruled the cancellation procedure was 'clearly not as easy to use as the initiation method,' violating ROSCA's simple-mechanism requirement, a ruling affirmed on appeal in November 2025.\nWHY IT MATTERS: Subscribers were made to spend far longer escaping a subscription than starting one, and SiriusXM has only begun letting New York online sign-ups cancel online — damages and disgorgement are still being contested on appeal.\n(evidence: Fees | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[AUTO_RENEWAL_FEES · FL-1] SiriusXM's 'all-in' price reportedly hides a separate Music Royalty and Admin fee\nWHAT THE TERMS SAY: Multiple active lawsuits and mass arbitration demands allege SiriusXM's advertised 'all-in' pricing hides a 'US Music Royalty Fee' and 'Administrative Fee' — several dollars per month not included in the advertised price — with past settlements in this category paying subscribers $20 to $100 or more each.\nWHY IT MATTERS: Subscribers may pay noticeably more than the advertised price every month because of fees left out of the headline figure.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] SiriusXM mandates binding AAA arbitration and a class waiver, with only a 30-day opt-out\nWHAT THE TERMS SAY: The SiriusXM Customer Agreement mandates binding arbitration under AAA rules with a class action waiver; subscribers have a 30-day opt-out by written notice to a specific New York address. SiriusXM has faced class actions over auto-renewal and promotional-rate expiration, for which the arbitration clause is the primary defense.\nWHY IT MATTERS: Subscribers who miss the narrow 30-day opt-out window lose the ability to join a class action over billing disputes like promotional-rate expiration.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=N; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Arbitration terms, cancellation litigation, and hidden-fee allegations are all clearly documented with specific court findings and figures.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Sirius XM  <-  Sirius XM Holdings Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Sirius XM you gave up your right to sue, your right to join a class action, and your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Sirius XM's most persistent consumer finding is not privacy but subscription mechanics - it has faced sustained regulatory and litigation attention over cancellation friction and over advertised prices that exclude a substantial mandatory fee, which is a negative-option and price-disclosure issue. The data note that does hold: satellite radio in a connected vehicle is one of the channels through which a car maintains a live link to the outside world, and listening data is a preference profile tied to a VIN. Cross-ref the Auto Apps tab.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Telecom & Media", "_row_id": 708, "_entity_id": 972, "_entity_slug": "sirius-xm", "_issuer": "Sirius XM Holdings Inc.", "_issuer_slug": "sirius-xm-holdings-inc", "_ticker": "SIRI", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "News Corp. (WSJ, NY Post, HarperCollins)", "Category": "Publishing, Printing", "Terms & Conditions URL": "newscorp.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "newscorp.com/privacy-statement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named recent data-privacy lawsuit or breach for News Corp's consumer subscription products (Wall Street Journal, NY Post, HarperCollins); recommend checking against the general newspaper-subscription tracking-pixel/surveillance-pricing pattern documented for The Washington Post and NYTimes elsewhere in this tracker, given the structural similarity of subscription news businesses.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual WSJ/subscription agreements.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the NYTimes row (Media, News & Creative Apps tab) for the Washington Post surveillance-pricing finding that may plausibly extend to WSJ given similar subscription business models.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": "$8.5B", "Market Cap": "$14.8B", "Employees": "23,900", "HQ City": "New York", "HQ State": "New York", "CEO": "Robert Thomson", "Ticker": "NWSA", "Website (Corporate)": "newscorp.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (NWSA). Service route: c/o General Counsel / Corporate Secretary, New York, New York — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware; most large filers use The Corporation Trust Company or Corporation Service Company) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] WSJ and NY Post reading habits sit with one News Corp parent as a political/financial profile\nWHAT THE TERMS SAY: The tracker notes subscriber reading data across the Wall Street Journal and the New York Post is a political and financial profile, and both titles sit under News Corp.\nWHY IT MATTERS: A single parent company holds reading data across both titles, which the tracker describes as a political and financial profile of the subscriber.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data sharing, arbitration and fees for News Corp's consumer subscription products are unconfirmed this pass; the state-linked-actor intrusion targeting journalists' communications is explicitly a press-freedom matter rather than a consumer-privacy one per the tracker, and News Corp's Perplexity lawsuit is News Corp acting as plaintiff, not a finding against its own consumers — so only the cross-publication reader-profiling note is counted here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Consumer subscription data-sharing and arbitration terms remain unconfirmed this pass; the substantive items found are explicitly categorized as non-consumer (press freedom, plaintiff litigation).", "Exposure Score (0-100)": 8, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "News Corp. (WSJ, NY Post, HarperCollins)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, News Corp. (WSJ, NY Post, HarperCollins) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing recent confirmed this pass on consumer data, but News Corp has appeared in this tracker already as a PLAINTIFF - Dow Jones and NY Post sued Perplexity seeking $150,000 per proven infringement, documented in the LLM Providers tab. News Corp did disclose a prolonged intrusion attributed to a state-linked actor targeting journalists' communications, which is a press-freedom finding rather than a consumer-privacy one and should be kept in that category. Subscriber reading data across WSJ and the Post is a political and financial profile.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Telecom & Media", "_row_id": 709, "_entity_id": 973, "_entity_slug": "news-corp-wsj-ny-post-harpercollins", "_issuer": "News Corp. (WSJ, NY Post, HarperCollins)", "_issuer_slug": "news-corp-wsj-ny-post-harpercollins", "_ticker": "NWSA", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "EchoStar (Dish Network)", "Category": "Telecommunications", "Terms & Conditions URL": "dish.com/legal/terms-of-service/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "dish.com/legal/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "HISTORICAL CONFIRMED BREACH (2023): Dish Network (now part of EchoStar following a 2023 merger) suffered a ransomware attack that caused a multi-day nationwide OUTAGE affecting billing systems, customer service, and internal operations — later confirmed to have exposed personal information of current/former employees and a smaller number of customers. Multiple class actions were filed shortly after.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. DISH Network Residential Customer Agreement. 30-day opt-out. EchoStar completed its merger with DISH in January 2024. The combined entity's arbitration clause covers both satellite TV and wireless (Boost Mobile) disputes.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "EchoStar/Dish's 2023 breach caused an unusually visible SERVICE OUTAGE (not just data exposure) — customers couldn't pay bills or reach customer service for days, a distinct operational-disruption harm beyond the typical 'your data was exposed' pattern documented elsewhere in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Englewood", "HQ State": "Colorado", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Colorado SOS Business Search — sos.state.co.us/biz/BusinessEntityCriteria. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2023 Dish ransomware outage also cut off customers' ability to pay bills or get help\nWHAT THE TERMS SAY: A 2023 ransomware attack on Dish Network (now EchoStar) caused a multi-day nationwide outage affecting billing systems, customer service and internal operations, and was later confirmed to have exposed personal information of current/former employees and a smaller number of customers. Multiple class actions were filed shortly after.\nWHY IT MATTERS: Beyond the data exposure, affected customers could not reach anyone to ask what had happened or even pay their bills for days — the incident disabled the very channel through which consumers would exercise any rights they had.\n(evidence: Data Sharing | Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] EchoStar's combined DISH-Boost Mobile arbitration clause spans TV and wireless disputes\nWHAT THE TERMS SAY: The DISH Network Residential Customer Agreement mandates binding arbitration with a class action waiver and a 30-day opt-out; following EchoStar's January 2024 merger with DISH, the combined entity's arbitration clause covers both satellite TV and wireless (Boost Mobile) disputes.\nWHY IT MATTERS: Customers of either service lose their day in court unless they opt out within 30 days, and that single clause now spans two previously separate businesses.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct, company-specific items are documented this pass — the 2023 breach/outage and the combined-entity arbitration clause; fees are not itemized, and the note about viewing data tied to a household address is too brief/generic to support a distinct third item.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2023 breach and outage are clearly documented, but the exact number of affected customers and fee details are not stated.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "EchoStar (Dish Network)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using EchoStar (Dish Network) you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2023 Dish breach is worth remembering for its operational shape: the ransomware attack took down customer service systems and the company's own websites for an extended period, meaning affected customers could not reach anyone to ask what had happened. That is a distinct category of harm from data exposure alone - the incident disabled the mechanism through which consumers would have exercised any right they had. Satellite TV also holds viewing data tied to a household address.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Telecom & Media", "_row_id": 710, "_entity_id": 974, "_entity_slug": "echostar-dish-network", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Altice USA (Optimum, fmr. Suddenlink)", "Category": "Telecommunications", "Terms & Conditions URL": "optimum.net/terms-of-service/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "optimum.net/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "See the Optimum row (Internet Providers tab) for the primary finding already documented in this tracker: an active 2025 MASS ARBITRATION (Milberg) involving 1 million+ Optimum subscribers over being billed for MSG Networks sports channels after a blackout made the channels unavailable.", "Arbitration / Class Action Waiver": "SEPARATE, HISTORICAL BILLING LAWSUIT (2019): a former Optimum customer sued Cablevision/Altice over a billing-policy change allegedly charging customers for the ENTIRE remaining billing period regardless of when service was actually cancelled mid-cycle.", "Fees / Billing Flags": "TEXAS AG SETTLEMENT (Assurance of Voluntary Compliance): CSC Holdings (Altice's operating subsidiary, operating as 'Suddenlink' before its August 2022 rebrand to 'Optimum') agreed to pay $350,000 to Texas after years of consumer complaints about suspect billing practices, slow internet speeds, frequent outages, poor customer service, and misleading promotions across 100+ Texas service areas.", "Notes": "See the Optimum row (Internet Providers tab) for the primary mass-arbitration finding; the Suddenlink-to-Optimum rebrand (2022) is worth noting since older complaints/settlements may reference the 'Suddenlink' name rather than 'Optimum' or 'Altice.'", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Long Island City", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] Texas AG settlement: Altice's Suddenlink/Optimum unit agreed to pay $350K over billing complaints\nWHAT THE TERMS SAY: CSC Holdings (operating as Suddenlink, rebranded Optimum in Aug 2022) agreed to pay Texas $350,000 in an Assurance of Voluntary Compliance after years of complaints about billing, slow speeds, outages, poor service, and misleading promotions across 100+ Texas service areas.\nWHY IT MATTERS: A $350,000 settlement is a modest penalty relative to complaints spanning 100+ service areas over multiple years, and may not meaningfully change billing or service practices.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "[AUTO_RENEWAL_FEES · FL-1] 2019 suit alleged Cablevision/Altice billed for the full period despite mid-cycle cancellation\nWHAT THE TERMS SAY: A former Optimum customer sued Cablevision/Altice over a billing-policy change allegedly charging customers for the entire remaining billing period regardless of when service was actually cancelled mid-cycle.\nWHY IT MATTERS: If true, a customer who cancels early in a billing cycle would still be charged as though they used the full period, penalizing early cancellation.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two company-specific items are directly stated in this row. The Data Sharing field and part of the SCARY field point to the Optimum row's mass-arbitration finding in a different tab rather than restating it here, so that is not counted as an independent finding for this row.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "A named AG settlement and a specific billing lawsuit are documented, but this row's own arbitration terms are unstated and its primary finding is deferred to a different tab's row.", "Exposure Score (0-100)": 10, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 7, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 7/20 (severity2+2, penalty+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Altice USA (Optimum, fmr. Suddenlink)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Altice USA (Optimum, fmr. Suddenlink) you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "See the Optimum row in Internet Providers for the primary analysis. The parent-level note worth recording here is that Suddenlink customers became Optimum customers through a rebrand rather than a choice, and Suddenlink's service quality drew sustained regulatory complaint in several states before the transition. Cable ISPs also occupy the observation position described in the Optimum row: every destination, every device, all timing, regardless of any individual website's privacy policy.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Telecom & Media", "_row_id": 711, "_entity_id": 975, "_entity_slug": "altice-usa-optimum-fmr-suddenlink", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Hershey", "Category": "Food Consumer Products", "Terms & Conditions URL": "See Hershey's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Hershey's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Data collection through Hersheypark ticketing, loyalty program, and Hershey Store e-commerce. Relatively limited compared to P&G or PepsiCo's data platforms.", "Arbitration / Class Action Waiver": "Hershey's website Terms of Use contain a mandatory arbitration clause with class action waiver. 30-day opt-out. Hershey's consumer digital footprint includes Hersheypark (amusement park) ticket purchases and the Hershey's loyalty program.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; the same Oracle EBS/Clop breach wave documented for Estée Lauder in this same tab affected roughly 100 organizations globally — worth checking whether this company was also named among the affected parties.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Hershey", "HQ State": "Pennsylvania", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "The Hershey Company", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: The Hershey Company). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CLASS_ACTION_WAIVER · FL-3] Hershey's terms block Hersheypark and loyalty customers from joining class actions\nWHAT THE TERMS SAY: Hershey's website Terms of Use include a class action waiver alongside a mandatory arbitration clause, covering Hersheypark ticketing, the Hershey's loyalty program, and Hershey Store e-commerce.\nWHY IT MATTERS: Customers with small individual claims, such as a ticketing or billing dispute, cannot band together to sue, which usually makes pursuing the claim not worth the cost.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Hershey requires Hersheypark and loyalty customers to arbitrate disputes, not sue\nWHAT THE TERMS SAY: The same Terms of Use make arbitration mandatory for disputes arising from Hersheypark ticket purchases and the Hershey's loyalty program.\nWHY IT MATTERS: Arbitration moves disputes into a private, typically company-favorable forum with no jury and limited appeal rights.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OPT_OUT_DEADLINE · FL-3] Hershey gives customers just 30 days to opt out of arbitration before it binds them\nWHAT THE TERMS SAY: The arbitration clause carries a 30-day opt-out window; after that it applies automatically.\nWHY IT MATTERS: Most customers never notice the clause within a 30-day window, so binding arbitration is the default nearly everyone ends up under.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are specifically documented, but data-sharing scope is described only as 'relatively limited' and fees are not itemized this pass.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Hershey  <-  The Hershey Company", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Hershey you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Retail-mediated confectionery with little direct consumer data. Hershey's substantive consumer-relevant issues are cocoa supply chain labour practices and heavy-metals content in dark chocolate — both matters of disclosure and sourcing rather than terms of service, and both far more consequential to a buyer than anything in its privacy policy.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Brands", "_row_id": 712, "_entity_id": 977, "_entity_slug": "hershey", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Campbell's", "Category": "Food Consumer Products", "Terms & Conditions URL": "See Campbell's's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Campbell's's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Data collection through recipe platforms and digital couponing. Campbell's is headquartered in Camden, NJ — near but not within the DMV corridor.", "Arbitration / Class Action Waiver": "Campbell's website Terms of Use contain a mandatory arbitration clause with class action waiver. 30-day opt-out. Brands: Campbell's Soup, V8, Pepperidge Farm, Goldfish, Prego, Swanson. Consumer digital footprint primarily through recipe sites.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; the same Oracle EBS/Clop breach wave documented for Estée Lauder in this same tab affected roughly 100 organizations globally — worth checking whether this company was also named among the affected parties.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Camden", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New Jersey' is a non-DMV US state", "Parent / Ultimate Owner": "Campbell Soup Company", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NJ Business Records Service — businessrecords.nj.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Campbell Soup Company). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CLASS_ACTION_WAIVER · FL-3] Campbell's terms block recipe-site and coupon users from joining a class action\nWHAT THE TERMS SAY: Campbell's website Terms of Use include a class action waiver alongside a mandatory arbitration clause, covering its recipe-site and digital-couponing footprint across brands like Soup, V8, Pepperidge Farm, Goldfish, Prego, and Swanson.\nWHY IT MATTERS: A customer with a small individual claim, e.g. over a coupon or promotion, cannot join others to sue, which usually makes the claim not worth pursuing alone.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Campbell's requires recipe-site and coupon users to arbitrate disputes, not sue\nWHAT THE TERMS SAY: The same Terms of Use make arbitration mandatory for disputes arising from Campbell's recipe sites and digital-couponing programs.\nWHY IT MATTERS: Arbitration moves disputes into a private forum with no jury and limited appeal rights, instead of open court.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OPT_OUT_DEADLINE · FL-3] Campbell's gives customers just 30 days to opt out of arbitration before it binds them\nWHAT THE TERMS SAY: The arbitration clause carries a 30-day opt-out window; after that it applies automatically.\nWHY IT MATTERS: Few customers notice the clause in time, so binding arbitration is the default most end up under.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are specifically documented, but fees are not itemized and data-sharing is described only in general terms this pass.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Campbell's  <-  Campbell Soup Company", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Campbell's you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Packaged food sold through retailers. Campbell's acquired Sovos Brands (Rao's) and Snyder's-Lance, so several brands consumers think of as independent sit under one parent with one data operation behind their loyalty and promotional programmes.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Brands", "_row_id": 713, "_entity_id": 979, "_entity_slug": "campbell-s", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Kellanova", "Category": "Food Consumer Products", "Terms & Conditions URL": "See Kellanova's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Kellanova's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a consumer packaged-goods manufacturer, most individual interaction is through retail purchases rather than a direct account relationship, meaning this company's direct consumer-data footprint is smaller than most other companies in this tracker — though loyalty/rewards programs (if any) and marketing-list data-sharing practices are worth a direct follow-up.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; the same Oracle EBS/Clop breach wave documented for Estée Lauder in this same tab affected roughly 100 organizations globally — worth checking whether this company was also named among the affected parties.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Chicago", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Kellanova's 2023 split and Mars acquisition ended its public disclosure obligations\nWHAT THE TERMS SAY: The snacks business separated from WK Kellogg in 2023 and was subsequently acquired by Mars, moving Kellanova from a publicly traded, disclosure-obligated company into private ownership.\nWHY IT MATTERS: Two corporate splits in three years scatter brand accountability across separate entities, and going private ends the public financial reporting a consumer or watchdog could review.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing and arbitration fields both say not independently confirmed this pass with company-specific facts; only the corporate-structure note in the SCARY field is stated as fact, and it concerns disclosure/ownership rather than a specific consumer-facing term.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nearly every field says not independently confirmed this pass; the only stated fact concerns corporate ownership, not terms or data practices.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Kellanova  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Kellanova takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The snacks business separated from WK Kellogg in 2023 and subsequently acquired by Mars. Two splits in three years means brand heritage a consumer assumes is one company is now spread across separate corporate entities with separate policies — and the Mars acquisition moves it into private ownership, ending public disclosure entirely.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Brands", "_row_id": 714, "_entity_id": 980, "_entity_slug": "kellanova", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Hormel Foods", "Category": "Food Consumer Products", "Terms & Conditions URL": "See Hormel Foods's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Hormel Foods's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a consumer packaged-goods manufacturer, most individual interaction is through retail purchases rather than a direct account relationship, meaning this company's direct consumer-data footprint is smaller than most other companies in this tracker — though loyalty/rewards programs (if any) and marketing-list data-sharing practices are worth a direct follow-up.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; the same Oracle EBS/Clop breach wave documented for Estée Lauder in this same tab affected roughly 100 organizations globally — worth checking whether this company was also named among the affected parties.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Austin", "HQ State": "Minnesota", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Minnesota' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Data-sharing, arbitration, and fees fields all say not independently confirmed this pass; the only SCARY-field fact (majority ownership by a charitable foundation trust) is a governance note, not a stated consumer-facing risk.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No field states a specific consumer term, data practice, or incident; everything is marked unconfirmed this pass.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Hormel Foods  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Hormel Foods takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Packaged meat sold through retailers with minimal direct consumer data. Hormel is majority-controlled by a charitable foundation trust, an unusual governance structure that insulates it from the shareholder pressure shaping most companies in this tab.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Brands", "_row_id": 715, "_entity_id": 981, "_entity_slug": "hormel-foods", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "J.M. Smucker", "Category": "Food Consumer Products", "Terms & Conditions URL": "See J.M. Smucker's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See J.M. Smucker's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a consumer packaged-goods manufacturer, most individual interaction is through retail purchases rather than a direct account relationship, meaning this company's direct consumer-data footprint is smaller than most other companies in this tracker — though loyalty/rewards programs (if any) and marketing-list data-sharing practices are worth a direct follow-up.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; the same Oracle EBS/Clop breach wave documented for Estée Lauder in this same tab affected roughly 100 organizations globally — worth checking whether this company was also named among the affected parties.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Orrville", "HQ State": "Ohio", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Ohio' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Data-sharing, arbitration, and fees fields all say not independently confirmed this pass; the SCARY field's one concrete fact (the Jif salmonella recall) is explicitly described as a food-safety matter reaching consumers through FDA channels, not a contractual/terms issue.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No field states a specific consumer term or data practice; the one concrete event named is explicitly a food-safety, not contractual, matter.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "J.M. Smucker  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, J.M. Smucker takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Retail-mediated packaged food. Smucker's most consumer-visible events have been recalls, including a significant Jif peanut butter salmonella recall — again a food safety matter reaching consumers through FDA channels rather than any contractual one.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Brands", "_row_id": 716, "_entity_id": 982, "_entity_slug": "j-m-smucker", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Colgate-Palmolive", "Category": "Household and Personal Products", "Terms & Conditions URL": "See Colgate-Palmolive's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Colgate-Palmolive's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "The Colgate Connect smart toothbrush collects oral-hygiene behavioral data (brushing frequency, duration, pressure, coverage). Hill's Pet Nutrition collects pet health data. Both are more sensitive than typical CPG data collection.", "Arbitration / Class Action Waiver": "Colgate-Palmolive's website Terms contain a mandatory arbitration clause with class action waiver. 30-day opt-out. Consumer-facing digital products include the Colgate Connect smart toothbrush (which tracks brushing habits) and the Hill's Pet Nutrition online portal.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; the same Oracle EBS/Clop breach wave documented for Estée Lauder in this same tab affected roughly 100 organizations globally — worth checking whether this company was also named among the affected parties.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Colgate-Palmolive Company", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Colgate-Palmolive Company). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Colgate Connect toothbrush tracks brushing frequency, duration, pressure, and coverage\nWHAT THE TERMS SAY: The Colgate Connect smart toothbrush collects behavioral oral-hygiene data (brushing frequency, duration, pressure, coverage). Hill's Pet Nutrition's online portal separately collects pet health data. Separately and unconfirmed, the tracker notes connected toothbrushes as a category have been marketed with dental-insurance tie-ins, but this is not confirmed specifically for Colgate.\nWHY IT MATTERS: This is health-adjacent behavioral data collected directly by Colgate, more sensitive than typical CPG data collection; whether it could reach an insurer via dental-insurance tie-ins is an unconfirmed, industry-wide pattern rather than something confirmed for Colgate specifically.\n(evidence: Data Sharing/Selling Flags | SCARY; Inferred from tracker text (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Colgate's terms block Connect toothbrush and Hill's Pet portal users from a class action\nWHAT THE TERMS SAY: Colgate-Palmolive's website Terms include a class action waiver alongside a mandatory arbitration clause, covering the Colgate Connect toothbrush and Hill's Pet Nutrition portal.\nWHY IT MATTERS: A customer with a small individual claim cannot join others to sue over these connected products.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Colgate requires Connect toothbrush and Hill's Pet portal users to arbitrate, not sue\nWHAT THE TERMS SAY: The same Terms make arbitration mandatory for disputes arising from these connected-device products, with a 30-day opt-out.\nWHY IT MATTERS: Arbitration moves disputes into a private forum with no jury and limited appeal rights.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and the connected-toothbrush data category are specifically documented, but no breach or sale is confirmed and fees are not itemized.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Colgate-Palmolive  <-  Colgate-Palmolive Company", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Colgate-Palmolive you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. The one genuinely interesting category note for oral care is connected toothbrushes, which transmit brushing data to a manufacturer app and have been marketed with dental insurance tie-ins - meaning a consumer product generates health-adjacent behavioural data that could plausibly reach an insurer. Recommend a follow-up on connected-device data flows rather than on consumer terms, which are minimal.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Brands", "_row_id": 717, "_entity_id": 984, "_entity_slug": "colgate-palmolive", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Kimberly-Clark", "Category": "Household and Personal Products", "Terms & Conditions URL": "See Kimberly-Clark's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Kimberly-Clark's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a consumer packaged-goods manufacturer, most individual interaction is through retail purchases rather than a direct account relationship, meaning this company's direct consumer-data footprint is smaller than most other companies in this tracker — though loyalty/rewards programs (if any) and marketing-list data-sharing practices are worth a direct follow-up.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; the same Oracle EBS/Clop breach wave documented for Estée Lauder in this same tab affected roughly 100 organizations globally — worth checking whether this company was also named among the affected parties.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Irving", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Kimberly-Clark's diaper and incontinence loyalty programs likely reveal life-stage health data\nWHAT THE TERMS SAY: Kimberly-Clark's diaper, feminine-care, and incontinence brands run loyalty and sampling programs that would collect life-stage data (pregnancy, infant age, menstrual and continence status) reasonably considered health-related but held by a paper-goods company outside HIPAA's reach.\nWHY IT MATTERS: This life-stage data can reveal a family's health status with no HIPAA-level protection or oversight of how it is used or shared.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing and arbitration fields both say not independently confirmed this pass; only the SCARY field's inference about loyalty-programme data categories is substantive, and even that is flagged as a recommended follow-up rather than a confirmed practice.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The underlying practice is inferred from brand categories, not confirmed as fact, and arbitration/data-sharing fields are both unconfirmed.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Kimberly-Clark  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Kimberly-Clark takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Kimberly-Clark's brands include diapers and feminine and incontinence care, so its loyalty and sampling programmes collect life-stage data - pregnancy, infant age, menstrual and continence status - that is health information by any reasonable definition and sits entirely outside HIPAA because the collector is a paper goods company. Recommend a follow-up on brand loyalty programme data practices.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Brands", "_row_id": 718, "_entity_id": 985, "_entity_slug": "kimberly-clark", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Estée Lauder", "Category": "Household and Personal Products", "Terms & Conditions URL": "esteelauder.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "esteelauder.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "TWO SEPARATE MAJOR BREACHES: (1) A VERY RECENT 2026 breach tied to a critical Oracle E-Business Suite vulnerability (CVE-2025-61882): an unauthorized party accessed Estée Lauder's Oracle EBS HR-management system around August 9, 2025 (confirmed via investigation June 19, 2026), exposing EMPLOYEES' names, addresses, birthdates, Social Security numbers, passport numbers, bank account numbers, HEALTH INFORMATION, and employment records (performance evaluations, payroll history). This was part of a BROADER CAMPAIGN by the CLOP ransomware/extortion group affecting roughly 100 OTHER ORGANIZATIONS through the same Oracle vulnerability, including Harvard University, University of Pennsylvania, Dartmouth, University of Phoenix, The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and American Airlines subsidiary Envoy Air — illustrating how a single critical software vulnerability can simultaneously compromise a remarkably diverse set of universities, media companies, and consumer brands. (2) A SEPARATE, EARLIER breach: Estée Lauder was ALSO compromised in 2023 when the same Clop group exploited a DIFFERENT zero-day in the MOVEit Transfer platform (the same underlying MOVEit vulnerability documented for Delta Dental, Hartford Insurance, TIAA, and AutoZone throughout this tracker).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual consumer accounts, separate from these employee-focused breaches.", "Fees / Billing Flags": "24 months of complimentary Kroll identity monitoring offered for the 2026 breach, with an enrollment deadline of October 31, 2026.", "Notes": "Estée Lauder has now been hit by the SAME threat actor (Clop) via TWO SEPARATE major software vulnerabilities (MOVEit in 2023, Oracle EBS in 2025-2026) within about 3 years — a notable repeat-victim pattern; both breaches were EMPLOYEE-focused (HR/payroll systems) rather than customer-facing.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Estee Lauder was hit twice by the same threat actor (Clop) via two separate vulnerabilities in ~3 years\nWHAT THE TERMS SAY: Clop exploited the MOVEit Transfer zero-day against Estée Lauder in 2023, then a separate Oracle EBS vulnerability around Aug 2025 (confirmed June 19, 2026), the second exposing employees' SSNs, passport numbers, bank details, and health information as part of a roughly 100-organization campaign.\nWHY IT MATTERS: The tracker records this as a notable repeat-victim pattern: the same threat actor (Clop) reached Estee Lauder through two separate major software vulnerabilities - MOVEit in 2023 and Oracle EBS in 2025-2026 - within about 3 years, and both breaches were employee-focused (HR/payroll systems) rather than customer-facing.\n(evidence: Data Sharing/Selling Flags | Notes; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Estée Lauder brands may supply the virtual try-on tech behind BIPA claims against Ulta, Sephora\nWHAT THE TERMS SAY: The tracker notes virtual try-on technology, the subject of BIPA biometric-privacy class actions against Ulta and Sephora elsewhere in this tracker, is 'brand-supplied as often as retailer-supplied,' meaning Estée Lauder brands (MAC, Clinique, La Mer) may be the actual source of that tech.\nWHY IT MATTERS: If Estée Lauder brands supply the underlying facial-scanning technology, the company could carry BIPA-style exposure even though the lawsuits named the retailers, not the brand owner.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct company-specific facts are stated: the repeat-breach pattern (both incidents share the same harm type and are counted once) and the inferred virtual-try-on/biometric exposure; the multi-brand loyalty-data note in SCARY restates the same theme rather than adding a third distinct harm.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Both breaches are extensively dated and detailed, but consumer-facing arbitration terms are unconfirmed and the biometric/virtual-try-on angle is an inference, not a confirmed EL-specific claim.", "Exposure Score (0-100)": 8, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Estée Lauder  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Estée Lauder takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Two separate major breaches including a very recent 2026 incident is the finding, and cosmetics retail carries a specific additional exposure: virtual try-on technology, which produced the BIPA class actions against Ulta and Sephora documented in Retail & Fintech, is brand-supplied as often as retailer-supplied. Estée Lauder also operates numerous brands - MAC, Clinique, La Mer and others - under one parent, so multi-brand loyalty data consolidates.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Brands", "_row_id": 719, "_entity_id": 986, "_entity_slug": "est-e-lauder", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Monster Beverage", "Category": "Beverages", "Terms & Conditions URL": "See Monster Beverage's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Monster Beverage's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a consumer packaged-goods manufacturer, most individual interaction is through retail purchases rather than a direct account relationship, meaning this company's direct consumer-data footprint is smaller than most other companies in this tracker — though loyalty/rewards programs (if any) and marketing-list data-sharing practices are worth a direct follow-up.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; the same Oracle EBS/Clop breach wave documented for Estée Lauder in this same tab affected roughly 100 organizations globally — worth checking whether this company was also named among the affected parties.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Corona", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] Monster's marketing to minors and caffeine-content disclosure have drawn AG scrutiny\nWHAT THE TERMS SAY: The tracker notes Monster's consumer-protection history concerns marketing energy drinks to minors and disclosure of caffeine content, which drew scrutiny from state attorneys general.\nWHY IT MATTERS: If marketing reaches minors without adequate caffeine disclosure, it raises a genuine health-and-safety concern for a population less able to gauge stimulant risk.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing and arbitration fields both say not independently confirmed this pass; only the marketing/AG-scrutiny note in SCARY is substantive, and it stops short of naming a specific penalty or settlement.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No specific penalty, settlement, or data practice is confirmed; only general AG scrutiny is mentioned.", "Exposure Score (0-100)": 8, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Monster Beverage  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Monster Beverage takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Retail-mediated energy drinks. Monster's consumer-protection history concerns marketing to minors and caffeine content disclosure, which drew state attorney general scrutiny — a genuine consumer harm question with no privacy dimension, and the honest content of this row.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Brands", "_row_id": 720, "_entity_id": 987, "_entity_slug": "monster-beverage", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Constellation Brands", "Category": "Beverages", "Terms & Conditions URL": "See Constellation Brands's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Constellation Brands's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a consumer packaged-goods manufacturer, most individual interaction is through retail purchases rather than a direct account relationship, meaning this company's direct consumer-data footprint is smaller than most other companies in this tracker — though loyalty/rewards programs (if any) and marketing-list data-sharing practices are worth a direct follow-up.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; the same Oracle EBS/Clop breach wave documented for Estée Lauder in this same tab affected roughly 100 organizations globally — worth checking whether this company was also named among the affected parties.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Victor", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Data-sharing, arbitration, and fees fields all say not independently confirmed this pass; the SCARY field describes three-tier distribution limiting direct consumer contact, with only DTC wine shipping (where permitted) creating a real customer record — a structural note, not a stated troubling term.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No field states a specific consumer term, data practice, or incident this pass.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Constellation Brands  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Constellation Brands takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Alcohol producer selling through three-tier distribution, which structurally prevents a direct consumer relationship in most states. The exception is direct-to-consumer wine shipping where permitted, which does create a real customer record with age verification and delivery address attached.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Brands", "_row_id": 721, "_entity_id": 988, "_entity_slug": "constellation-brands", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Molson Coors Beverage", "Category": "Beverages", "Terms & Conditions URL": "See Molson Coors Beverage's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Molson Coors Beverage's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a consumer packaged-goods manufacturer, most individual interaction is through retail purchases rather than a direct account relationship, meaning this company's direct consumer-data footprint is smaller than most other companies in this tracker — though loyalty/rewards programs (if any) and marketing-list data-sharing practices are worth a direct follow-up.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; the same Oracle EBS/Clop breach wave documented for Estée Lauder in this same tab affected roughly 100 organizations globally — worth checking whether this company was also named among the affected parties.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Chicago", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Data-sharing and arbitration fields say not independently confirmed this pass; the cyberattack noted in SCARY is explicitly described as a business-continuity/production event rather than a consumer-data incident, so it is not counted as a consumer-facing troubling term.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The one notable event (a cyberattack halting production) is explicitly framed as operational, not a consumer data incident.", "Exposure Score (0-100)": 8, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Molson Coors Beverage  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Molson Coors Beverage takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Three-tier alcohol distribution with minimal direct consumer data. Molson Coors suffered a significant cyberattack that halted brewery production and delayed its SEC filings — a business-continuity event rather than a consumer data one, and a reminder that operational disruption is the dominant cyber risk for manufacturers.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Brands", "_row_id": 722, "_entity_id": 989, "_entity_slug": "molson-coors-beverage", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Johnson & Johnson", "Category": "Pharmaceuticals", "Terms & Conditions URL": "jnj.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "jnj.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED BREACH (2023) AT PATIENT ASSISTANCE PROGRAM: Johnson & Johnson Health Care Systems' Janssen CarePath platform (a program helping patients afford J&J medications) was breached via IBM, the business associate managing the platform's application/database — an unauthorized third party accessed the system Aug 2, 2023, exposing thousands of patients' names, contact information, birthdates, health insurance information, MEDICATIONS, and HEALTH CONDITIONS; affected individuals were not notified until Sept 15, more than a month later. A class action was filed against BOTH IBM and J&J Health Care Systems in New York federal court.", "Arbitration / Class Action Waiver": "J&J's consumer-facing products are now under Kenvue (Tylenol, Band-Aid, Neutrogena, Listerine, Aveeno — spun off May 2023). J&J itself is now a pharmaceutical/medtech company. Patient-assistance programs (Janssen CarePath) contain arbitration provisions. Product-liability claims (talc, mesh, Risperdal) are governed by tort law, not T&C arbitration. The IBM/Janssen CarePath breach (Aug 2023, 631K patients) is subject to whatever arbitration clause was in the CarePath enrollment agreement.", "Fees / Billing Flags": "SEPARATE, UNRELATED REGULATORY DISPUTE (2024-2026): J&J is one of several major manufacturers (with Eli Lilly, Bristol Myers Squibb, Sanofi) suing the federal government (HRSA) over 340B drug-discount program rebate rules — J&J tried shifting two drugs (Xarelto, Stelara) from upfront discounts to a claims-data-validated rebate model, which HRSA warned was unlawful; a DC court upheld HRSA's authority in May 2025. This is a drug-PRICING dispute between manufacturers and hospitals, not a direct consumer-privacy issue, but relevant given how directly it affects what patients ultimately pay.", "Notes": "The Janssen CarePath breach is worth flagging specifically because patient-assistance programs, by design, serve financially vulnerable patients seeking help affording medication — a breach here carries a particular sensitivity given the population these programs are meant to serve.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New Brunswick", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.hipaajournal.com/ibm-johnson-johnson-health-care-systems-breach-lawsuit/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'New Jersey' is a non-DMV US state", "Parent / Ultimate Owner": "Johnson & Johnson (consumer health spun off as Kenvue Inc., May 2023)", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NJ Business Records Service — businessrecords.nj.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Johnson & Johnson (consumer health spun off as Kenvue Inc., May 2023)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] 2023 breach at J&J's Janssen CarePath assistance program exposed health data, notice delayed\nWHAT THE TERMS SAY: An unauthorized party accessed the IBM-managed Janssen CarePath system on Aug 2, 2023, exposing patients' names, contact info, birthdates, health insurance info, medications, and health conditions; affected patients weren't notified until Sept 15, over a month later. A class action was filed against IBM and J&J Health Care Systems.\nWHY IT MATTERS: The breach hit a financial-assistance program whose users are, by definition, patients who can't otherwise afford their medication, and they learned about it more than a month late.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Patients enrolling in J&J's Janssen CarePath assistance program agree to arbitration\nWHAT THE TERMS SAY: J&J's patient-assistance program (Janssen CarePath) contains arbitration provisions, separate from the tort-law path governing J&J's product-liability litigation (talc, mesh, Risperdal).\nWHY IT MATTERS: A patient seeking help affording medication may be steered into private arbitration for any dispute over the program, including one arising from the CarePath breach.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-1] J&J is paying up to $5B over nine years in opioid settlements, with no admission of wrongdoing\nWHAT THE TERMS SAY: J&J agreed to pay up to $5 billion over no more than nine years in the national opioid settlements (alongside a separate $21 billion distributor settlement), with no admission of wrongdoing.\nWHY IT MATTERS: A multibillion-dollar settlement paid without any admission of fault lets the company resolve mass litigation while avoiding a formal finding of liability.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The breach is dated and detailed with a filed class action and named parties, and CarePath's arbitration provisions are explicitly acknowledged even though the exact opt-out window isn't verified.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 14, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 14/30 (forced_arbitration+12, optout_window_unverified+2) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Johnson & Johnson  <-  Johnson & Johnson (consumer health spun off as Kenvue Inc., May 2023)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Johnson & Johnson you gave up your data shared corporate-wide and your right to sue. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2023 breach hit Johnson & Johnson's PATIENT ASSISTANCE programme - the mechanism through which people who cannot afford a drug apply for help paying for it. That means the exposed population was, by definition, selected for financial vulnerability and for having a specific diagnosis, and the application process itself requires disclosing both. J&J is also a defendant in the national opioid settlements, having agreed to pay up to $5 billion over no more than nine years alongside the $21 billion distributor settlement, with no admission of wrongdoing. Copay assistance is genuinely valuable and people should use it - but it should be understood as a data transaction as well as a financial one.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 723, "_entity_id": 990, "_entity_slug": "johnson-johnson", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Pfizer", "Category": "Pharmaceuticals", "Terms & Conditions URL": "See Pfizer's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Pfizer's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Pfizer processes patient data through its patient-assistance programs (PAPs) and clinical trial recruitment platforms. HIPAA does NOT govern Pfizer's own data collection from its consumer-facing website — it governs data shared with Pfizer BY healthcare providers. Pfizer's direct-to-consumer data (vaccine appointments, symptom trackers) is governed by Pfizer's own privacy policy, which may be less protective than HIPAA.", "Arbitration / Class Action Waiver": "Pfizer's website Terms of Use contain a mandatory arbitration clause with class action waiver. 30-day opt-out. AAA rules, New York law. Consumer-facing digital products include Pfizer's COVID vaccine scheduling portal, patient-assistance programs, and PfizerPro (for healthcare providers). Product-liability claims (e.g., Zantac litigation) are governed by state/federal tort law, not website T&C.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Johnson & Johnson row (this same tab) for a detailed, company-specific patient-assistance-program breach precedent; the Cencora/Tempus AI findings above are genuinely SHARED across most major pharmaceutical manufacturers rather than unique to any single company.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Pfizer Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Pfizer Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Pfizer's vaccine-scheduling and symptom-tracking tools are governed by its own policy, not HIPAA\nWHAT THE TERMS SAY: Pfizer's direct-to-consumer tools (its COVID vaccine scheduling portal and symptom trackers) are governed by Pfizer's own privacy policy rather than HIPAA, which only applies to data providers share with Pfizer, not data Pfizer collects directly.\nWHY IT MATTERS: Consumers may assume HIPAA-level protection for health data they enter, when the actual protection is whatever Pfizer's own policy, described as potentially less protective, provides.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Pfizer's terms block vaccine-portal and patient-assistance users from a class action\nWHAT THE TERMS SAY: Pfizer's website Terms of Use include a class action waiver alongside mandatory arbitration (AAA rules, New York law), covering its COVID vaccine scheduling portal and patient-assistance programs.\nWHY IT MATTERS: A customer with a small individual claim cannot join others to sue over these consumer-facing tools.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Pfizer requires vaccine-portal and patient-assistance users to arbitrate, not sue\nWHAT THE TERMS SAY: The same Terms make arbitration mandatory, with a 30-day opt-out, under AAA rules and New York law.\nWHY IT MATTERS: Arbitration moves disputes into a private forum with no jury and limited appeal rights.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are specifically documented, but no company-specific breach is confirmed and fees are not itemized this pass.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Pfizer  <-  Pfizer Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Pfizer you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing company-specific confirmed this pass on consumer data. The structural finding across this entire tab is worth stating once here: pharmaceutical manufacturers generally have no direct consumer relationship - your prescription runs through a prescriber, a PBM and a pharmacy - so they collect relatively little from you directly while nonetheless holding substantial patient-level data through clinical trials, patient support programmes and purchased datasets. The absence of a consumer contract is not the absence of a data relationship; it is the absence of a consumer-facing document that would disclose it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 724, "_entity_id": 992, "_entity_slug": "pfizer", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "AbbVie", "Category": "Pharmaceuticals", "Terms & Conditions URL": "See AbbVie's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See AbbVie's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "AbbVie's patient-assistance programs collect detailed health, insurance, and financial information. The myAbbVie Assist portal requires income verification, prescription details, and insurance status — highly sensitive data governed by AbbVie's privacy policy, not HIPAA (since AbbVie is the manufacturer, not a covered entity under HIPAA).", "Arbitration / Class Action Waiver": "AbbVie's website Terms of Use contain a mandatory arbitration clause with class action waiver. 30-day opt-out. Consumer-facing digital products include the myAbbVie Assist patient-assistance portal and the Humira (adalimumab) Complete app. Humira was the world's best-selling drug ($21.2B peak revenue, 2022).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Johnson & Johnson row (this same tab) for a detailed, company-specific patient-assistance-program breach precedent; the Cencora/Tempus AI findings above are genuinely SHARED across most major pharmaceutical manufacturers rather than unique to any single company.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "North Chicago", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "AbbVie Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: AbbVie Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] AbbVie's myAbbVie Assist portal collects income, prescription, and insurance data outside HIPAA\nWHAT THE TERMS SAY: The myAbbVie Assist patient-assistance portal requires income verification, prescription details, and insurance status, governed by AbbVie's own privacy policy since AbbVie, as manufacturer, is not a HIPAA covered entity.\nWHY IT MATTERS: Patients seeking help affording Humira or other specialty drugs must disclose detailed financial and health data to AbbVie itself, outside HIPAA's protections.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] AbbVie's terms block myAbbVie Assist and Humira Complete app users from a class action\nWHAT THE TERMS SAY: AbbVie's website Terms of Use include a class action waiver alongside mandatory arbitration, covering the myAbbVie Assist portal and the Humira Complete app.\nWHY IT MATTERS: A customer with a small individual claim cannot join others to sue over these patient-assistance tools.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] AbbVie requires myAbbVie Assist and Humira Complete app users to arbitrate, not sue\nWHAT THE TERMS SAY: The same Terms make arbitration mandatory, with a 30-day opt-out.\nWHY IT MATTERS: Arbitration moves disputes into a private forum with no jury and limited appeal rights.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and the patient-assistance data categories are specifically documented, but no breach is confirmed for AbbVie itself and fees are not itemized.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "AbbVie  <-  AbbVie Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using AbbVie you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing company-specific confirmed this pass. AbbVie's patient support programmes for high-cost specialty drugs collect diagnosis, insurance and financial information from patients who often have no alternative route to affording treatment - the same structural exposure documented concretely in the Johnson & Johnson and Cencora rows. The Cencora incident specifically caught data from at least 27 pharmaceutical and biotech companies' patient support programmes, so a manufacturer with no breach of its own may still have had its patients exposed through the distributor. Recommend checking AbbVie against the Cencora notification list.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 725, "_entity_id": 994, "_entity_slug": "abbvie", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Eli Lilly", "Category": "Pharmaceuticals", "Terms & Conditions URL": "See Eli Lilly's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Eli Lilly's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "LillyDirect represents a fundamental shift: Lilly now operates its own PHARMACY, collecting prescription, payment, and delivery data directly from patients without a retail-pharmacy intermediary. This data is governed by LillyDirect's privacy policy, not by CVS/Walgreens' terms. Lilly's market cap exceeded $800B in 2024, driven largely by GLP-1 drugs.", "Arbitration / Class Action Waiver": "Eli Lilly's website Terms of Use contain a mandatory arbitration clause with class action waiver. 30-day opt-out. Consumer digital products include LillyDirect (direct-to-patient pharmacy, launched 2024) and patient-assistance programs for Mounjaro/Zepbound (tirzepatide) and Trulicity (dulaglutide).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Johnson & Johnson row (this same tab) for a detailed, company-specific patient-assistance-program breach precedent; the Cencora/Tempus AI findings above are genuinely SHARED across most major pharmaceutical manufacturers rather than unique to any single company.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Indianapolis", "HQ State": "Indiana", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Indiana' is a non-DMV US state", "Parent / Ultimate Owner": "Eli Lilly and Company", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Indiana SOS INBiz — inbiz.in.gov/BOS/Home/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Eli Lilly and Company). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] LillyDirect lets Lilly collect prescription, payment, and delivery data with no pharmacy middleman\nWHAT THE TERMS SAY: LillyDirect, Lilly's own direct-to-patient pharmacy launched in 2024, collects prescription, payment, and delivery data directly from patients, governed by LillyDirect's own privacy policy rather than a retail pharmacy's terms.\nWHY IT MATTERS: Removing the retail-pharmacy intermediary consolidates a patient's prescription, payment, and address data entirely inside the drug manufacturer, under a policy Lilly wrote for itself.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-1] Lilly's insulin sits at the center of an FTC case alleging rebate competition raised list prices\nWHAT THE TERMS SAY: The tracker notes Lilly's product is central to the FTC's PBM case: manufacturers were allegedly incentivized to compete on rebate size off list price rather than net price, raising list prices that patients paying against list absorbed.\nWHY IT MATTERS: Patients paying cash or a percentage of list price can end up paying more because of the rebate competition the FTC alleges, even though PBMs, not manufacturers, were named as defendants.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CLASS_ACTION_WAIVER · FL-3] Eli Lilly's terms block LillyDirect and Mounjaro/Zepbound patients from a class action\nWHAT THE TERMS SAY: Eli Lilly's website Terms of Use include a class action waiver alongside mandatory arbitration, covering LillyDirect and patient-assistance programs for Mounjaro/Zepbound and Trulicity.\nWHY IT MATTERS: A patient with a small individual claim cannot join others to sue over these programs.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and the LillyDirect data shift are specifically documented, but no breach is confirmed and fees are not itemized this pass.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Eli Lilly  <-  Eli Lilly and Company", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Eli Lilly you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing company-specific confirmed this pass on data privacy, but Lilly is the manufacturer whose product sits at the centre of the FTC PBM case documented in the Pharmacy Benefit Managers tab - insulin. The finding that belongs on this row is the one the FTC alleged: manufacturers were pushed to compete on the size of the rebate off list price rather than on net price, which created a shared incentive to raise list prices that patients paying against list absorbed. Manufacturers were participants in that system, not bystanders to it, even where the FTC's action named the PBMs.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 726, "_entity_id": 996, "_entity_slug": "eli-lilly", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Merck", "Category": "Pharmaceuticals", "Terms & Conditions URL": "See Merck's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Merck's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Merck processes patient data through patient-assistance programs and clinical-trial recruitment. The Merck Manual website (merckmanuals.com) collects health-search query data similar to WebMD — symptom/condition queries that reveal sensitive health information.", "Arbitration / Class Action Waiver": "Merck's website Terms of Use contain a mandatory arbitration clause with class action waiver. 30-day opt-out. Consumer-facing products include the Merck Manual (medical reference), patient-assistance programs, and vaccine information portals. Merck's Keytruda (pembrolizumab) is the world's best-selling drug ($25B, 2023).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Johnson & Johnson row (this same tab) for a detailed, company-specific patient-assistance-program breach precedent; the Cencora/Tempus AI findings above are genuinely SHARED across most major pharmaceutical manufacturers rather than unique to any single company.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Rahway", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New Jersey' is a non-DMV US state", "Parent / Ultimate Owner": "Merck & Co., Inc.", "Years Referenced in Finding (heuristic)": "2017", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NJ Business Records Service — businessrecords.nj.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Merck & Co., Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Merck Manual's health-symptom searches reveal sensitive health info, similar to WebMD\nWHAT THE TERMS SAY: The Merck Manual website collects health-search query data, the same kind of symptom/condition searches WebMD collects, which can reveal sensitive health information about the searcher.\nWHY IT MATTERS: A search for a condition can itself disclose a suspected diagnosis, and users searching a drugmaker's own reference site may not expect that query to be collected.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Merck's terms block Merck Manual and patient-assistance users from a class action\nWHAT THE TERMS SAY: Merck's website Terms of Use include a class action waiver alongside mandatory arbitration, covering the Merck Manual, patient-assistance programs, and vaccine information portals.\nWHY IT MATTERS: A user with a small individual claim cannot join others to sue over these tools.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Merck requires Merck Manual and patient-assistance users to arbitrate, not sue\nWHAT THE TERMS SAY: The same Terms make arbitration mandatory, with a 30-day opt-out.\nWHY IT MATTERS: Arbitration moves disputes into a private forum with no jury and limited appeal rights.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and the Merck Manual data category are specifically documented, but no breach is confirmed and fees are not itemized this pass.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Merck  <-  Merck & Co., Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Merck you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing company-specific confirmed this pass on consumer data privacy. Merck's most significant cyber event was NotPetya in 2017 - a destructive attack rather than a data-theft one, notable mainly for the multi-year insurance litigation over whether an act-of-war exclusion applied, which reshaped how cyber coverage is written across every industry in this tracker. That is a corporate-risk finding rather than a consumer-privacy one and is recorded as such. Recommend checking Merck against the Cencora patient-support notification list.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 727, "_entity_id": 998, "_entity_slug": "merck", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Bristol-Myers Squibb", "Category": "Pharmaceuticals", "Terms & Conditions URL": "See Bristol-Myers Squibb's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Bristol-Myers Squibb's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "BMS processes patient data through patient-support programs. Celgene (acquired 2019 for $74B) brought Revlimid's patient registry (REMS program) into BMS's data footprint — REMS registries collect detailed patient health and treatment data under FDA oversight.", "Arbitration / Class Action Waiver": "BMS's website Terms of Use contain a mandatory arbitration clause with class action waiver. 30-day opt-out. Consumer-facing products include patient-support programs for Opdivo, Eliquis, and Revlimid.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Johnson & Johnson row (this same tab) for a detailed, company-specific patient-assistance-program breach precedent; the Cencora/Tempus AI findings above are genuinely SHARED across most major pharmaceutical manufacturers rather than unique to any single company.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Bristol-Myers Squibb Company", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Bristol-Myers Squibb Company). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] BMS's Revlimid REMS registry (via Celgene) collects detailed patient treatment data\nWHAT THE TERMS SAY: Celgene's Revlimid REMS patient registry, brought into BMS through the $74B Celgene acquisition, collects detailed patient health and treatment data as required by FDA oversight.\nWHY IT MATTERS: A federally mandated safety registry still means a pharmaceutical company holds detailed treatment records on a named patient population under its own privacy practices.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] BMS's terms block Opdivo, Eliquis, and Revlimid patient-support users from a class action\nWHAT THE TERMS SAY: BMS's website Terms of Use include a class action waiver alongside mandatory arbitration, covering patient-support programs for Opdivo, Eliquis, and Revlimid.\nWHY IT MATTERS: A patient with a small individual claim cannot join others to sue over these programs.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] BMS requires Opdivo, Eliquis, and Revlimid patient-support users to arbitrate, not sue\nWHAT THE TERMS SAY: The same Terms make arbitration mandatory, with a 30-day opt-out.\nWHY IT MATTERS: Arbitration moves disputes into a private forum with no jury and limited appeal rights.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and the Revlimid REMS data category are specifically documented, but no breach is confirmed for BMS itself and fees are not itemized.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Bristol-Myers Squibb  <-  Bristol-Myers Squibb Company", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Bristol-Myers Squibb you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing company-specific confirmed this pass. Same structural position as the other large-molecule manufacturers on this tab: minimal direct consumer contract, substantial indirect patient data through trials and support programmes, and exposure through shared distributors rather than through its own systems. BMS runs oncology patient support programmes, which means the diagnosis data involved is unusually sensitive. Recommend checking against the Cencora notification list before treating this row as clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 728, "_entity_id": 1000, "_entity_slug": "bristol-myers-squibb", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Amgen", "Category": "Pharmaceuticals", "Terms & Conditions URL": "amgen.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "amgen.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Amgen processes patient-assistance data including health conditions, insurance status, and income. Amgen Safety Net Foundation provides free medications to qualifying patients — application data is highly sensitive.", "Arbitration / Class Action Waiver": "Amgen's website Terms of Use contain a mandatory arbitration clause with class action waiver. 30-day opt-out. California law. Consumer-facing products include patient-assistance programs for Enbrel, Repatha, and biosimilars.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Johnson & Johnson row (this same tab) for the patient-assistance-program breach pattern worth checking against Amgen's own equivalent programs, if any.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Thousand Oaks", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Amgen Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Amgen Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Amgen's Safety Net Foundation collects health, insurance, and income data for free-drug patients\nWHAT THE TERMS SAY: Amgen processes patient-assistance data including health conditions, insurance status, and income; the Amgen Safety Net Foundation, which provides free medications to qualifying patients, collects highly sensitive application data.\nWHY IT MATTERS: Financially vulnerable patients applying for free medication must disclose income and diagnosis together, and that combined record sits with the drug's own manufacturer.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Amgen's terms block Enbrel, Repatha, and biosimilar patients from joining a class action\nWHAT THE TERMS SAY: Amgen's website Terms of Use include a class action waiver alongside mandatory arbitration (California law), covering patient-assistance programs for Enbrel, Repatha, and biosimilars.\nWHY IT MATTERS: A patient with a small individual claim cannot join others to sue over these programs.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Amgen requires Enbrel, Repatha, and biosimilar patients to arbitrate, not sue\nWHAT THE TERMS SAY: The same Terms make arbitration mandatory, with a 30-day opt-out, under California law.\nWHY IT MATTERS: Arbitration moves disputes into a private forum with no jury and limited appeal rights.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and the Safety Net Foundation data category are specifically documented, but no breach is confirmed and fees are not itemized this pass.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Amgen  <-  Amgen Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Amgen you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing company-specific confirmed this pass. Amgen's patient support infrastructure for biologics involves specialty pharmacy and distributor relationships of exactly the kind that produced the Cencora exposure, where diagnosis, prescription and medication data for patients across at least 27 manufacturers was taken from a distributor rather than from any drug maker. Unverified rather than clean; the correct follow-up is the Cencora notification list rather than a search for an Amgen-specific breach.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 729, "_entity_id": 1002, "_entity_slug": "amgen", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Gilead Sciences", "Category": "Pharmaceuticals", "Terms & Conditions URL": "See Gilead Sciences's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Gilead Sciences's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Gilead's HIV medication assistance programs collect data about patients' HIV status, viral load, and treatment history. This is among the most sensitive health data any company in this tracker collects directly from consumers. Gilead's privacy policy, not HIPAA, governs this collection since Gilead is the manufacturer.", "Arbitration / Class Action Waiver": "Gilead's website Terms of Use contain a mandatory arbitration clause with class action waiver. 30-day opt-out. Consumer-facing products include patient-assistance programs for Biktarvy, Descovy (HIV), and Sovaldi/Harvoni (hepatitis C).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the Johnson & Johnson row (this same tab) for the pattern of patient-assistance-program breaches worth checking against this company's own equivalent programs, if any.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Foster City", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Gilead Sciences, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Gilead Sciences, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Gilead's HIV assistance programs collect HIV status and viral load, among the most sensitive data here\nWHAT THE TERMS SAY: Gilead's assistance programs for Biktarvy and Descovy (HIV) collect patients' HIV status, viral load, and treatment history, governed by Gilead's own privacy policy rather than HIPAA since Gilead is the manufacturer.\nWHY IT MATTERS: HIV status disclosure carries acute stigma and discrimination risk; a comparable envelope-window disclosure at Aetna, documented elsewhere in this tracker, drew a significant settlement with no hacking involved.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] Gilead's terms block Biktarvy, Descovy, and hepatitis-C patients from a class action\nWHAT THE TERMS SAY: Gilead's website Terms of Use include a class action waiver alongside mandatory arbitration, covering patient-assistance programs for Biktarvy, Descovy, and Sovaldi/Harvoni.\nWHY IT MATTERS: A patient with a small individual claim cannot join others to sue over these programs.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Gilead requires Biktarvy, Descovy, and hepatitis-C patients to arbitrate, not sue\nWHAT THE TERMS SAY: The same Terms make arbitration mandatory, with a 30-day opt-out.\nWHY IT MATTERS: Arbitration moves disputes into a private forum with no jury and limited appeal rights.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and the HIV-status data category are specifically documented, but no breach is confirmed for Gilead itself and fees are not itemized.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Gilead Sciences  <-  Gilead Sciences, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Gilead Sciences you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing company-specific confirmed this pass. Gilead's portfolio includes HIV treatment and prevention, which makes any patient-level data it or its support programmes hold unusually consequential - the Aetna envelope-window incident documented in the Life-Health-Dental tab shows what disclosure of that status alone was worth in settlement terms, with no hacker involved. Recorded as unverified rather than clean, and flagged as a priority for follow-up precisely because the sensitivity is high rather than because any finding exists.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 730, "_entity_id": 1004, "_entity_slug": "gilead-sciences", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Regeneron Pharmaceuticals", "Category": "Pharmaceuticals", "Terms & Conditions URL": "See Regeneron Pharmaceuticals's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Regeneron Pharmaceuticals's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a company-specific consumer data lawsuit beyond the shared industry findings below. SHARED FINDING ACROSS MANY PHARMA COMPANIES: (1) A 2024 breach at CENCORA (a major pharmaceutical distributor, documented separately in the Healthcare Providers tab of this tracker) exposed patient information — names, addresses, birthdates, health diagnoses, and prescriptions — for patients receiving medications marketed by this company, among more than a dozen other manufacturers (Bayer, Genentech, AbbVie, Novartis, Regeneron, GSK, and others) whose distribution flowed through Cencora. (2) A SEPARATE, ACTIVE 2026 lawsuit (Illinois, under the state's Genetic Information Privacy Act) alleges Tempus AI illegally transferred patients' GENETIC/genomic testing data to numerous pharmaceutical and biotech partners — including this company — for drug-discovery purposes, without adequate patient consent; Tempus's own CFO reportedly described 2025 as 'a record year' for exactly this kind of data-sharing business.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Johnson & Johnson row (this same tab) for a detailed, company-specific patient-assistance-program breach precedent; the Cencora/Tempus AI findings above are genuinely SHARED across most major pharmaceutical manufacturers rather than unique to any single company.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Tarrytown", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] A 2024 breach at distributor Cencora exposed health data for patients on Regeneron's medicines\nWHAT THE TERMS SAY: A 2024 breach at pharmaceutical distributor Cencora exposed patients' names, addresses, birthdates, diagnoses, and prescriptions for patients on medications marketed by more than a dozen manufacturers, including Regeneron.\nWHY IT MATTERS: Patients need never have interacted with Regeneron directly to have their diagnosis and prescription data exposed through its distribution chain.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Active suit alleges Tempus AI shared patients' genetic data with Regeneron without consent\nWHAT THE TERMS SAY: A 2026 Illinois lawsuit under the state's Genetic Information Privacy Act alleges Tempus AI transferred patients' genomic testing data to pharma/biotech partners, including Regeneron, for drug-discovery purposes without adequate patient consent.\nWHY IT MATTERS: If true, patients' genetic data, among the most sensitive and immutable data categories, reached a drugmaker without proper consent, and genetic information cannot be changed once exposed.\n(evidence: Data Sharing/Selling Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct company-named findings are stated in this row's text (the Cencora exposure and the Tempus AI lawsuit); arbitration is unconfirmed and the SCARY field adds no new company-specific fact beyond these two.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Both the Cencora exposure and the Tempus AI lawsuit are dated and specific, but the row's own consumer arbitration terms remain unconfirmed.", "Exposure Score (0-100)": 22, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 15, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 7, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 15/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 7/20 (severity2+2, breach+3, litigation+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Regeneron Pharmaceuticals  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Regeneron Pharmaceuticals you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing company-specific confirmed this pass. Same analysis as the other manufacturers on this tab - limited direct consumer relationship, real indirect patient data through trials and support programmes, and shared-distributor exposure. Recommend the Cencora notification list as the efficient follow-up for every unconfirmed row in this tab rather than company-by-company searching.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 731, "_entity_id": 1005, "_entity_slug": "regeneron-pharmaceuticals", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Vertex Pharmaceuticals", "Category": "Pharmaceuticals", "Terms & Conditions URL": "See Vertex Pharmaceuticals's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Vertex Pharmaceuticals's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a primarily B2B/institutional pharmaceutical, medical-device, or lab-equipment manufacturer, most individual consumer exposure is INDIRECT (as a patient using a device/drug prescribed by a provider) rather than through a direct account relationship — recommend checking specifically for any patient-assistance/copay program or connected-device app this company operates, since those are the points where direct consumer data collection would occur.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the Johnson & Johnson row (this same tab) for the pattern of patient-assistance-program breaches worth checking against this company's own equivalent programs, if any.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Boston", "HQ State": "Massachusetts", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Massachusetts' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Massachusetts SOC Corporate Search — corp.sec.state.ma.us/corpweb/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Data-sharing and arbitration fields both say not independently confirmed this pass; the SCARY field's rare-disease re-identification risk is explicitly recorded as a structural note, not a finding, about this company.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No field states a confirmed consumer term, incident, or data practice this pass.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Vertex Pharmaceuticals  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Vertex Pharmaceuticals takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Vertex's focus on cystic fibrosis and other rare diseases creates a specific and underappreciated re-identification problem: in a small patient population, supposedly de-identified data can be far easier to trace back to an individual than the same de-identification applied to a common condition. Rare-disease patient registries are genuinely valuable for research and genuinely difficult to anonymise, and that tension is not resolved by any privacy policy. Recorded as a structural note, not a finding.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 732, "_entity_id": 1006, "_entity_slug": "vertex-pharmaceuticals", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Biogen", "Category": "Pharmaceuticals", "Terms & Conditions URL": "See Biogen's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Biogen's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a primarily B2B/institutional pharmaceutical, medical-device, or lab-equipment manufacturer, most individual consumer exposure is INDIRECT (as a patient using a device/drug prescribed by a provider) rather than through a direct account relationship — recommend checking specifically for any patient-assistance/copay program or connected-device app this company operates, since those are the points where direct consumer data collection would occur.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the Johnson & Johnson row (this same tab) for the pattern of patient-assistance-program breaches worth checking against this company's own equivalent programs, if any.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cambridge", "HQ State": "Massachusetts", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Massachusetts' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Massachusetts SOC Corporate Search — corp.sec.state.ma.us/corpweb/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Biogen's Alzheimer's programs use biomarker testing that predicts cognitive decline patients can't unknow\nWHAT THE TERMS SAY: Biogen's neurology patient-support programs and trial data touch cognitive/neurodegenerative diagnoses, and its Alzheimer's programs involve amyloid biomarker testing that produces predictive information about future cognitive decline.\nWHY IT MATTERS: Disclosure of neurological risk can carry employment, insurance, and legal-capacity consequences, and this is information a person cannot un-know once tested.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing and arbitration fields both say not independently confirmed this pass with a specific incident; only the SCARY field's structural note on amyloid biomarker testing is substantive, and it is framed as context rather than a confirmed practice or incident.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No specific breach, lawsuit, or disclosed program detail is confirmed; the biomarker-testing point is contextual.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Biogen  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Biogen takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Biogen's neurology portfolio means its patient support programmes and trial data touch cognitive and neurodegenerative diagnoses — a category where disclosure carries employment, insurance and legal-capacity consequences that no privacy framework specifically addresses. Its Alzheimer's programmes also involve amyloid biomarker testing, which produces predictive information about a person's future cognitive decline that they may not want, may not be able to act on, and cannot un-know. Recommend checking Biogen against the Cencora notification list.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 733, "_entity_id": 1007, "_entity_slug": "biogen", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Viatris", "Category": "Pharmaceuticals", "Terms & Conditions URL": "See Viatris's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Viatris's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a primarily B2B/institutional pharmaceutical, medical-device, or lab-equipment manufacturer, most individual consumer exposure is INDIRECT (as a patient using a device/drug prescribed by a provider) rather than through a direct account relationship — recommend checking specifically for any patient-assistance/copay program or connected-device app this company operates, since those are the points where direct consumer data collection would occur.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the Johnson & Johnson row (this same tab) for the pattern of patient-assistance-program breaches worth checking against this company's own equivalent programs, if any.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Canonsburg", "HQ State": "Pennsylvania", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Data-sharing and arbitration fields both say not independently confirmed this pass; the SCARY field places Viatris on the generics side of the FTC PBM case as a competitive-harm party, not as a source of any consumer-facing troubling term.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No field states a confirmed consumer term, incident, or data practice this pass.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Viatris  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Viatris takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Viatris is a generics and biosimilars manufacturer, which places it on the opposite side of the FTC PBM case from the brand makers: the rebate system the FTC challenged worked by preferencing high-list-price brands over cheaper alternatives on formularies, which is a competitive harm to generic manufacturers as well as a cost harm to patients. Worth noting because it shows the PBM finding is not a simple pharma-versus-patients story.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 734, "_entity_id": 1008, "_entity_slug": "viatris", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Intuitive Surgical", "Category": "Medical Products and Equipment", "Terms & Conditions URL": "See Intuitive Surgical's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Intuitive Surgical's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a primarily B2B/institutional pharmaceutical, medical-device, or lab-equipment manufacturer, most individual consumer exposure is INDIRECT (as a patient using a device/drug prescribed by a provider) rather than through a direct account relationship — recommend checking specifically for any patient-assistance/copay program or connected-device app this company operates, since those are the points where direct consumer data collection would occur.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the Johnson & Johnson row (this same tab) for the pattern of patient-assistance-program breaches worth checking against this company's own equivalent programs, if any.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Sunnyvale", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-4] During robotic surgery, operative data streams to Intuitive under agreements the patient never sees\nWHAT THE TERMS SAY: Operative data generated during a robotic-surgery procedure (instrument telemetry, video, timing) flows to Intuitive under agreements negotiated between Intuitive and the hospital; the patient on the table is not a party to that agreement and generally doesn't know it exists.\nWHY IT MATTERS: Patients consent to surgery, not to a specific data-sharing arrangement between their hospital and a device manufacturer, leaving a real gap in what informed consent covers.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing and arbitration fields both say not independently confirmed this pass with a specific incident; only the SCARY field's note on operative-data governance is substantive, and it describes a structural consent gap rather than a confirmed breach or lawsuit.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No specific breach or lawsuit is confirmed; the operative-data governance point is a structural observation.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Intuitive Surgical  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Intuitive Surgical takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Intuitive makes surgical robotics used inside hospitals, and the notable structural fact is that operative data generated during a procedure - instrument telemetry, video, timing - flows to the device manufacturer under agreements negotiated between the manufacturer and the hospital. The patient on the table is not a party to that agreement and generally does not know it exists. This is device-manufacturer data governance rather than a consumer terms question, and it is a real gap in how patients are asked to consent to surgery.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 735, "_entity_id": 1009, "_entity_slug": "intuitive-surgical", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "IQVIA", "Category": "Health Care: Pharmacy and Other Services", "Terms & Conditions URL": "See IQVIA's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See IQVIA's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a primarily B2B/institutional pharmaceutical, medical-device, or lab-equipment manufacturer, most individual consumer exposure is INDIRECT (as a patient using a device/drug prescribed by a provider) rather than through a direct account relationship — recommend checking specifically for any patient-assistance/copay program or connected-device app this company operates, since those are the points where direct consumer data collection would occur.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the Johnson & Johnson row (this same tab) for the pattern of patient-assistance-program breaches worth checking against this company's own equivalent programs, if any.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Durham", "HQ State": "North Carolina", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NC SOS Business Registration Search — sosnc.gov/online_services/search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] IQVIA licenses population-scale prescription and EHR data that patients can't see or opt out of\nWHAT THE TERMS SAY: IQVIA aggregates and analyzes prescription, claims, and electronic-health-record data at population scale, licensing it onward to pharmaceutical companies; because the data is handled as de-identified, most of it falls outside HIPAA's protections.\nWHY IT MATTERS: The company with arguably the deepest view of American prescribing behavior is also the one patients have the least visibility into or ability to opt out of.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing and arbitration fields both use the generic B2B/institutional disclaimer; only the SCARY field states a specific, substantive practice (population-scale de-identified data licensing), and it is the sole finding for this row.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "IQVIA's own row states it is the company patients have 'the least ability to see, question or opt out of' — a direct textual match for thick fog.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "IQVIA  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using IQVIA you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "IQVIA is the row on this tab that deserves the most attention and generates the least public record, which is itself the finding. It is a health-data and clinical-research company whose business is aggregating and analysing prescription, claims and electronic-health-record data at population scale, licensed onward to pharmaceutical companies and others. Because that data is handled as de-identified, most of it falls outside HIPAA's protections entirely - HIPAA governs identified protected health information held by covered entities, and a data aggregator working with de-identified datasets sits largely outside that perimeter. So the company with arguably the deepest view of American prescribing behaviour is also the one a patient has the least ability to see, question or opt out of. Specific figures were not independently verified this pass and none are asserted; recommend a direct follow-up focused on the de-identification and re-identification-risk question.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 736, "_entity_id": 1010, "_entity_slug": "iqvia", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Becton Dickinson", "Category": "Medical Products and Equipment", "Terms & Conditions URL": "See Becton Dickinson's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Becton Dickinson's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B semiconductor company — sells chips/components to device manufacturers. Consumer data is collected by the DEVICE MAKER (Samsung, Apple, etc.), not the chip supplier. Qualcomm/Intel/AMD processors execute on-device data processing but the data governance is the device manufacturer's responsibility, not the chipmaker's.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the Johnson & Johnson row (this same tab) for the pattern of patient-assistance-program breaches worth checking against this company's own equivalent programs, if any.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Franklin Lakes", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NJ Business Records Service — businessrecords.nj.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] BD's connected infusion pumps and medication cabinets have drawn FDA/CISA cybersecurity advisories\nWHAT THE TERMS SAY: BD's connected infusion pumps and medication dispensing cabinets sit on hospital networks and have been the subject of FDA and CISA cybersecurity advisories.\nWHY IT MATTERS: This is a patient-safety cybersecurity exposure governed by device regulation, not a consumer contract, and the patient has no visibility into it and no consent role.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — The Data Sharing field describes a B2B chip-supplier relationship that does not match BD's actual medical-device business and is not usable as a company-specific fact; only the SCARY field's note on connected-device cybersecurity advisories is substantive.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The row is classified B2B with no consumer contract, and the device-security advisories are structural rather than a stated consumer term.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Becton Dickinson  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Syringes, catheters, infusion systems and diagnostic equipment. BD's connected infusion pumps and medication dispensing cabinets sit on hospital networks and have been the subject of FDA and CISA cybersecurity advisories — a patient-safety exposure governed by device regulation rather than HIPAA, and one where the patient has no visibility and no consent role.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 737, "_entity_id": 1011, "_entity_slug": "becton-dickinson", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Boston Scientific", "Category": "Medical Products and Equipment", "Terms & Conditions URL": "See Boston Scientific's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Boston Scientific's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a primarily B2B/institutional pharmaceutical, medical-device, or lab-equipment manufacturer, most individual consumer exposure is INDIRECT (as a patient using a device/drug prescribed by a provider) rather than through a direct account relationship — recommend checking specifically for any patient-assistance/copay program or connected-device app this company operates, since those are the points where direct consumer data collection would occur.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the Johnson & Johnson row (this same tab) for the pattern of patient-assistance-program breaches worth checking against this company's own equivalent programs, if any.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Marlborough", "HQ State": "Massachusetts", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Massachusetts' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Massachusetts SOC Corporate Search — corp.sec.state.ma.us/corpweb/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Data-sharing and arbitration fields both say not independently confirmed this pass; the SCARY field explicitly states 'no finding is asserted' regarding implantable-device data transmission, so nothing in this row is asserted as a stated troubling term.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The row's most substantive note explicitly disclaims itself as a finding.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Boston Scientific  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Boston Scientific takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Boston Scientific makes implantable cardiac devices, and implantables raise the sharpest version of the connected-device question in this tracker: a pacemaker or defibrillator transmits data continuously from inside a patient's body to a manufacturer's platform, and the patient cannot turn it off, switch vendors, or meaningfully consent after implantation. The governing framework is FDA device regulation rather than consumer privacy law. No finding is asserted - this is a structural note about where the regulatory perimeter sits.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 738, "_entity_id": 1012, "_entity_slug": "boston-scientific", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Stryker", "Category": "Medical Products and Equipment", "Terms & Conditions URL": "stryker.com/us/en/legal.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "stryker.com/us/en/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED MARCH 2026 BREACH: Stryker discovered a cybersecurity incident (March 11, 2026) that disrupted its GLOBAL MICROSOFT ENVIRONMENT, in turn disrupting order processing, manufacturing, and shipping operations — Stryker states there is no indication ransomware/malware was involved, and that CONNECTED MEDICAL DEVICES and patient-related services were NOT impacted. A class action was filed shortly after alleging Stryker failed to protect private consumer and employee information.", "Arbitration / Class Action Waiver": "NOTABLE LEGAL DEVELOPMENT (June 2026): Stryker asked the federal court to DISMISS the class action, arguing the plaintiffs 'cannot show their personal information was accessed or that they suffered any injury tied to the incident' — a genuinely common defense argument in data-breach litigation (lack of concrete, provable harm) that courts sometimes accept and sometimes reject; the outcome was not yet resolved as of this research.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Stryker's explicit denial that connected MEDICAL DEVICES were affected is an important distinction worth flagging — this was primarily a back-office/business-systems disruption rather than a device-safety or patient-care incident, a meaningfully different (and less severe) risk category than if implanted or connected medical devices themselves had been compromised.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-1] Stryker faces a class action over a March 2026 cyber incident and is arguing plaintiffs can't prove harm\nWHAT THE TERMS SAY: After a March 2026 cybersecurity incident disrupted Stryker's Microsoft environment and business operations (Stryker says devices and patient services weren't affected), a class action was filed alleging failure to protect consumer and employee information; in June 2026 Stryker moved to dismiss, arguing plaintiffs can't show their data was accessed or that they suffered any injury.\nWHY IT MATTERS: If the 'no concrete injury' defense succeeds, affected consumers may have no path to compensation even if their data was in fact exposed, since courts sometimes accept this argument.\n(evidence: Data Sharing/Selling Flags | Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one distinct company-specific finding is stated: the March 2026 incident and the resulting, still-unresolved class action. Fees are not itemized, and the SCARY field adds no new fact beyond recommending a follow-up on AG notification filings.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The incident and lawsuit are dated and specific, but Stryker disputes whether any data was actually accessed, and the litigation outcome is unresolved.", "Exposure Score (0-100)": 10, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Stryker  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Stryker takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Stryker discovered a cybersecurity incident in March 2026 - recent enough that scope and data types were still developing as of this pass, and no figures are asserted here. Stryker makes orthopedic implants and surgical equipment, so the patient-facing data it holds runs through hospital and surgeon relationships rather than any direct consumer contract. Recommend a follow-up on state attorney general notification filings, which is typically where scope becomes public before any company announcement.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 739, "_entity_id": 1013, "_entity_slug": "stryker", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Danaher", "Category": "Medical Products and Equipment", "Terms & Conditions URL": "See Danaher's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Danaher's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B semiconductor company — sells chips/components to device manufacturers. Consumer data is collected by the DEVICE MAKER (Samsung, Apple, etc.), not the chip supplier. Qualcomm/Intel/AMD processors execute on-device data processing but the data governance is the device manufacturer's responsibility, not the chipmaker's.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the Johnson & Johnson row (this same tab) for the pattern of patient-assistance-program breaches worth checking against this company's own equivalent programs, if any.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Washington", "HQ State": "District of Columbia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Washington, District of Columbia (DC/MD/VA)", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): DC DLCP CorpOnline — corponline.dcra.dc.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — This row is confirmed B2B with no direct consumer relationship (per Finding Type and the SCARY field, which states Danaher holds no patient record itself); the Data Sharing field's semiconductor-supplier language does not describe Danaher's actual business and is not usable as a company-specific fact.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist for this B2B diagnostics conglomerate per the tracker's own classification.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Danaher  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Diversified life sciences and diagnostics conglomerate whose subsidiaries — Cepheid, Beckman Coulter, Leica among them — sell instruments and reagents to laboratories. No consumer relationship, but its diagnostic platforms run the tests behind clinical results, placing it upstream of the Quest and Labcorp rows without holding any patient record itself.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 740, "_entity_id": 1014, "_entity_slug": "danaher", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Zimmer Biomet", "Category": "Medical Products and Equipment", "Terms & Conditions URL": "zimmerbiomet.com/en/corporate/terms-of-use.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "zimmerbiomet.com/en/corporate/privacy-notice.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "GENUINELY NOTABLE FINDING: Zimmer Biomet publishes a DEDICATED 'Consumer Health Data Privacy Policy' — a supplemental notice specifically governing sensitive health data collected via its products/services (treatment/health-trend data from orthopedic devices, website cookies/analytics, marketing list sign-ups) — explicitly designed to comply with newer state 'Consumer Health Data' (CHD) laws (e.g., Washington's My Health My Data Act). This is a more explicit, dedicated health-data-specific privacy framework than most other medical-device companies in this tracker have been found to publish, worth noting as a comparatively transparent practice.", "Arbitration / Class Action Waiver": "MAJOR $172 MILLION LAWSUIT AGAINST DELOITTE (Zimmer's own IT/consulting vendor, not a data-privacy matter but a significant related dispute): Zimmer Biomet sued Deloitte over an IT-related business failure; Deloitte has asked the court to dismiss the case, arguing (per court filings, Nov 2025) that Zimmer failed to provide proper breach notice under their contract and that a private B2B contract dispute isn't 'consumer-oriented' conduct — an important reminder that even when $172 MILLION is at stake, this is a VENDOR CONTRACT DISPUTE between two businesses, not a consumer-facing privacy claim.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "SEPARATE, UNRELATED LITIGATION (July 2026): Zimmer Biomet sued a FORMER EXECUTIVE for allegedly stealing trade secrets and violating a non-compete agreement after joining a competitor — an employment/trade-secret dispute, not a consumer-privacy matter, included for completeness but not directly relevant to this tracker's core focus.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — The row's substantive content is either explicitly non-consumer (the $172M Deloitte vendor dispute and the former-executive trade-secret suit, both flagged in the tracker as not consumer-privacy matters) or a positive transparency practice (a dedicated Consumer Health Data privacy policy), rather than a troubling term.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Zimmer Biomet is unusual in publishing a dedicated Consumer Health Data privacy policy, but the row states no consumer arbitration terms, and the two litigation items are explicitly non-consumer.", "Exposure Score (0-100)": 4, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Zimmer Biomet  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Zimmer Biomet takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Zimmer Biomet publishes a dedicated Consumer Health Data privacy notice, and that is genuinely notable in a tab where most companies have no consumer-facing privacy documentation at all. Such notices exist largely because Washington State's My Health My Data Act and similar laws created obligations that reach health data outside HIPAA's perimeter - which means the disclosure exists because a state legislature compelled it, not because the sector chose transparency. Say plainly what is true: Zimmer Biomet is doing something its peers are not, and the reason is statutory rather than voluntary.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 741, "_entity_id": 1015, "_entity_slug": "zimmer-biomet", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Thermo Fisher Scientific", "Category": "Scientific, Photographic and Control Equipment", "Terms & Conditions URL": "See Thermo Fisher Scientific's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Thermo Fisher Scientific's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a primarily B2B/institutional pharmaceutical, medical-device, or lab-equipment manufacturer, most individual consumer exposure is INDIRECT (as a patient using a device/drug prescribed by a provider) rather than through a direct account relationship — recommend checking specifically for any patient-assistance/copay program or connected-device app this company operates, since those are the points where direct consumer data collection would occur.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the Johnson & Johnson row (this same tab) for the pattern of patient-assistance-program breaches worth checking against this company's own equivalent programs, if any.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Waltham", "HQ State": "Massachusetts", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Massachusetts' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Massachusetts SOC Corporate Search — corp.sec.state.ma.us/corpweb/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — This row is explicitly described as B2B with no meaningful consumer terms per the SCARY field; data-sharing and arbitration fields both use the generic unconfirmed disclaimer.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The SCARY field states plainly there are no meaningful consumer terms for this lab-equipment supplier.", "Exposure Score (0-100)": 2, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Thermo Fisher Scientific  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Thermo Fisher supplies laboratory instruments, reagents and clinical research services - B2B throughout, with no meaningful consumer terms. Its indirect relevance is that it provides infrastructure to the labs and trial sites that do hold patient data, which places it in the same vendor-concentration category as AMCA, SITA and MOVEit elsewhere in this tracker: invisible to consumers, load-bearing for their data.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 742, "_entity_id": 1016, "_entity_slug": "thermo-fisher-scientific", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Abbott Laboratories", "Category": "Medical Products and Equipment", "Terms & Conditions URL": "abbott.com/terms-of-use.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "abbott.com/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MAJOR, VERY RECENT (JULY 2026) DOUBLE BREACH: (1) The ShinyHunters group (the same extortion actor behind Amtrak, Charter Communications, Panera, and dozens of other breaches documented throughout this tracker) claimed to have exfiltrated more than 30 MILLION ROWS of patient data — names, emails, phone numbers, physical addresses, birthdates, and OVER 1 MILLION SOCIAL SECURITY NUMBERS — from Abbott's Cancer Diagnostics business, specifically LEGACY SYSTEMS at its subsidiary Exact Sciences (a Wisconsin-based at-home cancer-screening company). (2) A SEPARATE, apparently unrelated threat actor ('ShadowByt3$') separately claims to have breached Abbott's LabCentral customer portal (July 4, 2026) using compromised credentials, allegedly exfiltrating TECHNICAL/MANUFACTURING documentation (manufacturing certificates, operating manuals, regulatory filings) rather than direct patient data — this second group sent Abbott a ransom ultimatum threatening 'digital problems' if unpaid by July 21, 2026. Abbott has NOT independently confirmed the full scope of either claim, and neither group's claims have been independently verified through publicly leaked data as of this research.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass for standard consumer/patient Terms of Use.", "Fees / Billing Flags": "SIGNIFICANT LEGAL EXPOSURE: as of this writing (late July 2026), Abbott and Exact Sciences had NOT YET BEGUN notifying affected individuals of the Cancer Diagnostics breach — which plaintiffs' attorneys specifically argue may violate state and federal breach-notification laws requiring prompt disclosure. At least one class action (Troesch v. Abbott Laboratories, Illinois federal court) was already filed within days of the breach becoming public. SEPARATE, UNRELATED LITIGATION: Abbott ALSO faces an employee class action alleging the company OVERCHARGED WORKERS for health insurance — a distinct labor/benefits dispute, not a data-privacy matter.", "Notes": "This is one of the MOST RECENT, still-unfolding breaches documented anywhere in this entire tracker (within the last week of this research) — the allegation that Abbott/Exact Sciences delayed legally-required notification is a particularly serious compliance concern given how sensitive CANCER DIAGNOSIS data is; recommend a direct follow-up to track how this develops, including whether the stolen SSNs/patient data are ultimately confirmed and published.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Abbott Park", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Hackers claim 30M+ rows incl. 1M+ SSNs stolen from Abbott's Exact Sciences unit (unconfirmed)\nWHAT THE TERMS SAY: The ShinyHunters group claims to have exfiltrated more than 30 million rows of patient data, including over 1 million Social Security numbers, from legacy systems at Abbott's Exact Sciences cancer-screening subsidiary; Abbott has not independently confirmed the full scope, and the claim hasn't been independently verified through published leaked data.\nWHY IT MATTERS: If accurate, this would expose cancer-screening patients' identities and SSNs at massive scale; even unconfirmed, the allegation alone creates real uncertainty for potentially millions of patients.\n(evidence: Data Sharing/Selling Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[PENDING_LITIGATION · FL-1] Plaintiffs allege Abbott delayed legally required breach notification to Exact Sciences patients\nWHAT THE TERMS SAY: As of late July 2026, Abbott and Exact Sciences had not yet begun notifying affected individuals about the Cancer Diagnostics breach claim; plaintiffs argue this may violate breach-notification laws, and a class action (Troesch v. Abbott Laboratories) was filed within days of the breach becoming public.\nWHY IT MATTERS: A delay in legally required notification means potentially affected cancer-screening patients, an especially sensitive diagnosis category, may not yet know to protect themselves.\n(evidence: Fees / Billing Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-1] A separate extortion group claims a LabCentral portal breach and threatened Abbott by July 21, 2026\nWHAT THE TERMS SAY: A separate threat actor ('ShadowByt3$') claims to have breached Abbott's LabCentral customer portal on July 4, 2026 using compromised credentials, allegedly taking technical/manufacturing documentation, and sent a ransom ultimatum threatening consequences if unpaid by July 21, 2026.\nWHY IT MATTERS: Abbott faces two apparently unrelated extortion claims in the same window; this second, unverified claim involves technical/manufacturing documentation (manufacturing certificates, operating manuals, regulatory filings) rather than direct patient data, and Abbott has not independently confirmed the full scope of either claim.\n(evidence: Data Sharing/Selling Flags; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Abbott's own row states neither breach claim has been independently confirmed or verified, so scope and legitimacy remain genuinely unresolved even though dates and figures are specific.", "Exposure Score (0-100)": 13, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Abbott Laboratories  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Abbott Laboratories takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Abbott's July 2026 double breach is the most recent significant finding on this tab, and one of the two incidents is attributed to ShinyHunters - the group behind the Salesforce social-engineering campaign that this tracker treats as its single biggest connective thread, reaching dozens of companies across many tabs. Abbott is also unusual among the manufacturers here in having a genuine direct consumer relationship through continuous glucose monitors, which stream physiological data from a person's body to a manufacturer platform continuously. That combination - a real consumer data stream plus exposure to the campaign already documented across this tracker - makes this row a priority for verification of scope and data types as notifications develop.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Pharma & Biotech", "_row_id": 743, "_entity_id": 1017, "_entity_slug": "abbott-laboratories", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "HCA Healthcare", "Category": "Health Care: Medical Facilities", "Terms & Conditions URL": "hcahealthcare.com/util/terms-of-use.dot", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "hcahealthcare.com/util/privacy-notice.dot", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "TWO SEPARATE MAJOR FINDINGS: (1) A 2023 breach: hackers stole a database from an EXTERNAL STORAGE location HCA used to automate email formatting, exposing information for approximately 11.27 MILLION PATIENTS across HCA's 190+ hospitals and doctors' offices in 20 states — the stolen database reportedly contained 27.7 million total records; when HCA did not pay the ransom, hackers listed it for sale. 27 separate class actions were filed and later consolidated; HCA agreed to an $11 MILLION settlement (final court approval Oct 30, 2025), offering up to $5,000 for documented losses plus 1 year of credit monitoring. (2) A SEPARATE, MORE RECENT lawsuit (2026) alleges HCA's CareNow urgent-care subsidiary (20+ Middle Tennessee locations) 'surreptitiously' shared patients' PROTECTED HEALTH INFORMATION with GOOGLE and other marketing/advertising companies via tracking technology embedded in its online appointment-scheduling platform — the SAME Meta/Google Pixel-in-healthcare pattern documented extensively for MyChart/Epic Systems elsewhere in this tracker, here alleged specifically to let Google 'exploit their health information for advertising purposes' by linking patients to their Google accounts.", "Arbitration / Class Action Waiver": "HCA Healthcare is a hospital operator — patient disputes are primarily governed by state medical-malpractice law and hospital consent forms, not website T&C. HCA's website Terms of Use contain a mandatory arbitration clause with class action waiver (AAA rules, Tennessee law, 30-day opt-out) covering website/app interactions, but clinical-care disputes follow a separate legal path through hospital admission agreements. The July 2023 breach (11M patients, external storage location) would be governed by the website arbitration clause for patients who interacted with HCA's patient portal, but by state law for patients whose data was compromised solely through hospital records.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "As the LARGEST hospital operator in the US, HCA now has TWO separate, serious findings (a 27-million-record breach affecting 11+ million patients, and an active tracking-pixel lawsuit against a subsidiary) — worth cross-referencing with the MyChart/Epic Systems row (Health, Fitness & Misc Services tab) for the broader hospital-industry pixel-tracking pattern this CareNow allegation fits into.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Nashville", "HQ State": "Tennessee", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.hipaajournal.com/hca-healthcare-cyberattack-data-breach-2023/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Tennessee' is a non-DMV US state", "Parent / Ultimate Owner": "HCA Healthcare, Inc.", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Tennessee SOS Business Search — tnbear.tn.gov/Ecommerce/FilingSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: HCA Healthcare, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] HCA's 2023 breach exposed 11.27M patients via an external email-formatting store; $11M settlement\nWHAT THE TERMS SAY: Hackers stole a database from an external storage location HCA used to automate email formatting, exposing information for approximately 11.27 million patients across HCA's 190+ hospitals and doctors' offices in 20 states; the stolen database reportedly contained 27.7 million total records. When HCA did not pay the ransom, hackers listed it for sale. 27 separate class actions were filed and later consolidated, and HCA agreed to an $11 million settlement (final court approval Oct 30, 2025) offering up to $5,000 for documented losses plus 1 year of credit monitoring.\nWHY IT MATTERS: The breach came from marketing-adjacent administrative plumbing rather than the clinical record system, and reached a patient population larger than most U.S. states.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] A new 2026 suit alleges HCA's CareNow shared patient health data with Google via tracking tech\nWHAT THE TERMS SAY: A 2026 lawsuit alleges HCA's CareNow urgent-care subsidiary 'surreptitiously' shared patients' protected health information with Google and other marketing companies through tracking technology on its online scheduling platform, allegedly letting Google link patients to their Google accounts to 'exploit their health information for advertising purposes.'\nWHY IT MATTERS: If true, scheduling a doctor's appointment could feed a patient's health information into an advertising profile linked to their personal Google account, without the patient's knowledge.\n(evidence: Data Sharing/Selling Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CLASS_ACTION_WAIVER · FL-3] HCA's website/app terms impose arbitration and a class-action waiver, separate from care disputes\nWHAT THE TERMS SAY: HCA's website Terms of Use contain a mandatory arbitration clause with class action waiver (AAA rules, Tennessee law, 30-day opt-out) covering website/app interactions; clinical-care disputes instead follow hospital admission agreements and state malpractice law.\nWHY IT MATTERS: Patients who used HCA's patient portal around the 2023 breach may be bound to arbitrate any resulting claim rather than join the consolidated litigation, absent the 30-day opt-out.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Both the breach settlement and the CareNow tracking-tech lawsuit are dated, quantified, and specifically described, and the arbitration terms are explicitly stated with a defined opt-out window.", "Exposure Score (0-100)": 48, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "HCA Healthcare  <-  HCA Healthcare, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using HCA Healthcare you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2023 HCA breach exposed data on roughly 11 million patients, and the mechanism is the part worth understanding: the stolen database was an external storage location used to automate email formatting - appointment reminders and similar - not the clinical record system. So the exposure came from the marketing-adjacent plumbing rather than the medical vault, which is exactly the layer patients never think about and hospitals defend least. HCA is the largest for-profit hospital operator in the country, which means a single administrative-systems decision reached a patient population larger than most states.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Healthcare Providers", "_row_id": 744, "_entity_id": 1019, "_entity_slug": "hca-healthcare", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Tenet Healthcare", "Category": "Health Care: Medical Facilities", "Terms & Conditions URL": "See Tenet Healthcare's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Tenet Healthcare's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a company-specific consumer lawsuit distinct from the general hospital/health-system pixel-tracking and breach patterns documented for HCA, MyChart/Epic, and Community Health Systems elsewhere in this tracker; see the Cencora patient-data breach finding (F500 Pharma & Biotech tab) which specifically names Cencora as the source of a major 2024 patient-data exposure affecting more than a dozen pharma manufacturers' patients.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; cross-reference with the Cencora breach (F500 Pharma & Biotech tab) if this company is Cencora itself.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Dallas", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Data-sharing and arbitration fields both say not independently confirmed this pass; the SCARY field's discussion of patients' inability to shop hospitals on privacy terms is stated as a structural point about any large for-profit hospital system generally, not a fact specific to Tenet.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No company-specific incident, term, or data practice is confirmed; the substantive note is industry-wide context.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Tenet Healthcare  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Tenet Healthcare takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing company-specific confirmed this pass. The structural finding for any large for-profit hospital system is that a patient has no realistic ability to shop on privacy terms: hospital choice is driven by insurance network, ambulance routing, and which specialists have admitting privileges, and none of those channels surface a data-handling comparison. The notice of privacy practices handed over at registration is presented for signature at a moment of maximum stress and minimum leverage, and declining it does not change the treatment or the data flow. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Healthcare Providers", "_row_id": 745, "_entity_id": 1020, "_entity_slug": "tenet-healthcare", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Community Health Systems", "Category": "Health Care: Medical Facilities", "Terms & Conditions URL": "chs.net/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "chs.net/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "VERY RECENT CONFIRMED BREACH (Feb 28, 2026): Community Health Systems (CHS) discovered unusual network activity, leading to an investigation with third-party specialists that confirmed unauthorized access to certain network data — a comprehensive review of the full scope remained ONGOING as of this research (April 2026), meaning the true extent is not yet fully known. CHS was ALSO separately documented (Health, Fitness & Misc Services tab, MyChart row) as one of the health systems that settled a Meta Pixel patient-tracking lawsuit involving its own MyChart implementation, covering patients who logged into CHS's MyChart portal between Jan 1, 2020 and Dec 11, 2025.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the MyChart/Epic Systems row (Health, Fitness & Misc Services tab) for the CHS-specific pixel-tracking settlement already documented in this tracker; the Feb 2026 breach above is a SEPARATE, distinct incident.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Franklin", "HQ State": "Tennessee", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Tennessee' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Tennessee SOS Business Search — tnbear.tn.gov/Ecommerce/FilingSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] CHS confirmed unauthorized network access Feb 28, 2026; full scope still unknown as of April 2026\nWHAT THE TERMS SAY: Community Health Systems discovered unusual network activity and, after a third-party investigation, confirmed unauthorized access to certain network data; a comprehensive review of the full scope remained ongoing as of April 2026.\nWHY IT MATTERS: Patients can't yet know how their data was affected, and the tracker notes this is a repeat pattern for CHS, which has appeared in major breach coverage before.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] CHS separately settled a Meta Pixel tracking suit covering MyChart logins from 2020 to 2025\nWHAT THE TERMS SAY: CHS was documented elsewhere in this tracker as one of the health systems that settled a Meta Pixel patient-tracking lawsuit tied to its MyChart implementation, covering patients who logged into CHS's MyChart portal between Jan 1, 2020 and Dec 11, 2025.\nWHY IT MATTERS: Nearly six years of patient portal logins were potentially exposed to tracking technology shared with a third party, a separate issue from the Feb 2026 network breach.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — A possible third item, the rural/sole-provider lock-in point in SCARY, is a structural market observation rather than a stated term or practice, so it is not counted as a third distinct troubling item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Feb 2026 breach is confirmed but its scope is explicitly still under investigation, and the MyChart settlement is dated and specific — a genuine mix of confirmed and still-unfolding facts.", "Exposure Score (0-100)": 15, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Community Health Systems  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Community Health Systems you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "CHS confirmed a breach on February 28, 2026, and the row is a reminder that this is a repeat pattern for the company rather than a first event - CHS has appeared in major breach coverage before. What compounds the harm at rural hospital systems specifically is that CHS operates many facilities that are the only hospital in their county. A patient there cannot respond to a breach by taking their care elsewhere, so the ordinary market consequence that is supposed to discipline this behaviour simply does not arrive.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Healthcare Providers", "_row_id": 746, "_entity_id": 1021, "_entity_slug": "community-health-systems", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Centene", "Category": "Health Care: Insurance and Managed Care", "Terms & Conditions URL": "See Centene's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Centene's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a company-specific consumer lawsuit distinct from the general hospital/health-system pixel-tracking and breach patterns documented for HCA, MyChart/Epic, and Community Health Systems elsewhere in this tracker; see the Cencora patient-data breach finding (F500 Pharma & Biotech tab) which specifically names Cencora as the source of a major 2024 patient-data exposure affecting more than a dozen pharma manufacturers' patients.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; cross-reference with the Cencora breach (F500 Pharma & Biotech tab) if this company is Cencora itself.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Centene, the largest Medicaid MCO, requires richer enrollment disclosures with no confirmed incident\nWHAT THE TERMS SAY: Centene is the largest Medicaid managed-care organization in the country; Medicaid enrollment requires disclosing income, household composition, and immigration-adjacent documentation beyond what a commercial plan requires, while the tracker found no company-specific data-privacy incident or lawsuit this pass.\nWHY IT MATTERS: Centene's members are disproportionately low-income and least able to absorb identity-theft costs, yet the tracker notes this population's insurer attracts comparatively little public scrutiny.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing and arbitration fields both say not independently confirmed this pass; only the SCARY field's note about Medicaid enrollment's broader disclosure requirements and the lack of public scrutiny is substantive, and it is explicitly framed as a concerning null result rather than a confirmed incident.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No confirmed incident or term exists; the note concerns the absence of scrutiny given Centene's enrollment data requirements.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Centene  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Centene takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing company-specific confirmed this pass. Centene is the largest Medicaid managed-care organisation in the country, which makes the blank row uncomfortable rather than reassuring: its members are disproportionately low-income, and the population least able to absorb the cost of identity theft is the one whose insurer's data practices attract the least scrutiny. Medicaid enrolment also requires disclosing far more than commercial insurance does - income, household composition, immigration-adjacent documentation - so the records held are richer than a commercial plan's. Recommend a targeted follow-up; this is the highest-stakes null result in this tab.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Healthcare Providers", "_row_id": 747, "_entity_id": 1022, "_entity_slug": "centene", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Molina Healthcare", "Category": "Health Care: Insurance and Managed Care", "Terms & Conditions URL": "See Molina Healthcare's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Molina Healthcare's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a company-specific consumer lawsuit distinct from the general hospital/health-system pixel-tracking and breach patterns documented for HCA, MyChart/Epic, and Community Health Systems elsewhere in this tracker; see the Cencora patient-data breach finding (F500 Pharma & Biotech tab) which specifically names Cencora as the source of a major 2024 patient-data exposure affecting more than a dozen pharma manufacturers' patients.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; cross-reference with the Cencora breach (F500 Pharma & Biotech tab) if this company is Cencora itself.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Molina, a Medicaid/marketplace insurer, collects richer financial detail with no confirmed incident\nWHAT THE TERMS SAY: Molina Healthcare is a Medicaid and marketplace-focused insurer whose enrollment process collects household and financial detail beyond what a commercial plan requires; the tracker found no company-specific incident or lawsuit distinct from industry-wide patterns this pass.\nWHY IT MATTERS: The tracker frames this as a consumer-protection asymmetry: populations least able to monitor credit, freeze files, or litigate are covered by insurers generating the least public accountability record.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing and arbitration fields both say not independently confirmed this pass; only the SCARY field's note about Molina's enrollment-data breadth and the lack of public scrutiny is substantive, and it stops short of a confirmed incident.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No confirmed incident or term exists; the note concerns the absence of scrutiny given Molina's enrollment data requirements.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Molina Healthcare  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Molina Healthcare takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing company-specific confirmed this pass. Same analysis as Centene: Molina is a Medicaid and marketplace-focused insurer whose membership skews low-income, and the enrolment process collects household and financial detail that a commercial plan never asks for. The consumer-protection asymmetry is the finding - populations with the least capacity to monitor credit, freeze files or litigate are covered by insurers that generate the least public accountability record. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Healthcare Providers", "_row_id": 748, "_entity_id": 1023, "_entity_slug": "molina-healthcare", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Oscar Health", "Category": "Health Care: Insurance and Managed Care", "Terms & Conditions URL": "See Oscar Health's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Oscar Health's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a company-specific consumer lawsuit distinct from the general hospital/health-system pixel-tracking and breach patterns documented for HCA, MyChart/Epic, and Community Health Systems elsewhere in this tracker; see the Cencora patient-data breach finding (F500 Pharma & Biotech tab) which specifically names Cencora as the source of a major 2024 patient-data exposure affecting more than a dozen pharma manufacturers' patients.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; cross-reference with the Cencora breach (F500 Pharma & Biotech tab) if this company is Cencora itself.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Oscar's app-first insurance model means more telemetry and third-party integrations than a legacy carrier\nWHAT THE TERMS SAY: Oscar was built as a technology-first insurer with far more of the member relationship running through its app than at a legacy carrier, meaning more telemetry, more behavioral data, and more third-party service integration points for a plan of comparable size.\nWHY IT MATTERS: This larger data surface is entirely invisible when members compare plans on premium, deductible, and network, the factors that actually drive the choice.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing and arbitration fields both say not independently confirmed this pass; only the SCARY field's inference about Oscar's app-first data surface is substantive, and it stops short of naming a specific SDK, partner, or disclosure.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No specific incident, SDK, or partner disclosure is confirmed; the app-first data-surface point is a structural inference.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Oscar Health  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Oscar Health takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Oscar's distinguishing feature is that it was built as a technology-first insurer, with far more of the member relationship running through an app than at a legacy carrier - more telemetry, more behavioural data, more integration points with third-party services. That is a structurally larger data surface than a traditional plan of comparable size, and it is entirely invisible in a plan comparison, where members choose on premium, deductible and network. Recommend a follow-up on Oscar's app SDK inventory and third-party sharing disclosures.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Healthcare Providers", "_row_id": 749, "_entity_id": 1024, "_entity_slug": "oscar-health", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Henry Schein", "Category": "Wholesalers: Health Care", "Terms & Conditions URL": "See Henry Schein's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Henry Schein's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a company-specific consumer lawsuit distinct from the general hospital/health-system pixel-tracking and breach patterns documented for HCA, MyChart/Epic, and Community Health Systems elsewhere in this tracker; see the Cencora patient-data breach finding (F500 Pharma & Biotech tab) which specifically names Cencora as the source of a major 2024 patient-data exposure affecting more than a dozen pharma manufacturers' patients.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; cross-reference with the Cencora breach (F500 Pharma & Biotech tab) if this company is Cencora itself.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Melville", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Henry Schein's practice-management software is a single point of failure for small dental/medical practices\nWHAT THE TERMS SAY: Henry Schein supplies dental and medical practices with products and practice-management software; tens of thousands of small independent practices rely on it, many without security staff of their own, and a patient at a small practice generally can't know their record's real custodian is Henry Schein's platform.\nWHY IT MATTERS: A single vendor's security failure could expose patient records across a very large number of small, otherwise-unconnected practices simultaneously.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing and arbitration fields both say not independently confirmed this pass; only the SCARY field's note on Henry Schein's vendor-concentration risk across small practices is substantive, and no specific incident is confirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No confirmed incident exists; the vendor-concentration risk is a structural inference about Henry Schein's role underneath small practices.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Henry Schein  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Henry Schein takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Henry Schein is a healthcare products distributor serving dental and medical practices, and its consumer relevance is indirect but real: it is a supplier to tens of thousands of small independent practices, many of which rely on it for practice-management software as well as supplies. That makes it a single point of failure sitting underneath a very large number of small providers who have no security staff of their own. The patient at a two-dentist practice has no way to know that their record's real custodian is a distributor's software platform. Nothing company-specific confirmed this pass; recommend a follow-up given the vendor-concentration risk.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Healthcare Providers", "_row_id": 750, "_entity_id": 1025, "_entity_slug": "henry-schein", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Owens & Minor", "Category": "Wholesalers: Health Care", "Terms & Conditions URL": "See Owens & Minor's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Owens & Minor's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; cross-reference with the Cencora breach (F500 Pharma & Biotech tab) if this company is Cencora itself.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Owens & Minor's Apria home-health arm holds patient clinical data despite the parent's B2B profile\nWHAT THE TERMS SAY: Owens & Minor is framed as a B2B medical supply distributor, but its Apria home healthcare arm has a direct patient relationship, supplying home oxygen, sleep apnea and mobility equipment, and holds patient-level clinical and insurance data.\nWHY IT MATTERS: Consumers dealing with what looks like a pure supply-chain company may not realize a subsidiary holds their clinical and insurance records.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-1] Apria has been subject to federal false claims settlements, per the tracker\nWHAT THE TERMS SAY: The tracker states Apria 'has been subject to federal false claims settlements' without specifying amounts or years.\nWHY IT MATTERS: Federal false-claims settlements signal past billing-practice issues in a unit that also holds patient data, though the tracker gives no dollar figure or date.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two substantive items are stated; Arbitration and Fees fields are both hedged as 'not confirmed'/'not itemized,' leaving no third distinct company-specific harm.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration and fee details are unconfirmed, but the SCARY field surfaces a specific, stated fact about Apria's patient data and settlements.", "Exposure Score (0-100)": 6, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 3, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 3/20 (severity1+0, penalty+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Owens & Minor  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Medical supply distributor to healthcare providers, with a home healthcare arm (Apria) that DOES have a direct patient relationship — supplying home oxygen, sleep apnea and mobility equipment. That arm has been subject to federal false claims settlements, and it holds patient-level clinical and insurance data, so this row is not the pure B2B entry the parent company profile suggests.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Healthcare Providers", "_row_id": 751, "_entity_id": 1026, "_entity_slug": "owens-minor", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "GE HealthCare Technologies", "Category": "Medical Products and Equipment", "Terms & Conditions URL": "See GE HealthCare Technologies's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See GE HealthCare Technologies's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a company-specific consumer lawsuit distinct from the general hospital/health-system pixel-tracking and breach patterns documented for HCA, MyChart/Epic, and Community Health Systems elsewhere in this tracker; see the Cencora patient-data breach finding (F500 Pharma & Biotech tab) which specifically names Cencora as the source of a major 2024 patient-data exposure affecting more than a dozen pharma manufacturers' patients.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; cross-reference with the Cencora breach (F500 Pharma & Biotech tab) if this company is Cencora itself.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] GE HealthCare's connected imaging and monitoring devices route telemetry outside HIPAA's primary reach\nWHAT THE TERMS SAY: GE HealthCare makes networked imaging and monitoring equipment used inside hospitals; per the tracker, the device manufacturer rather than the hospital controls the software update path and telemetry, and device security falls under FDA premarket guidance rather than HIPAA in the first instance.\nWHY IT MATTERS: Patients whose treatment involves this equipment have device-generated data flow through a regulatory framework built for device safety, not patient privacy.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No company-specific breach, lawsuit or arbitration term is confirmed for this row; Data Sharing and Arbitration fields explicitly say 'not confirmed,' leaving only the general connected-device regulatory-gap observation from the SCARY field.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing, arbitration and fees are all explicitly unconfirmed; only a general device-security observation is documented.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "GE HealthCare Technologies  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, GE HealthCare Technologies takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing company-specific confirmed this pass. The finding worth recording is that GE HealthCare makes imaging and monitoring equipment that sits inside hospitals and increasingly connects to networks and cloud services - a category where the device manufacturer, not the hospital, controls the software update path and the telemetry. Medical device security is governed by FDA premarket guidance rather than by HIPAA in the first instance, so the regulatory regime a patient would expect to apply largely does not. Recommend a follow-up on connected-device data flows.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Healthcare Providers", "_row_id": 752, "_entity_id": 1027, "_entity_slug": "ge-healthcare-technologies", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "McKesson", "Category": "Wholesalers: Health Care", "Terms & Conditions URL": "See McKesson's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See McKesson's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "McKesson processes pharmaceutical distribution data for ~1/3 of all US prescriptions. CoverMyMeds processes prior-authorization requests containing patient diagnosis codes, medication history, and insurance information. The $7.9B opioid settlement component (of the $21B total) arose from distribution data showing McKesson shipped suspicious opioid volumes.", "Arbitration / Class Action Waiver": "Primarily B2B — McKesson is the largest pharmaceutical distributor in the US by revenue ($276.7B, FY2023). Consumer exposure through McKesson's pharmacy-technology platforms and the CoverMyMeds prior-authorization service. No consumer arbitration clause in the core distribution business.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; cross-reference with the Cencora breach (F500 Pharma & Biotech tab) if this company is Cencora itself.\n\nAUG 2026 RE-VERIFICATION: the ~$21B figure is the COMBINED total across McKesson, Cardinal Health and AmerisourceBergen/Cencora, not McKesson's individual share. Cencora's own SEC filing puts its individual allocation at up to ~$6.4B over 18 years (see the Cencora row). Individual allocations were set by market share, not by any finding or admission of liability. If a per-company figure is ever published from this tracker, use the company-specific allocation, not the combined headline.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Irving", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://nationalopioidsettlement.com/executive-summary/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "McKesson Corporation", "Years Referenced in Finding (heuristic)": "2022, 2032", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: McKesson Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] McKesson's opioid settlement rests on an allegation it failed to monitor and report suspicious orders\nWHAT THE TERMS SAY: McKesson agreed, with Cardinal Health and Cencora, to pay up to $21B over 18 years to resolve state and local government opioid claims, without admitting wrongdoing; the allegation was failure to monitor and report suspicious orders. The tracker states McKesson's own component of that combined total is $7.9B.\nWHY IT MATTERS: The settlement's injunctive term required the three distributors to build and maintain an independent centralised clearinghouse giving regulators aggregated distribution data through roughly 2032 -- a data-sharing obligation imposed as a remedy, which the tracker calls the inverse of every other finding in this tracker.\n(evidence: Notes | SCARY; Stated in tracker (fidelity pass 1: Cross-ref leak corrected) (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] CoverMyMeds handles prior-authorization data containing diagnosis codes and medication history\nWHAT THE TERMS SAY: McKesson's CoverMyMeds platform processes prior-authorization requests containing patient diagnosis codes, medication history, and insurance information.\nWHY IT MATTERS: Patients seeking prescription approvals have sensitive diagnostic and medication data pass through a distributor's subsidiary rather than solely their provider or insurer.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct consumer-facing findings are documented — the opioid settlement and CoverMyMeds' sensitive data handling; the settlement's injunctive clearinghouse term is a regulatory transparency measure rather than a consumer harm, and no consumer arbitration clause is stated for the core distribution business.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The opioid settlement and CoverMyMeds data handling are specifically documented, but no consumer-facing arbitration or fee terms are detailed.", "Exposure Score (0-100)": 23, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "McKesson  <-  McKesson Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, McKesson takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "McKesson, Cardinal Health and AmerisourceBergen (now Cencora) agreed to pay up to $21 billion over 18 years to resolve opioid claims brought by states and local governments - the largest national settlement of the epidemic to date, with payments beginning in May 2022 and none of the companies admitting wrongdoing. The allegation was not that they made the drugs but that they failed to monitor and report suspicious orders, allowing diversion into illegal channels. The injunctive term is the one worth noting: the settlement required the three distributors to build and maintain an independent centralised clearinghouse giving regulators aggregated distribution data through roughly 2032 - a data-sharing obligation imposed as a remedy, which is the inverse of every other finding in this tracker.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Healthcare Providers", "_row_id": 753, "_entity_id": 1029, "_entity_slug": "mckesson", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cencora", "Category": "Wholesalers: Health Care", "Terms & Conditions URL": "See Cencora's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Cencora's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Cencora distributes ~20% of all pharmaceuticals sold in the US. Processes pharmaceutical supply-chain data including drug pricing, distribution volumes, and pharmacy-level dispensing patterns. The $6.6B opioid settlement (part of the $21B distributor settlement with McKesson and Cardinal Health) arose from distribution data showing Cencora shipped suspicious volumes of opioids without adequate controls.", "Arbitration / Class Action Waiver": "Primarily B2B — Cencora is a pharmaceutical distribution company. Consumer exposure through Good Neighbor Pharmacy (independent pharmacy network) and the PharMerica long-term-care subsidiary. Website ToS contain arbitration provisions but the core business relationship is between Cencora and pharmacies/health systems, not individual patients.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; cross-reference with the Cencora breach (F500 Pharma & Biotech tab) if this company is Cencora itself.\n\nAUG 2026 RE-VERIFICATION (triple-check pass): Cencora's own SEC filing confirms its INDIVIDUAL allocation under the July 20 2021 nationwide opioid distributor settlement is up to approximately $6.4 billion over 18 years, determined by its share of the relevant market rather than by any finding or admission of liability, plus injunctive relief measures. The $21 billion figure used in the McKesson and Cardinal Health rows is the COMBINED three-distributor total - do not attribute $21B to any single company. Primary source: Cencora, Inc. Form 8-K exhibit, SEC EDGAR CIK 1140859.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Conshohocken", "HQ State": "Pennsylvania", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://nationalopioidsettlement.com/executive-summary/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Cencora, Inc. (fmr. AmerisourceBergen, renamed Aug 2023)", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Cencora, Inc. (fmr. AmerisourceBergen, renamed Aug 2023)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Cencora paid $75M in Bitcoin to ransomware attackers who stole diagnosis-level patient data\nWHAT THE TERMS SAY: Cencora paid $75 million in Bitcoin to the Dark Angels ransomware group across three transactions in March 2024 — the largest known cyber extortion payment ever made, against an initial $150 million demand. The stolen data included names, addresses, dates of birth, diagnoses, prescriptions and medications, held through Cencora's partnerships with drugmakers running patient support programs; at least 27 other pharmaceutical and biotech companies were caught in the same incident.\nWHY IT MATTERS: A patient enrolling in a manufacturer's copay-assistance program had their diagnosis-level data routed to a wholesale distributor most people have never heard of, then exposed in one of the largest known ransomware payouts.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-1] Cencora's SEC filing puts its individual opioid-settlement share at $6.4B, not the $21B combined headline\nWHAT THE TERMS SAY: Per Cencora's own SEC Form 8-K filing (EDGAR CIK 1140859), its individual allocation under the July 2021 nationwide opioid distributor settlement is up to approximately $6.4 billion over 18 years, determined by market share rather than any finding or admission of liability, plus injunctive relief measures. The commonly cited $21 billion figure is the combined total across Cencora, McKesson and Cardinal Health.\nWHY IT MATTERS: Attributing the full $21B headline figure to Cencora alone would overstate its individual financial exposure relative to its own SEC-filed figure.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Cencora processes pharmacy-level dispensing data across roughly 20% of all US drug distribution\nWHAT THE TERMS SAY: Cencora distributes roughly 20% of all pharmaceuticals sold in the US, processing drug pricing, distribution volumes, and pharmacy-level dispensing-pattern data. Direct consumer exposure runs through its Good Neighbor Pharmacy independent-pharmacy network and its PharMerica long-term-care subsidiary; website ToS contain arbitration provisions, though the tracker says the core business relationship is between Cencora and pharmacies/health systems, not individual patients.\nWHY IT MATTERS: Even though patients don't contract with Cencora directly, it distributes roughly 20% of all pharmaceuticals sold in the US and processes pharmacy-level dispensing-pattern data.\n(evidence: Data Sharing | Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The ransomware payment amount, date, and stolen-data categories, plus the SEC-filed settlement allocation, are all specifically documented with dates and dollar figures.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Cencora  <-  Cencora, Inc. (fmr. AmerisourceBergen, renamed Aug 2023)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Cencora you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Cencora paid $75 million in Bitcoin to the Dark Angels ransomware group in three March 2024 transactions - the largest known cyber extortion payment ever made, against an initial demand of $150 million. The stolen data included names, addresses, dates of birth, DIAGNOSES, prescriptions and medications, and Cencora held it through partnerships with drug makers running patient support programmes: at least 27 other pharmaceutical and biotech companies were caught in the same incident. That is the finding a patient could not have anticipated - enrolling in a manufacturer's copay assistance programme routed diagnosis-level data to a wholesale distributor most people have never heard of. No ransomware group ever publicly claimed the attack, which is consistent with a payment having been made. Cencora is also a defendant in the $21 billion opioid distributor settlement.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Healthcare Providers", "_row_id": 754, "_entity_id": 1031, "_entity_slug": "cencora", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cardinal Health", "Category": "Wholesalers: Health Care", "Terms & Conditions URL": "See Cardinal Health's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Cardinal Health's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Cardinal Health distributes pharmaceuticals and medical supplies to ~90% of US hospitals and 60,000+ pharmacies. The $6.6B opioid settlement component (of the $21B total) arose from distribution data showing suspicious opioid shipment volumes. Cardinal Health's nuclear pharmacy division also handles radioactive pharmaceutical data.", "Arbitration / Class Action Waiver": "Primarily B2B — pharmaceutical and medical-product distribution. Consumer exposure through Cardinal Health's at-Home division (home healthcare products). No consumer arbitration clause in the core distribution business.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; cross-reference with the Cencora breach (F500 Pharma & Biotech tab) if this company is Cencora itself.\n\nAUG 2026 RE-VERIFICATION: as with McKesson, the ~$21B is the COMBINED three-distributor total. Use company-specific allocations for any per-company claim - see the Cencora row, whose SEC-filed individual figure is up to ~$6.4B over 18 years.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Dublin", "HQ State": "Ohio", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://nationalopioidsettlement.com/executive-summary/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Ohio' is a non-DMV US state", "Parent / Ultimate Owner": "Cardinal Health, Inc.", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Cardinal Health, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] Cardinal Health faces the 18-year opioid settlement plus a further $300M health-plan settlement (Sept 2024)\nWHAT THE TERMS SAY: Cardinal Health is the third of the 'big three' distributors in the opioid settlement, paid over 18 years with no admission of wrongdoing, plus a further $300 million agreed in September 2024 to settle separate health-plan claims. Per the tracker's later correction, the $21B figure is the combined three-distributor total, not Cardinal Health's individual share (Cencora's own SEC-filed individual allocation is roughly $6.4B, for comparison).\nWHY IT MATTERS: Structuring the settlement over eighteen years reduces its present-day financial impact well below the headline figure, per the tracker's own analysis.\n(evidence: SCARY | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Cardinal Health's nuclear pharmacy division handles radioactive pharmaceutical data\nWHAT THE TERMS SAY: Cardinal Health distributes pharmaceuticals and medical supplies to about 90% of US hospitals and 60,000+ pharmacies; its nuclear pharmacy division separately handles radioactive pharmaceutical data, and its at-Home division is the company's direct consumer exposure point.\nWHY IT MATTERS: Cardinal Health's data footprint extends into specialized, sensitive categories beyond ordinary drug distribution, alongside a direct-to-consumer home healthcare business.\n(evidence: Data Sharing | Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No consumer arbitration clause is stated for the core distribution business, and no breach is confirmed; the two substantive findings are the settlement structure and the company's data footprint across its nuclear pharmacy and at-Home divisions.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Settlement figures and divisional data footprint are documented, but no consumer-facing arbitration clause or confirmed breach is stated.", "Exposure Score (0-100)": 23, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Cardinal Health  <-  Cardinal Health, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Cardinal Health takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Cardinal Health is the third of the big three distributors in the $21 billion opioid settlement, paid over 18 years with no admission of wrongdoing, plus a further $300 million agreed in September 2024 to settle health-plan claims. The number to sit with is not the total but the term: eighteen years. A settlement structured over nearly two decades converts a moral catastrophe into a manageable line item, and the discounted present value of $21 billion spread that thin is a fraction of the headline. For this tracker's purposes, the row also demonstrates that the largest financial consequences in healthcare attach to distribution conduct, not to data handling - which is precisely why data handling gets less attention.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Healthcare Providers", "_row_id": 755, "_entity_id": 1033, "_entity_slug": "cardinal-health", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Berkshire Hathaway", "Category": "Insurance: Property and Casualty (Stock)", "Terms & Conditions URL": "See Berkshire Hathaway's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Berkshire Hathaway's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Conglomerate. Berkshire's portfolio includes insurance (GEICO, General Re), railroads (BNSF), utilities (Berkshire Hathaway Energy), and consumer brands (Dairy Queen, Duracell, Fruit of the Loom). Warren Buffett is chairman/CEO. Each subsidiary has independent data practices.", "Arbitration / Class Action Waiver": "Berkshire Hathaway is a holding company — no direct consumer relationship. Consumer interactions are with subsidiaries: GEICO (already documented in this tracker), General Re, Berkshire Hathaway HomeServices (real estate), See's Candies, Dairy Queen. Each subsidiary maintains its own T&C.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; Berkshire Hathaway specifically owns GEICO (already documented in the Insurance tab) among many other subsidiaries — worth checking whether this parent-company relationship extends any findings.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Omaha", "HQ State": "Nebraska", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Nebraska' is a non-DMV US state", "Parent / Ultimate Owner": "Berkshire Hathaway Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Nebraska) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Nebraska. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] Berkshire's holding-company structure hides which subsidiary actually handles a customer's data\nWHAT THE TERMS SAY: Berkshire Hathaway is a pure holding company with no direct consumer relationship; each subsidiary (GEICO, General Re, Berkshire Hathaway HomeServices, See's Candies, Dairy Queen) maintains independent data practices and T&C, per the tracker.\nWHY IT MATTERS: A consumer would not search 'Berkshire Hathaway breach' to learn about issues at a subsidiary like their car insurer — the parent layer obscures rather than reveals which entity holds their data.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No parent-level finding is confirmed; the only substantive point is structural opacity from the holding-company layer. GEICO's own documented findings belong to its separate row, not this one.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed at the parent level; consumer relationships exist only through subsidiaries documented elsewhere.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Berkshire Hathaway  <-  Berkshire Hathaway Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Berkshire Hathaway takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass at the parent level, which is unsurprising given the structure: Berkshire is a holding company whose subsidiaries - GEICO among them - operate independently. GEICO's own findings are substantial and documented in the Insurance tab, including a $9.75 million New York penalty. The point for this row is that a consumer would never search 'Berkshire Hathaway breach' to learn about their car insurer, and the holding-company layer obscures rather than reveals.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Remainder", "_row_id": 756, "_entity_id": 1034, "_entity_slug": "berkshire-hathaway", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "GuideWell Mutual", "Category": "Insurance: Life, Health (Stock)", "Terms & Conditions URL": "See GuideWell Mutual's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See GuideWell Mutual's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "GuideWell/Florida Blue is the largest health insurer in Florida. HIPAA-covered entity. Customer data governed by HIPAA + FL OIR regulations.", "Arbitration / Class Action Waiver": "GuideWell is the parent of Florida Blue (BCBS of Florida). Health insurance disputes governed by FL Office of Insurance Regulation. No private arbitration clause in consumer-facing terms.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; Berkshire Hathaway specifically owns GEICO (already documented in the Insurance tab) among many other subsidiaries — worth checking whether this parent-company relationship extends any findings.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Jacksonville", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] As a Blue Cross licensee, GuideWell sits where a breach elsewhere carries no notice obligation here\nWHAT THE TERMS SAY: GuideWell (Florida Blue) is one of dozens of independent Blue Cross Blue Shield licensees sharing a common brand; the tracker states a breach at one licensee produces no notification obligation at another, and a member often cannot tell which corporate entity holds their file.\nWHY IT MATTERS: A Florida Blue member has no easy way to know whether a breach reported by a differently-named Blues licensee elsewhere affects their own data.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No confirmed breach, arbitration clause, or fee issue is stated for GuideWell specifically; only the structural Blues-system opacity point is substantive, and the tracker explicitly marks it 'unverified rather than clean.'", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing confirmed this pass; explicitly marked unverified rather than clean.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "GuideWell Mutual  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, GuideWell Mutual takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. GuideWell is the parent of Florida Blue and related Blue Cross entities, and health insurance holding structures are among the most opaque in this tracker - the Blues system comprises dozens of independent licensees sharing a brand, so a breach at one produces no notification obligation at another and a member cannot tell which corporate entity holds their file. Cross-ref CareFirst and Elevance in the Insurance and Life-Health-Dental tabs. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Remainder", "_row_id": 757, "_entity_id": 1035, "_entity_slug": "guidewell-mutual", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Reinsurance of America", "Category": "Insurance: Life, Health (Stock)", "Terms & Conditions URL": "See Reinsurance of America's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Reinsurance of America's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B reinsurance. No consumer data.", "Arbitration / Class Action Waiver": "B2B — reinsurance companies operate exclusively between insurers, not consumers. No consumer-facing products.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; Berkshire Hathaway specifically owns GEICO (already documented in the Insurance tab) among many other subsidiaries — worth checking whether this parent-company relationship extends any findings.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Chesterfield", "HQ State": "Missouri", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Missouri' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Missouri SOS Business Search — bsd.sos.mo.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] RGA holds consumers' medical underwriting data despite never contracting with them directly\nWHAT THE TERMS SAY: As a reinsurer, RGA holds policyholder-level data — including medical underwriting answers given when applying for life insurance — passed from the primary carriers it reinsures, per the tracker.\nWHY IT MATTERS: A consumer's health information can sit with a reinsurer they've never heard of and cannot practically submit a data request to, since they have no direct contractual relationship.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Reinsurance is a B2B relationship with no consumer-facing arbitration or fee terms stated; the only substantive point is the medical-data exposure inherent to the reinsurance structure itself.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Reinsurers are the least visible layer of the insurance data chain; the tracker states a consumer cannot easily identify or request data from RGA directly.", "Exposure Score (0-100)": 9, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Reinsurance of America  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Reinsurance of America you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "RGA holds policyholder-level data from the primary carriers it reinsures, which means a consumer's medical underwriting information — the health questions they answered when applying for life insurance — can sit with a company they have never heard of, never contracted with, and cannot practically make a data request to. Reinsurance is the least visible layer of the insurance data chain and among the most genuinely underexamined categories in this entire tracker.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Remainder", "_row_id": 758, "_entity_id": 1036, "_entity_slug": "reinsurance-of-america", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Corebridge Financial", "Category": "Diversified Financials", "Terms & Conditions URL": "corebridgefinancial.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "corebridgefinancial.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Corebridge processes retirement savings, life insurance, and annuity data. As a former AIG subsidiary, data migration from AIG's systems was a significant component of the 2022 spin-off.", "Arbitration / Class Action Waiver": "Corebridge Financial (spun off from AIG in 2022) offers retirement, life, and annuity products. Arbitration varies by product — annuity contracts typically contain arbitration clauses while life insurance disputes are often governed by state insurance department oversight.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is ANOTHER confirmed name added to the extensive list of companies affected by the 2023 MOVEit vulnerability documented throughout this tracker — worth treating as part of that connected, industry-wide incident rather than an isolated Corebridge-specific failure.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Corebridge was caught in the 2023 MOVEit file-transfer vulnerability breach\nWHAT THE TERMS SAY: The tracker confirms Corebridge as another named company affected by the 2023 MOVEit vulnerability, a file-transfer flaw that produced breaches across many unrelated organizations documented throughout the tracker.\nWHY IT MATTERS: Retirement and annuity customers' data was exposed through a third-party vendor flaw, not any action of their own.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] Corebridge customers' accounts and data moved to a new company in AIG's 2022 spin-off without their input\nWHAT THE TERMS SAY: Corebridge was spun off from AIG in 2022; retirement and annuity customers found their accounts and data moved to the newly separated company, a reorganization the tracker describes as invisible to them.\nWHY IT MATTERS: Customers had no say in which corporate entity now controls their retirement and annuity data.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Two distinct facts are confirmed — the MOVEit breach and the AIG spin-off data transfer; arbitration terms vary by product without specifics, so no third distinct item is stated.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The MOVEit breach and AIG spin-off are confirmed facts, but arbitration terms vary by product without further detail.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Corebridge Financial  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Corebridge Financial takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Corebridge was caught in the MOVEit vulnerability - the 2023 file-transfer flaw that produced breaches across dozens of unrelated organisations documented throughout this tracker. Corebridge was also spun out of AIG, so retirement and annuity customers found their accounts moved to a newly separated company; the corporate reorganisation was invisible to them and the data moved with the business.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Remainder", "_row_id": 759, "_entity_id": 1037, "_entity_slug": "corebridge-financial", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Equitable", "Category": "Insurance: Life, Health (Stock)", "Terms & Conditions URL": "See Equitable's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Equitable's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Equitable processes retirement plan assets ($911B AUM), life insurance, and wealth management data. Demutualized in 2018 (IPO). GLB Act privacy notice for financial products.", "Arbitration / Class Action Waiver": "Equitable Holdings (fmr. AXA Equitable) offers retirement, life, and wealth management products. FINRA arbitration for securities products. Insurance disputes governed by state insurance departments.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; Berkshire Hathaway specifically owns GEICO (already documented in the Insurance tab) among many other subsidiaries — worth checking whether this parent-company relationship extends any findings.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: New York, New York (non-US)", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Equitable's demutualization and AXA spin-off shifted data-governing incentives without policyholder consent\nWHAT THE TERMS SAY: Equitable (formerly AXA Equitable) converted from policyholder ownership to shareholder ownership in a 2018 demutualization IPO, then was later spun out of AXA — decisions the tracker says altered the incentive structure governing customer data without any policyholder being asked.\nWHY IT MATTERS: A medical underwriting file completed decades ago can travel through multiple ownership changes a policyholder never approved.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No confirmed breach or specific consumer arbitration clause is detailed; the substantive point is the demutualization/spin-off history and its data-retention implications.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Ownership history and retention profile are documented, but no confirmed breach or specific consumer arbitration term is stated.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Equitable  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Equitable takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Life insurance and retirement accounts with the multi-decade retention profile common to this sector. Equitable demutualised — converting from policyholder ownership to shareholder ownership — which altered the incentive structure governing customer data without any policyholder being asked, and it was subsequently spun out of AXA. Two ownership changes, and the medical underwriting file a customer completed in the 1990s travelled through both.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Remainder", "_row_id": 760, "_entity_id": 1038, "_entity_slug": "equitable", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Loews", "Category": "Insurance: Property and Casualty (Stock)", "Terms & Conditions URL": "See Loews's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Loews's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Conglomerate. CNA Financial is primarily commercial insurance (B2B). Loews Hotels collects guest reservation, loyalty, and payment data.", "Arbitration / Class Action Waiver": "Loews Corporation is a holding company — consumer exposure primarily through CNA Financial (commercial insurance, mostly B2B) and Loews Hotels (which has its own consumer-facing T&C with arbitration). Boardwalk Pipelines is B2B energy.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; Berkshire Hathaway specifically owns GEICO (already documented in the Insurance tab) among many other subsidiaries — worth checking whether this parent-company relationship extends any findings.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: New York, New York (non-US)", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] Loews Hotels guest data sits under the same parent as insurer CNA, obscured by holding-company structure\nWHAT THE TERMS SAY: Loews Corporation is a holding company; consumer exposure runs mainly through Loews Hotels, which has its own consumer-facing T&C with arbitration, while CNA Financial (commercial insurance) and Boardwalk Pipelines are B2B.\nWHY IT MATTERS: A hotel guest may not realize their reservation data sits under the same corporate parent as a commercial insurer.\n(evidence: SCARY | Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the holding-company structural point is substantive; no confirmed breach, specific arbitration term, or fee detail is stated for Loews Hotels itself.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Loews Hotels has a stated consumer arbitration clause, but no further specific terms or incidents are confirmed.", "Exposure Score (0-100)": 20, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Loews  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Loews you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Diversified holding company whose insurance exposure runs through CNA. Loews also owns Boardwalk Pipelines and Loews Hotels — the hotel arm being a genuine consumer relationship with the reservation and stay data profile documented in the Student Loans, Hotels & Auto tab. The holding-company structure obscures that a guest's data sits under the same parent as a commercial insurer.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Remainder", "_row_id": 761, "_entity_id": 1039, "_entity_slug": "loews", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Markel", "Category": "Insurance: Property and Casualty (Stock)", "Terms & Conditions URL": "See Markel's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Markel's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the shared MOVEit/Kelly Benefits vendor-breach waves documented extensively for other insurers throughout this tracker (Lincoln National, Hartford, Corebridge), since third-party benefits-administration and file-transfer vendors serve the insurance industry broadly.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; Berkshire Hathaway specifically owns GEICO (already documented in the Insurance tab) among many other subsidiaries — worth checking whether this parent-company relationship extends any findings.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Glen Allen", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Virginia' is DC/MD/VA", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] Markel underwrites consumer pet insurance brands as an entity most customers never identify\nWHAT THE TERMS SAY: Markel American has appeared as the underwriter behind consumer-facing pet insurance brands; the tracker notes this is the entity most customers never identify, and that contract disputes over premium increases turn on the underwriter's own filings rather than the brand's marketing.\nWHY IT MATTERS: A pet-insurance customer disputing a premium increase may not realize Markel, not the branded company they signed up with, controls the relevant filings.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data sharing and arbitration are both explicitly unconfirmed for Markel; only the hidden-underwriter structural point is stated.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing and arbitration fields are both explicitly unconfirmed; only the underwriter-visibility point is documented.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Markel  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Markel takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Specialty and excess lines insurer with limited direct personal-lines exposure. Markel American has appeared as the underwriter behind consumer-facing pet insurance brands — cross-ref the Healthy Paws row in the Insurance tab, where the underwriter is precisely the entity most customers never identify, and where the contract dispute over what may justify a premium increase turns on the underwriter's filings rather than the brand's marketing.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Remainder", "_row_id": 762, "_entity_id": 1040, "_entity_slug": "markel", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "FM", "Category": "Insurance: Property and Casualty (Stock)", "Terms & Conditions URL": "See FM's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See FM's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B commercial property insurance. FM Global insures industrial facilities, not consumers.", "Arbitration / Class Action Waiver": "FM Global (Factory Mutual) is a commercial/industrial property insurer — no consumer products. B2B only. Disputes governed by commercial insurance contract terms.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; Berkshire Hathaway specifically owns GEICO (already documented in the Insurance tab) among many other subsidiaries — worth checking whether this parent-company relationship extends any findings.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Johnston", "HQ State": "Rhode Island", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Johnston, Rhode Island (non-US)", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): RI SOS Corporate Database — business.sos.ri.gov/CorpWeb/CorpSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — FM Global is a commercial/industrial-only property insurer with no consumer products or relationship stated anywhere in the row.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship exists, so no consumer terms are documented.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "FM  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Mutual commercial property insurer (formerly FM Global) serving large corporate clients, owned by its policyholders. Its business model is unusual and worth noting: FM invests heavily in loss-prevention engineering and site inspection rather than pure risk transfer, which means it holds detailed physical and operational data about its insureds' facilities. No consumer relationship.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Remainder", "_row_id": 763, "_entity_id": 1041, "_entity_slug": "fm", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Securian Financial", "Category": "Insurance: Life, Health (Stock)", "Terms & Conditions URL": "See Securian Financial's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Securian Financial's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Securian processes employee benefits data (life insurance, disability, retirement) through employer relationships. Group insurance data governed by ERISA and state insurance regulations.", "Arbitration / Class Action Waiver": "Securian Financial offers employer-sponsored life, disability, and retirement products. Consumer relationship is typically through the employer, not directly. Insurance disputes governed by MN Department of Commerce.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; Berkshire Hathaway specifically owns GEICO (already documented in the Insurance tab) among many other subsidiaries — worth checking whether this parent-company relationship extends any findings.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "St. Paul", "HQ State": "Minnesota", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Minnesota' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] Securian's employer/bank distribution model means members often can't identify who holds their coverage\nWHAT THE TERMS SAY: Securian provides life, disability and retirement products largely through employers, banks and credit unions rather than directly; the tracker states a member frequently could not name the underwriter if asked.\nWHY IT MATTERS: A person may not know or be able to easily locate who holds their medical underwriting answers because the distribution channel obscures the actual insurer.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data sharing, arbitration and fees are described only generically (ERISA/state oversight); the only distinct point is Securian's intermediated distribution model.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Regulatory oversight framework is named, but no confirmed breach or specific consumer-facing terms are stated.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Securian Financial  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Securian Financial takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Mutual holding company providing life insurance and retirement products largely THROUGH employers, banks and credit unions rather than directly — so a member frequently holds Securian coverage via their bank or workplace and could not name the underwriter if asked. That intermediated distribution is the finding: the entity holding your medical underwriting answers is one you never chose and may never have heard of.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Remainder", "_row_id": 764, "_entity_id": 1042, "_entity_slug": "securian-financial", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Thrivent Financial for Lutherans", "Category": "Insurance: Life, Health (Mutual)", "Terms & Conditions URL": "See Thrivent Financial for Lutherans's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Thrivent Financial for Lutherans's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Fraternal benefit society serving Lutheran communities. Processes financial, insurance, and charitable-giving data. Thrivent's membership model creates a data relationship different from a standard insurer — it functions more like a membership organization.", "Arbitration / Class Action Waiver": "Thrivent is a fraternal benefit society (membership-based, not-for-profit), which gives it a unique regulatory status. Disputes handled through Thrivent's internal appeals process and state insurance departments. FINRA arbitration for securities products.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; Berkshire Hathaway specifically owns GEICO (already documented in the Insurance tab) among many other subsidiaries — worth checking whether this parent-company relationship extends any findings.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Minneapolis", "HQ State": "Minnesota", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Minnesota' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Thrivent membership records carry an inherent religious-affiliation inference\nWHAT THE TERMS SAY: Thrivent is a fraternal benefit society whose membership criterion has historically been Lutheran/religious affiliation; the tracker notes membership records themselves therefore carry a religious-affiliation inference treated as sensitive elsewhere in the tracker.\nWHY IT MATTERS: A member's mere presence on Thrivent's rolls implies a religious affiliation, a sensitive-category inference, even though nothing else is confirmed this pass.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Nothing else is confirmed this pass; explicitly marked 'unverified rather than clean,' so only the religious-affiliation-inference structural point is stated.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Explicitly marked 'nothing confirmed this pass' and 'unverified rather than clean.'", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Thrivent Financial for Lutherans  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Thrivent Financial for Lutherans takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Thrivent is a fraternal benefit society - a member-owned structure with a membership criterion, which historically has been religious affiliation. That is worth noting factually because it means membership records themselves carry an inference this tracker treats as sensitive elsewhere, and fraternal benefit societies operate under a distinct regulatory framework from ordinary insurers. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Remainder", "_row_id": 765, "_entity_id": 1043, "_entity_slug": "thrivent-financial-for-lutherans", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Western & Southern Financial", "Category": "Insurance: Life, Health (Mutual)", "Terms & Conditions URL": "See Western & Southern Financial's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Western & Southern Financial's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Western & Southern processes life insurance, annuity, and investment data. Privately held (mutual holding company structure).", "Arbitration / Class Action Waiver": "Western & Southern offers life insurance, annuities, and mutual funds. Insurance disputes governed by OH Department of Insurance. FINRA arbitration for securities.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; Berkshire Hathaway specifically owns GEICO (already documented in the Insurance tab) among many other subsidiaries — worth checking whether this parent-company relationship extends any findings.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cincinnati", "HQ State": "Ohio", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Ohio' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[RETENTION_PERIOD · FL-2] Western & Southern's life/annuity files can retain medical underwriting data for sixty-plus years\nWHAT THE TERMS SAY: The tracker states life and annuity files carry the longest retention profile in financial services — medical underwriting answers can sit on file for sixty years or more, and beneficiary designations map family structure including estranged relationships.\nWHY IT MATTERS: Decades after an applicant forgets disclosing sensitive health information, that data — plus a record of their family relationships — remains on file.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Nothing company-specific is confirmed; the tracker itself frames the retention-horizon point as an industry pattern rather than a Western & Southern-specific fact.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Explicitly 'nothing company-specific confirmed'; only a generic retention-period observation is offered.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "Western & Southern Financial  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Western & Southern Financial takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A mutual holding company selling life insurance and annuities largely through career agents and independent distributors. Life and annuity files carry the longest retention profile in financial services — medical underwriting answers given at application can sit on file for sixty years or more, long after the applicant has forgotten disclosing them, and beneficiary designations map family structure including estranged relationships. Nothing company-specific confirmed; the retention horizon is the finding.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Remainder", "_row_id": 766, "_entity_id": 1044, "_entity_slug": "western-southern-financial", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fidelity National Financial", "Category": "Insurance: Property and Casualty (Stock)", "Terms & Conditions URL": "See Fidelity National Financial's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Fidelity National Financial's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "FNF processes title insurance, escrow, and real estate transaction data — including property purchase prices, mortgage amounts, and buyer/seller identity information. The Nov 2023 breach compromised SSNs and bank account numbers.", "Arbitration / Class Action Waiver": "FNF is a title insurance company — the largest in the US. Title insurance disputes are typically governed by state insurance department oversight. FNF ToS contain arbitration provisions for its digital platforms. FNF suffered a major ransomware attack (Nov 2023, ALPHV/BlackCat) affecting 1.3M customers.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; Berkshire Hathaway specifically owns GEICO (already documented in the Insurance tab) among many other subsidiaries — worth checking whether this parent-company relationship extends any findings.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Jacksonville", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Opt-out exists - window not verified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] FNF's Nov 2023 ransomware attack affected 1.3M customers; the breach compromised SSNs and bank account numbers\nWHAT THE TERMS SAY: FNF, the largest US title insurer, suffered a November 2023 ransomware attack (ALPHV/BlackCat) affecting 1.3 million customers and compromising Social Security numbers and bank account numbers; the incident disrupted title and closing operations, though the tracker flags full scope and notification detail as needing follow-up confirmation.\nWHY IT MATTERS: Title files already contain purchase prices, mortgage terms and identity documents; a closing disruption during a home purchase can strand the transaction, and exposed SSNs/bank numbers create direct fraud risk.\n(evidence: Data Sharing | Arbitration | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — The Nov 2023 ransomware breach is the one confirmed, specific, consumer-facing harm; arbitration terms exist but the opt-out window and full clause language are not detailed, and fees were not itemized.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach's headline facts (date, actor, victim count, data types) are stated, but the tracker itself flags scope and notification detail as needing follow-up confirmation.", "Exposure Score (0-100)": 19, "Exposure Band": "Low", "Sub: Dispute Rights /30": 14, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 14/30 (forced_arbitration+12, optout_window_unverified+2) | Data 0/30 (none) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Fidelity National Financial  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Fidelity National Financial you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass in this pass's searching, and this row should be treated as a gap rather than a clean result: FNF is the largest title insurance underwriter in the country and experienced a significant, widely reported cyber incident that disrupted title and closing operations. Title files contain purchase prices, mortgage terms and identity documents, and a closing disruption can strand a home purchase. Recommend a direct follow-up to confirm scope and notification detail before publishing.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Insurance Remainder", "_row_id": 767, "_entity_id": 1045, "_entity_slug": "fidelity-national-financial", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "General Motors", "Category": "Motor Vehicles & Parts", "Terms & Conditions URL": "gm.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "gm.com/privacy-statement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "GM collected and sold granular driving data (location, speed, braking, acceleration) through OnStar Smart Driver to LexisNexis and Verisk, which used it to set insurance rates — consumers didn't know their car was reporting to their insurer. GM discontinued Smart Driver in April 2024 after the FTC investigation. The CA AG found GM violated CCPA's opt-out requirements.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. GM's Terms of Use + OnStar Smart Driver ToS. 30-day opt-out. The FTC finalized a consent order against GM (Jan 2026) over selling driver geolocation and behavior data to LexisNexis and Verisk without consent — the order includes a 5-year ban on sharing driver data with consumer-reporting agencies. Separately, the CA AG secured a $12.75M CCPA settlement (May 2026) — the largest CCPA settlement to date, surpassing Disney's $2.75M.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Treat as part of GM's overall profile — see the myChevrolet/myGMC/myBuick/myCadillac row (Auto Apps tab) for the comprehensive findings that apply to this same corporate entity.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Detroit", "HQ State": "Michigan", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Michigan' is a non-DMV US state", "Parent / Ultimate Owner": "General Motors Company", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Michigan LARA Business Entity Search — cofs.lara.state.mi.us/SearchApi/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: General Motors Company). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SALE · FL-2] GM sold OnStar driving data to LexisNexis and Verisk, which set insurance rates without drivers' knowledge\nWHAT THE TERMS SAY: GM's OnStar Smart Driver program collected granular driving data (location, speed, braking, acceleration) and sold it to LexisNexis and Verisk, who used it to set insurance rates; consumers reportedly did not know their car was reporting to their insurer. GM discontinued Smart Driver in April 2024 after an FTC investigation, and the CA AG found GM violated CCPA's opt-out requirements.\nWHY IT MATTERS: Drivers who enrolled thinking they were using a safety or rewards feature instead found their driving behavior affecting their insurance premiums, without informed consent.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-2] The FTC and California both penalized GM over unconsented driver-data sales in 2026\nWHAT THE TERMS SAY: The FTC finalized a consent order against GM in January 2026 over selling driver geolocation and behavior data to LexisNexis and Verisk without consent, including a five-year ban on sharing driver data with consumer-reporting agencies. Separately, the California AG secured a $12.75 million CCPA settlement in May 2026 — the largest CCPA settlement to date, surpassing Disney's $2.75 million.\nWHY IT MATTERS: Two separate regulators acted over the same conduct: the FTC's consent order includes a 5-year ban on sharing driver data with consumer-reporting agencies, and the California AG's $12.75M settlement is the largest CCPA settlement to date, surpassing Disney's $2.75M.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] GM's Terms of Use impose mandatory arbitration and a class-action waiver with a 30-day opt-out\nWHAT THE TERMS SAY: GM's Terms of Use and OnStar Smart Driver ToS impose mandatory binding arbitration with a class-action waiver, with a 30-day window to opt out.\nWHY IT MATTERS: Consumers harmed by the data-sale practices above must arbitrate individually rather than join a class action, unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Specific dates, dollar figures, and named regulators are documented for both the data-sale practice and the resulting enforcement actions.", "Exposure Score (0-100)": 47, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 7, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 0/20 (none) | Record 7/20 (severity2+2, penalty+3, litigation+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "General Motors  <-  General Motors Company", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using General Motors you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, and your right to join a class action. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "See the GM/myChevrolet row in Auto Apps for the fully detailed findings. The short version belongs here too because it is one of the sharpest consumer harms in the tracker: driving behaviour data collected from connected vehicles was shared onward in ways that reached insurance risk scoring, and drivers who had enrolled in what they understood as a safety or rewards feature found it affecting their premiums. Texas sued GM in August 2024 over sale of driving data - cross-ref the Allstate/Arity finding in the Insurance tab, which is the same market seen from the buyer's side.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Auto & Dealerships", "_row_id": 768, "_entity_id": 1046, "_entity_slug": "general-motors", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Lear", "Category": "Motor Vehicles & Parts", "Terms & Conditions URL": "See Lear's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Lear's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "B2B — Lear Corporation is an automotive seat and electrical systems supplier. No consumer-facing products.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Southfield", "HQ State": "Michigan", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Michigan' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Michigan LARA Business Entity Search — cofs.lara.state.mi.us/SearchApi/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Lear is a B2B auto-parts supplier with no consumer-facing products or data collection stated; its E-Systems division manufactures connectivity infrastructure but does not hold data itself, per the tracker.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or terms exist for this B2B supplier.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Lear  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Seating and electrical distribution systems sold to automakers. Lear's E-Systems division builds the wiring and connectivity architecture underlying the connected-vehicle data flows documented in the Auto Apps tab — it manufactures the nervous system that carries the telematics, without holding any of the data itself.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Auto & Dealerships", "_row_id": 769, "_entity_id": 1047, "_entity_slug": "lear", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Autoliv", "Category": "Motor Vehicles & Parts", "Terms & Conditions URL": "See Autoliv's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Autoliv's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "B2B — Autoliv is an automotive safety systems supplier (airbags, seatbelts). No consumer-facing products.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Stockholm", "HQ State": "Sweden", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Stockholm, Sweden (non-US)", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Sweden) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Sweden. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Autoliv is a B2B safety-systems supplier with no consumer relationship; the tracker notes the framework a consumer actually encounters is a recall notice, not a privacy policy, which falls outside this tracker's ToS/privacy scope.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or data-privacy terms exist for this B2B supplier.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Autoliv  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The largest airbag and seatbelt manufacturer, selling to automakers. No consumer relationship, but its products are regulated by NHTSA and its components have featured in major recalls — the framework a consumer actually encounters here is a recall notice, not a privacy policy.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Auto & Dealerships", "_row_id": 770, "_entity_id": 1048, "_entity_slug": "autoliv", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "BorgWarner", "Category": "Motor Vehicles & Parts", "Terms & Conditions URL": "See BorgWarner's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See BorgWarner's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "B2B — BorgWarner is a powertrain and electrification supplier. No consumer-facing products.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Auburn Hills", "HQ State": "Michigan", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Michigan' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Michigan LARA Business Entity Search — cofs.lara.state.mi.us/SearchApi/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — BorgWarner is a B2B powertrain/electrification supplier with no consumer relationship or data-holding role stated.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or terms exist for this B2B supplier.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "BorgWarner  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Powertrain and drivetrain components for automakers, increasingly focused on electrification. No consumer relationship. Its EV components tie into the charging and battery data questions raised in the Auto Apps tab, but always as a supplier rather than a data holder.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Auto & Dealerships", "_row_id": 771, "_entity_id": 1049, "_entity_slug": "borgwarner", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Lithia Motors", "Category": "Automotive Retailing, Services", "Terms & Conditions URL": "See Lithia Motors's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Lithia Motors's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a company-specific data-privacy lawsuit or breach. A large multi-brand dealership group; recommend checking against the AutoNation/CarMax used-car consumer-protection enforcement pattern documented elsewhere in this tab given structural similarity.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.\n\nCDK GLOBAL CROSS-REFERENCE (verified this pass): On June 18 2024 the BlackSuit ransomware group - a rebrand of Royal, itself an offshoot of the Conti syndicate - hit CDK Global, whose dealer management software ran roughly half the North American market. About 15,000 dealer locations across the US and Canada went down; a SECOND attack struck on June 19 during recovery. CDK reportedly paid approximately $25 million (about 387 Bitcoin) on June 21 against demands that escalated from $10M to over $50M. Dealerships reverted to pen and paper for nearly two weeks; systems were substantially restored by July 4. Lithia Motors, Group 1 Automotive, Penske Automotive, Sonic Automotive, AutoNation and Asbury Automotive all disclosed the disruption to the SEC in 8-K filings. Estimated dealer losses ranged from roughly $605 million to over $1 billion, with J.D. Power/GlobalData recording a 7.2% year-over-year decline in June 2024 new-vehicle sales. BlackSuit subsequently used the stolen PII to run social-engineering campaigns against CDK's own customers, and CDK warned that attackers were phoning dealers posing as CDK support. TRACKER NOTE: treat this as ONE connected event across every dealership row, not six independent incidents - the pattern matches SITA (Global Airlines), AMCA (Pharma & Health Services), MOVEit and Salesloft/Salesforce (F500 Tech).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Medford", "HQ State": "Oregon", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Oregon' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Non-US entity (Oregon) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Oregon. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Lithia disclosed the June 2024 CDK ransomware outage; dealerships ran on pen and paper for nearly two weeks\nWHAT THE TERMS SAY: Lithia disclosed to the SEC that the June 2024 CDK Global ransomware attack (BlackSuit group) disrupted its operations; CDK's software ran roughly half the North American dealer-management market, taking about 15,000 dealer locations offline and forcing pen-and-paper operation for nearly two weeks. Dealerships hold complete credit applications, income verification and driver's license data, and BlackSuit used stolen PII to run social-engineering attacks against CDK's customers.\nWHY IT MATTERS: A Lithia customer's exposure depended on a vendor Lithia chose, not anything the customer did; BlackSuit subsequently used the stolen PII to run social-engineering campaigns against CDK's own customers, and CDK warned that attackers were phoning dealers posing as CDK support.\n(evidence: Notes | SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the CDK Global vendor breach is confirmed and company-specific (via Lithia's own SEC disclosure); data-sharing and arbitration fields are both explicitly unconfirmed for Lithia specifically.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The CDK breach and its scale are well documented, but Lithia-specific arbitration and data-sharing terms are unconfirmed.", "Exposure Score (0-100)": 11, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Lithia Motors  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Lithia Motors takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Lithia disclosed the CDK Global outage to the SEC in June 2024 - one of six large dealership groups that did. The finding is concentration: CDK's dealer management software ran roughly half the North American market, so a single ransomware attack took about 15,000 dealer locations offline simultaneously and forced pen-and-paper operation for nearly two weeks. Dealerships hold complete credit applications, income verification and driver's licence data, and BlackSuit subsequently used stolen PII to run social-engineering attacks against CDK's own customers. Lithia is also the largest US dealership group by revenue and owns Driveway and Green Car, so its customer data spans traditional and online sales.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Auto & Dealerships", "_row_id": 772, "_entity_id": 1050, "_entity_slug": "lithia-motors", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Penske Automotive", "Category": "Automotive Retailing, Services", "Terms & Conditions URL": "See Penske Automotive's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Penske Automotive's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Penske processes vehicle purchase financial data (credit applications, income, SSNs), trade-in valuations, service records, and connected-vehicle telematics. The CDK Global breach exposed dealership-management-system data across the industry — estimated $605M-$1B+ in total losses.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Penske's vehicle purchase/lease agreements, AAA rules. The arbitration clause covers vehicle defect, financing, and service disputes. The June 2024 CDK Global ransomware attack (BlackSuit group) shut down ~15,000 dealerships including Penske locations — Penske filed an 8-K disclosing the impact.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.\n\nCDK GLOBAL CROSS-REFERENCE (verified this pass): On June 18 2024 the BlackSuit ransomware group - a rebrand of Royal, itself an offshoot of the Conti syndicate - hit CDK Global, whose dealer management software ran roughly half the North American market. About 15,000 dealer locations across the US and Canada went down; a SECOND attack struck on June 19 during recovery. CDK reportedly paid approximately $25 million (about 387 Bitcoin) on June 21 against demands that escalated from $10M to over $50M. Dealerships reverted to pen and paper for nearly two weeks; systems were substantially restored by July 4. Lithia Motors, Group 1 Automotive, Penske Automotive, Sonic Automotive, AutoNation and Asbury Automotive all disclosed the disruption to the SEC in 8-K filings. Estimated dealer losses ranged from roughly $605 million to over $1 billion, with J.D. Power/GlobalData recording a 7.2% year-over-year decline in June 2024 new-vehicle sales. BlackSuit subsequently used the stolen PII to run social-engineering campaigns against CDK's own customers, and CDK warned that attackers were phoning dealers posing as CDK support. TRACKER NOTE: treat this as ONE connected event across every dealership row, not six independent incidents - the pattern matches SITA (Global Airlines), AMCA (Pharma & Health Services), MOVEit and Salesloft/Salesforce (F500 Tech).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Bloomfield Hills", "HQ State": "Michigan", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.techtarget.com/whatis/feature/The-CDK-Global-outage-Explaining-how-it-happened", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Michigan' is a non-DMV US state", "Parent / Ultimate Owner": "Penske Automotive Group, Inc. (Roger Penske, chairman)", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Michigan LARA Business Entity Search — cofs.lara.state.mi.us/SearchApi/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Penske Automotive Group, Inc. (Roger Penske, chairman)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] The CDK Global ransomware attack shut down Penske dealerships and disrupted dealer-management systems\nWHAT THE TERMS SAY: The June 2024 CDK Global ransomware attack (BlackSuit group) shut down roughly 15,000 dealerships including Penske locations; Penske filed an 8-K disclosing the impact. Total industry losses are estimated at $605M-$1B+.\nWHY IT MATTERS: Penske customers' data sat inside a third-party system Penske chose, and the outage disrupted service for nearly two weeks industry-wide.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Penske's purchase/lease agreements impose mandatory arbitration over defect, financing and service disputes\nWHAT THE TERMS SAY: Penske's vehicle purchase/lease agreements require mandatory binding arbitration with a class-action waiver under AAA rules, covering vehicle defect, financing, and service disputes.\nWHY IT MATTERS: A buyer with a defective vehicle or financing dispute must arbitrate individually rather than sue or join a class action.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] Penske holds SSNs, income data and connected-vehicle telematics from its purchase and service process\nWHAT THE TERMS SAY: Penske processes vehicle purchase financial data including credit applications, income, and Social Security numbers, plus trade-in valuations, service records, and connected-vehicle telematics.\nWHY IT MATTERS: A car buyer's full financial identity file and driving telematics sit with the dealership group, extending well beyond the vehicle transaction itself.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Arbitration terms, data types collected, and the CDK breach are all specifically documented with dates and figures.", "Exposure Score (0-100)": 51, "Exposure Band": "High", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 7/30 (precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Penske Automotive  <-  Penske Automotive Group, Inc. (Roger Penske, chairman)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Penske Automotive you gave up your physical movements, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "One of the six large dealership groups that disclosed the June 2024 CDK Global ransomware disruption to the SEC. The consumer-facing point is that a car buyer's exposure had nothing to do with which dealership group they chose - CDK controlled about half the dealer management software market, and the attack reached 15,000 locations at once. Estimated dealer losses across the industry ran from roughly $605 million to over $1 billion, with new-vehicle sales down 7.2% year over year that June.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Auto & Dealerships", "_row_id": 773, "_entity_id": 1052, "_entity_slug": "penske-automotive", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "AutoNation", "Category": "Automotive Retailing, Services", "Terms & Conditions URL": "autonation.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "autonation.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MAJOR CALIFORNIA CONSUMER PROTECTION SETTLEMENT (2025): a coalition of California district attorneys (San Francisco, Santa Clara, Sonoma, Los Angeles, Ventura, Riverside) sued AutoNation-affiliated dealerships over used-car sales practices, resulting in a settlement that included a COURT INJUNCTION specifically designed to protect consumers going forward — this case directly set the precedent that the same DA coalition later used against CarMax (see that row) for structurally similar allegations.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual vehicle-purchase agreements.", "Fees / Billing Flags": "Not itemized this pass beyond the settlement above.", "Notes": "This is the FIRST of two nearly identical California DA settlements against major used-car retailers (AutoNation in 2025, then CarMax in 2026) — worth treating as a connected pattern of enforcement against similar used-car sales practices across the industry's largest players.\n\nCDK GLOBAL CROSS-REFERENCE (verified this pass): On June 18 2024 the BlackSuit ransomware group - a rebrand of Royal, itself an offshoot of the Conti syndicate - hit CDK Global, whose dealer management software ran roughly half the North American market. About 15,000 dealer locations across the US and Canada went down; a SECOND attack struck on June 19 during recovery. CDK reportedly paid approximately $25 million (about 387 Bitcoin) on June 21 against demands that escalated from $10M to over $50M. Dealerships reverted to pen and paper for nearly two weeks; systems were substantially restored by July 4. Lithia Motors, Group 1 Automotive, Penske Automotive, Sonic Automotive, AutoNation and Asbury Automotive all disclosed the disruption to the SEC in 8-K filings. Estimated dealer losses ranged from roughly $605 million to over $1 billion, with J.D. Power/GlobalData recording a 7.2% year-over-year decline in June 2024 new-vehicle sales. BlackSuit subsequently used the stolen PII to run social-engineering campaigns against CDK's own customers, and CDK warned that attackers were phoning dealers posing as CDK support. TRACKER NOTE: treat this as ONE connected event across every dealership row, not six independent incidents - the pattern matches SITA (Global Airlines), AMCA (Pharma & Health Services), MOVEit and Salesloft/Salesforce (F500 Tech).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Fort Lauderdale", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] California prosecutors secured a court injunction against AutoNation dealerships over used-car sales practices\nWHAT THE TERMS SAY: A coalition of California district attorneys (San Francisco, Santa Clara, Sonoma, Los Angeles, Ventura, Riverside) sued AutoNation-affiliated dealerships over used-car sales practices in 2025, resulting in a settlement with a court injunction designed to protect consumers going forward; this case set the precedent the same DA coalition later used against CarMax for structurally similar allegations.\nWHY IT MATTERS: The injunction constrains AutoNation's future sales conduct, though the specific practices alleged aren't itemized beyond 'used-car sales practices' in this row.\n(evidence: Data Sharing | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] AutoNation also disclosed operational disruption from the 2024 CDK Global ransomware attack\nWHAT THE TERMS SAY: AutoNation notified regulators that the June 2024 CDK Global ransomware attack adversely affected its operations, part of an incident that took roughly 15,000 dealer locations offline industry-wide.\nWHY IT MATTERS: AutoNation customers faced the same vendor-driven outage and PII exposure risk documented across the dealership sector, unrelated to their choice of dealer.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration terms are not independently confirmed (expected only); the two substantive, dated findings are the 2025 California consumer-protection settlement and the CDK Global disruption.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The California settlement and CDK disruption are documented, but arbitration terms remain unconfirmed/expected only.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity3+8, breach+3, penalty+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "AutoNation  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, AutoNation takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "AutoNation notified regulators that the CDK attack adversely affected its operations, and separately reached a major California consumer protection settlement in 2025 with a coalition of prosecutors. That combination is the row's value: one finding is an external supply-chain failure and the other is the company's own sales practices, and for a car buyer the second is the more likely harm. Dealership consumer protection actions typically concern add-on products, financing disclosure and advertised pricing - the parts of a car purchase that happen in the finance office.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Auto & Dealerships", "_row_id": 774, "_entity_id": 1053, "_entity_slug": "autonation", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Asbury Automotive", "Category": "Automotive Retailing, Services", "Terms & Conditions URL": "See Asbury Automotive's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Asbury Automotive's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a company-specific data-privacy lawsuit or breach. A large multi-brand dealership group; similarly recommend checking against the AutoNation/CarMax pattern.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.\n\nCDK GLOBAL CROSS-REFERENCE (verified this pass): On June 18 2024 the BlackSuit ransomware group - a rebrand of Royal, itself an offshoot of the Conti syndicate - hit CDK Global, whose dealer management software ran roughly half the North American market. About 15,000 dealer locations across the US and Canada went down; a SECOND attack struck on June 19 during recovery. CDK reportedly paid approximately $25 million (about 387 Bitcoin) on June 21 against demands that escalated from $10M to over $50M. Dealerships reverted to pen and paper for nearly two weeks; systems were substantially restored by July 4. Lithia Motors, Group 1 Automotive, Penske Automotive, Sonic Automotive, AutoNation and Asbury Automotive all disclosed the disruption to the SEC in 8-K filings. Estimated dealer losses ranged from roughly $605 million to over $1 billion, with J.D. Power/GlobalData recording a 7.2% year-over-year decline in June 2024 new-vehicle sales. BlackSuit subsequently used the stolen PII to run social-engineering campaigns against CDK's own customers, and CDK warned that attackers were phoning dealers posing as CDK support. TRACKER NOTE: treat this as ONE connected event across every dealership row, not six independent incidents - the pattern matches SITA (Global Airlines), AMCA (Pharma & Health Services), MOVEit and Salesloft/Salesforce (F500 Tech).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Duluth", "HQ State": "Georgia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Georgia' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Georgia SOS eCorp — ecorp.sos.ga.gov/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Asbury flagged CDK Global-related disruption affecting its dealership operations\nWHAT THE TERMS SAY: Asbury is one of the dealership groups that disclosed disruption from the June 2024 CDK Global ransomware attack, which took roughly 15,000 dealer locations offline industry-wide.\nWHY IT MATTERS: Customer credit and identity data held in CDK's system was exposed to the same vendor-driven risk documented across the dealership sector.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Asbury's Clicklane platform extends data collection into online browsing and pre-qualification behavior\nWHAT THE TERMS SAY: Asbury operates Clicklane, an online sales platform that the tracker says extends the data relationship beyond the showroom into browsing and pre-qualification behavior.\nWHY IT MATTERS: Customers researching a purchase online generate a data trail before ever setting foot in a dealership, even if they don't ultimately buy through Clicklane.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and standalone data-sharing facts are both explicitly unconfirmed for Asbury; the CDK breach and the Clicklane online data footprint are the two stated findings.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The CDK breach and Clicklane's online data footprint are documented, but arbitration and standalone data-sharing terms are unconfirmed.", "Exposure Score (0-100)": 8, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Asbury Automotive  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Asbury Automotive takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "One of the dealership groups that flagged CDK-related disruption. Asbury also operates Clicklane, an online sales platform, which extends the data relationship beyond the showroom into browsing and pre-qualification behaviour. The dealership finance office remains the highest-friction consumer environment in this tracker - a buyer negotiates for hours, then signs a stack of documents including credit authorisations and add-on products under time pressure, having already committed emotionally to the car.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Auto & Dealerships", "_row_id": 775, "_entity_id": 1054, "_entity_slug": "asbury-automotive", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sonic Automotive", "Category": "Automotive Retailing, Services", "Terms & Conditions URL": "See Sonic Automotive's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Sonic Automotive's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a company-specific data-privacy lawsuit or breach. A large multi-brand dealership group; similarly recommend checking against the AutoNation/CarMax pattern.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.\n\nCDK GLOBAL CROSS-REFERENCE (verified this pass): On June 18 2024 the BlackSuit ransomware group - a rebrand of Royal, itself an offshoot of the Conti syndicate - hit CDK Global, whose dealer management software ran roughly half the North American market. About 15,000 dealer locations across the US and Canada went down; a SECOND attack struck on June 19 during recovery. CDK reportedly paid approximately $25 million (about 387 Bitcoin) on June 21 against demands that escalated from $10M to over $50M. Dealerships reverted to pen and paper for nearly two weeks; systems were substantially restored by July 4. Lithia Motors, Group 1 Automotive, Penske Automotive, Sonic Automotive, AutoNation and Asbury Automotive all disclosed the disruption to the SEC in 8-K filings. Estimated dealer losses ranged from roughly $605 million to over $1 billion, with J.D. Power/GlobalData recording a 7.2% year-over-year decline in June 2024 new-vehicle sales. BlackSuit subsequently used the stolen PII to run social-engineering campaigns against CDK's own customers, and CDK warned that attackers were phoning dealers posing as CDK support. TRACKER NOTE: treat this as ONE connected event across every dealership row, not six independent incidents - the pattern matches SITA (Global Airlines), AMCA (Pharma & Health Services), MOVEit and Salesloft/Salesforce (F500 Tech).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Charlotte", "HQ State": "North Carolina", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'North Carolina' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NC SOS Business Registration Search — sosnc.gov/online_services/search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Sonic disclosed CDK Global-related disruption alongside five other major dealership groups\nWHAT THE TERMS SAY: Sonic disclosed CDK-related disruption to the SEC in June 2024, alongside Lithia, Group 1, Penske, AutoNation and Asbury, as part of the connected CDK Global ransomware event that took roughly 15,000 dealer locations offline.\nWHY IT MATTERS: Sonic customers faced the same vendor-driven outage and PII-exposure risk documented across the dealership sector.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] Sonic operates EchoPark as a separate brand, so a customer may deal with the same parent under another name\nWHAT THE TERMS SAY: Sonic Automotive operates EchoPark as a separate used-vehicle brand, so a customer may deal with the same parent company under a different name, per the tracker.\nWHY IT MATTERS: A customer comparison-shopping between what look like competing brands may not realize both are the same corporate entity, undermining the comparison.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and standalone data-sharing facts are unconfirmed for Sonic; the CDK breach and the EchoPark brand-structure point are the two stated findings.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The CDK breach and EchoPark's brand structure are documented, but arbitration and standalone data-sharing terms are unconfirmed.", "Exposure Score (0-100)": 11, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Sonic Automotive  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Sonic Automotive takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Disclosed CDK-related disruption to the SEC in June 2024 alongside Lithia, Group 1, Penske, AutoNation and Asbury. Sonic also operates EchoPark as a separate used-vehicle brand, so a customer may deal with the same parent under a different name. Recorded as part of the single connected CDK event rather than an independent incident, per this tracker's cross-reference standard.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Auto & Dealerships", "_row_id": 776, "_entity_id": 1055, "_entity_slug": "sonic-automotive", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Group 1 Automotive", "Category": "Automotive Retailing, Services", "Terms & Conditions URL": "group1auto.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "group1auto.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the general used-car-retailer consumer-protection pattern documented for AutoNation and CarMax elsewhere in this tab, given the structural similarity of large multi-brand dealership groups.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.\n\nCDK GLOBAL CROSS-REFERENCE (verified this pass): On June 18 2024 the BlackSuit ransomware group - a rebrand of Royal, itself an offshoot of the Conti syndicate - hit CDK Global, whose dealer management software ran roughly half the North American market. About 15,000 dealer locations across the US and Canada went down; a SECOND attack struck on June 19 during recovery. CDK reportedly paid approximately $25 million (about 387 Bitcoin) on June 21 against demands that escalated from $10M to over $50M. Dealerships reverted to pen and paper for nearly two weeks; systems were substantially restored by July 4. Lithia Motors, Group 1 Automotive, Penske Automotive, Sonic Automotive, AutoNation and Asbury Automotive all disclosed the disruption to the SEC in 8-K filings. Estimated dealer losses ranged from roughly $605 million to over $1 billion, with J.D. Power/GlobalData recording a 7.2% year-over-year decline in June 2024 new-vehicle sales. BlackSuit subsequently used the stolen PII to run social-engineering campaigns against CDK's own customers, and CDK warned that attackers were phoning dealers posing as CDK support. TRACKER NOTE: treat this as ONE connected event across every dealership row, not six independent incidents - the pattern matches SITA (Global Airlines), AMCA (Pharma & Health Services), MOVEit and Salesloft/Salesforce (F500 Tech).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Group 1 activated incident response and disclosed CDK Global-related disruption\nWHAT THE TERMS SAY: Group 1 Automotive activated cyber incident response procedures and disclosed CDK-related disruption from the June 2024 CDK Global ransomware attack, part of the connected event across dealership rows.\nWHY IT MATTERS: Group 1 customers faced the same vendor-driven outage and PII-exposure risk documented across the dealership sector.\n(evidence: Notes | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-3] Group 1's US customers lack the enforceable privacy rights their UK counterparts get under GDPR\nWHAT THE TERMS SAY: Group 1 Automotive operates in both the US and UK; the tracker states its customer data sits under two materially different privacy regimes — GDPR in the UK and a state-by-state patchwork in the US — with UK customers holding enforceable rights their American counterparts do not.\nWHY IT MATTERS: An American Group 1 customer has structurally weaker privacy recourse than a UK customer of the same company, simply due to geography.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and standalone data-sharing facts are unconfirmed for Group 1; the CDK breach and the US/UK jurisdictional privacy-rights gap are the two stated findings.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The CDK breach and the US/UK jurisdictional gap are documented, but arbitration and standalone data-sharing terms are unconfirmed.", "Exposure Score (0-100)": 11, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Group 1 Automotive  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Group 1 Automotive takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Activated cyber incident response procedures and disclosed CDK-related disruption to the SEC. Group 1 operates in both the US and UK, which means its customer data sits under two materially different privacy regimes - GDPR on one side and a state-by-state patchwork on the other - with UK customers holding enforceable rights their American counterparts do not. Same connected CDK event.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Auto & Dealerships", "_row_id": 777, "_entity_id": 1056, "_entity_slug": "group-1-automotive", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Carvana", "Category": "Automotive Retailing, Services", "Terms & Conditions URL": "carvana.com/legal/tos", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "carvana.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Carvana processes financial data (credit applications, income verification, trade-in valuations), vehicle history, and delivery logistics. As a fully digital platform, Carvana collects more granular purchase-journey data than traditional dealerships.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Carvana's Terms of Use, AAA rules. 30-day opt-out. Carvana's fully-digital car-buying model means the ToS governs the ENTIRE purchase relationship — unlike traditional dealerships where in-person negotiation creates a separate contractual layer.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The VEHICLE TITLING/REGISTRATION disputes are a distinctive, structural concern for an online-only car retailer specifically — unlike a typical data-privacy issue, a titling problem can leave a customer legally unable to register or insure a car they've already paid for, a genuinely serious practical harm beyond data exposure.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Tempe", "HQ State": "Arizona", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Arizona' is a non-DMV US state", "Parent / Ultimate Owner": "Carvana Co.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Arizona Corporation Commission eCorp — ecorp.azcc.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Carvana Co.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Carvana's online-only model creates a distinctive titling/registration risk not present at traditional dealers\nWHAT THE TERMS SAY: The tracker flags vehicle titling and registration disputes as a distinctive, structural concern for Carvana's online-only model — a titling problem can leave a customer legally unable to register or insure a car they've already paid for.\nWHY IT MATTERS: Unlike a typical data-privacy issue, this is a direct practical harm: a paid-for vehicle a customer cannot legally drive or insure.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Carvana's Terms of Use impose mandatory arbitration over the entire digital purchase relationship\nWHAT THE TERMS SAY: Carvana's Terms of Use require mandatory binding arbitration with a class-action waiver under AAA rules, with a 30-day opt-out; because Carvana's model is fully digital, the ToS governs the entire purchase relationship rather than sharing that role with an in-person negotiated contract.\nWHY IT MATTERS: Every dispute over Carvana's online purchase process — not just a subset — funnels into individual arbitration.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[PENDING_LITIGATION · FL-2] A 2026 lawsuit alleges Carvana installed unauthorized tracking across its entire purchase site\nWHAT THE TERMS SAY: A 2026 lawsuit alleges Carvana installed unauthorized tracking technology on its site; because the entire purchase happens on the website, browsing behavior, financing pre-qualification, and trade-in valuation would all occur where the alleged tracking sits. The tracker labels this an allegation, not a confirmed finding.\nWHY IT MATTERS: If proven, the tracking would capture financially sensitive purchase-journey behavior for customers who complete their entire transaction online.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and the titling risk are clearly stated, but the tracking-technology claim is an unconfirmed allegation.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Carvana  <-  Carvana Co.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Carvana you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2026 tracking-technology lawsuit alleges Carvana installed unauthorised tracking on its site, and the online-only model makes that allegation more consequential than it would be for a traditional dealer: the entire purchase happens on the website, so browsing behaviour, financing pre-qualification and trade-in valuation all occur where the tracking sits. Carvana also holds full credit applications for customers who never entered a building. Allegations, not findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Auto & Dealerships", "_row_id": 778, "_entity_id": 1058, "_entity_slug": "carvana", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Avis Budget", "Category": "Automotive Retailing, Services", "Terms & Conditions URL": "See Avis Budget's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Avis Budget's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Avis Budget processes rental transaction data, GPS tracking data from connected vehicles, and Zipcar membership/location data. Connected-car data from rental fleet vehicles creates a detailed driving-behavior profile for each renter.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Avis/Budget Rental Terms, AAA rules. 30-day opt-out. Covers Avis, Budget, and Zipcar (acquired 2013). A single arbitration clause governs three brands that appear to be competitors.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Parsippany", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Parsippany, New Jersey (non-US)", "Parent / Ultimate Owner": "Avis Budget Group, Inc.", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NJ Business Records Service — businessrecords.nj.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Avis Budget Group, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Avis disclosed a 2024 breach exposing customer information including driver's license numbers\nWHAT THE TERMS SAY: Avis disclosed a 2024 breach affecting customer information including license numbers, filed with multiple state attorneys general.\nWHY IT MATTERS: License numbers combined with rental records (name, vehicle, location, dates) create a detailed identity and movement profile exposed to unauthorized access.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[LOCATION_TRACKING · FL-2] Avis, Budget and Zipcar's connected fleets build detailed driving-behavior profiles under one shared policy\nWHAT THE TERMS SAY: Avis Budget processes GPS tracking data from connected rental vehicles and Zipcar membership/location data; the tracker states connected-car data from rental fleets creates a detailed driving-behavior profile for each renter, and rental records tie a named person to a specific vehicle, place and dates with an attached driver's-license scan.\nWHY IT MATTERS: A renter's precise movements and driving behavior are captured and tied to their identity, under brands (Avis, Budget, Zipcar) many customers don't realize are the same company.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] One mandatory-arbitration clause covers Avis, Budget and Zipcar despite their appearing to be rival brands\nWHAT THE TERMS SAY: Avis Budget imposes mandatory binding arbitration with a class-action waiver under AAA rules across Avis, Budget, and Zipcar (acquired 2013), with a 30-day opt-out.\nWHY IT MATTERS: A customer who avoids one brand for another, believing them to be competitors, remains bound by the identical arbitration terms and forfeits class-action rights across all three.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Breach details, telematics data types, and arbitration terms (AAA rules, 30-day opt-out) are all specifically documented.", "Exposure Score (0-100)": 39, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Avis Budget  <-  Avis Budget Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Avis Budget you gave up your physical movements, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Avis and Budget are one company, so brand choice is not data choice. A rental record ties a named person to a specific vehicle in a specific place on specific dates, with a driver's licence scan attached — and connected fleets add telematics on top. Avis disclosed a 2024 breach affecting customer information including licence numbers, filed with multiple state attorneys general, which is the route by which most rental-car incidents become public.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Auto & Dealerships", "_row_id": 779, "_entity_id": 1059, "_entity_slug": "avis-budget", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "D.R. Horton", "Category": "Homebuilders", "Terms & Conditions URL": "drhorton.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "drhorton.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "D.R. Horton collects mortgage-application data, income verification, and home-customization preferences through its sales process. As the largest volume homebuilder, D.R. Horton processes more new-home-purchase financial data than any competitor.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration in home-purchase contracts. D.R. Horton is the largest US homebuilder by volume. The arbitration clause in the purchase agreement covers CONSTRUCTION DEFECTS — a homebuyer who discovers foundation cracks, plumbing failures, or structural issues must arbitrate rather than sue or join a class action. No opt-out in the purchase agreement.", "Fees / Billing Flags": "MAJOR ACTIVE CLASS ACTION (filed Dec 3, 2025, Nevada federal court): alleges D.R. Horton and its captive mortgage lender, DHI MORTGAGE, ran a 'bait-and-switch' scheme deliberately EXCLUDING the full cost of property taxes from monthly mortgage-payment quotes given to prospective buyers — making homes appear artificially affordable, with buyers only discovering the TRUE monthly cost (hundreds of dollars higher) after closing, when an escrow re-analysis revealed the shortfall. Numerous consumer comments describe real payment jumps of $600-$1,600/month. SEPARATELY, D.R. Horton and other major builders face a WAVE of construction-defect complaints (cracking foundations, structural issues) often surfacing only after standard 1-year cosmetic/2-year mechanical/10-year structural warranty periods have partially or fully expired.", "Notes": "Given that a HOME PURCHASE is likely the single largest financial transaction most people will ever make, the property-tax bait-and-switch allegation — combined with a near-total inability to win meaningful compensation in the mandatory arbitration that follows — makes D.R. Horton one of the most consequential consumer-protection findings in this ENTIRE 600+ company tracker, despite housing not being the primary focus of most other entries.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Arlington", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "D.R. Horton, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: D.R. Horton, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] D.R. Horton's captive lender allegedly hid property-tax costs from mortgage quotes until after closing\nWHAT THE TERMS SAY: A December 2025 Nevada federal class action alleges D.R. Horton and its captive lender DHI Mortgage ran a bait-and-switch scheme, deliberately excluding the full cost of property taxes from monthly mortgage-payment quotes given to prospective buyers; buyers only discovered the true monthly cost after closing, when an escrow re-analysis revealed the shortfall, with reported jumps of $600-$1,600/month.\nWHY IT MATTERS: A homebuyer can be steered into believing a home is affordable, then find hundreds of extra dollars due monthly only after they're already locked into the largest purchase of their life.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] D.R. Horton's purchase contracts force construction-defect claims into arbitration with no opt-out\nWHAT THE TERMS SAY: D.R. Horton's mandatory arbitration clause in home-purchase contracts covers construction defects — a buyer who discovers foundation cracks, plumbing failures, or structural issues must arbitrate rather than sue or join a class action, and the tracker states there is no opt-out in the purchase agreement.\nWHY IT MATTERS: A buyer with a serious structural defect has no ability to sue or join other affected buyers, and cannot opt out of arbitration at all.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Builders frequently run affiliated mortgage, title and insurance arms; D.R. Horton's lender is DHI Mortgage\nWHAT THE TERMS SAY: The tracker states builders frequently operate affiliated mortgage, title and insurance businesses, so a buyer steered to the in-house lender has their financial file -- mortgage pre-approval, income verification, credit information and their future address -- handled inside one corporate group, a steering incentive the Real Estate Settlement Procedures Act regulates. D.R. Horton's own captive mortgage lender is DHI Mortgage.\nWHY IT MATTERS: A buyer's complete financial dossier can move entirely within D.R. Horton's corporate family rather than through independently chosen, competing providers.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=N; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=Y; b2b=?", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The class action's filing date, court, allegations, and dollar figures are specifically documented, along with a clear no-opt-out arbitration term.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 10/20 (severity3+8, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "D.R. Horton  <-  D.R. Horton, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using D.R. Horton you gave up your data shared corporate-wide, your right to sue, and your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing itemised separately this pass. Homebuilder data is more sensitive than the sector suggests: a purchase file contains mortgage pre-approval, income verification, credit information and the buyer's future address before they live there. Builders also frequently operate affiliated mortgage, title and insurance businesses, so a buyer steered to the in-house lender has their financial file handled inside one corporate group - a structure the Real Estate Settlement Procedures Act regulates precisely because the steering incentive is strong.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Homebuilders & RealEst", "_row_id": 780, "_entity_id": 1061, "_entity_slug": "d-r-horton", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Lennar", "Category": "Homebuilders", "Terms & Conditions URL": "lennar.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "lennar.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED 2023 BREACH: Lennar detected unauthorized computer-system activity on July 20, 2023, exposing personal information of over 7,400 customers specifically within its home-building business systems (Lennar's broader operations, including its Eagle/Lennar Mortgage arm, were reportedly NOT affected by this specific incident).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration in home-purchase contracts. Lennar is the 2nd-largest US homebuilder. Same construction-defect arbitration model as D.R. Horton. Lennar's 'Everything's Included' model means the purchase agreement covers more fixtures/appliances than a traditional build — expanding the scope of what the arbitration clause covers.", "Fees / Billing Flags": "SEPARATE, SERIOUS ALLEGATIONS: (1) A 2019 whistleblower lawsuit against Lennar's mortgage arm (Eagle Home Mortgage) alleged FRAUDULENT LENDING PRACTICES — falsifying borrower documents to boost approval odds, misleading a reverse-mortgage borrower, and improperly collecting fees; a related entity (Universal Mortgage) paid $13.2 MILLION to settle. (2) SEPARATE, MORE RECENT (2026) reporting describes a Native American tribe alleging Lennar misled tribal officials for months about resolving construction/development issues while allegedly concealing the full extent of problems. (3) Lennar shares the SAME industry-wide construction-defect and property-tax-disclosure concerns documented for D.R. Horton in this same tab.", "Notes": "See D.R. Horton row for the shared forced-arbitration/0.7%-consumer-win-rate finding and the general construction-defect pattern across major homebuilders; the Eagle Home Mortgage fraudulent-lending settlement is a distinctly serious, company-specific finding worth flagging on its own.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Miami", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "Lennar Corporation", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Lennar Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Lennar detected unauthorized system access in July 2023, exposing personal information of 7,400+ customers\nWHAT THE TERMS SAY: Lennar detected unauthorized computer-system activity on July 20, 2023, exposing personal information of over 7,400 customers within its home-building business systems; its Eagle/Lennar Mortgage arm was reportedly not affected by this specific incident.\nWHY IT MATTERS: Homebuyers' personal information was exposed through Lennar's own systems, separate from any third-party vendor.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-1] A whistleblower suit alleged Lennar's Eagle Home Mortgage falsified documents and misled a borrower\nWHAT THE TERMS SAY: A 2019 whistleblower lawsuit against Lennar's mortgage arm, Eagle Home Mortgage, alleged fraudulent lending practices — falsifying borrower documents to boost approval odds, misleading a reverse-mortgage borrower, and improperly collecting fees; a related entity, Universal Mortgage, paid $13.2 million to settle.\nWHY IT MATTERS: Borrowers relying on Lennar's in-house lender for financing information faced alleged document falsification and improper fees, with a related entity paying a substantial settlement.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[PENDING_LITIGATION · FL-1] A tribe alleges Lennar concealed the extent of construction/development problems for months\nWHAT THE TERMS SAY: 2026 reporting describes a Native American tribe alleging Lennar misled tribal officials for months about resolving construction/development issues while allegedly concealing the full extent of the problems.\nWHY IT MATTERS: If accurate, this suggests a pattern of downplaying known defects to the people affected while issues persisted unresolved.\n(evidence: Fees; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2023 breach and mortgage-fraud settlement are specifically documented, but the tribal allegation and current litigation status remain unconfirmed.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 7, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 7/20 (severity2+2, breach+3, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Lennar  <-  Lennar Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Lennar you gave up your data shared corporate-wide and your right to sue. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Lennar detected unauthorised access in 2023. The affiliated-services note from the D.R. Horton row applies here at scale - Lennar operates mortgage, title and insurance arms, so a homebuyer's complete financial dossier moves through several related entities in a single transaction, each a separate data holder, none individually chosen by the buyer.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Homebuilders & RealEst", "_row_id": 781, "_entity_id": 1063, "_entity_slug": "lennar", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Pulte", "Category": "Homebuilders", "Terms & Conditions URL": "pulte.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "pulte.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not itemized separately from the findings below.", "Arbitration / Class Action Waiver": "Same general forced-arbitration structure documented for D.R. Horton and Lennar (this same tab) applies to Pulte's standard purchase contracts.", "Fees / Billing Flags": "SEPARATE, DOCUMENTED CONSUMER FRAUD ALLEGATIONS: Pulte Mortgage (Pulte's captive lending arm) has faced multiple lawsuits over the years, including a consumer fraud complaint alleging it PROMISED a specific interest rate during mortgage pre-qualification but then offered a MUCH HIGHER rate at closing — causing some buyers to forfeit their deposits when they could no longer afford the home at the new rate. SEPARATELY, Pulte is named among the major homebuilders (with D.R. Horton and Lennar) facing a documented wave of CONSTRUCTION-DEFECT complaints — one reported case (Wall Street Journal, cited in Moneywise reporting) describes a couple whose new Pulte home developed spreading ceiling cracks and a sinking foundation, leaving them in an ongoing legal dispute with the builder.", "Notes": "See the D.R. Horton row (this same tab) for the shared forced-arbitration/construction-defect pattern across major homebuilders — the 'promised rate vs. actual closing rate' allegation here is a distinctive, Pulte-specific mortgage-practices concern worth flagging separately.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] Pulte Mortgage allegedly raised its rate at closing after pre-qualification, costing buyers their deposits\nWHAT THE TERMS SAY: A consumer fraud complaint alleges Pulte Mortgage promised a specific interest rate during pre-qualification but then offered a much higher rate at closing, causing some buyers to forfeit their deposits when they could no longer afford the home at the new rate.\nWHY IT MATTERS: Buyers who budgeted around the quoted rate can lose their deposit entirely when the rate changes at the point of closing.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Pulte's purchase agreements funnel construction-defect disputes into arbitration, as with other major builders\nWHAT THE TERMS SAY: Pulte's standard purchase contracts follow the same general forced-arbitration structure documented for D.R. Horton and Lennar, and Pulte has faced significant construction-defect litigation historically — including a WSJ-reported case of a couple whose new Pulte home developed spreading ceiling cracks and a sinking foundation.\nWHY IT MATTERS: A buyer with a serious structural defect faces the same arbitration-limited recourse documented across major homebuilders.\n(evidence: Arbitration | Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Two distinct, Pulte-specific findings are documented — the promised-rate bait-and-switch and the construction-defect/arbitration pattern; the affiliated-lender structure point is presented as the same pattern already documented for D.R. Horton and Lennar, not a distinct Pulte fact.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=Y; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The rate bait-and-switch complaint and construction-defect pattern are documented, but arbitration opt-out terms and current litigation status are not detailed.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 10/20 (severity3+8, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Pulte  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Pulte you gave up your data shared corporate-wide, your right to sue, and your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Homebuilder operating Pulte Mortgage as an affiliated lender, with the same one-group financial dossier structure as D.R. Horton and Lennar. Pulte also faced significant construction defect litigation historically — a product-quality matter, but the one that actually reaches homeowners, and one where the arbitration clauses common in new-home purchase agreements determine whether a buyer can sue at all.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Homebuilders & RealEst", "_row_id": 782, "_entity_id": 1064, "_entity_slug": "pulte", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "NVR", "Category": "Homebuilders", "Terms & Conditions URL": "See NVR's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See NVR's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "NVR processes home-purchase financial data for Ryan Homes and NVHomes buyers in the DMV corridor. HQ: Reston, VA (DMV).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration in home-purchase contracts. NVR (parent of Ryan Homes, NVHomes, Heartland Homes) is headquartered in Reston, Virginia (DMV). Construction-defect arbitration. NVR's land-option model (options rather than ownership) is unique among large builders.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See D.R. Horton row for the fullest treatment of the shared homebuilder-industry consumer-protection pattern.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Reston", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Reston, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "NVR, Inc. (Reston, VA)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: NVR, Inc. (Reston, VA)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] NVR's mandatory arbitration shapes what recourse Ryan Homes buyers have after defect and warranty disputes\nWHAT THE TERMS SAY: NVR (Ryan Homes, NVHomes, Heartland Homes) imposes mandatory binding arbitration in home-purchase contracts covering construction defects. Ryan Homes has been the subject of sustained consumer complaint and litigation over construction defects and warranty handling in Virginia, Maryland and Pennsylvania, where the tracker states mandatory arbitration shapes what recourse a buyer actually has.\nWHY IT MATTERS: Buyers with structural or warranty complaints in NVR's core Mid-Atlantic market are limited to individual arbitration rather than court or class action.\n(evidence: Arbitration | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one distinct NVR-specific finding is documented — the construction-defect/warranty arbitration pattern in its Mid-Atlantic market; data sharing and fees are not itemized, and the affiliated-lender point repeats the pattern already documented for other builder rows rather than adding a distinct NVR fact.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The construction-defect/arbitration pattern is documented for NVR's core market, but no confirmed breach or fee detail is stated.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "NVR  <-  NVR, Inc. (Reston, VA)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using NVR you gave up your data shared corporate-wide and your right to sue. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "NVR — Ryan Homes, NVHomes, Heartland Homes — has a heavily Mid-Atlantic footprint, making it the most locally relevant builder in this tracker, and operates NVR Mortgage as an affiliated lender. Ryan Homes has been the subject of sustained consumer complaint and litigation over construction defects and warranty handling in Virginia, Maryland and Pennsylvania, where mandatory arbitration in the purchase agreement shapes what recourse a buyer actually has.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Homebuilders & RealEst", "_row_id": 783, "_entity_id": 1066, "_entity_slug": "nvr", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Toll Brothers", "Category": "Homebuilders", "Terms & Conditions URL": "See Toll Brothers's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Toll Brothers's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Homebuilder — collects mortgage-application data, income verification, credit reports, and home-customization preferences during the sales process. This is among the most financially sensitive consumer data in the tracker, collected over a multi-month relationship. Post-closing, data retention practices vary by builder.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration in home-purchase contracts. Toll Brothers specializes in luxury homes — the purchase amounts (often $500K-$2M+) are the highest per-transaction values covered by an arbitration clause in this tracker.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See D.R. Horton row for the fullest treatment of the shared homebuilder-industry consumer-protection pattern.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Horsham", "HQ State": "Pennsylvania", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Toll Brothers, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Toll Brothers, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Toll Brothers' arbitration clause covers the highest-value transactions in this tracker, $500K-$2M+\nWHAT THE TERMS SAY: Toll Brothers imposes mandatory binding arbitration in home-purchase contracts; as a luxury homebuilder, its purchase amounts (often $500K-$2M+) are the highest per-transaction values covered by an arbitration clause anywhere in this tracker.\nWHY IT MATTERS: The largest dollar amounts at stake in this entire tracker are resolved through individual arbitration rather than court, if a dispute arises.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Toll Brothers' affiliated lender, title and insurance arms keep a buyer's financial dossier in one group\nWHAT THE TERMS SAY: Toll Brothers operates affiliated mortgage, title and insurance arms; a buyer steered to the in-house lender has their tax returns, bank statements and credit file handled inside one corporate group. RESPA requires disclosure of this arrangement, which the tracker notes most buyers sign at closing without reading.\nWHY IT MATTERS: Buyers rarely scrutinize the RESPA disclosure, so the concentration of their most sensitive financial data within one company goes largely unnoticed.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No confirmed breach or specific fee dispute is stated for Toll Brothers; the two documented findings are its arbitration clause's transaction-value scale and its affiliated-business financial-data concentration.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration scope and affiliated-business structure are documented, but no confirmed breach or itemized fee dispute is stated.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Toll Brothers  <-  Toll Brothers, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Toll Brothers you gave up your data shared corporate-wide and your right to sue. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Luxury homebuilder operating affiliated mortgage, title and insurance arms, so a buyer steered to the in-house lender has their full financial dossier — tax returns, bank statements, credit file — handled inside one corporate group. Higher purchase values mean correspondingly more detailed files. RESPA regulates exactly this steering incentive, which is why builders must disclose affiliated business arrangements; most buyers sign that disclosure at closing without reading it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Homebuilders & RealEst", "_row_id": 784, "_entity_id": 1068, "_entity_slug": "toll-brothers", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Taylor Morrison Home", "Category": "Homebuilders", "Terms & Conditions URL": "See Taylor Morrison Home's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Taylor Morrison Home's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Homebuilder — collects mortgage-application data, income verification, credit reports, and home-customization preferences during the sales process. This is among the most financially sensitive consumer data in the tracker, collected over a multi-month relationship. Post-closing, data retention practices vary by builder.", "Arbitration / Class Action Waiver": "Same general forced-arbitration structure documented for D.R. Horton/Lennar/Pulte (this same tab) likely applies to this homebuilder's standard purchase contracts.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See D.R. Horton row for the fullest treatment of the shared homebuilder-industry consumer-protection pattern.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Taylor Morrison collects the same sensitive mortgage/credit file as peer homebuilders, via affiliates\nWHAT THE TERMS SAY: Taylor Morrison collects mortgage-application data, income verification, credit reports, and customization preferences during its sales process — data the tracker describes as among the most financially sensitive it tracks. Taylor Morrison shares the same affiliated mortgage/title structure as D.R. Horton, Lennar and Toll Brothers, with a buyer's financial dossier moving through several related entities under an affiliated-business disclosure signed at closing.\nWHY IT MATTERS: As with peer homebuilders, a Taylor Morrison buyer's complete financial file can move through multiple related corporate entities they didn't individually choose.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No confirmed breach, specific arbitration term (arbitration is only 'likely' to apply per the tracker), or itemized fee dispute is stated for Taylor Morrison specifically; the row's SCARY assessment is explicitly a shared one across six builder rows rather than a distinct Taylor Morrison fact, so only the general data-sensitivity point is retained here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration terms are only presumed to apply ('likely'), and the SCARY assessment is explicitly shared across multiple builder rows rather than distinct to this company.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Taylor Morrison Home  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Taylor Morrison Home you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Homebuilder with the same affiliated mortgage and title structure as D.R. Horton, Lennar and Toll Brothers — recorded as one shared structural assessment across the six builder rows rather than six independent ones. The consistent finding: the buyer's complete financial dossier moves through several related entities in a single transaction, none of which the buyer selected individually, under an affiliated business disclosure signed at the closing table.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Homebuilders & RealEst", "_row_id": 785, "_entity_id": 1069, "_entity_slug": "taylor-morrison-home", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CBRE", "Category": "Real Estate", "Terms & Conditions URL": "See CBRE's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See CBRE's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly for Compass given its direct-to-consumer residential brokerage model.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] CBRE's workplace analytics business tracks individual employee location and desk usage via sensors\nWHAT THE TERMS SAY: CBRE's workplace analytics business installs occupancy sensing in offices — badge data, desk sensors, and meeting-room utilization — producing detailed records of where individual employees are and for how long, held by a landlord's advisor rather than the employer.\nWHY IT MATTERS: An employee's granular movement data is governed by a lease-adjacent contract they are not a party to and likely never see.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — CBRE is a B2B commercial real estate firm with no direct consumer relationship or confirmed breach/arbitration; the only substantive point is its workplace occupancy-sensing business, which tracks employees rather than consumers.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship exists; only the B2B workplace-sensing business is documented.", "Exposure Score (0-100)": 4, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "CBRE  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The largest commercial real estate services firm in the world, advising corporate and institutional clients. CBRE's workplace analytics business installs occupancy sensing in offices — badge data, desk sensors, meeting room utilisation — which produces detailed records of where individual employees are and for how long, held by a landlord's advisor rather than the employer, and governed by a lease-adjacent contract the worker is not party to.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Homebuilders & RealEst", "_row_id": 786, "_entity_id": 1070, "_entity_slug": "cbre", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Jones Lang LaSalle", "Category": "Real Estate", "Terms & Conditions URL": "See Jones Lang LaSalle's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Jones Lang LaSalle's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly for Compass given its direct-to-consumer residential brokerage model.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] JLL's facilities-management role puts it inside buildings monitoring people with no relationship to it\nWHAT THE TERMS SAY: JLL operates the same workplace-occupancy analytics business as CBRE and also manages facilities on behalf of corporate tenants, meaning its personnel and systems operate inside buildings where the people being measured have no direct relationship with JLL.\nWHY IT MATTERS: Someone whose movements are measured by JLL's systems may never have agreed to any JLL terms at all, since their relationship is with their employer or the landlord, not JLL.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — JLL is a B2B commercial real estate firm with no confirmed consumer breach or arbitration; the only substantive point is its facilities-management occupancy-sensing role affecting people with no direct relationship to it.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship exists; only the B2B facilities-management sensing role is documented.", "Exposure Score (0-100)": 4, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Jones Lang LaSalle  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Commercial real estate services with the same workplace-occupancy analytics business as CBRE. JLL also manages facilities on behalf of corporate tenants, which means its personnel and systems operate inside buildings where the people being measured have no relationship with the company doing the measuring.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Homebuilders & RealEst", "_row_id": 787, "_entity_id": 1071, "_entity_slug": "jones-lang-lasalle", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cushman & Wakefield", "Category": "Real Estate", "Terms & Conditions URL": "See Cushman & Wakefield's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Cushman & Wakefield's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly for Compass given its direct-to-consumer residential brokerage model.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Cushman & Wakefield's own row explicitly defers to the shared CBRE/JLL occupancy-sensing assessment ('recorded as one shared assessment across the three rather than three independent ones') rather than presenting a distinct company-specific fact; it is a B2B firm with no confirmed consumer breach, arbitration, or fee issue.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No distinct company-specific fact is presented; the row explicitly points to a shared assessment documented under CBRE and JLL.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Cushman & Wakefield  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Commercial real estate services and facilities management. Same structural position as CBRE and JLL — recorded as one shared assessment across the three rather than three independent ones. The consumer-adjacent exposure across all of them is workplace occupancy data, not tenant or homeowner data.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Homebuilders & RealEst", "_row_id": 788, "_entity_id": 1072, "_entity_slug": "cushman-wakefield", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Prologis", "Category": "Real Estate", "Terms & Conditions URL": "See Prologis's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Prologis's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly for Compass given its direct-to-consumer residential brokerage model.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Prologis's warehouses increasingly ship with owner-installed camera and access-control systems\nWHAT THE TERMS SAY: Prologis is an industrial/logistics REIT landlord rather than an operator, so warehouse worker surveillance documented elsewhere belongs to its tenants — but the tracker notes its buildings increasingly ship with owner-installed camera and access systems.\nWHY IT MATTERS: Even as a landlord, Prologis is beginning to directly install monitoring infrastructure inside buildings occupied by workers who are not its own employees or customers.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Prologis is a B2B industrial REIT with no confirmed consumer breach or arbitration term; the only substantive point is its shift toward owner-installed building surveillance systems.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship exists; only the owner-installed building surveillance point is documented.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Prologis  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Industrial and logistics REIT leasing warehouse space, including a large share of the e-commerce fulfilment network. Prologis is a landlord rather than an operator, so the warehouse worker surveillance documented in retail and logistics reporting belongs to its tenants — but the buildings themselves increasingly ship with owner-installed camera and access systems.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Homebuilders & RealEst", "_row_id": 789, "_entity_id": 1073, "_entity_slug": "prologis", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "American Tower", "Category": "Real Estate", "Terms & Conditions URL": "See American Tower's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See American Tower's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly for Compass given its direct-to-consumer residential brokerage model.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — American Tower explicitly holds no consumer data and has no consumer relationship, per the tracker; it owns physical tower infrastructure but never sees the traffic carried over it.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The tracker explicitly states American Tower holds no consumer data and has no consumer relationship.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "American Tower  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Owns and leases the physical cell tower infrastructure that carriers operate on. It holds no consumer data and has no consumer relationship, but its towers are the physical layer beneath every location record in the Carriers tab — the cell-site data that appears in law enforcement requests originates at antennas mounted on structures this company owns and never sees the traffic from.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Homebuilders & RealEst", "_row_id": 790, "_entity_id": 1074, "_entity_slug": "american-tower", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Equinix", "Category": "Real Estate", "Terms & Conditions URL": "See Equinix's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Equinix's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly for Compass given its direct-to-consumer residential brokerage model.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no consumer terms; arbitration and fees are unconfirmed hedges, and the SCARY note is industry-level commentary on data-centre jurisdiction rather than an Equinix-specific practice.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer-facing terms exist to review, and arbitration status is unconfirmed and only 'expected.'", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Equinix  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Operates the data centres and interconnection points where a very large share of internet traffic physically exchanges — the buildings inside which most of the data documented in this tracker actually sits. No consumer relationship, but the physical and jurisdictional location of a data centre determines which government can compel access to what is inside it, which is a more consequential fact than most privacy policies acknowledge.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Homebuilders & RealEst", "_row_id": 791, "_entity_id": 1075, "_entity_slug": "equinix", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Welltower", "Category": "Real Estate", "Terms & Conditions URL": "See Welltower's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Welltower's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly for Compass given its direct-to-consumer residential brokerage model.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Welltower's REIT landlord structure obscures who's accountable for senior-housing conditions.\nWHAT THE TERMS SAY: Welltower owns senior housing and medical office properties but leases them to operators rather than running them directly, and holds no patient data itself.\nWHY IT MATTERS: Families trying to identify who is responsible for care conditions may never learn a REIT landlord sits behind the operator they deal with.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one substantive item; the row is B2B with no consumer data-sharing terms, and arbitration/fees are both unconfirmed hedges.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist for this REIT; arbitration is an unconfirmed expectation, and the one substantive fact concerns landlord structure, not disclosed terms.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Welltower  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Healthcare REIT owning senior housing and medical office properties, leased to operators rather than run directly. It holds no patient data — but senior housing ownership structures are notoriously opaque to residents and families trying to identify who is accountable for conditions, and a REIT landlord is a layer most families never learn exists.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Homebuilders & RealEst", "_row_id": 792, "_entity_id": 1076, "_entity_slug": "welltower", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Compass", "Category": "Real Estate", "Terms & Conditions URL": "See Compass's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Compass's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Homebuilder — collects mortgage-application data, income verification, credit reports, and home-customization preferences during the sales process. This is among the most financially sensitive consumer data in the tracker, collected over a multi-month relationship. Post-closing, data retention practices vary by builder.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly for Compass given its direct-to-consumer residential brokerage model.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Compass-style data covers mortgage applications, income and credit reports; retention unclear.\nWHAT THE TERMS SAY: During the sales process the company collects mortgage-application data, income verification, credit reports, and home-customization preferences; the tracker notes retention practices after closing vary by builder.\nWHY IT MATTERS: This is among the most financially sensitive data categories in the tracker, and consumers may not know how long it is kept once the sale closes.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Compass's platform reportedly aggregates buyer financial and tour data across thousands of agents, unverified.\nWHAT THE TERMS SAY: As a residential brokerage, agents handle buyer financial pre-qualification, home tour histories and negotiation communications, and the brokerage's technology platform aggregates this across thousands of agents.\nWHY IT MATTERS: If accurate, a single platform would hold a consolidated financial and behavioral profile of home buyers, but the tracker states nothing here is confirmed.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two company-specific facts are stated; arbitration/class-action terms are an unconfirmed hedge rather than a distinct finding, and fees are not itemized.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Data categories collected are described concretely, but arbitration terms and the brokerage-aggregation claim are both explicitly unconfirmed.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Compass  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Compass takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Compass is a residential brokerage, which puts it closer to consumers than the rest of this tab: agents handle buyer financial pre-qualification, home tour histories and negotiation communications, and brokerage technology platforms aggregate that across thousands of agents. The Zillow and Redfin findings in Payroll/RealEstate & Finance describe the same data category from the portal side. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Homebuilders & RealEst", "_row_id": 793, "_entity_id": 1077, "_entity_slug": "compass", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Procter & Gamble", "Category": "Household and Personal Products", "Terms & Conditions URL": "See Procter & Gamble's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Procter & Gamble's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "P&G's privacy policy discloses sharing data with advertising partners, analytics providers, and retail partners. The Pampers Club app, Oral-B app, and P&G Good Everyday loyalty programs collect purchase behavior, household composition, and usage frequency. P&G operates one of the largest consumer data platforms in CPG — estimated 1.5B+ consumer profiles.", "Arbitration / Class Action Waiver": "P&G's website Terms of Use contain a mandatory arbitration clause with class action waiver. 30-day opt-out. However, P&G's consumer relationship is primarily through PRODUCT PURCHASES at retailers — product-liability disputes (defective Tide pods, contaminated Pampers) are governed by state product-liability law, NOT by website T&C arbitration. The arbitration clause covers only digital interactions (P&G's website, Pampers Club app, Tide loyalty program, etc.).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cincinnati", "HQ State": "Ohio", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Ohio' is a non-DMV US state", "Parent / Ultimate Owner": "The Procter & Gamble Company", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: The Procter & Gamble Company). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] P&G's life-stage data spanning feminine care, pregnancy and infant brands functions as health data outside HIP\nWHAT THE TERMS SAY: P&G's loyalty and sampling programs collect life-stage data across a brand portfolio spanning feminine care, incontinence, pregnancy testing and infant products; separately, its named apps -- Pampers Club, Oral-B, and P&G Good Everyday -- collect purchase behavior, household composition, and usage frequency.\nWHY IT MATTERS: This life-stage information is health information by ordinary definition but sits entirely outside HIPAA protections, per the tracker.\n(evidence: SCARY, Data Sharing; Stated in tracker (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] P&G shares data with ad, analytics and retail partners; its platform holds an estimated 1.5B+ profiles.\nWHAT THE TERMS SAY: P&G's privacy policy discloses sharing data with advertising partners, analytics providers and retail partners; separately, the tracker says P&G operates one of the largest consumer data platforms in CPG, an estimated 1.5B+ consumer profiles.\nWHY IT MATTERS: Consumers using loyalty apps for diapers or toothbrushes feed a data platform that is shared broadly with third parties for advertising purposes.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] P&G's arbitration clause covers only digital touchpoints, not product-injury claims like Tide Pods or Pampers.\nWHAT THE TERMS SAY: P&G's website Terms of Use impose mandatory arbitration with a class-action waiver and a 30-day opt-out, but this covers only digital interactions (website, apps, loyalty programs) -- not product-liability disputes, which the tracker says are governed by state law instead.\nWHY IT MATTERS: Most consumers interact with P&G through retail purchases, not its website, so the arbitration clause may not reach the disputes that matter most.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and data-sharing practices are clearly described, but fees are not itemized and the health-adjacent data is characterized as sitting outside any dedicated privacy framework.", "Exposure Score (0-100)": 41, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 15, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 15/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Procter & Gamble  <-  The Procter & Gamble Company", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Procter & Gamble you gave up your personal data sold onward, your data shared corporate-wide, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "P&G's brand portfolio spans feminine care, incontinence, pregnancy testing and infant products, and its loyalty and sampling programmes collect life-stage data that is health information by any ordinary definition while sitting entirely outside HIPAA. P&G is also among the largest advertisers in the world, which makes it a major buyer in the audience-data market this tracker documents from the seller's side — the demand behind the Omnicom and Interpublic rows.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 794, "_entity_id": 1079, "_entity_slug": "procter-gamble", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "PepsiCo", "Category": "Food Consumer Products", "Terms & Conditions URL": "See PepsiCo's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See PepsiCo's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "PepsiCo's brand portfolio (Pepsi, Lay's, Gatorade, Quaker, Doritos, Mountain Dew) spans 23 billion-dollar brands. Data collection through PepsiCo's shopper marketing platform. Partnership with Instacart and retailer loyalty programs creates cross-brand purchase tracking.", "Arbitration / Class Action Waiver": "PepsiCo's website Terms of Use contain a mandatory arbitration clause with class action waiver. 30-day opt-out. Same product-vs-digital distinction as P&G — the clause covers PepsiCo.com, PepsiCo loyalty apps, and online promotions, but product-liability claims (contaminated beverages, allergen mislabeling) are governed by state law.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Purchase", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "PepsiCo, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: PepsiCo, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] PepsiCo's Instacart and retailer loyalty partnerships create cross-brand purchase tracking.\nWHAT THE TERMS SAY: PepsiCo's shopper marketing platform, combined with an Instacart partnership and retailer loyalty programs, creates tracking of purchases across its brand portfolio (Pepsi, Lay's, Gatorade, Quaker, Doritos, Mountain Dew).\nWHY IT MATTERS: A shopper buying different snack and beverage brands may not realize purchases are being linked into one cross-brand profile.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] PepsiCo's arbitration clause reaches only its website and apps, not product-liability claims.\nWHAT THE TERMS SAY: PepsiCo's website Terms of Use carry mandatory arbitration with a class-action waiver and 30-day opt-out, but the clause covers only PepsiCo.com, loyalty apps and online promotions -- not product-liability claims, which fall under state law.\nWHY IT MATTERS: Consumers harmed by a product defect, rather than a website dispute, are not covered by this arbitration clause.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two company-specific facts are stated; the SCARY note flags marketing-to-children and labeling as FTC/FDA matters without citing a specific regulatory action, and fees are not itemized.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration scope and cross-brand tracking are described concretely, but fees are unitemized and the regulatory angle (marketing/labeling) is referenced without a specific confirmed action.", "Exposure Score (0-100)": 36, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "PepsiCo  <-  PepsiCo, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using PepsiCo you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Retail-mediated sales with limited direct consumer data, collected mainly through promotional codes, contests and branded apps. PepsiCo's more consequential consumer issues are marketing to children and beverage labelling, which are FTC and FDA matters rather than terms-of-service ones.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 795, "_entity_id": 1081, "_entity_slug": "pepsico", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Coca-Cola", "Category": "Beverages", "Terms & Conditions URL": "coca-colacompany.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "coca-colacompany.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED VERY RECENT BREACH (July 2026): Coca-Cola disclosed a data breach affecting its DAIRY BEVERAGE SUBSIDIARY, Fairlife (which Coca-Cola owns and operates) — specific scope/data types not fully detailed in sources reviewed this pass, though the disclosure itself confirms the parent company's exposure through a wholly-owned subsidiary brand many consumers may not realize is part of Coca-Cola's corporate family.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is one of the MOST RECENT breaches documented anywhere in this entire tracker — recommend a direct follow-up to confirm final scope given how new this disclosure is; worth noting Fairlife is a less obviously 'Coca-Cola' brand than the company's flagship soda products.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Atlanta", "HQ State": "Georgia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Georgia' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Georgia SOS eCorp — ecorp.sos.ga.gov/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Coca-Cola confirmed a July 2026 data breach at its Fairlife dairy subsidiary; scope not yet detailed.\nWHAT THE TERMS SAY: Coca-Cola disclosed a data breach affecting Fairlife, its wholly-owned dairy beverage subsidiary; the tracker notes specific scope and data types were not fully detailed as of this pass.\nWHY IT MATTERS: Fairlife is a wholly-owned subsidiary brand many consumers may not realize is part of Coca-Cola's corporate family.\n(evidence: Data Sharing, SCARY, Notes; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one confirmed, company-specific fact exists this pass -- the Fairlife breach; arbitration is an unconfirmed hedge, fees are not itemized, and the breach's scope itself is still developing so no further detail can be stated without inventing facts.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Fairlife breach itself is confirmed, but its scope is still developing and every other field (arbitration, fees) is unconfirmed or unitemized.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Coca-Cola  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Coca-Cola takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Coca-Cola disclosed a confirmed breach in July 2026 - very recent, with scope still developing as of this pass, so no figures are asserted here. Coca-Cola runs one of the largest consumer promotional data operations in the world through loyalty codes and contest entries, which is where whatever consumer data it holds originates. Recommend a follow-up on state attorney general notification filings, which is typically where scope becomes public first.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 796, "_entity_id": 1082, "_entity_slug": "coca-cola", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Mondelez", "Category": "Food Consumer Products", "Terms & Conditions URL": "See Mondelez's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Mondelez's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a consumer packaged-goods/food manufacturer, most individual interaction is through retail purchases rather than a direct account relationship, meaning this company's direct consumer-data footprint is smaller than most other companies in this tracker — worth checking loyalty/rewards app data practices specifically if this company operates one.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Chicago", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Mondelez's promotional and children's-marketing data collection is governed by COPPA, not a privacy policy.\nWHAT THE TERMS SAY: Mondelez runs promotional and children's-marketing data collection like its packaged-food peers; the tracker notes this is governed by COPPA rather than any company privacy policy.\nWHY IT MATTERS: Parents may assume a privacy policy covers this data, but the tracker says COPPA is what governs it instead.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is company-specific and consumer-facing; the NotPetya/Zurich insurance litigation concerns Mondelez's own cyber-insurance coverage, not a consumer harm, and data-sharing/arbitration fields are both unconfirmed this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data-sharing and arbitration are both explicitly unconfirmed this pass, leaving only the COPPA-governed marketing note as a stated fact.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Mondelez  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Mondelez takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Mondelez was a major casualty of NotPetya, and its insurance litigation against Zurich over an act-of-war exclusion reshaped how cyber coverage is written across every industry in this tracker — the case settled, but the underlying question of whether a state-attributed attack is 'war' now drives policy wording everywhere. On the consumer side, Mondelez runs the same promotional and children's-marketing data collection as its packaged-food peers, governed by COPPA rather than by any privacy policy.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 797, "_entity_id": 1083, "_entity_slug": "mondelez", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Kraft Heinz", "Category": "Food Consumer Products", "Terms & Conditions URL": "See Kraft Heinz's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Kraft Heinz's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Kraft Heinz operates 200+ brands (Oscar Mayer, Philadelphia, Heinz, Jell-O, Maxwell House). Data collection primarily through Kraft's cooking/recipe platforms and digital couponing. Berkshire Hathaway is a major shareholder.", "Arbitration / Class Action Waiver": "Kraft Heinz's website Terms of Use contain a mandatory arbitration clause with class action waiver. 30-day opt-out. AAA rules, Illinois law (despite Pittsburgh HQ, Kraft's legacy corporate registration is in Illinois). Product-liability claims are separate.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Pittsburgh", "HQ State": "Pennsylvania", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "The Kraft Heinz Company (Berkshire Hathaway + 3G Capital)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: The Kraft Heinz Company (Berkshire Hathaway + 3G Capital)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Kraft Heinz's arbitration clause uses Illinois law and AAA rules but excludes product-liability claims.\nWHAT THE TERMS SAY: Kraft Heinz's website Terms of Use impose mandatory arbitration with a class-action waiver under AAA rules and Illinois law (its legacy corporate registration, despite a Pittsburgh HQ), with a 30-day opt-out; product-liability claims are handled separately.\nWHY IT MATTERS: Consumers must act within 30 days to opt out, and the clause governs website disputes rather than claims over the food itself.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the arbitration clause is a concrete, consumer-facing item; the SEC settlement over procurement accounting is explicitly an investor matter per the tracker, and the labelling/nutrition-claims exposure is named only as a category, with no specific case cited.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly detailed, but the SEC accounting settlement and labelling exposure are only broadly characterized, and fees are not itemized.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, penalty+3) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Kraft Heinz  <-  The Kraft Heinz Company (Berkshire Hathaway + 3G Capital)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Kraft Heinz you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Packaged food sold through retailers, so consumer data arrives via promotions rather than purchases. Kraft Heinz's notable corporate event was a large goodwill write-down and SEC settlement over procurement accounting — an investor matter. Its consumer-facing exposure is labelling and nutrition claims.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 798, "_entity_id": 1085, "_entity_slug": "kraft-heinz", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "General Mills", "Category": "Food Consumer Products", "Terms & Conditions URL": "See General Mills's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See General Mills's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Brands: Cheerios, Betty Crocker, Häagen-Dazs, Nature Valley, Old El Paso, Pillsbury, Annie's. Box Tops for Education program collects purchase data from millions of families with school-age children.", "Arbitration / Class Action Waiver": "General Mills' Terms of Use contain a mandatory arbitration clause with class action waiver. General Mills notably ATTEMPTED to extend its arbitration clause to include people who merely 'liked' the company on Facebook or downloaded a digital coupon (2014) — the backlash was so severe that General Mills reversed the policy within 48 hours after a NYT editorial and AG threats. The current clause covers only registered website users, not social-media followers or coupon clippers.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Minneapolis", "HQ State": "Minnesota", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Minnesota' is a non-DMV US state", "Parent / Ultimate Owner": "General Mills, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: General Mills, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-3] General Mills once tried binding Facebook 'likers' and coupon downloaders to arbitration, then reversed.\nWHAT THE TERMS SAY: In 2014, General Mills attempted to extend its arbitration clause to cover anyone who merely 'liked' the company on Facebook or downloaded a digital coupon; after a NYT editorial and state AG threats, it reversed the policy within 48 hours.\nWHY IT MATTERS: The episode shows how far a company was willing to stretch 'consent' to a dispute-resolution clause, even though the current policy only covers registered website users.\n(evidence: Arbitration, SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] General Mills' Box Tops program collects purchase data tied to families with school-age children.\nWHAT THE TERMS SAY: The Box Tops for Education program collects purchase data from millions of families with school-age children; the tracker notes marketing directed at children is governed by COPPA's parental-consent requirement rather than a terms acceptance.\nWHY IT MATTERS: Data collection tied to children's education programs raises the stakes of consent, since the actual legal safeguard is COPPA, not a clickthrough agreement most parents never see.\n(evidence: Data Sharing, SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] General Mills currently requires arbitration with a 30-day opt-out for registered website users.\nWHAT THE TERMS SAY: General Mills' Terms of Use contain mandatory arbitration with a class-action waiver, with a 30-day window to opt out, covering registered website users.\nWHY IT MATTERS: Consumers who don't act within 30 days give up the right to sue or join a class action over website-related disputes.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration history and current scope are clearly documented, but fees are unitemized and children's-data handling is described only at a category level.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "General Mills  <-  General Mills, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using General Mills you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Retail-mediated packaged food where the meaningful consumer data comes from branded websites, games and promotions rather than purchases — and because much of that marketing is directed at children, COPPA is the regulatory framework that actually governs it, requiring verifiable parental consent rather than a terms acceptance. General Mills also drew attention for briefly adding an arbitration clause purporting to bind anyone who downloaded a coupon or liked its Facebook page, then reversing after public backlash.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 799, "_entity_id": 1087, "_entity_slug": "general-mills", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Tyson Foods", "Category": "Food Production", "Terms & Conditions URL": "See Tyson Foods's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Tyson Foods's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Primarily B2B (meat processing/distribution). Consumer data collection limited. Tyson settled a chicken price-fixing class action for $222M (2021) — that was B2B litigation, not consumer.", "Arbitration / Class Action Waiver": "Tyson Foods' website Terms of Use contain a mandatory arbitration clause. 30-day opt-out. Tyson's consumer-facing digital footprint is minimal (no significant loyalty app or consumer data platform) — the clause primarily covers the corporate website. Tyson's bigger legal exposure is in its B2B relationships (price-fixing class actions, worker safety OSHA violations).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Springdale", "HQ State": "Arkansas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Arkansas' is a non-DMV US state", "Parent / Ultimate Owner": "Tyson Foods, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Arkansas) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Arkansas. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] Tyson's $222M chicken price-fixing settlement is described as raising what shoppers paid at the counter.\nWHAT THE TERMS SAY: Tyson settled a chicken price-fixing class action for $222M in 2021; the tracker notes this was B2B litigation, but its SCARY entry frames the underlying conduct as having raised what shoppers paid at the counter.\nWHY IT MATTERS: Even though the settlement itself resolved a business dispute, the tracker treats the price-fixing conduct as a real cost passed to consumers.\n(evidence: Data Sharing, SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the price-fixing/consumer-cost note is a distinct, taggable finding; the OSHA and child-labor findings mentioned in the SCARY field are labor and safety matters with no vocabulary tag distinct from the pricing item, and arbitration/data fields are otherwise thin.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration and price-fixing consumer-cost framing are stated, but the underlying settlement is characterized as B2B and consumer data collection is described only as minimal.", "Exposure Score (0-100)": 18, "Exposure Band": "Low", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 3, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 3/20 (severity1+0, penalty+3) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Tyson Foods  <-  Tyson Foods, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Tyson Foods you gave up your right to sue. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Meat processor selling to retailers and foodservice. Tyson's consumer-relevant record is labour and safety rather than data: it has faced significant OSHA findings, child labour enforcement involving contracted sanitation crews at its facilities, and price-fixing litigation that raised what shoppers paid at the counter. Recorded so a blank privacy row is not read as a blank record.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 800, "_entity_id": 1089, "_entity_slug": "tyson-foods", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Archer Daniels Midland", "Category": "Food Production", "Terms & Conditions URL": "See Archer Daniels Midland's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Archer Daniels Midland's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no consumer data collection; the accounting-irregularities/SEC-DOJ matter is explicitly framed in the tracker as an investor issue, not a consumer one, and arbitration/fees are unconfirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the one substantive fact (SEC/DOJ scrutiny) is explicitly an investor matter, and arbitration status is unconfirmed.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Archer Daniels Midland  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Agricultural commodity processor and trader with no consumer relationship. ADM disclosed accounting irregularities in its Nutrition segment in 2024 that triggered SEC and DOJ scrutiny and the departure of its CFO — an investor matter, not a consumer one, but the reason this row is not simply empty.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 801, "_entity_id": 1090, "_entity_slug": "archer-daniels-midland", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Bunge", "Category": "Food", "Terms & Conditions URL": "See Bunge's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Bunge's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "St. Louis", "HQ State": "Missouri", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Missouri' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Missouri SOS Business Search — bsd.sos.mo.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no consumer relationship; the SCARY note is general commentary on commodity traders' invisibility to consumers, not a specific practice, and arbitration/fees are unconfirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms or confirmed practices exist for this commodity trader.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Bunge  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Agricultural commodity processor and trader, merged with Viterra. No consumer relationship. Companies at this layer set the input costs behind grocery prices without ever appearing on a label or a receipt, which is the honest description of their consumer relevance.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 802, "_entity_id": 1091, "_entity_slug": "bunge", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Conagra Brands", "Category": "Food Consumer Products", "Terms & Conditions URL": "See Conagra Brands's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Conagra Brands's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Data collection through digital couponing and recipe platform. Consumer data shared with retail partners for targeted promotions.", "Arbitration / Class Action Waiver": "Conagra's website Terms of Use contain a mandatory arbitration clause with class action waiver. 30-day opt-out. Brands: Healthy Choice, Marie Callender's, Slim Jim, Reddi-wip, Duncan Hines, Birds Eye. Consumer digital footprint primarily through recipe sites and couponing.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Chicago", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Conagra Brands, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Conagra Brands, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Conagra shares digital coupon and recipe-platform data with retail partners for targeted promotions.\nWHAT THE TERMS SAY: Conagra collects data through digital couponing and a recipe platform and shares consumer data with retail partners for targeted promotions.\nWHY IT MATTERS: Consumers using recipe or coupon tools may not realize that data is passed to retail partners for ad targeting.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Conagra requires arbitration with a class-action waiver and a 30-day opt-out window.\nWHAT THE TERMS SAY: Conagra's website Terms of Use contain a mandatory arbitration clause with a class-action waiver and a 30-day opt-out.\nWHY IT MATTERS: Consumers who miss the 30-day window lose the ability to sue or join a class action over website-related disputes.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct facts are stated; the recall/labelling exposure is described only generically with no specific case, and fees are not itemized.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Data-sharing and arbitration terms are clearly stated, but fees are unitemized and the labelling/recall exposure is only generically described.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Conagra Brands  <-  Conagra Brands, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Conagra Brands you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Packaged food sold through retailers with minimal direct consumer data. Conagra's consumer-relevant record is product recalls and labelling rather than privacy — the harm arrives through the FDA notification system, which most consumers never monitor.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 803, "_entity_id": 1093, "_entity_slug": "conagra-brands", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Smithfield Foods", "Category": "Food", "Terms & Conditions URL": "See Smithfield Foods's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Smithfield Foods's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Smithfield", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Smithfield, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] Smithfield's hog waste lagoons drew jury verdicts for NC neighbors who had no contract with it.\nWHAT THE TERMS SAY: Smithfield faced environmental litigation over hog waste lagoons in North Carolina, where juries returned substantial verdicts for neighboring residents.\nWHY IT MATTERS: These are people harmed by Smithfield's operations despite having no customer or contractual relationship with it -- a harm outside any terms of service entirely.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item -- Smithfield is B2B with no consumer data-sharing or confirmed arbitration terms, so the jury-verdict litigation is the sole substantive, stated fact.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "No consumer terms exist to review, but the hog-lagoon litigation and jury verdicts are stated as confirmed fact rather than hedged.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Smithfield Foods  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Pork processor, Virginia-headquartered, and one of the largest industrial employers in this tracker's core region. Its consumer-relevant record runs through environmental litigation over hog waste lagoons in North Carolina, where juries returned substantial verdicts for neighbouring residents — people harmed by a company they had no contract with, which is the purest form of the non-customer harm this tracker keeps documenting.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 804, "_entity_id": 1094, "_entity_slug": "smithfield-foods", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Seaboard", "Category": "Food Production", "Terms & Conditions URL": "See Seaboard's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Seaboard's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Merriam", "HQ State": "Kansas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Kansas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Non-US entity (Kansas) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Kansas. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no consumer relationship; the SCARY note describes general corporate opacity rather than a specific practice, and arbitration/fees are unconfirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist, and the tracker explicitly notes minimal public disclosure for this closely held company.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Seaboard  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Agribusiness and ocean transport conglomerate, unusually diversified and unusually opaque — controlled by a single family, thinly traded, and generating minimal public disclosure for a company of its size. No consumer relationship, and the opacity is the honest note.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 805, "_entity_id": 1095, "_entity_slug": "seaboard", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Pilgrim's Pride", "Category": "Food", "Terms & Conditions URL": "See Pilgrim's Pride's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Pilgrim's Pride's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Greeley", "HQ State": "Colorado", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Colorado' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Colorado SOS Business Search — sos.state.co.us/biz/BusinessEntityCriteria. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] Pilgrim's Pride pleaded guilty and paid a criminal fine in the broiler chicken price-fixing prosecution.\nWHAT THE TERMS SAY: Pilgrim's Pride was a defendant in the federal broiler chicken price-fixing prosecutions, pleaded guilty, and paid a substantial criminal fine.\nWHY IT MATTERS: The tracker frames this as a direct consumer-cost harm -- shoppers paid more for chicken -- resolved through antitrust enforcement rather than anything in a terms of service.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item; Pilgrim's Pride is otherwise B2B with no consumer data-sharing or confirmed arbitration terms.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "No consumer terms exist, but the price-fixing guilty plea and criminal fine are stated as confirmed fact.", "Exposure Score (0-100)": 3, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 3, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 3/20 (severity1+0, penalty+3) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Pilgrim's Pride  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Poultry processor and a defendant in the federal broiler chicken price-fixing prosecutions, where the company pleaded guilty and paid a substantial criminal fine. That is a direct consumer-cost harm — shoppers paid more for chicken — resolved through antitrust enforcement rather than anything in a terms of service. Majority-owned by JBS.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 806, "_entity_id": 1096, "_entity_slug": "pilgrim-s-pride", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Land O'Lakes", "Category": "Food Consumer Products", "Terms & Conditions URL": "See Land O'Lakes's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Land O'Lakes's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a consumer packaged-goods/food manufacturer, most individual interaction is through retail purchases rather than a direct account relationship, meaning this company's direct consumer-data footprint is smaller than most other companies in this tracker — worth checking loyalty/rewards app data practices specifically if this company operates one.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Arden Hills", "HQ State": "Minnesota", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Minnesota' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Land O'Lakes holds farm and financial data on member-owners, with no consumer-privacy analogue.\nWHAT THE TERMS SAY: As a farmer-owned cooperative, Land O'Lakes' primary data relationship is with member producers rather than shoppers; member data includes farm operations and financial information.\nWHY IT MATTERS: This is genuinely individual financial data held by an entity its subjects also own -- a governance structure the tracker says has no consumer-privacy analogue, meaning standard consumer protections may not clearly apply.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is stated; consumer-facing data sharing and arbitration are both unconfirmed this pass, with no named breach or lawsuit.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing and arbitration are both unconfirmed, leaving only the co-op governance structure as a stated fact.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Land O'Lakes  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Land O'Lakes takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A farmer-owned agricultural cooperative, so its primary relationships are with member producers rather than shoppers despite the retail dairy brand on the carton. Member data includes farm operations and financial information — genuinely individual data, held by an entity its subjects also own, which is a governance model with no consumer-privacy analogue.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 807, "_entity_id": 1097, "_entity_slug": "land-o-lakes", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CHS", "Category": "Food Production", "Terms & Conditions URL": "See CHS's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See CHS's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Inver Grove Heights", "HQ State": "Minnesota", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Minnesota' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no consumer relationship; the SCARY note describes general cooperative governance rather than a specific practice, and arbitration/fees are unconfirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist and the tracker notes very little public record for this cooperative.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "CHS  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Farmer-owned agricultural and energy cooperative serving member producers rather than consumers. The cooperative structure means its 'customers' are also its owners, which is a genuinely different governance model from every other company in this tab — and one that produces very little public record either way.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 808, "_entity_id": 1098, "_entity_slug": "chs", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Kenvue", "Category": "Household and Personal Products", "Terms & Conditions URL": "See Kenvue's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Kenvue's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; as a consumer packaged-goods/food manufacturer, most individual interaction is through retail purchases rather than a direct account relationship, meaning this company's direct consumer-data footprint is smaller than most other companies in this tracker — worth checking loyalty/rewards app data practices specifically if this company operates one.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Skillman", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NJ Business Records Service — businessrecords.nj.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Kenvue's OTC health loyalty programs reportedly collect symptom data outside any health-privacy perimeter.\nWHAT THE TERMS SAY: Kenvue's over-the-counter health product loyalty and sampling programs collect symptom and condition data; the tracker states this sits outside any health privacy perimeter.\nWHY IT MATTERS: Consumers signing up for coupons on Tylenol or Neutrogena may be handing over health-adjacent data with fewer protections than they'd expect from a healthcare provider.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item, and it is explicitly unverified rather than confirmed; no named lawsuit, breach, or arbitration term is stated this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed this pass -- data sharing, arbitration, and the symptom-data claim are all explicitly unverified.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Kenvue  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Kenvue takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Kenvue is the consumer health business spun out of Johnson & Johnson - Tylenol, Band-Aid, Listerine, Neutrogena - and the spin-off is the note: brands consumers associate with J&J are now a separate company with separate policies and a separate record. Over-the-counter health product loyalty and sampling programmes also collect symptom and condition data outside any health privacy perimeter. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 809, "_entity_id": 1099, "_entity_slug": "kenvue", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Dollar General", "Category": "Specialty Retailers: Other", "Terms & Conditions URL": "dollargeneral.com/terms-of-use.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "dollargeneral.com/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named recent data-privacy lawsuit or breach; recommend checking against the same 'broken banner' tracking-consent pattern documented for Dollar Tree (this same tab), given the structural similarity of the two discount-retail competitors.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Dollar General app ToS. 30-day opt-out. Dollar General serves predominantly low-income and rural communities — the arbitration clause affects a population less likely to have access to legal resources.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See Dollar Tree row for the shared discount-retail sector pattern that may plausibly extend here.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Goodlettsville", "HQ State": "Tennessee", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Tennessee' is a non-DMV US state", "Parent / Ultimate Owner": "Dollar General Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Tennessee SOS Business Search — tnbear.tn.gov/Ecommerce/FilingSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Dollar General Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Dollar General's arbitration clause reaches a customer base with less access to legal recourse.\nWHAT THE TERMS SAY: Dollar General's app Terms of Service impose mandatory binding arbitration with a class-action waiver and a 30-day opt-out.\nWHY IT MATTERS: The tracker notes Dollar General serves predominantly low-income and rural communities, a population less likely to have access to legal resources to challenge the clause or navigate the opt-out.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-1] Dollar General has faced extensive state enforcement over shelf-tag-to-register pricing discrepancies.\nWHAT THE TERMS SAY: Dollar General has faced extensive state enforcement action over pricing discrepancies between shelf tags and register scans.\nWHY IT MATTERS: This is a harm customers actually encounter directly at checkout, compounded by stores that are often the only retailer within reach in the communities they serve.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two items are consumer-facing and company-specific; data-sharing/breach is explicitly unconfirmed this pass (the 'broken banner' pattern is documented for Dollar Tree, not Dollar General), and workplace-safety penalties are not a consumer harm.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and the pricing-enforcement record are clearly stated, but data-sharing/breach status is explicitly unconfirmed and fees are unitemized.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 5/20 (severity2+2, penalty+3) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Dollar General  <-  Dollar General Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Dollar General you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass on data. Dollar General's substantiated consumer findings are elsewhere: it has faced extensive state enforcement over pricing discrepancies between shelf tags and register scans, and repeated workplace safety penalties. Those are the harms its customers actually encounter, and its store footprint concentrates in rural and low-income areas where it is frequently the only retailer within reach - the no-alternative structure documented throughout this tracker.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 810, "_entity_id": 1101, "_entity_slug": "dollar-general", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Dollar Tree", "Category": "Specialty Retailers: Other", "Terms & Conditions URL": "dollartree.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "dollartree.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "GENUINELY NOTABLE 'BROKEN BANNER' PRIVACY CASE (D'Antonio v. Dollar Tree, N.D. Cal., filed 2025): alleges Dollar Tree's website presented a cookie-consent banner offering a clear 'Reject Advertising Cookies' choice — but CONTINUED TRACKING users who clicked reject anyway. A magistrate judge denied Dollar Tree's motion to dismiss claims of invasion of privacy, intrusion upon seclusion, and CIPA pen-register violations, with courts in similar 'broken banner' cases reasoning that promising to stop tracking and then not doing so makes the resulting intrusion 'deceptive' and 'highly offensive' — even though ordinary public web browsing isn't normally considered private. The named plaintiff ultimately voluntarily dismissed his own individual claim (Feb 2026), though the case had already survived the key dismissal motion. This 'broken banner' pattern was separately documented hitting companies across many sectors, including Nvidia (Tech & Semiconductors tab, if covered).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Dollar Tree/Family Dollar app ToS. 30-day opt-out. HQ: Chesapeake, Virginia (DMV). Dollar Tree operates 16,000+ stores including Family Dollar (acquired 2015 for $9.2B).", "Fees / Billing Flags": "SEPARATE, ONGOING LITIGATION (Murphy v. Dollar Tree, 2026): alleges Dollar Tree printed MORE THAN THE LAST FIVE DIGITS of customers' credit card numbers on receipts — a direct violation of the federal Fair and Accurate Credit Transactions Act (FACTA), which specifically limits how much card-number information can appear on a printed receipt to prevent exactly this kind of exposure.", "Notes": "Dollar Tree now has THREE separate, distinct issue categories (broken-banner tracking, a vendor employee/customer breach, and a FACTA receipt violation) — the FACTA receipt issue specifically is a concrete, easily-verifiable problem: anyone can check their own Dollar Tree receipt to see how much of their card number is printed on it.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Chesapeake", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Chesapeake, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "Dollar Tree, Inc. (Chesapeake, VA)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Dollar Tree, Inc. (Chesapeake, VA)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] Dollar Tree's cookie banner let users 'Reject Advertising Cookies' but allegedly kept tracking them anyway.\nWHAT THE TERMS SAY: In D'Antonio v. Dollar Tree (N.D. Cal., filed 2025), plaintiffs allege the website's cookie-consent banner offered a clear 'Reject Advertising Cookies' option but continued tracking users who clicked it; a magistrate judge denied Dollar Tree's motion to dismiss invasion-of-privacy, intrusion-upon-seclusion and CIPA pen-register claims.\nWHY IT MATTERS: The consent interface existed and appeared functional but allegedly changed nothing about what the site did -- the named plaintiff later dropped his individual claim, but the case survived the key dismissal motion.\n(evidence: Data Sharing, SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-1] Dollar Tree allegedly printed more than the legally allowed last five digits of card numbers on receipts.\nWHAT THE TERMS SAY: In Murphy v. Dollar Tree (2026), plaintiffs allege Dollar Tree printed more than the FACTA-permitted last five digits of customers' credit card numbers on receipts.\nWHY IT MATTERS: This is a concrete, easily verifiable exposure -- the tracker notes anyone can check their own Dollar Tree receipt to see how much of their card number is printed on it -- and FACTA exists specifically to prevent this kind of exposure.\n(evidence: Fees, Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CONFIRMED_BREACH · FL-2] Dollar Tree carries a third, undetailed issue category: a vendor employee/customer breach.\nWHAT THE TERMS SAY: The tracker's Notes list a 'vendor employee/customer breach' as a third distinct issue category for Dollar Tree, alongside the broken-banner and FACTA matters, without further detail on scope, date, or data involved this pass.\nWHY IT MATTERS: Without more detail this can't be assessed for severity, but the tracker treats it as a separate, named category rather than speculation.\n(evidence: Notes; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The broken-banner and FACTA cases are well-documented with court outcomes, but the third breach category is named without detail.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 7, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 7/20 (severity2+2, breach+3, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Dollar Tree  <-  Dollar Tree, Inc. (Chesapeake, VA)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Dollar Tree you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 'broken banner' case in D'Antonio is the finding, and it names the failure precisely: a cookie consent banner that presented choices which did not actually govern what the site did, so a user who declined tracking was tracked anyway. That inverts the entire consent model - the interface exists, the button works, and nothing changes. Dollar Tree also owned Family Dollar during the relevant period, and the same low-income, limited-alternative customer base noted for Dollar General applies. Allegations, not findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 811, "_entity_id": 1103, "_entity_slug": "dollar-tree", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Macy's", "Category": "General Merchandisers", "Terms & Conditions URL": "macys.com/customer-service/policies/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "macys.com/customer-service/policies/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "HISTORICAL CONFIRMED BREACH (2024): Macy's disclosed a cybersecurity incident where an employee disabled some tracking tools to hide personal online purchases from oversight — a distinctive INSIDER MISCONDUCT pattern rather than an external hacking incident, though the company's broader financial reporting was affected as a result.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass on the specific customer-data impact of the 2024 incident, since the publicly available detail focuses more on the employee-misconduct/accounting angle than customer-data exposure specifically.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Macy's 2024 incident was an employee disabling tracking tools to hide purchases, not an external hack.\nWHAT THE TERMS SAY: Macy's disclosed a 2024 cybersecurity incident in which an employee disabled some tracking tools to hide personal online purchases from oversight -- an insider-misconduct pattern rather than external hacking -- which also affected the company's broader financial reporting.\nWHY IT MATTERS: The tracker notes the customer-data impact specifically is unclear, since public detail has focused more on the employee-misconduct and accounting angle than on what customer data, if any, was exposed.\n(evidence: Data Sharing, Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-1] Macy's separately disclosed an employee concealed delivery expenses over multiple years.\nWHAT THE TERMS SAY: The tracker notes a second Macy's finding: a single employee had concealed a substantial sum of delivery expenses over a period of years -- an internal-controls failure distinct from the 2024 data incident.\nWHY IT MATTERS: It's not a data harm, but it speaks to the same oversight question the 2024 breach raises about how well Macy's monitors its own employees.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct facts are stated; the private-label credit-card note points to the separate Synchrony row rather than a Macy's-specific finding, and arbitration/fees are both unconfirmed or unitemized.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2024 incident and internal-controls failure are confirmed, but arbitration is unconfirmed and the customer-data-specific impact of the breach remains unclear per the tracker's own note.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Macy's  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Macy's takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The 2024 breach is confirmed, and Macy's carries a second finding worth pairing with it: the company disclosed that a single employee had concealed a substantial sum of delivery expenses over a period of years, which is an internal controls failure rather than a data one but speaks to the same oversight question. Macy's also operates a large private-label credit programme - cross-ref the Synchrony row in Credit Card Companies for who actually holds a store card and why disputes go to the wrong entity.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 812, "_entity_id": 1104, "_entity_slug": "macy-s", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Burlington Stores", "Category": "Specialty Retailers: Apparel", "Terms & Conditions URL": "burlington.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "burlington.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; check against the broader off-price-retail sector patterns documented for TJX/Ross Stores elsewhere in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Burlington", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NJ Business Records Service — businessrecords.nj.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Burlington runs in-store analytics on shoppers who never identified themselves.\nWHAT THE TERMS SAY: Burlington runs in-store analytics on shoppers who never identified themselves, per the tracker.\nWHY IT MATTERS: Even customers who never join a loyalty program or provide personal information may still be tracked and analyzed while shopping in-store.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one Burlington-specific fact is stated; the TJX card-breach comparison and non-loyalty-transaction point are context for the sector, not Burlington's own confirmed practice, and data-sharing/arbitration are both unconfirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data-sharing and arbitration are both unconfirmed, leaving only the in-store analytics note as a stated fact.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "App / Service", "Ownership Path": "Burlington Stores  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Burlington Stores takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Off-price retail with a large share of non-loyalty transactions, which is an incidental data-minimisation advantage rather than a deliberate one. TJX's history in the Retail & Fintech tab shows the limit of that advantage: payment systems alone were sufficient exposure for 45.7 million cards, because the card is identifying whether or not a loyalty programme exists. Burlington also runs in-store analytics on shoppers who never identified themselves.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 813, "_entity_id": 1105, "_entity_slug": "burlington-stores", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Darden Restaurants (Olive Garden, LongHorn)", "Category": "Food Services", "Terms & Conditions URL": "darden.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "darden.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; recommend checking against the broader restaurant-industry Meta Pixel/tracking-technology and delivery-fee patterns documented extensively for Chick-fil-A, McDonald's, Panera, and others throughout this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Darden disclosed a payment-card breach affecting its Cheddar's locations.\nWHAT THE TERMS SAY: Darden disclosed a payment card breach affecting Cheddar's locations; the tracker notes restaurant point-of-sale systems have historically been among the most breached in retail due to heterogeneous, inconsistently patched terminals with card data sitting directly on the device.\nWHY IT MATTERS: Diners at Cheddar's had payment card data exposed through infrastructure the tracker describes as a chronic weak point across the restaurant industry.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] One Darden loyalty system links diner profiles across Olive Garden, LongHorn and Cheddar's.\nWHAT THE TERMS SAY: Darden operates Olive Garden, LongHorn, Cheddar's, Yard House, Ruth's Chris and others under one parent with shared loyalty infrastructure, so a diner visiting what feel like different restaurants is building one profile.\nWHY IT MATTERS: Consumers who think they're patronizing distinct, unrelated restaurant brands are actually contributing to a single consolidated dining profile.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two items are Darden-specific and confirmed; the Meta Pixel/delivery-fee pattern is documented for other chains (Chick-fil-A, McDonald's, Panera) and only recommended for follow-up here, and arbitration/fees remain unconfirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Cheddar's payment breach and shared loyalty structure are stated as fact, but arbitration is unconfirmed and fees are unitemized.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Darden Restaurants (Olive Garden, LongHorn)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Darden Restaurants (Olive Garden, LongHorn) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Darden operates Olive Garden, LongHorn, Cheddar's, Yard House, Ruth's Chris and others under one parent with shared loyalty infrastructure, so a diner visiting what feel like different restaurants is building one profile. Restaurant point-of-sale systems have historically been among the most breached in retail because multi-location operators run heterogeneous terminals with inconsistent patching and card data sits directly on the device. Darden disclosed a payment card breach affecting Cheddar's locations.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 814, "_entity_id": 1106, "_entity_slug": "darden-restaurants-olive-garden-longhorn", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Yum China (KFC/Pizza Hut China)", "Category": "Food Services", "Terms & Conditions URL": "yumchina.com/terms-of-use", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "yumchina.com/privacy-policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; Yum China is an INDEPENDENT, separately-traded company (spun off from Yum Brands in 2016) operating KFC/Pizza Hut specifically within China — subject to Chinese data-localization/PIPL requirements rather than US consumer-protection frameworks for its China-based operations.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Yum China is a SEPARATE, independently-operated company from Yum Brands (see that row) despite the shared brand names — worth being precise about this distinction, since US consumers interacting with KFC/Pizza Hut in the US are dealing with Yum Brands, not Yum China.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-3] Yum China's huge loyalty program sits under China's PIPL and security rules, largely unresearched here.\nWHAT THE TERMS SAY: Yum China operates a very large digital ordering and loyalty program with hundreds of millions of members and is subject to China's Personal Information Protection Law alongside national security and intelligence law obligations; the tracker notes a US-language search systematically under-detects Chinese regulatory action.\nWHY IT MATTERS: This row should be treated as unexamined rather than clean -- a large loyalty program under a different legal regime than the one most of this tracker's other findings are drawn from, comparable in kind to obligations documented for other China-based companies elsewhere in the tracker.\n(evidence: SCARY, Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item -- nothing is confirmed this pass for Yum China specifically; data-sharing and arbitration are both explicitly unconfirmed, and the PIPL/opacity note is the sole substantive fact.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed this pass, and the tracker explicitly notes that US-language research under-detects Chinese regulatory action for this company.", "Exposure Score (0-100)": 8, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Yum China (KFC/Pizza Hut China)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Yum China (KFC/Pizza Hut China) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass in this pass's searching, and this row should be treated as unexamined rather than clean: Yum China is a separate listed company from Yum Brands, operates a very large digital ordering and loyalty programme with hundreds of millions of members, and is subject to China's Personal Information Protection Law alongside the national security and intelligence law obligations documented in the DeepSeek and Moonshot rows. A US-language search systematically under-detects Chinese regulatory action.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 815, "_entity_id": 1107, "_entity_slug": "yum-china-kfc-pizza-hut-china", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Yum Brands (KFC, Taco Bell, Pizza Hut)", "Category": "Food Services", "Terms & Conditions URL": "yum.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "yum.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "HISTORICAL CONFIRMED BREACH (Jan 2023): Yum Brands (parent of KFC, Taco Bell, and Pizza Hut) disclosed a ransomware attack that forced the temporary closure of approximately 300 UK restaurants and exposed some employee data — an operationally disruptive incident distinct from a typical customer-data exposure.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Given Yum Brands' three major fast-food chains, recommend a direct follow-up on whether any of KFC/Taco Bell/Pizza Hut's own mobile ordering apps have separately faced the tracking-pixel litigation documented for peer restaurant chains elsewhere in this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Yum Brands' January 2023 ransomware attack closed about 300 UK restaurants and exposed employee data.\nWHAT THE TERMS SAY: A January 2023 ransomware attack on Yum Brands (parent of KFC, Taco Bell and Pizza Hut) forced the temporary closure of approximately 300 UK restaurants and exposed some employee data, with the employee-data scope disclosed after the initial assessment.\nWHY IT MATTERS: This was an operationally disruptive incident distinct from typical customer-data exposure, and the scope grew after the company's first assessment -- a pattern the tracker notes shows up even more sharply elsewhere, as context.\n(evidence: Data Sharing, SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-4] Yum Brands' franchised structure means mobile-order data may sit with operators, not the national brand.\nWHAT THE TERMS SAY: Yum's brands run heavily franchised digital ordering, so customer data may sit with independent franchise operators rather than the national brand, per the tracker.\nWHY IT MATTERS: A customer assuming KFC, Taco Bell or Pizza Hut corporate holds their order data may actually have it held by a franchisee with its own, unknown security practices.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two Yum Brands-specific facts are stated; the tracking-pixel litigation is only recommended for follow-up (not confirmed) and the cross-tracker scope-creep comparison is another company's finding used only as context.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The 2023 ransomware breach is confirmed with a specific scope revision noted, but arbitration is unconfirmed and franchise data-holding is described only generally.", "Exposure Score (0-100)": 11, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Yum Brands (KFC, Taco Bell, Pizza Hut)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Yum Brands (KFC, Taco Bell, Pizza Hut) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The January 2023 ransomware attack forced Yum to close hundreds of restaurants in the UK, and the company later disclosed that employee data had been exposed as well - a scope revision after the initial assessment, which is the recurring pattern this tracker documents most sharply in the Aflac row (500 to 26.5 million). Yum's brands run heavily franchised digital ordering, so customer data may sit with independent operators rather than the national brand.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Consumer Goods & Food", "_row_id": 816, "_entity_id": 1108, "_entity_slug": "yum-brands-kfc-taco-bell-pizza-hut", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Nvidia", "Category": "Semiconductors and Other Electronic Components", "Terms & Conditions URL": "nvidia.com/en-us/about-nvidia/privacy-policy-legacy/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "nvidia.com/en-us/about-nvidia/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Nvidia's GeForce Experience and GeForce NOW collect GPU usage telemetry, game-performance data, and driver-crash reports. The consumer data footprint is moderate. The enterprise AI data footprint (through DGX Cloud and CUDA ecosystem) is enormous but governed by enterprise agreements, not consumer T&C.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Nvidia ToS, AAA rules, California law. 30-day opt-out. Nvidia's consumer products (GeForce GPUs, GeForce NOW cloud gaming, SHIELD devices) and its enterprise AI platform (DGX, H100/H200) are governed by different agreements — the consumer ToS covers gaming, the enterprise agreements cover AI infrastructure. Nvidia's $3.4T market cap (2024 peak) makes it the world's most valuable company.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Dollar Tree row (F500 Consumer Goods & Food tab) for the fullest treatment of this 'broken banner' litigation pattern, which is spreading across many sectors including Nvidia specifically.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Santa Clara", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "NVIDIA Corporation", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: NVIDIA Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] Nvidia was named in a Dec 2025 'broken banner' suit alleging its cookie choices didn't stop tracking.\nWHAT THE TERMS SAY: Nvidia was named in December 2025 in a 'broken banner' tracking-consent action alleging a cookie banner presented choices that did not actually govern what the site did, so a user who declined tracking was tracked anyway.\nWHY IT MATTERS: This is an allegation, not a confirmed finding, but if accurate it means declining tracking on Nvidia's site had no real effect.\n(evidence: SCARY, Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Nvidia requires arbitration under AAA rules for consumer products, separate from its enterprise AI agreements.\nWHAT THE TERMS SAY: Nvidia's consumer Terms of Service impose mandatory arbitration with a class-action waiver under AAA rules and California law, with a 30-day opt-out; this covers gaming products (GeForce, GeForce NOW, SHIELD) while its enterprise AI agreements (DGX, H100/H200) are governed separately.\nWHY IT MATTERS: Consumers of Nvidia's gaming hardware and cloud gaming service give up the right to sue or join a class action unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two items are distinct and stated; GeForce Experience telemetry collection is described as moderate with no specific troubling practice cited beyond what's already covered by the arbitration item, and fees are not itemized.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly detailed, but the broken-banner claim is explicitly an allegation and fees are not itemized.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Nvidia  <-  NVIDIA Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Nvidia you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nvidia was named in December 2025 in a 'broken banner' tracking-consent action - the allegation being that a cookie banner presented choices that did not actually govern what the site did, so a user who declined tracking was tracked anyway. That is a category worth naming precisely because it inverts the entire consent model: the interface exists, the button works, and the outcome is unchanged. Nvidia is otherwise a chip designer with minimal direct consumer data relationship - its consumer touchpoint is GeForce Experience and driver software, which does collect telemetry. Allegations, not findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Tech & Semiconductors", "_row_id": 817, "_entity_id": 1110, "_entity_slug": "nvidia", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Oracle", "Category": "Computer Software", "Terms & Conditions URL": "oracle.com/legal/terms.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "oracle.com/legal/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Oracle Health (Cerner) processes electronic health records for ~25% of US hospitals. Oracle's advertising division (Oracle Data Cloud, fmr. BlueKai/AddThis) was shut down in 2024 after data-brokerage practices drew regulatory scrutiny — but the underlying data may still reside in Oracle's systems.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Oracle ToS. 30-day opt-out. Oracle's consumer exposure is primarily through Oracle Health (fmr. Cerner, acquired 2022 for $28.3B) — the largest electronic health records vendor in the US after Epic. Oracle Cloud Infrastructure hosts consumer-facing apps. A February 2025 breach of Oracle Health/Cerner systems affected hospital patient data.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Estée Lauder row (F500 Consumer Brands tab) for the fullest treatment of this specific vulnerability's real-world impact — Oracle is the underlying SOFTWARE VENDOR whose product vulnerability enabled that entire wave of ~100 organizational breaches.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Austin", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Oracle Corporation", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Oracle Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] A February 2025 breach of Oracle Health/Cerner affected hospital patient data at a top US EHR vendor.\nWHAT THE TERMS SAY: A February 2025 breach of Oracle Health/Cerner systems affected hospital patient data; Oracle Health processes electronic health records for roughly 25% of US hospitals.\nWHY IT MATTERS: Patients never chose Oracle and can't evaluate its security, yet their hospital records may pass through Oracle's systems.\n(evidence: Arbitration, Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] An Oracle E-Business Suite flaw (CVE-2025-61882) exposed payroll and HR data at employers using it.\nWHAT THE TERMS SAY: CVE-2025-61882 in Oracle's E-Business Suite affects back-office software running payroll, HR and financial records for a large number of employers.\nWHY IT MATTERS: The people exposed are employees of Oracle's business customers -- with no relationship to Oracle, no ability to evaluate its security, and no notice that their employer's HR system runs on an Oracle product.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[DATA_SALE · FL-2] Oracle shut down its ad-data brokerage in 2024, but the underlying data may still sit in its systems.\nWHAT THE TERMS SAY: Oracle's advertising division (Oracle Data Cloud, formerly BlueKai/AddThis) was shut down in 2024 after its data-brokerage practices drew regulatory scrutiny -- but the tracker notes the underlying data may still reside in Oracle's systems.\nWHY IT MATTERS: Shutting down the storefront doesn't necessarily mean previously brokered consumer data was deleted, and Oracle is separately named as one of the largest data brokers in the world, a role no consumer ever consented to.\n(evidence: Data Sharing, SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Oracle Health breach and EBS vulnerability are confirmed facts, but the fate of the shuttered ad-data business's underlying data is unconfirmed and fees are not itemized.", "Exposure Score (0-100)": 44, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 15, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 15/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Oracle  <-  Oracle Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Oracle you gave up your personal data sold onward, your data shared corporate-wide, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "CVE-2025-61882 in Oracle's E-Business Suite is the row's substance, and the reason it matters to consumers who have never heard of EBS is that it is back-office software running payroll, HR and financial records for a very large number of employers. A vulnerability there exposes employees, not customers - people with no relationship to Oracle, no ability to evaluate its security, and no notice that their employer's HR system is an Oracle product. Oracle is separately one of the largest data brokers in the world through its advertising and data cloud businesses, a fact that receives far less attention than its database business and that no consumer has ever consented to.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Tech & Semiconductors", "_row_id": 818, "_entity_id": 1112, "_entity_slug": "oracle", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "IBM", "Category": "Information Technology Services", "Terms & Conditions URL": "ibm.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "ibm.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "IBM appears in MULTIPLE roles across this tracker: (1) as a NAMED VICTIM whose credentials were exposed in the Cisco/Red Hat GitLab breach (see Cisco row, this same tab); (2) as the BUSINESS ASSOCIATE managing Johnson & Johnson's Janssen CarePath patient-assistance platform, which was itself breached in 2023, resulting in IBM being named as a CO-DEFENDANT in the resulting patient class action (see Johnson & Johnson row, F500 Pharma & Biotech tab).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — IBM primarily serves enterprise/government customers rather than individual consumers directly.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "IBM's dual role — both as a breach VICTIM (Cisco/GitLab) and as a business associate whose OWN platform-management failure exposed a THIRD PARTY's patients (J&J/Janssen CarePath) — illustrates how large enterprise IT vendors can appear on both sides of the same broader security landscape depending on which specific engagement is examined.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Armonk", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-1] IBM was named co-defendant in the patient suit over the 2023 Janssen CarePath breach it managed.\nWHAT THE TERMS SAY: IBM managed Johnson & Johnson's Janssen CarePath patient-assistance platform as a business associate; that platform was breached in 2023, and IBM was named as a co-defendant in the resulting patient class action.\nWHY IT MATTERS: Patients using a J&J patient-assistance program may not know IBM was the vendor actually running the platform, or that IBM itself faces legal liability for the breach.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] IBM's own credentials were exposed in the Cisco/Red Hat GitLab breach.\nWHAT THE TERMS SAY: IBM appears as a named victim whose credentials were exposed in the Cisco/Red Hat GitLab breach documented elsewhere in this tracker.\nWHY IT MATTERS: IBM sits on both sides of the security landscape in this tracker -- as a victim of one incident and as the vendor whose platform-management failure exposed a third party's patients in another.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct facts are stated; arbitration is not applicable since IBM primarily serves enterprise/government customers, and fees are not itemized.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "IBM's dual breach-victim and co-defendant roles are stated as fact, but arbitration terms are unconfirmed since IBM has no direct consumer relationship, and fees are not itemized.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "IBM  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, IBM takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "IBM appears in this tracker in multiple roles simultaneously - as a breach victim, as a vendor whose software sits inside other companies' incidents, and as a security provider selling the remedy. That triple position is the finding, and it generalises: in enterprise technology the same handful of firms are the attack surface, the incident responder and the auditor, which makes genuinely independent assessment of any of them difficult to obtain. IBM has essentially no direct consumer relationship today; its consumer relevance is entirely through systems that hold your data on someone else's behalf.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Tech & Semiconductors", "_row_id": 819, "_entity_id": 1113, "_entity_slug": "ibm", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cisco Systems", "Category": "Network and Other Communications Equipment", "Terms & Conditions URL": "cisco.com/c/en/us/about/legal/terms-conditions.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "cisco.com/c/en/us/about/legal/privacy-full.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Cisco processes network traffic metadata through its enterprise products — routers, firewalls, and Umbrella DNS see substantial internet traffic. Consumer data collection is primarily through Webex (meeting recordings, transcripts) and Meraki (home network traffic patterns).", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Cisco EULA/ToS, AAA rules. 30-day opt-out. Cisco's consumer products include Meraki home networking and Webex (consumer version). Enterprise products (routers, switches, security) governed by separate commercial agreements. Cisco acquired Duo Security (2018, $2.35B) and Splunk (2024, $28B).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The GitLab-repository breach specifically naming IBM, American Express, NSA, and DoD credentials illustrates a genuinely serious SUPPLY-CHAIN security concern extending into national-security-adjacent infrastructure — worth flagging distinctly from the more typical consumer-data-exposure pattern found elsewhere in this tracker.\n\nSALESFORCE / SHINYHUNTERS CAMPAIGN MASTER CROSS-REFERENCE (verified this pass - the tracker's single biggest connective thread): PHASE 1, vishing (June-Aug 2025, tracked by Google Threat Intelligence as UNC6040/UNC6240): attackers phoned employees posing as IT or HR staff, walked them to Salesforce's connected-app setup page, and had them enter a code that authorised a malicious fake Data Loader app. Confirmed targets included Google and Workday. Victims from this wave include Adidas, Allianz Life, Qantas (cross-ref Global Airlines tab). PHASE 2, Salesloft Drift supply chain (Aug 2025, UNC6395): attacker had access to Salesloft's GitHub from as early as March 2025, ran TruffleHog to find secrets, reached Drift's AWS environment and stole OAuth tokens - reaching roughly 760 downstream Salesforce customer organisations, with reporting citing on the order of 1.5 billion records. Exfiltration began Aug 12 2025. Attackers ran SOQL queries hunting AWS keys, Snowflake tokens and stored passwords, then deleted their query jobs to slow investigators. Salesforce blocked Drift from Salesforce, Slack and Pardot on Aug 28. PHASE 3, Gainsight (Nov 2025): same play, different vendor; 200+ Salesforce instances; Salesforce pulled Gainsight-published apps. PHASE 4 (2026): Klue (June 2026) and Anodot (April 2026), the latter cascading to Rockstar Games (78.6M records), Vimeo (119K), Zara/Inditex (197K) and Woflow (reaching DoorDash, Walmart, Uber). Grubhub confirmed Jan 2026. Across the campaign, more than 1,000 organisations were breached. FBI issued a FLASH alert Sept 12 2025. Salesforce faced 14 lawsuits by late Sept 2025 and reportedly refused to pay a ransom in Oct 2025. KEY POINT FOR THE TRACKER: no zero-day and no malware was required at any stage - the campaign ran on social engineering, OAuth trust and integration sprawl. Whenever a company row in any tab cites a '2025-26 breach' with no named technical exploit, check it against this campaign before writing it up as an independent incident.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Jose", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Cisco Systems, Inc.", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Cisco Systems, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Cisco was breached in the 2025 Salesforce social-engineering campaign via a phone call, not an exploit.\nWHAT THE TERMS SAY: Cisco was among the named victims of the 2025 Salesforce social-engineering campaign, breached by attackers telephoning employees and getting them to authorize a malicious app -- no exploit or malware was used.\nWHY IT MATTERS: This shows a security-focused company can be compromised through simple social engineering rather than a technical weakness, and the tracker notes Cisco separately had a second incident.\n(evidence: SCARY, Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] A separate Cisco GitLab-repository breach exposed credentials for IBM, American Express, NSA and DoD.\nWHAT THE TERMS SAY: The tracker documents a separate Cisco GitLab-repository breach naming IBM, American Express, NSA, and DoD credentials among those exposed, describing it as a genuinely serious supply-chain security concern extending into national-security-adjacent infrastructure.\nWHY IT MATTERS: This is distinct from the more typical consumer-data-exposure pattern found elsewhere in the tracker -- a security-infrastructure failure with national-security implications.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct incidents are attributed to Cisco itself; the broader Salesforce/ShinyHunters campaign narrative in the Notes field is largely a cross-cutting master reference covering many other companies, not an additional Cisco-specific fact, and fees are not itemized.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Both Cisco incidents are stated as confirmed fact, but fees are unitemized and the precise scope of the GitLab-repo exposure isn't detailed.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Cisco Systems  <-  Cisco Systems, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Cisco Systems you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Cisco was among the named victims of the 2025 Salesforce social-engineering campaign - the security company was breached by people telephoning its employees and asking them to click something. No exploit, no malware. That is not a criticism unique to Cisco; it is the point of the entire campaign, which reached more than a thousand organisations including Google and Workday by exploiting trust in a phone call and an OAuth prompt rather than any technical weakness. Cisco also had a second separate incident. For consumers, Cisco's relevance is infrastructure: its equipment carries traffic for a large share of the internet and for most corporate networks.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Tech & Semiconductors", "_row_id": 820, "_entity_id": 1114, "_entity_slug": "cisco-systems", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Intel", "Category": "Semiconductors and Other Electronic Components", "Terms & Conditions URL": "See Intel's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Intel's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Intel's consumer telemetry is limited compared to software companies — processor usage data, driver updates, and compatibility reports. Intel's Connected Home division (Wind River, McAfee — since divested) historically collected more granular consumer data.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Intel ToS. 30-day opt-out. Intel's consumer-facing products include processors (marketed directly via 'Intel Inside'), Intel Arc GPUs, and Intel Unison app. The Spectre/Meltdown vulnerability disclosures (2018) affected billions of Intel processors — the arbitration clause would govern individual consumer disputes over the vulnerability, though the major lawsuits were class actions (consolidated in N.D. Cal.).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Santa Clara", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Intel Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Intel Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] Intel's Spectre/Meltdown vulnerabilities affected billions of chips with no way for consumers to act.\nWHAT THE TERMS SAY: The Spectre/Meltdown speculative-execution vulnerabilities, disclosed in 2018, affected essentially every modern Intel processor and could not be fully fixed in software; major lawsuits were consolidated as class actions in N.D. Cal.\nWHY IT MATTERS: The tracker describes this as a category of consumer exposure with no notification requirement, no settlement, and no way for an individual to act; the arbitration clause would technically govern individual consumer disputes over the vulnerability, though the major lawsuits were consolidated as class actions in N.D. Cal.\n(evidence: Arbitration, SCARY; Stated in tracker (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one substantive item; nothing consumer-facing is confirmed beyond the historical Spectre/Meltdown vulnerability, and Intel's telemetry footprint is explicitly described as limited.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and the Spectre/Meltdown history are clearly stated, but nothing consumer-facing is confirmed for this pass beyond that historical episode.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Intel  <-  Intel Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Intel you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass. The structural note that belongs on the semiconductor rows in this tab: chip makers hold almost no personal data and sit almost entirely outside consumer privacy law, but they determine what security is possible for everyone downstream. The Spectre and Meltdown class of speculative-execution vulnerabilities affected essentially every modern processor and could not be fully fixed in software - which is a category of consumer exposure with no notification requirement, no settlement, and no way for an individual to act. Recorded as an honest structural entry rather than a manufactured finding.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Tech & Semiconductors", "_row_id": 821, "_entity_id": 1116, "_entity_slug": "intel", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Qualcomm", "Category": "Semiconductors and Other Electronic Components", "Terms & Conditions URL": "See Qualcomm's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Qualcomm's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B chip/patent company. Qualcomm processors include always-on sensor hubs that can process audio, motion, and location data at the hardware level — but this data is governed by the phone manufacturer's privacy policy, not Qualcomm's.", "Arbitration / Class Action Waiver": "B2B — Qualcomm primarily sells chips and patents to device manufacturers, not consumers. Consumer exposure through Qualcomm Snapdragon processors embedded in Android phones, but the consumer relationship is with the phone manufacturer (Samsung, Google), not Qualcomm directly.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Diego", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] Qualcomm's baseband firmware is a privileged, opaque layer neither users nor phone makers fully control.\nWHAT THE TERMS SAY: Qualcomm's modems and system-on-chip designs include baseband processors that run their own firmware largely outside the operating system's visibility; security researchers have long noted this is a privileged, opaque layer neither the user nor the phone maker fully controls.\nWHY IT MATTERS: No finding is asserted, but this hardware-level opacity sits underneath every phone using a Qualcomm chip, and the consumer's contractual relationship is with the phone maker, not Qualcomm.\n(evidence: SCARY, Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item; Qualcomm is B2B with no direct consumer contract, and no consumer-facing lawsuit, breach, or arbitration term is confirmed this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer contract exists with Qualcomm directly, and the one stated fact is about baseband opacity rather than a confirmed practice or incident.", "Exposure Score (0-100)": 2, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Qualcomm  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass. Qualcomm's consumer relevance is that its modems and system-on-chip designs are inside a very large share of the world's smartphones, including baseband processors that run their own firmware largely outside the operating system's visibility. Security researchers have long noted that the baseband is a privileged, opaque layer that neither the user nor the phone maker fully controls. No finding is asserted; the opacity is the note worth keeping.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Tech & Semiconductors", "_row_id": 822, "_entity_id": 1117, "_entity_slug": "qualcomm", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Broadcom", "Category": "Semiconductors and Other Electronic Components", "Terms & Conditions URL": "See Broadcom's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Broadcom's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named consumer-facing data-privacy lawsuit or breach; most semiconductor/component manufacturers sell primarily to OTHER BUSINESSES (device makers, cloud providers) rather than directly to consumers, meaning individual exposure is typically indirect (as a user of a device containing this company's chips) rather than through a direct account relationship — recommend checking specifically for any consumer-facing software/account products this company operates (e.g., driver-download portals, developer accounts).", "Arbitration / Class Action Waiver": "Primarily B2B — Broadcom acquired VMware (2023, $69B). Consumer exposure through Symantec (Norton antivirus, acquired via the CA Technologies deal). Norton's consumer ToS contain mandatory arbitration with 30-day opt-out.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Palo Alto", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Broadcom Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Broadcom Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Broadcom's Norton antivirus consumer terms carry mandatory arbitration with a 30-day opt-out.\nWHAT THE TERMS SAY: Broadcom's consumer exposure runs through Symantec's Norton antivirus (acquired via the CA Technologies deal); Norton's consumer Terms of Service contain mandatory arbitration with a 30-day opt-out.\nWHY IT MATTERS: This is Broadcom's only clearly consumer-facing arbitration exposure, since the rest of the company (chips, VMware) sells to businesses, not individuals.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is genuinely consumer-facing; the VMware licensing-cost story is explicitly a B2B pricing matter, not a consumer privacy finding, per the tracker.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Norton arbitration term is clearly stated, but the rest of Broadcom's consumer data practices are unconfirmed and fees are unitemized.", "Exposure Score (0-100)": 17, "Exposure Band": "Low", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Broadcom  <-  Broadcom Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Broadcom you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass. Broadcom's more consequential consumer effect is commercial rather than technical: its acquisition of VMware and subsequent licensing changes materially raised costs for organisations running virtualised infrastructure, which flows through to the price and viability of services those organisations provide. That is a B2B pricing story, recorded honestly as such, not a privacy finding dressed up as one.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Tech & Semiconductors", "_row_id": 823, "_entity_id": 1119, "_entity_slug": "broadcom", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Micron Technology", "Category": "Semiconductors and Other Electronic Components", "Terms & Conditions URL": "See Micron Technology's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Micron Technology's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named consumer-facing data-privacy lawsuit or breach; most semiconductor/component manufacturers sell primarily to OTHER BUSINESSES (device makers, cloud providers) rather than directly to consumers, meaning individual exposure is typically indirect (as a user of a device containing this company's chips) rather than through a direct account relationship — recommend checking specifically for any consumer-facing software/account products this company operates (e.g., driver-download portals, developer accounts).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Boise", "HQ State": "Idaho", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Idaho' is a non-DMV US state", "Parent / Ultimate Owner": "Micron Technology, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Non-US entity (Idaho) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Idaho. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[RETENTION_PERIOD · FL-2] No storage maker's terms address data remanence -- recoverable data left on discarded drives and phones.\nWHAT THE TERMS SAY: The tracker notes data remanence -- the persistence of recoverable data on discarded drives and phones -- remains a real and badly understood risk, and no component maker's terms address what happens to the device after it's thrown away.\nWHY IT MATTERS: Consumers who discard old phones or drives may leave recoverable personal data behind with no company's terms addressing the gap.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item, and it is an industry-wide structural note (data remanence) rather than a Micron-specific practice; no consumer lawsuit, breach, or confirmed arbitration term exists for Micron itself this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed for Micron specifically; the one stated point is a structural industry-wide risk, not a company practice.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Micron Technology  <-  Micron Technology, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Micron Technology takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass. Micron makes memory and storage components sold overwhelmingly into other manufacturers' products, so the consumer almost never has a direct relationship. The one genuine consumer-adjacent note across all storage makers is that data remanence - the persistence of recoverable data on discarded drives and phones - remains a real and badly understood risk, and no component maker's terms address what happens to the device after you throw it away.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Tech & Semiconductors", "_row_id": 824, "_entity_id": 1121, "_entity_slug": "micron-technology", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Advanced Micro Devices", "Category": "Semiconductors and Other Electronic Components", "Terms & Conditions URL": "See Advanced Micro Devices's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Advanced Micro Devices's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B semiconductor company — sells chips/components to device manufacturers. Consumer data is collected by the DEVICE MAKER (Samsung, Apple, etc.), not the chip supplier. Qualcomm/Intel/AMD processors execute on-device data processing but the data governance is the device manufacturer's responsibility, not the chipmaker's.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Santa Clara", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Advanced Micro Devices, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Advanced Micro Devices, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] Speculative-execution flaws in this class forced microcode fixes with performance costs users never accepted.\nWHAT THE TERMS SAY: The tracker notes AMD holds essentially no personal data while determining the security floor for every system built on its processors, and that speculative-execution and side-channel vulnerabilities in this class have repeatedly required firmware and microcode mitigations carrying performance costs users are never asked to consent to.\nWHY IT MATTERS: This is a category of consumer exposure with no notification requirement, no settlement, and no way for an individual to act, per the tracker.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item; AMD is B2B with no direct consumer contract, so this structural chip-security note is the sole stated fact.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer contract exists with AMD directly, and no confirmed incident or lawsuit is cited beyond the general speculative-execution risk.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Advanced Micro Devices  <-  Advanced Micro Devices, Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "AMD holds essentially no personal data while determining the security floor for every system built on its processors. Speculative-execution and side-channel vulnerabilities in this class have repeatedly required firmware and microcode mitigations carrying performance costs users are never asked to consent to — a category of consumer exposure with no notification requirement, no settlement and no way for an individual to act.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Tech & Semiconductors", "_row_id": 825, "_entity_id": 1123, "_entity_slug": "advanced-micro-devices", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "HP", "Category": "Computers, Office Equipment", "Terms & Conditions URL": "See HP's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See HP's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named consumer-facing data-privacy lawsuit or breach; most semiconductor/component manufacturers sell primarily to OTHER BUSINESSES (device makers, cloud providers) rather than directly to consumers, meaning individual exposure is typically indirect (as a user of a device containing this company's chips) rather than through a direct account relationship — recommend checking specifically for any consumer-facing software/account products this company operates (e.g., driver-download portals, developer accounts).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Palo Alto", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "HP Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: HP Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[UNILATERAL_CHANGES · FL-4] HP printer firmware updates reportedly disable third-party ink cartridges on printers already owned.\nWHAT THE TERMS SAY: HP's printer business has generated sustained consumer complaint and litigation over firmware updates that disable third-party ink cartridges, and over subscription ink programs whose cancellation terms and printer-disabling behavior surprised customers.\nWHY IT MATTERS: A device bought outright can be changed by an update the customer never chose, to enforce a commercial preference they never agreed to -- exactly the kind of terms-and-conditions problem this tracker exists to surface.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item, and it is explicitly unconfirmed with no specific case cited this pass; data-sharing, breach, and arbitration status are all unconfirmed as well.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is independently confirmed this pass; the printer-firmware finding is described as a pattern without a specific cited case.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "HP  <-  HP Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, HP takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing independently confirmed this pass, and the honest finding for HP is commercial rather than privacy: HP's printer business has generated sustained consumer complaint and litigation over firmware updates that disable third-party ink cartridges and over subscription ink programmes whose cancellation terms and printer-disabling behaviour surprised customers. That is a terms-and-conditions finding of exactly the kind this tracker exists to surface - a device you bought outright, changed by an update you did not choose, to enforce a commercial preference you never agreed to. No specific case is cited because none was verified this pass; recommend a direct follow-up.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Tech & Semiconductors", "_row_id": 826, "_entity_id": 1125, "_entity_slug": "hp", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Hewlett Packard (HPE)", "Category": "Computers, Office Equipment", "Terms & Conditions URL": "See Hewlett Packard (HPE)'s own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Hewlett Packard (HPE)'s own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named consumer-facing data-privacy lawsuit or breach; most semiconductor/component manufacturers sell primarily to OTHER BUSINESSES (device makers, cloud providers) rather than directly to consumers, meaning individual exposure is typically indirect (as a user of a device containing this company's chips) rather than through a direct account relationship — recommend checking specifically for any consumer-facing software/account products this company operates (e.g., driver-download portals, developer accounts).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — HPE has no meaningful consumer terms; the SCARY note exists only to distinguish HPE from HP Inc., and data-sharing/arbitration are both unconfirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No meaningful consumer terms exist for HPE, and nothing else is confirmed this pass.", "Exposure Score (0-100)": 2, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Hewlett Packard (HPE)  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass. HPE is the enterprise half of the old Hewlett-Packard - servers, storage and networking sold to businesses - and has no meaningful consumer terms. Worth noting only to prevent confusion with HP Inc., which does have a consumer relationship through PCs and printers; the two are separate companies with separate policies and separate records, and consumers searching for one routinely find the other.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Tech & Semiconductors", "_row_id": 827, "_entity_id": 1126, "_entity_slug": "hewlett-packard-hpe", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Salesforce", "Category": "Computer Software", "Terms & Conditions URL": "salesforce.com/company/legal/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "salesforce.com/company/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "THE SINGLE MOST CONSEQUENTIAL SHARED VULNERABILITY DOCUMENTED THROUGHOUT THIS ENTIRE 640+ COMPANY TRACKER: starting mid-2025, the ShinyHunters/Scattered Spider extortion collective (tracked by Google as UNC6040) ran a sustained social-engineering campaign against Salesforce CUSTOMERS — voice-phishing employees at English-speaking multinational branches into installing a fake replica of Salesforce's own 'Data Loader' app, then exfiltrating data at scale. The attackers themselves claimed to have compromised 91+ organizations worldwide; independent trackers estimate the true 'blast radius' at OVER 700 ORGANIZATIONS once misconfigured 'Experience Cloud' guest-user sites are included. CONFIRMED NAMED VICTIMS documented elsewhere in this same tracker include: Google, Cisco, TransUnion, Adidas, Farmers Insurance, Qantas, Air France-KLM, Workday, Amtrak, FedEx, Advance Auto Parts, CarMax, Match Group, Grubhub, and Chanel/Dior/Louis Vuitton/Tiffany & Co./Cartier/Pandora (documented via various rows throughout this tracker) — spanning airlines, luxury retail, insurance, telecom, HR software, and delivery services simultaneously. ShinyHunters demanded a ransom (deadline Oct 10, 2025) threatening to leak 1 BILLION total records; Salesforce REFUSED to pay, and the FBI seized a BreachForums domain the group used for extortion — though partial data from at least 6 companies (Qantas, Gap, Vietnam Airlines, Albertsons, FujiFilm, Engie Resources) was still leaked afterward.", "Arbitration / Class Action Waiver": "Salesforce itself faces AT LEAST 14 LAWSUITS arising from this campaign; Salesforce's own legal position is that its CORE PLATFORM was never directly breached — the exposures resulted from customers' own security choices (phished employees, misconfigured guest-user permissions) rather than a Salesforce vulnerability — a technically defensible distinction that nonetheless doesn't change the real-world exposure customers experienced.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "GIVEN HOW MANY SEPARATE ROWS THROUGHOUT THIS ENTIRE 640+ COMPANY TRACKER TRACE BACK TO THIS SAME UNDERLYING CAMPAIGN, this is arguably the single most important CROSS-CUTTING finding in the whole audit — worth reading this row alongside every other 'ShinyHunters' or 'Scattered Spider' mention elsewhere in this tracker as ONE CONNECTED STORY about social-engineering attacks against a shared CRM platform, rather than dozens of unrelated incidents.\n\nSALESFORCE / SHINYHUNTERS CAMPAIGN MASTER CROSS-REFERENCE (verified this pass - the tracker's single biggest connective thread): PHASE 1, vishing (June-Aug 2025, tracked by Google Threat Intelligence as UNC6040/UNC6240): attackers phoned employees posing as IT or HR staff, walked them to Salesforce's connected-app setup page, and had them enter a code that authorised a malicious fake Data Loader app. Confirmed targets included Google and Workday. Victims from this wave include Adidas, Allianz Life, Qantas (cross-ref Global Airlines tab). PHASE 2, Salesloft Drift supply chain (Aug 2025, UNC6395): attacker had access to Salesloft's GitHub from as early as March 2025, ran TruffleHog to find secrets, reached Drift's AWS environment and stole OAuth tokens - reaching roughly 760 downstream Salesforce customer organisations, with reporting citing on the order of 1.5 billion records. Exfiltration began Aug 12 2025. Attackers ran SOQL queries hunting AWS keys, Snowflake tokens and stored passwords, then deleted their query jobs to slow investigators. Salesforce blocked Drift from Salesforce, Slack and Pardot on Aug 28. PHASE 3, Gainsight (Nov 2025): same play, different vendor; 200+ Salesforce instances; Salesforce pulled Gainsight-published apps. PHASE 4 (2026): Klue (June 2026) and Anodot (April 2026), the latter cascading to Rockstar Games (78.6M records), Vimeo (119K), Zara/Inditex (197K) and Woflow (reaching DoorDash, Walmart, Uber). Grubhub confirmed Jan 2026. Across the campaign, more than 1,000 organisations were breached. FBI issued a FLASH alert Sept 12 2025. Salesforce faced 14 lawsuits by late Sept 2025 and reportedly refused to pay a ransom in Oct 2025. KEY POINT FOR THE TRACKER: no zero-day and no malware was required at any stage - the campaign ran on social engineering, OAuth trust and integration sprawl. Whenever a company row in any tab cites a '2025-26 breach' with no named technical exploit, check it against this campaign before writing it up as an independent incident.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://cloudsecurityalliance.org/blog/2025/09/25/the-salesloft-drift-oauth-supply-chain-attack-cross-industry-lessons-in-third-party-access-visibility", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Salesforce, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Salesforce, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Attackers used Salesforce's connected-app authorization flow, not an exploit; trackers estimate 700+ orgs hit.\nWHAT THE TERMS SAY: Starting mid-2025, attackers phoned Salesforce customers' employees, walked them to Salesforce's connected-app setup page, and had them enter a code authorizing a fake 'Data Loader' app; the attackers claimed 91+ compromised organizations, while independent trackers estimate the blast radius at over 700 organizations once misconfigured 'Experience Cloud' guest-user sites are included, among them Google, Cisco, Adidas, Qantas and Workday named elsewhere in this tracker.\nWHY IT MATTERS: No zero-day or malware was required at any stage -- the campaign ran entirely on social engineering, OAuth trust and integration sprawl, meaning any Salesforce customer's employees were a potential entry point.\n(evidence: Data Sharing, Notes, SCARY; Stated in tracker (fidelity pass 1: Overstated corrected) (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-4] Compromised vendor Salesloft let attackers steal OAuth tokens reaching ~760 downstream Salesforce customers.\nWHAT THE TERMS SAY: Attackers had access to Salesloft's GitHub from as early as March 2025, used it to reach Salesloft Drift's AWS environment, and stole OAuth tokens that reached approximately 760 downstream Salesforce customer organizations -- reporting cites on the order of 1.5 billion records -- before Salesforce blocked Drift from Salesforce, Slack and Pardot on Aug 28, 2025.\nWHY IT MATTERS: None of the affected customers chose Salesloft directly -- the security boundary determining their exposure sat several companies removed from the platform they actually gave their data to.\n(evidence: Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[LIABILITY_CAP_INDEMNITY · FL-1] Salesforce says its core platform was never breached, placing blame on customers' own phished employees.\nWHAT THE TERMS SAY: Salesforce's legal position is that its core platform was never directly breached and that exposures resulted from customers' own security choices; the company faces at least 14 lawsuits from the campaign and reportedly refused to pay ShinyHunters' ransom demand (deadline Oct 10, 2025) after the group threatened to leak 1 billion records.\nWHY IT MATTERS: The tracker calls this a technically defensible distinction that doesn't change the real-world exposure customers experienced -- and partial data from at least six companies leaked anyway despite Salesforce's refusal to pay.\n(evidence: Arbitration, Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The campaign's mechanism, timeline, named victims, and figures are documented in specific, dated detail rather than hedged or unconfirmed.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 20/20 (severity5+20, litigation+2) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Salesforce  <-  Salesforce, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Salesforce you gave up your data shared corporate-wide and your right to meaningful compensation. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "This is the most consequential single row in the tracker, because it is not one company's breach but the mechanism behind dozens of them. Attackers phoned employees pretending to be IT support, walked them to Salesforce's connected-app page and had them type a code that authorised a malicious app - and separately compromised the GitHub account of an integration vendor, Salesloft, to steal OAuth tokens that reached roughly 760 downstream Salesforce customers at once. More than a thousand organisations were breached across the campaign, with reporting citing on the order of 1.5 billion records. No zero-day and no malware were required at any point. The victims a consumer would recognise - Qantas, Adidas, Allianz Life, Google, Workday, Stellantis, Gucci, Grubhub - had no common vendor a customer could see, and none of them chose Salesloft. This is what concentrated SaaS infrastructure means in practice: the security boundary that determines your exposure is several companies removed from the one you gave your data to.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Tech & Semiconductors", "_row_id": 828, "_entity_id": 1127, "_entity_slug": "salesforce", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "ServiceNow", "Category": "Computer Software", "Terms & Conditions URL": "See ServiceNow's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See ServiceNow's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named consumer-facing data-privacy lawsuit or breach; most semiconductor/component manufacturers sell primarily to OTHER BUSINESSES (device makers, cloud providers) rather than directly to consumers, meaning individual exposure is typically indirect (as a user of a device containing this company's chips) rather than through a direct account relationship — recommend checking specifically for any consumer-facing software/account products this company operates (e.g., driver-download portals, developer accounts).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] ServiceNow holds employee and customer records for many orgs, invisible to the people it holds data on.\nWHAT THE TERMS SAY: ServiceNow occupies the same category as Salesforce -- a workflow platform holding employee and customer records for a very large number of organizations -- and the tracker notes the relevant risk question for platforms in this category is OAuth and third-party integration governance, not the platform's own perimeter.\nWHY IT MATTERS: The Salesforce campaign documented elsewhere in this tab shows what that kind of concentration costs when it fails; nothing is confirmed for ServiceNow specifically, so this row should be read as unverified rather than clean.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item, and it is explicitly a structural comparison to the Salesforce campaign rather than a confirmed ServiceNow-specific incident; no lawsuit, breach, or arbitration term is confirmed this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed for ServiceNow this pass; the entry is explicitly unverified rather than clean.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "ServiceNow  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, ServiceNow takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass. ServiceNow occupies the same category as Salesforce - a workflow platform holding employee and customer records for a very large number of organisations, invisible to the people whose data it holds. The Salesforce campaign documented in this tab is the demonstration of what that concentration costs when it fails, and the relevant question for every platform in this category is OAuth and third-party integration governance rather than the platform's own perimeter. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Tech & Semiconductors", "_row_id": 829, "_entity_id": 1128, "_entity_slug": "servicenow", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Palo Alto Networks", "Category": "Network and Other Communications Equipment", "Terms & Conditions URL": "See Palo Alto Networks's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Palo Alto Networks's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named consumer-facing data-privacy lawsuit or breach; most semiconductor/component manufacturers sell primarily to OTHER BUSINESSES (device makers, cloud providers) rather than directly to consumers, meaning individual exposure is typically indirect (as a user of a device containing this company's chips) rather than through a direct account relationship — recommend checking specifically for any consumer-facing software/account products this company operates (e.g., driver-download portals, developer accounts).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — No finding is asserted against Palo Alto Networks itself this pass; the SCARY note is general commentary on security vendors as targets (illustrated concretely by the separate Cisco row), and data-sharing/arbitration are both unconfirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed for Palo Alto Networks this pass, and no company-specific incident is asserted.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Palo Alto Networks  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Palo Alto Networks takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass. The note worth recording is the one the Cisco row makes concrete: security vendors are themselves targets, and a compromise at a security company propagates differently from one anywhere else because its products sit in a privileged position inside customer networks. No finding is asserted against Palo Alto; the structural exposure is real and is why supply-chain compromise of security tooling is treated as a distinct risk category.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Tech & Semiconductors", "_row_id": 830, "_entity_id": 1129, "_entity_slug": "palo-alto-networks", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Synopsys", "Category": "Software", "Terms & Conditions URL": "See Synopsys's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Synopsys's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B semiconductor company — sells chips/components to device manufacturers. Consumer data is collected by the DEVICE MAKER (Samsung, Apple, etc.), not the chip supplier. Qualcomm/Intel/AMD processors execute on-device data processing but the data governance is the device manufacturer's responsibility, not the chipmaker's.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is a B2B EDA software company with no consumer relationship; the data-sharing text is generic semiconductor-industry boilerplate (consumer data is collected by device makers, not chipmakers), and arbitration is only described as 'expected,' not confirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=N; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist to locate for this B2B chip-design software company, and the only other item (arbitration) is merely 'expected,' not confirmed.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Synopsys  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Electronic design automation software used to design chips — about as far from a consumer relationship as this tracker reaches. The one genuinely interesting note: Synopsys also owned a major application security testing business (since divested to Black Duck), meaning the same company sold both chip design tools and the software used to audit other companies' code for vulnerabilities.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Tech & Semiconductors", "_row_id": 831, "_entity_id": 1130, "_entity_slug": "synopsys", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Arista Networks", "Category": "Technology Hardware", "Terms & Conditions URL": "See Arista Networks's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Arista Networks's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B semiconductor company — sells chips/components to device manufacturers. Consumer data is collected by the DEVICE MAKER (Samsung, Apple, etc.), not the chip supplier. Qualcomm/Intel/AMD processors execute on-device data processing but the data governance is the device manufacturer's responsibility, not the chipmaker's.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Santa Clara", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Arista Networks, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Arista Networks, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is a B2B networking-hardware company with no consumer relationship; the SCARY field states its switches 'handle everyone's data in transit and retain none of it,' and arbitration is only described as 'expected,' not confirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=N; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist for this enterprise networking-hardware supplier; the tracker itself notes the real risk category is supply-chain firmware integrity, not privacy.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Arista Networks  <-  Arista Networks, Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Networking hardware for data centres and large enterprises. Arista's switches move traffic inside the facilities described in the Equinix row, which means they handle everyone's data in transit and retain none of it. The genuine risk category here is supply-chain firmware integrity, not privacy.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Tech & Semiconductors", "_row_id": 832, "_entity_id": 1132, "_entity_slug": "arista-networks", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Marvell Technology", "Category": "Semiconductors", "Terms & Conditions URL": "See Marvell Technology's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Marvell Technology's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B semiconductor company — sells chips/components to device manufacturers. Consumer data is collected by the DEVICE MAKER (Samsung, Apple, etc.), not the chip supplier. Qualcomm/Intel/AMD processors execute on-device data processing but the data governance is the device manufacturer's responsibility, not the chipmaker's.", "Arbitration / Class Action Waiver": "B2B — semiconductor company. No consumer-facing products.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Wilmington", "HQ State": "Delaware", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Delaware' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Delaware Division of Corporations Entity Search — icis.corp.delaware.gov/ecorp/entitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row explicitly states no consumer-facing products exist for this data-infrastructure semiconductor company; the data-sharing text is generic industry boilerplate and no company-specific consumer terms are stated.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or terms exist; the tracker states explicitly there are no consumer-facing products.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Marvell Technology  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Data infrastructure semiconductors sold to equipment manufacturers — storage controllers, networking silicon, custom compute for AI datacentres. No consumer relationship. Its storage controllers govern how data is written and, critically, how completely it is erased, which connects to the data-remanence problem flagged in the Micron and Sandisk rows.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Tech & Semiconductors", "_row_id": 833, "_entity_id": 1133, "_entity_slug": "marvell-technology", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Analog Devices", "Category": "Semiconductors and Other Electronic Components", "Terms & Conditions URL": "See Analog Devices's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Analog Devices's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B semiconductor company — sells chips/components to device manufacturers. Consumer data is collected by the DEVICE MAKER (Samsung, Apple, etc.), not the chip supplier. Qualcomm/Intel/AMD processors execute on-device data processing but the data governance is the device manufacturer's responsibility, not the chipmaker's.", "Arbitration / Class Action Waiver": "B2B — semiconductor company. No consumer-facing products.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Wilmington", "HQ State": "Massachusetts", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Massachusetts' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Massachusetts SOC Corporate Search — corp.sec.state.ma.us/corpweb/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row explicitly states no consumer-facing products exist for this sensor/signal-processing chipmaker; the SCARY field's discussion of motion sensors is framed as industry context ('the sensor is neutral; the SDK reading it is not'), not a stated ADI practice.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or terms exist; the tracker states explicitly there are no consumer-facing products.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Analog Devices  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Signal-processing and sensor components inside other manufacturers' products. Worth more than a boilerplate line: accelerometers, gyroscopes and magnetometers of the kind ADI makes are the physical origin of the driving-behaviour data at issue in the Allstate/Arity finding, and of the motion signatures that make VR headsets identifying. The sensor is neutral; the SDK reading it is not.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Tech & Semiconductors", "_row_id": 834, "_entity_id": 1134, "_entity_slug": "analog-devices", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "KLA", "Category": "Semiconductors and Other Electronic Components", "Terms & Conditions URL": "See KLA's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See KLA's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B semiconductor company — sells chips/components to device manufacturers. Consumer data is collected by the DEVICE MAKER (Samsung, Apple, etc.), not the chip supplier. Qualcomm/Intel/AMD processors execute on-device data processing but the data governance is the device manufacturer's responsibility, not the chipmaker's.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B chip-fabrication inspection equipment sold only to fabricators, with the tracker stating 'no consumer relationship and none possible'; arbitration is only described as 'expected,' not confirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=N; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist for this capital-equipment maker; the tracker states no consumer relationship is even possible.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "KLA  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Semiconductor process control and inspection equipment — pure capital equipment sold to chip fabricators. No consumer relationship and none possible. KLA, Lam and Applied Materials together form a US chokepoint in global chipmaking, which is why they sit at the centre of export control policy rather than privacy policy.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Tech & Semiconductors", "_row_id": 835, "_entity_id": 1135, "_entity_slug": "kla", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Lam Research", "Category": "Semiconductors and Other Electronic Components", "Terms & Conditions URL": "See Lam Research's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Lam Research's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B semiconductor company — sells chips/components to device manufacturers. Consumer data is collected by the DEVICE MAKER (Samsung, Apple, etc.), not the chip supplier. Qualcomm/Intel/AMD processors execute on-device data processing but the data governance is the device manufacturer's responsibility, not the chipmaker's.", "Arbitration / Class Action Waiver": "B2B — semiconductor equipment manufacturer. No consumer-facing products.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Fremont", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row explicitly states no consumer-facing products exist for this fab-equipment maker; the SCARY field frames its significance as geopolitical export policy, not privacy.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or terms exist; the tracker states explicitly there are no consumer-facing products.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Lam Research  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Semiconductor fabrication equipment (etch and deposition) sold to chipmakers. No consumer relationship. Like KLA and Applied Materials, its significance is geopolitical — export restrictions on this equipment are a primary instrument of US technology policy toward China, which is the backdrop to the DeepSeek and Moonshot rows in the LLM Providers tab.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Tech & Semiconductors", "_row_id": 836, "_entity_id": 1136, "_entity_slug": "lam-research", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Western Digital", "Category": "Computers, Office Equipment", "Terms & Conditions URL": "See Western Digital's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Western Digital's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named consumer-facing data-privacy lawsuit or breach; most semiconductor/component manufacturers sell primarily to OTHER BUSINESSES (device makers, cloud providers) rather than directly to consumers, meaning individual exposure is typically indirect (as a user of a device containing this company's chips) rather than through a direct account relationship — recommend checking specifically for any consumer-facing software/account products this company operates (e.g., driver-download portals, developer accounts).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Jose", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Arbitration and named-breach fields are both explicitly unconfirmed this pass; the SCARY field states 'nothing confirmed this pass' for Western Digital specifically and offers only general consumer-NAS-industry context, not a company-specific finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Both arbitration and data-sharing practices are explicitly unconfirmed, and even the SCARY field states nothing was confirmed for this company this pass.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Western Digital  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Western Digital takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Western Digital does have a genuine consumer relationship through external drives and network storage, and the category note worth recording is that consumer network-attached storage devices have repeatedly been the subject of security advisories requiring users to disconnect them from the internet - a remediation instruction that arrives by email or press release and that most owners never see, because a storage device is not something people expect to require patching. Recommend a follow-up on WD's advisory history and end-of-support policy for consumer NAS products.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Tech & Semiconductors", "_row_id": 837, "_entity_id": 1137, "_entity_slug": "western-digital", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sandisk", "Category": "Technology Hardware", "Terms & Conditions URL": "See Sandisk's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Sandisk's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named consumer-facing data-privacy lawsuit or breach; most semiconductor/component manufacturers sell primarily to OTHER BUSINESSES (device makers, cloud providers) rather than directly to consumers, meaning individual exposure is typically indirect (as a user of a device containing this company's chips) rather than through a direct account relationship — recommend checking specifically for any consumer-facing software/account products this company operates (e.g., driver-download portals, developer accounts).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[RETENTION_PERIOD · FL-2] Sandisk cards/drives may leave deleted photos recoverable — unconfirmed, category-wide flash-storage finding\nWHAT THE TERMS SAY: The tracker states this is an unconfirmed, category-wide finding (same issue noted in the Micron row), not something confirmed specifically for Sandisk this pass: deleted files on flash storage are frequently recoverable, sold/discarded cards routinely still contain data, and no product packaging or terms of sale addresses secure disposal.\nWHY IT MATTERS: Consumers who sell, discard, or return Sandisk cards or drives may unknowingly pass along recoverable personal photos and documents.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 1: Hedge lost corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one substantive item was found; arbitration and any named breach/lawsuit are both explicitly unconfirmed this pass, and the data-remanence point is framed as a category-wide issue shared with the Micron row rather than a Sandisk-specific confirmed event.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "No breach or arbitration terms are confirmed for Sandisk specifically; the one substantive item is an inferred, category-wide data-remanence concern.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Sandisk  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Sandisk takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Sandisk memory cards and drives are among the most common places consumers store photographs and documents, and the category finding is the same data-remanence problem noted in the Micron row: deleted files on flash storage are frequently recoverable, sold and discarded cards routinely still contain data, and no product packaging or terms of sale addresses secure disposal. Low drama, real and universal.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Tech & Semiconductors", "_row_id": 838, "_entity_id": 1138, "_entity_slug": "sandisk", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Super Micro Computer", "Category": "Computers, Office Equipment", "Terms & Conditions URL": "See Super Micro Computer's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Super Micro Computer's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B semiconductor company — sells chips/components to device manufacturers. Consumer data is collected by the DEVICE MAKER (Samsung, Apple, etc.), not the chip supplier. Qualcomm/Intel/AMD processors execute on-device data processing but the data governance is the device manufacturer's responsibility, not the chipmaker's.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2018, 2024", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is a B2B server/storage company with no consumer relationship or terms; the SCARY field's substantiated point (2024-25 accounting and SEC-filing delinquency, auditor resignation) is a corporate-governance matter, not a consumer contract term, and the widely circulated 2018 hardware-implant claim is explicitly flagged by the tracker as disputed and unsubstantiated and should not be repeated as fact.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=N; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the row's one substantiated point is a corporate accounting/filing issue, not a disclosed consumer term, and the notorious implant claim is explicitly marked unsubstantiated.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Super Micro Computer  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Server and storage systems sold to data centre operators. Two things belong on this row and neither is privacy. First: the 2018 hardware-implant report was publicly disputed by the company, its named customers and US officials and has never been independently substantiated — it recirculates constantly and should NOT be repeated as fact. Second: Supermicro had genuine accounting and filing-delinquency problems in 2024-25, including an auditor resignation and delayed SEC filings, which is the substantiated concern.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Tech & Semiconductors", "_row_id": 839, "_entity_id": 1139, "_entity_slug": "super-micro-computer", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Texas Instruments", "Category": "Semiconductors and Other Electronic Components", "Terms & Conditions URL": "See Texas Instruments's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Texas Instruments's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Primarily B2B. TI calculators collect minimal user data. TI-Nspire CX connected calculators can send/receive files wirelessly but don't transmit data to TI servers.", "Arbitration / Class Action Waiver": "B2B — Texas Instruments sells semiconductors to manufacturers. Consumer exposure through TI calculators (TI-84, TI-Nspire) — the educational calculator market. Calculator T&C are minimal.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Dallas", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Company is primarily B2B semiconductors; its one consumer product (TI graphing calculators) is explicitly described as having minimal T&C, with TI-Nspire CX explicitly not transmitting data to TI servers, and the SCARY field's captive-market pricing point is a market-structure observation, not a stated contract term.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=N; location=N; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The one consumer product's data practice is clearly and specifically described: TI-Nspire calculators do not transmit data to TI servers and calculator T&C are described as minimal.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Texas Instruments  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Analog and embedded processing chips sold to manufacturers — plus the graphing calculators a generation of American students were required to buy at prices sustained by curriculum and exam-board requirements rather than by competition. That calculator market is a genuine consumer-cost story: a decades-old product held at a high price because school systems mandate it, which is a small but perfect example of captive-market pricing.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Tech & Semiconductors", "_row_id": 840, "_entity_id": 1140, "_entity_slug": "texas-instruments", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Applied Materials", "Category": "Semiconductors and Other Electronic Components", "Terms & Conditions URL": "See Applied Materials's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Applied Materials's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B semiconductor company — sells chips/components to device manufacturers. Consumer data is collected by the DEVICE MAKER (Samsung, Apple, etc.), not the chip supplier. Qualcomm/Intel/AMD processors execute on-device data processing but the data governance is the device manufacturer's responsibility, not the chipmaker's.", "Arbitration / Class Action Waiver": "B2B — semiconductor equipment manufacturer. No consumer-facing products.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Santa Clara", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row explicitly states no consumer relationship exists for this semiconductor-equipment maker; the disclosed federal subpoenas concern export control of China shipments, not consumer data or contract terms.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or terms exist; the one disclosed legal matter (federal subpoenas) concerns export control, not privacy.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Applied Materials  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The largest semiconductor equipment maker, selling to fabricators worldwide. No consumer relationship. Applied has disclosed federal subpoenas concerning China shipments — an export-control matter, and the third member of the equipment chokepoint noted in the KLA and Lam rows.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Tech & Semiconductors", "_row_id": 841, "_entity_id": 1141, "_entity_slug": "applied-materials", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Coupang", "Category": "Internet Services and Retailing", "Terms & Conditions URL": "See Coupang's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Coupang's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named consumer-facing data-privacy lawsuit or breach; most semiconductor/component manufacturers sell primarily to OTHER BUSINESSES (device makers, cloud providers) rather than directly to consumers, meaning individual exposure is typically indirect (as a user of a device containing this company's chips) rather than through a direct account relationship — recommend checking specifically for any consumer-facing software/account products this company operates (e.g., driver-download portals, developer accounts).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; see the shared Salesforce/ShinyHunters campaign (this same tab) for a cross-cutting finding that may extend here given how widely that campaign spread across the tech sector.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Nothing was confirmed this pass; the tracker explicitly flags this row as an unexamined gap because a US-focused search under-detects Korean-language regulatory sources, not because Coupang's practices were found clean.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Tracker explicitly states nothing was confirmed and flags this row as an unexamined gap, recommending Korean-language follow-up before treating it as clean.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Coupang  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Coupang takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass in the searching done here, and this row should be flagged as a genuine gap rather than a clean result: Coupang is a dominant e-commerce and delivery platform in South Korea with a large consumer relationship, extensive delivery and location data, and a regulatory environment - South Korea's Personal Information Protection Commission - that is among the more active in the world. A US-focused search will systematically under-detect Korean regulatory actions. Recommend a targeted follow-up in Korean-language sources before treating this row as anything other than unexamined.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Tech & Semiconductors", "_row_id": 842, "_entity_id": 1142, "_entity_slug": "coupang", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Amphenol", "Category": "Network and Other Communications Equipment", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B electronic connector manufacturer", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Amphenol manufactures electronic/fiber-optic connectors and interconnect systems sold to OTHER ELECTRONICS MANUFACTURERS (aerospace, automotive, telecom, industrial equipment) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to). This closes out the FULL Fortune 500 list from the user's original document — every company from that list is now either directly researched in this tracker or cross-referenced to an existing entry under a different name (Delta Air Lines, Venmo/PayPal, ADP, QVC).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Wallingford", "HQ State": "Connecticut", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Connecticut' is a non-DMV US state", "Parent / Ultimate Owner": "Amphenol Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Connecticut SOTS CONCORD — service.ct.gov/business/s/onlinebusinesssearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Amphenol Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row explicitly states no consumer relationship or Terms of Service exist for this B2B connector manufacturer; the SCARY field notes only that its components are embedded, unnamed, in other companies' consumer products.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist to locate; the tracker states this explicitly as not applicable.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Amphenol  <-  Amphenol Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Connectors and interconnect systems inside other companies' products — cables, sensors and antennas across automotive, defence, medical and consumer devices. No consumer relationship and no consumer terms. Its components are in the connected cars, medical devices and phones documented throughout this tracker, invisible at every step.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Tech & Semiconductors", "_row_id": 843, "_entity_id": 1144, "_entity_slug": "amphenol", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Exxon Mobil", "Category": "Petroleum Refining", "Terms & Conditions URL": "See Exxon Mobil's own published terms of service (gas station rewards app, if any)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Exxon Mobil's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "ExxonMobil Rewards+ collects fueling frequency, location, purchase amounts, and payment data. The app tracks which stations a consumer visits — a detailed driving/commuting pattern. Exxon processes this data under its own privacy policy, not under any energy-sector-specific data regulation.", "Arbitration / Class Action Waiver": "Exxon Mobil's consumer-facing relationship is through ExxonMobil Rewards+ (gas station loyalty program) and the Exxon/Mobil app. Website ToS contain mandatory arbitration with class action waiver. 30-day opt-out. Product-liability claims (oil spills, environmental damage) are governed by separate legal frameworks (Clean Water Act, CERCLA), not website T&C.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, focused specifically on the consumer-facing fuel rewards/payment app rather than the company's broader upstream operations.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Spring", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Exxon Mobil Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Exxon Mobil Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] ExxonMobil Rewards+ logs which stations you visit, building a location-tagged driving/commuting record\nWHAT THE TERMS SAY: ExxonMobil Rewards+ collects fueling frequency, location, purchase amounts and payment data, and the tracker states the app 'tracks which stations a consumer visits' to build a detailed driving/commuting pattern.\nWHY IT MATTERS: Enrolling in the loyalty program to save on gas creates a location history that maps where and how often a person drives.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Exxon's website terms impose binding arbitration and a class-action waiver, with only a 30-day opt-out window\nWHAT THE TERMS SAY: The tracker states Exxon's website ToS contain mandatory arbitration with a class action waiver, and a 30-day opt-out window.\nWHY IT MATTERS: Consumers who don't act within 30 days give up the right to sue Exxon in court or join a class action over disputes.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-1] At the pump, a local franchisee, not Exxon, usually holds your card data, so breach accountability is unclear\nWHAT THE TERMS SAY: The tracker notes Exxon's US pump network is run by independent branded distributors, so the entity taking a consumer's payment card is typically a local jobber, not Exxon Mobil, meaning a card-skimming incident is the franchisee's breach to report and the consumer generally can't tell which company holds the transaction record.\nWHY IT MATTERS: A driver hit by a pump-skimming incident may not know which company to hold accountable or notify.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Rewards+ data practices and arbitration terms are clearly stated, but pump-level payment handling and breach accountability sit with unnamed franchisees, per the tracker.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Exxon Mobil  <-  Exxon Mobil Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Exxon Mobil you gave up your physical movements, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Exxon's US pump network is run by independent branded distributors, so the entity that takes your payment card at an Exxon station is usually a local jobber and not Exxon Mobil — which means a card-skimming incident at the pump is the franchisee's breach to report, not the oil company's, and the consumer generally cannot tell which company holds their transaction record. Exxon Mobil Rewards+ is the one place a direct consumer data relationship exists, tying fuel purchases to an identity and a location pattern.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 844, "_entity_id": 1146, "_entity_slug": "exxon-mobil", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Chevron", "Category": "Petroleum Refining", "Terms & Conditions URL": "See Chevron's own published terms of service (gas station rewards app, if any)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Chevron's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Techron Advantage collects fueling data, location, and payment information. Chevron's data practices are governed by California law, including the CCPA/CPRA — giving California consumers stronger opt-out rights than consumers in other states using the same app.", "Arbitration / Class Action Waiver": "Chevron's consumer-facing relationship is through the Techron Advantage loyalty program and Chevron/Texaco apps. Website ToS contain mandatory arbitration with class action waiver. 30-day opt-out. California law governs (Chevron HQ). Environmental litigation governed by separate frameworks.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, focused specifically on the consumer-facing fuel rewards/payment app rather than the company's broader upstream operations.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Ramon", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Chevron Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Chevron Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Techron Advantage app ties Chevron gas purchases to a location and vehicle-movement record\nWHAT THE TERMS SAY: Techron Advantage collects fueling data, location and payment information; the tracker describes fuel purchase history as 'a vehicle-use and movement record — where you drive, how often, and how far between fills.'\nWHY IT MATTERS: Signing up for fuel discounts creates a record of a driver's movement patterns tied to their identity.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Chevron's website terms require binding arbitration and a class-action waiver, with a 30-day opt-out window\nWHAT THE TERMS SAY: The tracker states website ToS contain mandatory arbitration with a class action waiver and a 30-day opt-out; California law governs since that is where Chevron is headquartered.\nWHY IT MATTERS: Missing the 30-day window means giving up the right to sue Chevron in court or join a class action.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-2] CCPA/CPRA gives California users of Chevron's app stronger opt-out rights than users in other states\nWHAT THE TERMS SAY: The tracker states Chevron's data practices are governed by California law, including the CCPA/CPRA, giving California consumers stronger opt-out rights than consumers in other states using the same app.\nWHY IT MATTERS: Two Chevron customers using the identical app get different privacy protections depending only on which state they live in.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Techron Advantage data practices and arbitration terms are stated, but privacy protections vary by state and pump-level payment security sits with independently operated stations.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Chevron  <-  Chevron Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Chevron you gave up your physical movements, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same franchised-retail structure as Exxon: the Chevron and Texaco stations a driver uses are overwhelmingly independently operated, so the pump payment terminal and its security posture belong to a small business rather than to Chevron. The Chevron Rewards programme is the direct consumer touchpoint, and fuel purchase history is a vehicle-use and movement record — where you drive, how often, and how far between fills.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 845, "_entity_id": 1148, "_entity_slug": "chevron", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Marathon Petroleum", "Category": "Petroleum Refining", "Terms & Conditions URL": "See Marathon Petroleum's own published terms of service (gas station rewards app, if any)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Marathon Petroleum's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Upstream oil & gas company — E&P (exploration and production). No consumer data collection. Produces crude oil/natural gas sold to refiners/distributors at wholesale.", "Arbitration / Class Action Waiver": "Marathon's consumer touchpoint is through Speedway gas stations (acquired 2021 from 7-Eleven, which bought Marathon's retail business). The current consumer relationship is with 7-Eleven/Speedway, not Marathon Petroleum itself.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, focused specifically on the consumer-facing fuel rewards/payment app rather than the company's broader upstream operations.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Findlay", "HQ State": "Ohio", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Ohio' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[DATA_SALE · FL-4] Speedway loyalty and payment records built under Marathon transferred to 7-Eleven in the 2021 sale, unasked\nWHAT THE TERMS SAY: The tracker states Marathon's former Speedway retail chain held direct consumer loyalty and payment data at scale, and when Speedway was sold to 7-Eleven, the consumer records built under Marathon's ownership transferred to the new owner with no consumer asked.\nWHY IT MATTERS: A customer's loyalty and payment history can change corporate hands entirely as a business asset in a sale, with no chance to consent or opt out.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one substantive item was found; Marathon is now upstream E&P with no direct consumer data collection, and the tracker states the current consumer touchpoint belongs to 7-Eleven/Speedway, not Marathon Petroleum.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Marathon's current lack of a consumer relationship is clearly stated, but the one substantive finding — the Speedway data transfer — is a historical fact with no disclosure of what terms, if any, governed it.", "Exposure Score (0-100)": 8, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (data_sold_or_shared_for_value+8) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Marathon Petroleum  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Marathon refines and wholesales fuel to branded operators. Its former Speedway retail chain — which did hold direct consumer loyalty and payment data at scale — was sold to 7-Eleven, so the consumer records built under Marathon's ownership transferred to a different company entirely, with no consumer asked. That transfer is the finding: retail divestitures move loyalty databases as assets.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 846, "_entity_id": 1149, "_entity_slug": "marathon-petroleum", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Phillips 66", "Category": "Petroleum Refining", "Terms & Conditions URL": "See Phillips 66's own published terms of service (gas station rewards app, if any)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Phillips 66's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named consumer data-privacy lawsuit or breach; unlike most upstream oil/gas companies in this tab, this company operates CONSUMER-FACING GAS STATIONS AND REWARDS APPS (fuel discount cards, mobile payment) that collect direct consumer data — recommend a direct follow-up specifically on this company's fuel-rewards/loyalty app privacy practices, since that's the primary point of direct consumer data collection for a petroleum company.", "Arbitration / Class Action Waiver": "Phillips 66's consumer-facing brand is its gas station network. Website ToS contain arbitration provisions. The Phillips 66 app collects fueling and location data.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, focused specifically on the consumer-facing fuel rewards/payment app rather than the company's broader upstream operations.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Phillips 66 app collects fueling and location data as part of its branded loyalty program\nWHAT THE TERMS SAY: The tracker states the Phillips 66 app collects fueling and location data as part of the branded loyalty/rewards program.\nWHY IT MATTERS: Using the discount app to save on gas builds a location-tagged record of where and when a driver fuels up.\n(evidence: Arbitration; Stated in tracker (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Phillips 66's website terms include arbitration provisions, with a 30-day opt-out window recorded\nWHAT THE TERMS SAY: The tracker states Phillips 66's website ToS 'contain arbitration provisions,' without detailing a class-action waiver, and separately records a 30-day arbitration opt-out window.\nWHY IT MATTERS: An arbitration clause can limit a customer's ability to sue in court over billing or data disputes.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-2] Phillips 66's loyalty app data typically sits with an unnamed third-party program administrator, not the refiner\nWHAT THE TERMS SAY: The tracker notes the branded loyalty app is 'typically operated under licence rather than by the refiner,' so a customer's data sits with a program administrator most drivers could not name.\nWHY IT MATTERS: Consumers may not know which company actually controls or is accountable for their loyalty-program data.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration and app data collection are stated but thinly detailed (no class-waiver mention), and the loyalty program's actual data custodian is described as typically unnamed to consumers.", "Exposure Score (0-100)": 19, "Exposure Band": "Low", "Sub: Dispute Rights /30": 15, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 15/30 (forced_arbitration+12, optout_30d+3) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Phillips 66  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Phillips 66 you gave up your physical movements and your right to sue. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Refiner and wholesaler supplying independently operated 76, Phillips 66 and Conoco stations. The consumer-facing layer is the branded loyalty app, which is typically operated under licence rather than by the refiner, so a customer's data sits with a programme administrator most drivers could not name.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 847, "_entity_id": 1150, "_entity_slug": "phillips-66", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Valero Energy", "Category": "Petroleum Refining", "Terms & Conditions URL": "See Valero Energy's own published terms of service (gas station rewards app, if any)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Valero Energy's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Upstream oil & gas company — E&P (exploration and production). No consumer data collection. Produces crude oil/natural gas sold to refiners/distributors at wholesale.", "Arbitration / Class Action Waiver": "Primarily refining/marketing — consumer exposure through Valero-branded gas stations. Limited consumer-digital footprint.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, focused specifically on the consumer-facing fuel rewards/payment app rather than the company's broader upstream operations.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Antonio", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Valero states its consumer exposure runs only through independently branded stations with a 'limited consumer-digital footprint,' and the Data Sharing field explicitly says there is no consumer data collection; the SCARY item concerns EPA renewable-fuel regulation, not any consumer-facing term.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=N; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The row states essentially no direct consumer contract exists, and the arbitration opt-out window is explicitly recorded as not stated.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Valero Energy  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Refiner supplying independently operated branded stations, with essentially no direct consumer contract. Valero is worth noting for a different reason: it is one of the largest US refiners of renewable diesel and ethanol, so its regulatory exposure runs through EPA fuel standards rather than through anything a consumer signs.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 848, "_entity_id": 1151, "_entity_slug": "valero-energy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "ConocoPhillips", "Category": "Mining, Crude-Oil Production", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Primarily B2B — ConocoPhillips is an E&P company (exploration and production) that sells crude oil and natural gas to refiners, not directly to consumers. No consumer loyalty program or app.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2012", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row explicitly states ConocoPhillips is pure upstream E&P with no consumer loyalty program, app, or terms since divesting its retail arm (now Phillips 66) in 2012; the tracker states 'genuinely no consumer terms exist.'", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; explicitly confirmed by the tracker following the 2012 divestiture of the retail business that became Phillips 66.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "ConocoPhillips  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Pure upstream exploration and production — ConocoPhillips sold its refining and retail arm (which became Phillips 66) in 2012 and has had no consumer relationship since. A driver who sees a Conoco sign is dealing with Phillips 66's licensee, not with this company. Genuinely no consumer terms exist.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 849, "_entity_id": 1152, "_entity_slug": "conocophillips", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Plains All American Pipeline", "Category": "Pipelines", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Plains All American Pipeline, L.P.", "Years Referenced in Finding (heuristic)": "2015", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Plains All American Pipeline, L.P.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row explicitly states no consumer relationship or Terms of Service exist for this pipeline operator; the SCARY field notes a substantiated environmental enforcement record (2015 Refugio spill conviction and civil settlements) but flags that as a separate, non-privacy accountability matter, not a consumer contract term.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms or relationship exist; the row's only substantiated record is a 2015 pipeline-spill conviction, which the tracker explicitly flags as a separate, non-privacy matter.", "Exposure Score (0-100)": 3, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 3, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 3/20 (severity1+0, penalty+3) | flags stated 9/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Plains All American Pipeline  <-  Plains All American Pipeline, L.P.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Crude oil pipelines and storage. Plains is the operator behind the 2015 Refugio spill off the California coast, which produced criminal conviction and substantial civil settlements — a real accountability record, but an environmental one, and a blank privacy row should not be read as a blank record generally.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 850, "_entity_id": 1154, "_entity_slug": "plains-all-american-pipeline", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Plains GP", "Category": "Pipelines", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Plains GP Holdings, L.P.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Plains GP Holdings, L.P.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is a B2B pass-through general-partner holding entity for Plains All American with no operations and no consumer relationship or terms; nothing troubling to a consumer is stated.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer disclosure regime exists because the entity has no consumer relationship or terms to find.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Plains GP  <-  Plains GP Holdings, L.P.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A pass-through general-partner holding entity for Plains All American with no operations, no employees in the ordinary sense and no consumer relationship. The row exists for Fortune 500 completeness; the operating findings belong to the Plains All American row and should not be double-counted.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 851, "_entity_id": 1156, "_entity_slug": "plains-gp", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "World Kinect", "Category": "Energy", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Miami", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "World Kinect Corporation (fmr. World Fuel Services)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: World Kinect Corporation (fmr. World Fuel Services)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is a B2B fuel distributor for aviation, marine, and commercial fleets with no consumer account relationship or terms; its only consumer link is indirect fuel-price pass-through, per the row's own notes.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No terms exist to locate because the company has no direct consumer relationship.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "World Kinect  <-  World Kinect Corporation (fmr. World Fuel Services)", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Fuel distribution and energy management for aviation, marine and commercial fleets — the company that fuels the aircraft in this tracker's Global Airlines tab rather than the one that sells you the ticket. Its customers are operators, and a consumer's only connection is that fuel-price volatility passes through into fares.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 852, "_entity_id": 1158, "_entity_slug": "world-kinect", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "SLB", "Category": "Oil & Gas", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row explicitly states this is an honest no-consumer-relationship entry; SLB holds only clients' subsurface/production data, not consumer data.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms or disclosure regime applies to this B2B oilfield-services relationship.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "SLB  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Oilfield technology and services sold to producers. SLB (formerly Schlumberger) holds detailed subsurface and production data on its clients' wells, which is commercially sensitive to those clients but contains nothing about consumers. An honest no-consumer-relationship row.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 853, "_entity_id": 1159, "_entity_slug": "slb", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Oneok", "Category": "Pipelines", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B gas gathering/pipelines with no consumer terms; consumer exposure to Oneok is entirely mediated through local utilities, which hold the meter data instead.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; any household exposure runs through a separate utility that is not this row's subject.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Oneok  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Natural gas gathering, processing and pipelines. Oneok sits upstream of the utilities in the F500 Electric-Gas Utilities tab — it moves the gas those utilities deliver — so a household's exposure to Oneok is entirely mediated through its local distribution company, which is the entity that actually holds the meter data.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 854, "_entity_id": 1160, "_entity_slug": "oneok", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "PBF Energy", "Category": "Petroleum Refining", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Parsippany", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New Jersey' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NJ Business Records Service — businessrecords.nj.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is a B2B wholesale refiner with no retail network and no consumer contract; its only consumer effect noted is regional fuel-price impact from operational disruptions.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist for a wholesale-only refiner with no retail network.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "PBF Energy  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Independent refiner selling wholesale, with no retail network and no consumer contract. PBF's East Coast refineries supply a large share of Mid-Atlantic fuel, so its operational disruptions show up as regional price spikes rather than as any data event.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 855, "_entity_id": 1161, "_entity_slug": "pbf-energy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Baker Hughes", "Category": "Oil and Gas Equipment, Services", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "B2B — oilfield services. No consumer-facing products.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Baker Hughes was among the companies affected by the MOVEit file-transfer vulnerability\nWHAT THE TERMS SAY: The row states Baker Hughes was among the companies affected by the MOVEit file-transfer vulnerability, reaching it through the same vendor flaw noted in the Delta Dental and AutoZone rows.\nWHY IT MATTERS: It shows even a purely B2B oilfield-services firm with no consumer relationship can still be caught in a shared-vendor security incident.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Row is otherwise B2B oilfield services with no consumer relationship or terms; the MOVEit vulnerability is a vendor security event rather than a consumer-facing practice, so only one item is substantive.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=Y; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the only stated fact is a vendor security incident, not a disclosure regime.", "Exposure Score (0-100)": 3, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 3, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 3/20 (severity1+0, breach+3) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Baker Hughes  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Oilfield equipment and services. Baker Hughes is notable in a security context rather than a privacy one: it was among the companies affected by the MOVEit file-transfer vulnerability documented across this tracker, which reached it through the same vendor flaw that hit Delta Dental and AutoZone — a reminder that even pure B2B firms sit in the shared-vendor blast radius.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 856, "_entity_id": 1162, "_entity_slug": "baker-hughes", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "HF Sinclair", "Category": "Petroleum Refining", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Dallas", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "HF Sinclair Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: HF Sinclair Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row states the refiner supplies independently operated, franchisee-branded stations; any consumer relationship, including the loyalty app and payment data, belongs to the franchisees, not to HF Sinclair itself.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The consumer-facing relationship and any related terms belong to franchisees, not to this row's entity.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "HF Sinclair  <-  HF Sinclair Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Refiner supplying independently operated Sinclair-branded stations. The Sinclair brand and its dinosaur logo are licensed to station owners, so the consumer relationship — including the loyalty app and any payment data — belongs to franchisees rather than to the refiner.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 857, "_entity_id": 1164, "_entity_slug": "hf-sinclair", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Halliburton", "Category": "Oil and Gas Equipment, Services", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "B2B — oilfield services. No consumer-facing products.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Halliburton disclosed a 2024 cyberattack that disrupted operations, revealed via SEC filing rather than consumer notice\nWHAT THE TERMS SAY: The row states Halliburton disclosed a significant cyberattack in 2024 that disrupted business operations and prompted an SEC filing.\nWHY IT MATTERS: As a B2B company, the incident surfaced through securities-disclosure obligations rather than consumer breach-notification law, so the public learned via investors rather than a direct notice.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Row is otherwise B2B oilfield services with no consumer relationship or terms; only the disclosed cyberattack is a substantive, company-specific fact.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=Y; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the only stated fact is a disclosed cyberattack surfaced via SEC filing.", "Exposure Score (0-100)": 3, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 3, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 3/20 (severity1+0, breach+3) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Halliburton  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Oilfield services. Halliburton disclosed a significant cyberattack in 2024 that disrupted business operations and prompted an SEC filing, which is the pattern worth noting: for B2B companies, incidents surface through securities disclosure obligations rather than consumer breach-notification law, so the public learns via investors.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 858, "_entity_id": 1165, "_entity_slug": "halliburton", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Occidental Petroleum", "Category": "Mining, Crude-Oil Production", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Occidental Petroleum Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Occidental Petroleum Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B exploration/production and carbon capture with no consumer relationship; its only consumer-adjacent relevance is political, as a prominent voice in the carbon-removal policy debate, not contractual.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or terms exist to locate.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Occidental Petroleum  <-  Occidental Petroleum Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Exploration and production, plus a carbon-capture business. No consumer relationship exists. Occidental's consumer-adjacent relevance is indirect and political rather than contractual — it is among the most prominent US companies in the carbon-removal policy debate.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 859, "_entity_id": 1167, "_entity_slug": "occidental-petroleum", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cheniere Energy", "Category": "Pipelines", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "B2B — LNG export. No consumer-facing products.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is a B2B LNG exporter selling under long-term contracts to international buyers with no consumer relationship; consumer relevance is limited to price transmission into utility bills.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; household impact is limited to price transmission, not a data or contract relationship.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Cheniere Energy  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Liquefied natural gas export terminals selling to international buyers under long-term contracts. Cheniere is the largest US LNG exporter, and its relevance to a household is price transmission: US gas exports link domestic heating costs to global demand, which shows up on a utility bill rather than in any terms of service.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 860, "_entity_id": 1168, "_entity_slug": "cheniere-energy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Murphy USA", "Category": "Specialty Retailers: Other", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Murphy USA's fuel rewards programme ties purchases to identity, but no specific data practice was confirmed this pass\nWHAT THE TERMS SAY: The row identifies Murphy USA as the one genuine consumer-facing company in this tab, operating fuel and convenience stores, largely adjacent to Walmart locations, with a rewards programme that ties fuel purchases to identity.\nWHY IT MATTERS: Fuel purchase records are a vehicle-use and movement pattern -- when and where a person drives, at what frequency -- the same inference category the tracker documents for other convenience-store chains (the Casey's and Royal Farms rows), though nothing company-specific was confirmed for Murphy USA itself this pass.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fee fields are not applicable or not stated, and the row explicitly says nothing company-specific was confirmed this pass beyond the existence of the identity-linked rewards programme.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "A consumer relationship exists via the rewards programme, but the row explicitly confirms nothing company-specific about data practices this pass.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Murphy USA  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Murphy USA takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Murphy USA is the one genuine consumer-facing company in this tab: it operates fuel and convenience stores, largely adjacent to Walmart locations, with a rewards programme that ties fuel purchases to identity. Fuel purchase records are a vehicle-use and movement pattern - when and where a person drives, at what frequency - the same inference category documented in the Casey's and Royal Farms rows. Nothing company-specific confirmed this pass; unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 861, "_entity_id": 1169, "_entity_slug": "murphy-usa", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Global Partners", "Category": "Energy", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Waltham", "HQ State": "Massachusetts", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Global Partners LP", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Massachusetts SOC Corporate Search — corp.sec.state.ma.us/corpweb/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Global Partners LP). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is primarily a B2B fuel wholesaler/terminal operator; the limited consumer relationship from its company-run convenience stores is described only by reference to the Mid-Atlantic Convenience Chains tab, with no company-specific detail given here.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No company-specific consumer terms or data practices are described in this row; the relevant profile is attributed to another tab.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Global Partners  <-  Global Partners LP", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Primarily a fuel wholesaler and terminal operator, but unlike the pure refiners in this tab it does operate company-run convenience stores under several banners — so a limited direct consumer relationship exists, with the loyalty and payment data profile described in the Mid-Atlantic Convenience Chains tab.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 862, "_entity_id": 1171, "_entity_slug": "global-partners", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Devon Energy", "Category": "Mining, Crude-Oil Production", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "B2B — E&P company. No consumer-facing products.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Oklahoma City", "HQ State": "Oklahoma", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Oklahoma' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Oklahoma) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Oklahoma. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B exploration & production with no consumer relationship; its individual-data concern is royalty owners' mineral-rights payments, a category the row notes sits outside consumer privacy law rather than a consumer-facing term.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the only individual-data category noted (royalty owners) falls outside this tracker's consumer scope.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Devon Energy  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Onshore US exploration and production with no consumer relationship. Devon's disclosures concern royalty owners — the landowners who receive payments for mineral rights — which is a genuine individual-data category that sits entirely outside consumer privacy law and receives almost no attention.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 863, "_entity_id": 1172, "_entity_slug": "devon-energy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Targa Resources", "Category": "Pipelines", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "B2B — natural gas gathering and processing. No consumer-facing products.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B natural gas gathering/processing infrastructure with no consumer relationship; the row states it holds no consumer data at all.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the row states the company holds no consumer data.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Targa Resources  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Natural gas gathering and processing infrastructure. No consumer relationship. Targa's midstream assets are the layer between wellhead and utility, invisible to households and unregulated as to consumer data because it holds none.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 864, "_entity_id": 1173, "_entity_slug": "targa-resources", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Kinder Morgan", "Category": "Pipelines", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "B2B — pipeline/infrastructure operator. No consumer-facing products.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2021", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B pipeline/terminal operations with no consumer data; the TSA security-directive regime it notes is a national-security requirement for critical infrastructure generally, not a company-specific consumer finding.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer data or terms exist; the noted security regime is industry-wide, not a company-specific consumer finding.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Kinder Morgan  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "One of the largest US pipeline and terminal operators. Kinder Morgan holds no consumer data, but it is worth recording that critical-infrastructure operators of this kind are subject to TSA security directives issued after the 2021 Colonial Pipeline ransomware attack — a regime driven by national security rather than privacy.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 865, "_entity_id": 1174, "_entity_slug": "kinder-morgan", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Diamondback Energy", "Category": "Mining, Crude-Oil Production", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "B2B — E&P company. No consumer-facing products.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Midland", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B Permian Basin exploration & production with no consumer relationship or terms; like Devon, its individual-data concern is mineral-rights (royalty) owners rather than consumers.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the only individual-data category noted (royalty owners) falls outside this tracker's consumer scope.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Diamondback Energy  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Permian Basin exploration and production. No consumer relationship and no consumer terms. Like Devon, its individual-level data concerns mineral rights owners rather than customers.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 866, "_entity_id": 1175, "_entity_slug": "diamondback-energy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Venture Global", "Category": "Oil & Gas", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B LNG export with no consumer relationship; the commercial arbitration noted is explicitly a business-to-business contract-performance dispute with its own customers, not a consumer finding.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=Y; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the stated arbitration is a B2B commercial dispute, not a consumer-facing finding.", "Exposure Score (0-100)": 2, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity1+0, litigation+2) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Venture Global  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "LNG export developer. Venture Global is distinctive in this tab for being the subject of major commercial arbitration with its own long-term customers over contract performance — a business-to-business dispute, recorded here only so a reader does not mistake the absence of consumer findings for the absence of litigation.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 867, "_entity_id": 1176, "_entity_slug": "venture-global", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Hess", "Category": "Mining, Crude-Oil Production", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Hess Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Hess Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B exploration & production with no consumer relationship; the noted arbitration over Guyana asset rights was a business dispute that concluded ahead of Chevron's acquisition, not a consumer finding.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or terms exist; the noted arbitration was a concluded B2B asset dispute.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Hess  <-  Hess Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Exploration and production, acquired by Chevron following a protracted arbitration over Guyana asset rights. No consumer relationship exists, and the row's practical status is that it may not survive as an independent entity in future Fortune 500 lists — worth flagging before the next repopulation.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 868, "_entity_id": 1178, "_entity_slug": "hess", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Expand Energy", "Category": "Oil & Gas", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B natural gas production, formed from the Chesapeake/Southwestern merger, with no consumer relationship; the row's only substantive note is a tracker-methodology caution about searching under the company's former name.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the row's note concerns tracker methodology around the company's name change, not a consumer finding.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Expand Energy  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The natural gas producer formed from the Chesapeake Energy and Southwestern Energy merger. Name changes of this kind are a recurring problem for this tracker: a consumer or researcher searching the historical name finds a company that no longer exists under it, and the corporate record does not follow the search.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 869, "_entity_id": 1179, "_entity_slug": "expand-energy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Williams", "Category": "Pipelines", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B natural gas pipeline/midstream infrastructure with no consumer data; the Transco line's capacity constraints affect regional heating costs only indirectly, and the row's other note is a name-collision caution versus Sherwin-Williams, not a consumer finding.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer data or terms exist; heating-cost impact is indirect price transmission, not a data or contract relationship.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Williams  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Natural gas pipeline and midstream infrastructure, including the Transco line that supplies much of the Mid-Atlantic and Southeast. No consumer data, but Transco's capacity constraints are a direct input into winter heating costs for households across this tracker's core region. NOTE: do not confuse with Sherwin-Williams in the Chemicals tab — a name-collision hazard for any fuzzy matching.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 870, "_entity_id": 1180, "_entity_slug": "williams", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Delek US", "Category": "Petroleum Refining", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Brentwood", "HQ State": "Tennessee", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Tennessee' is a non-DMV US state", "Parent / Ultimate Owner": "Delek US Holdings, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Tennessee SOS Business Search — tnbear.tn.gov/Ecommerce/FilingSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Delek US Holdings, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] Delek's retail network creates a limited direct consumer relationship the row doesn't detail\nWHAT THE TERMS SAY: The row notes Delek also operates a retail convenience-store network in the southern US with a loyalty programme, unlike the pure refiners elsewhere in this tab, but gives no detail on what that loyalty programme's terms, data collection, or arbitration provisions actually say.\nWHY IT MATTERS: Consumers who fuel up or join the loyalty programme are agreeing to some terms, but this pass didn't locate or describe them, so their actual privacy and dispute-resolution exposure is unknown.\n(evidence: SCARY; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only a brief SCARY-field mention of a retail/loyalty consumer touchpoint exists; the row otherwise follows the standard B2B upstream boilerplate with no specific terms, data-sharing, or arbitration language located for that consumer-facing side of the business.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The row says no consumer ToS exists for the core business, and the one acknowledged consumer touchpoint (retail/loyalty) is undocumented.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Delek US  <-  Delek US Holdings, Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Refiner that also operates a retail convenience network in the southern US, so a limited direct consumer relationship exists through fuel and in-store purchases plus a loyalty programme — unlike the pure refiners elsewhere in this tab.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 871, "_entity_id": 1182, "_entity_slug": "delek-us", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "APA", "Category": "Mining, Crude-Oil Production", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is explicitly B2B upstream exploration/production with no consumer account relationship or Terms of Service stated; the only other content is a naming/search-continuity note unrelated to consumer harm.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer disclosure regime exists for this upstream B2B company.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "APA  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Exploration and production (formerly Apache Corporation). No consumer relationship. The renaming is another instance of the search-continuity problem noted in the Expand Energy row.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 872, "_entity_id": 1183, "_entity_slug": "apa", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ovintiv", "Category": "Mining, Crude-Oil Production", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Denver", "HQ State": "Colorado", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Colorado' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2020", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Colorado SOS Business Search — sos.state.co.us/biz/BusinessEntityCriteria. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B upstream exploration/production with no consumer terms; the only additional content is a jurisdictional note about the 2020 US redomiciliation, which the row itself says matters only as a note, not a consumer harm.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer-facing terms exist for this company.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Ovintiv  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Exploration and production, formerly Encana, redomiciled from Canada to the US in 2020. No consumer relationship. The redomiciliation matters only as a jurisdictional note: which country's law governs a company's data obligations can change without any customer being consulted.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 873, "_entity_id": 1184, "_entity_slug": "ovintiv", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "NOV", "Category": "Oil and Gas Equipment, Services", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is explicitly B2B (drilling equipment sold to producers and drilling contractors); the row states no consumer relationship exists and no consumer terms are published.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row states no consumer terms are published.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "NOV  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Drilling equipment and technology manufacturer (formerly National Oilwell Varco). Sells to producers and drilling contractors; no consumer relationship exists and no consumer terms are published.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 874, "_entity_id": 1185, "_entity_slug": "nov", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "EQT", "Category": "Oil & Gas", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B natural gas production with no consumer account relationship; the only additional content (royalty-owner disputes with Appalachian landowners) is described as an individual-harm category outside consumer law, not a consumer terms/data issue.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer disclosure regime exists; the company sells to other businesses, not individuals.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "EQT  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The largest US natural gas producer, Appalachian-focused, with substantial Pennsylvania and West Virginia operations. No consumer relationship — but EQT's production feeds the same regional gas system that heats homes across this tracker's core region, and its royalty-owner disputes with Appalachian landowners are a genuine individual-harm category outside consumer law.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 875, "_entity_id": 1186, "_entity_slug": "eqt", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Energy Transfer", "Category": "Pipelines", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/upstream energy company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company operates primarily in UPSTREAM oil/gas production, pipeline transportation, or oilfield services — selling to other businesses (refiners, utilities, industrial customers) rather than directly to individual consumers. As such, it has NO direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to, unlike the vast majority of other entries in this tracker.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "This entry is included for FORTUNE 500 COMPLETENESS per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to) — individuals are affected by this company only indirectly, through fuel/energy prices or environmental/safety impacts, not through a direct account relationship.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Dallas", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Energy Transfer LP", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Energy Transfer LP). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B pipeline/midstream with no consumer relationship; the litigation note concerns Energy Transfer suing environmental organizations (not litigation against consumers or a data/terms issue), included only for public-interest completeness.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; row is included for tracker completeness only.", "Exposure Score (0-100)": 2, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity1+0, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Energy Transfer  <-  Energy Transfer LP", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Pipeline and midstream operator. Energy Transfer is the company behind the Dakota Access Pipeline and has pursued aggressive litigation against environmental organisations — recorded here because a blank consumer-privacy row would otherwise imply a blank record, and the litigation posture is a matter of significant public interest even though it involves no consumer data.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Energy Oil-Gas", "_row_id": 876, "_entity_id": 1188, "_entity_slug": "energy-transfer", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Duke Energy", "Category": "Utilities: Gas and Electric", "Terms & Conditions URL": "duke-energy.com/legal/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "duke-energy.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Regulated utility serving 8.4M customers across 6 states. Smart-meter data, usage analytics, and billing data governed by state PUC rules. Duke's coal ash litigation (multi-billion-dollar remediation costs) involved extensive customer data sharing with regulators.", "Arbitration / Class Action Waiver": "Duke Energy's website Terms of Use contain a dispute resolution clause but rely on STATE PUBLIC UTILITY COMMISSION oversight for rate and service disputes rather than private arbitration — a regulated-utility model. Customer complaints go to the NC Utilities Commission (or the relevant state commission in SC, OH, IN, KY, FL). This is structurally different from unregulated companies' arbitration clauses.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The tension between Duke Energy's public denial ('no PII was exposed') and its simultaneous decision to settle SEVEN separate lawsuits over the same incident is worth flagging — companies frequently settle to avoid litigation costs regardless of their view of the underlying merits, so a settlement alone shouldn't be read as an admission, nor should a denial be read as proof nothing happened.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Charlotte", "HQ State": "North Carolina", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'North Carolina' is a non-DMV US state", "Parent / Ultimate Owner": "Duke Energy Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NC SOS Business Registration Search — sosnc.gov/online_services/search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Duke Energy Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Court held reading a meter this finely is a Fourth Amendment search; Duke customers cannot switch providers\nWHAT THE TERMS SAY: The row states a federal appeals court has already held that reading a meter this finely is a search under the Fourth Amendment, and that Duke customers, like every utility customer in this tracker, cannot switch providers.\nWHY IT MATTERS: The row states Duke customers, like every utility customer in this tracker, cannot switch providers - which removes every market mechanism consumer privacy law assumes exists. Nothing company-specific was confirmed this pass.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[PENDING_LITIGATION · FL-2] Duke denied any PII was exposed but settled seven separate lawsuits over the same incident\nWHAT THE TERMS SAY: The row notes a tension between Duke's public denial that 'no PII was exposed' and its decision to settle seven separate lawsuits over the same incident.\nWHY IT MATTERS: A settlement doesn't confirm wrongdoing and a denial doesn't prove nothing happened, but affected customers were left with an unresolved factual question about whether their personal information was exposed.\n(evidence: Notes; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two company-specific items are substantiated; the dispute-resolution clause explicitly routes rate and service disputes to state PUCs rather than private arbitration ('no arbitration clause identified'), so no forced-arbitration finding applies, leaving no third distinct harm to report.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Key facts are stated but hedged — the breach question is disputed (denial vs. settlement) and the smart-meter finding lacks Duke-specific retention or collection detail.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Duke Energy  <-  Duke Energy Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Duke Energy takes nothing from the list this tracker checks - but 10 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A federal appeals court has already held that reading a meter this finely is a search under the Fourth Amendment. Duke is one of the largest US utilities, serving the Carolinas, Florida, Indiana, Ohio and Kentucky, and like every utility in this tracker its customers cannot switch providers - which removes every market mechanism consumer privacy law assumes exists. Nothing company-specific confirmed this pass; recommend a follow-up on collection interval, retention period and the written law enforcement request policy, which are the three questions that actually determine a household's exposure.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Electric-Gas Utilities", "_row_id": 877, "_entity_id": 1190, "_entity_slug": "duke-energy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "NRG Energy", "Category": "Energy", "Terms & Conditions URL": "See NRG Energy's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See NRG Energy's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not applicable in the typical consumer-arbitration sense for many utilities, which are often regulated monopolies subject to state public utility commission oversight rather than private arbitration — recommend confirming this utility's specific dispute-resolution process.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "NRG Energy, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: NRG Energy, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] NRG owns Vivint, so the company billing you for power also holds your home security footage and entry logs\nWHAT THE TERMS SAY: The row states NRG owns Vivint Smart Home, and that NRG also sells retail electricity in deregulated markets, describing the combination as the finding: the entity billing you for power also watches your front door.\nWHY IT MATTERS: An energy company now sits on household security camera footage, entry/exit logs, and alarm states in addition to billing data — combining two categories of sensitive household data under one corporate parent.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-1] Vivint, now owned by NRG, had a $20M FTC settlement over sales staff pulling unrelated people's credit files\nWHAT THE TERMS SAY: The row states Vivint's sales staff pulled unrelated people's credit files, resulting in a $20 million FTC settlement, documented in the tracker's Home Security & Entertainment tab.\nWHY IT MATTERS: The row records a $20 million FTC settlement over Vivint sales staff pulling unrelated people's credit files, documented in the Home Security & Entertainment tab, at a company NRG now owns.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Two substantive, company-specific items are supported (the Vivint data combination and its FTC settlement); the only other candidate — door-to-door and telemarketing sales enforcement — is described as sector-wide, not NRG-specific, so a third distinct item wasn't added.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are unconfirmed and the row itself recommends confirming the dispute process, but the Vivint ownership and FTC settlement facts are clearly stated.", "Exposure Score (0-100)": 8, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 5/20 (severity2+2, penalty+3) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "NRG Energy  <-  NRG Energy, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, NRG Energy takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "NRG owns Vivint Smart Home, whose $20 million FTC settlement over sales staff pulling unrelated people's credit files is documented in the Home Security & Entertainment tab - so an energy company now sits on household security camera footage, entry and exit logs and alarm states. NRG also sells retail electricity in deregulated markets, where door-to-door and telemarketing sales practices have drawn sustained state enforcement across the sector. That combination is the finding: the entity billing you for power also watches your front door.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Electric-Gas Utilities", "_row_id": 878, "_entity_id": 1191, "_entity_slug": "nrg-energy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "NextEra Energy", "Category": "Utilities: Gas and Electric", "Terms & Conditions URL": "See NextEra Energy's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See NextEra Energy's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission rules in addition to NextEra's own privacy policy. Smart-meter data provides granular household activity patterns (when residents wake, sleep, leave, return). Utility data sharing with law enforcement generally requires a warrant or subpoena under state utility commission regulations.", "Arbitration / Class Action Waiver": "NextEra Energy (parent of Florida Power & Light) ToS contain a binding arbitration clause with class action waiver. 30-day opt-out. AAA rules, Florida law. As a regulated utility, customer disputes over rates are governed by the Florida Public Service Commission, not the arbitration clause — the clause covers disputes over NextEra's website, app, and non-rate-related service issues.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Juno Beach", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "NextEra Energy, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: NextEra Energy, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] NextEra/FPL's terms bind non-rate disputes to arbitration with a class action waiver\nWHAT THE TERMS SAY: The row states NextEra Energy (parent of Florida Power & Light) ToS contain a binding arbitration clause with a class action waiver, using AAA rules under Florida law, covering disputes over the website, app, and non-rate-related service issues.\nWHY IT MATTERS: Customers with disputes about the app or non-rate service issues are pushed into individual arbitration and lose the ability to join a class action.\n(evidence: Arbitration / Class Action Waiver; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OPT_OUT_DEADLINE · FL-3] NextEra gives customers just 30 days to opt out of the arbitration clause\nWHAT THE TERMS SAY: The row states the arbitration clause carries a 30-day opt-out window.\nWHY IT MATTERS: Customers who miss the narrow 30-day window remain bound to arbitration and the class action waiver even if they later object.\n(evidence: Arbitration Opt-Out Window (Days); Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] NextEra's smart meters generate data covered by the Naperville analysis referenced across this tab\nWHAT THE TERMS SAY: The row states smart-meter data provides granular household activity patterns (when residents wake, sleep, leave, return), noting the Naperville smart-meter analysis applies here as elsewhere in the tab.\nWHY IT MATTERS: This level of detail can reveal daily household routines; the row states law-enforcement access generally requires a warrant or subpoena, but retention and sharing specifics for NextEra itself aren't detailed.\n(evidence: Data Sharing/Selling Flags; Inferred from tracker text (fidelity pass 1: Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated with specifics, but smart-meter data retention and sharing details specific to NextEra aren't given.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "NextEra Energy  <-  NextEra Energy, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (10 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using NextEra Energy you gave up your right to sue and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Parent of Florida Power & Light and the largest renewable generator in the world. FPL drew significant scrutiny over political spending and rate-case conduct in Florida — a governance matter rather than a data one, but the reason this row is not blank. The Naperville smart-meter analysis applies as everywhere in this tab.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Electric-Gas Utilities", "_row_id": 879, "_entity_id": 1193, "_entity_slug": "nextera-energy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Constellation Energy", "Category": "Energy", "Terms & Conditions URL": "See Constellation Energy's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Constellation Energy's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not applicable in the typical consumer-arbitration sense for many utilities, which are often regulated monopolies subject to state public utility commission oversight rather than private arbitration — recommend confirming this utility's specific dispute-resolution process.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Baltimore", "HQ State": "Maryland", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Baltimore, Maryland (DC/MD/VA)", "Parent / Ultimate Owner": "Constellation Energy Corporation", "Years Referenced in Finding (heuristic)": "2022", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Maryland SDAT Business Entity Search — egov.maryland.gov/businessexpress/entitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Constellation Energy Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Constellation's 2022 split from Exelon leaves DMV customers juggling two companies' separate policies for what was one relationship\nWHAT THE TERMS SAY: The row states Constellation was separated from Exelon in 2022, with Constellation now the generation business while Exelon retains the regulated utilities (Pepco, BGE, Delmarva), so a customer who gets a Constellation retail energy offer and an Exelon utility bill is dealing with two companies that were formerly one, each with its own policies.\nWHY IT MATTERS: Customers may not realize their retail energy supplier and their regulated utility are now legally separate companies with different data and service terms, making it harder to know which policy governs a given interaction.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the Exelon/Constellation split is company-specific and confirmed; retail energy marketing enforcement is described as sector-wide, not Constellation-specific, and the arbitration field says the opt-out window is not stated, leaving no second or third distinct, sourced item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration and fee terms are unconfirmed, and most data-sharing text is generic boilerplate shared across the tab rather than Constellation-specific.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Constellation Energy  <-  Constellation Energy Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Constellation Energy takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Constellation was separated from Exelon in 2022 and is now the generation business, while Exelon retains the regulated utilities including Pepco, BGE and Delmarva documented in the Power Utilities tab. The split is the note worth recording: customers in the DMV who receive a Constellation retail energy offer and an Exelon utility bill are dealing with two companies that were one, with separate policies. Retail energy supply marketing has also drawn extensive state enforcement for deceptive rate practices.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Electric-Gas Utilities", "_row_id": 880, "_entity_id": 1195, "_entity_slug": "constellation-energy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "PG&E", "Category": "Utilities: Gas and Electric", "Terms & Conditions URL": "See PG&E's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See PG&E's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not applicable in the typical consumer-arbitration sense for many utilities, which are often regulated monopolies subject to state public utility commission oversight rather than private arbitration — recommend confirming this utility's specific dispute-resolution process.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Oakland", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "PG&E Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: PG&E Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] PG&E pleaded guilty to involuntary manslaughter over the Camp Fire and operated under criminal probation after bankruptcy\nWHAT THE TERMS SAY: The row states PG&E pleaded guilty to involuntary manslaughter over the Camp Fire, filed for bankruptcy under wildfire liabilities, and has operated under criminal probation.\nWHY IT MATTERS: The row frames this as the dominant risk for PG&E customers, more significant than any privacy issue, cautioning that a quiet privacy record shouldn't be mistaken for an overall clean record.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Naperville smart-meter analysis applies to PG&E; California residents at least have CCPA rights others lack\nWHAT THE TERMS SAY: The row states the Naperville smart-meter analysis applies to PG&E as to every utility in the tab, and notes California residents have CCPA rights that most other states' utility customers do not.\nWHY IT MATTERS: Smart meter data can reveal detailed household patterns; CCPA gives Californians some recourse, but the row states nothing PG&E-specific was confirmed this pass on collection or retention.\n(evidence: SCARY; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two items are supported by the row's text: the Camp Fire criminal/bankruptcy history and the generic smart-meter/CCPA note. Arbitration is described as not confirmed ('opt-out window not stated'), leaving no third distinct, company-specific harm.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=Y; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The wildfire criminal history is clearly stated, but privacy/data practices are explicitly unconfirmed this pass.", "Exposure Score (0-100)": 8, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 5/20 (severity2+2, penalty+3) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "PG&E  <-  PG&E Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, PG&E takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "PG&E is the utility whose findings are least about data: it pleaded guilty to involuntary manslaughter over the Camp Fire, filed for bankruptcy under wildfire liabilities, and has operated under criminal probation. That belongs in this row so a future reader does not mistake a quiet privacy record for a clean one. On the data question, the Naperville smart meter analysis applies as it does to every utility here, and California residents at least have CCPA rights that most other states' utility customers do not.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Electric-Gas Utilities", "_row_id": 881, "_entity_id": 1197, "_entity_slug": "pg-e", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Exelon", "Category": "Utilities: Gas and Electric", "Terms & Conditions URL": "See Exelon's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Exelon's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Exelon is the parent of THREE DMV utilities (BGE, Pepco, Delmarva Power). Customer data practices governed by respective state PUC regulations. Smart-meter deployment varies by subsidiary. DC PSC has specific rules about utility data sharing and customer privacy that override Exelon's corporate policies.", "Arbitration / Class Action Waiver": "Regulated utility — disputes governed by state public utility commissions. Exelon subsidiaries include ComEd (IL), PECO (PA), BGE (MD — DMV), Pepco (DC/MD — DMV), Delmarva Power (DE/MD — DMV), Atlantic City Electric (NJ). BGE, Pepco, and Delmarva are DMV utilities regulated by the DC PSC, MD PSC, and DE PSC respectively.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Chicago", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Parent of BGE (MD), Pepco (DC/MD), Delmarva Power (DE/MD) — DMV tag based on subsidiary operations, not corporate HQ (Chicago, IL)", "Parent / Ultimate Owner": "Exelon Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Exelon Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] One Exelon parent sets data-governance choices for three utility brands across DC, Maryland and Delaware\nWHAT THE TERMS SAY: The row states Exelon is the parent of Pepco, BGE, and Delmarva Power, and that Washington, Baltimore, and Delaware households are all governed by data-governance decisions — collection interval, retention, and law-enforcement response — made centrally by Exelon, none of which is prominent in any customer-facing document.\nWHY IT MATTERS: Customers of what look like separate regional utility brands are governed by collection-interval, retention and law-enforcement-response choices made in one place, none of which is prominent in any customer-facing document.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is company-specific and substantive — centralized data governance across Exelon's three DMV subsidiaries. The row states disputes are handled by state PUCs (no arbitration clause identified) and directs readers to the separate Power Utilities tab for subsidiary-level detail, leaving no other distinct harm to report here.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The centralized governance structure is stated clearly, but the underlying data policies themselves are described as not prominent in customer-facing documents.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Exelon  <-  Exelon Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Exelon you gave up your data shared corporate-wide. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Exelon is the parent of Pepco, BGE and Delmarva Power - the three utilities serving most of DC, Maryland and Delaware, documented individually in the Power Utilities tab. The finding worth stating once at the parent level: those three brands share one set of data-governance decisions, so a Washington household, a Baltimore household and a Delaware household are all governed by choices made in one place about collection interval, retention and law enforcement response. None of those choices is prominent in any customer-facing document.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Electric-Gas Utilities", "_row_id": 882, "_entity_id": 1198, "_entity_slug": "exelon", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "American Electric Power", "Category": "Utilities: Gas and Electric", "Terms & Conditions URL": "See American Electric Power's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See American Electric Power's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not applicable in the typical consumer-arbitration sense for many utilities, which are often regulated monopolies subject to state public utility commission oversight rather than private arbitration — recommend confirming this utility's specific dispute-resolution process.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Columbus", "HQ State": "Ohio", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Ohio' is a non-DMV US state", "Parent / Ultimate Owner": "American Electric Power Company, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: American Electric Power Company, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] AEP subsidiary Appalachian Power leaves Virginia and West Virginia customers with no alternative electricity provider at any price\nWHAT THE TERMS SAY: The row states AEP is the parent of Appalachian Power, serving VA/WV territory where no alternative electricity provider exists at any price, and that the Seventh Circuit in Naperville held smart-meter interval data to be a Fourth Amendment search because it reveals occupancy, sleep, meal, and EV-charging patterns.\nWHY IT MATTERS: Customers who object to how their granular usage data is handled have no competing provider to switch to; the row states nothing AEP-specific was confirmed this pass on retention or sharing.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one substantive item is supported — the monopoly/smart-meter finding — and the row explicitly states nothing company-specific was confirmed this pass; arbitration terms are also unconfirmed ('opt-out window not stated'), leaving no other distinct, sourced harm.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row explicitly states nothing company-specific was confirmed this pass, and arbitration terms are unstated.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "American Electric Power  <-  American Electric Power Company, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, American Electric Power takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "AEP is the parent of Appalachian Power, documented in the Power Utilities tab, serving Virginia and West Virginia territory where no alternative electricity provider exists at any price. Smart meter interval data was held by the Seventh Circuit in Naperville to constitute a Fourth Amendment search, because appliance-level consumption signatures reveal occupancy, sleep and meal routines and EV charging patterns. Nothing company-specific confirmed this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Electric-Gas Utilities", "_row_id": 883, "_entity_id": 1200, "_entity_slug": "american-electric-power", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "DTE Energy", "Category": "Utilities: Gas and Electric", "Terms & Conditions URL": "See DTE Energy's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See DTE Energy's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not applicable in the typical consumer-arbitration sense for many utilities, which are often regulated monopolies subject to state public utility commission oversight rather than private arbitration — recommend confirming this utility's specific dispute-resolution process.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Detroit", "HQ State": "Michigan", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Michigan' is a non-DMV US state", "Parent / Ultimate Owner": "DTE Energy Company", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Michigan LARA Business Entity Search — cofs.lara.state.mi.us/SearchApi/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: DTE Energy Company). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] DTE's meters collect the interval data the Seventh Circuit found constitutionally significant in Naperville\nWHAT THE TERMS SAY: The row states DTE's meters collect the interval consumption data the Seventh Circuit found constitutionally significant in Naperville, while noting DTE's most prominent consumer harms are reliability/outage duration and rate increases rather than data practices.\nWHY IT MATTERS: Even though DTE's dominant complaints described in the row are service and billing related, its meters still gather granular usage data whose legal sensitivity has been recognized by a federal court.\n(evidence: SCARY; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — The row's own framing states that for DTE, practical consumer harm is far more often an outage or a bill than a data event, and no DTE-specific breach, arbitration, or fee detail is given, so only the generic smart-meter item is substantive enough to report.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No DTE-specific data, arbitration, or fee practices are confirmed; the row's main content is reliability/rate criticism, not terms disclosure.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "DTE Energy  <-  DTE Energy Company", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, DTE Energy takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Michigan utility that has faced sustained regulatory and legislative criticism over reliability and outage duration, and over the size of its rate increases. For a household, the practical harm from a monopoly utility is far more often an outage or a bill than a data event — though its meters collect the interval data the Seventh Circuit found constitutionally significant in Naperville.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Electric-Gas Utilities", "_row_id": 884, "_entity_id": 1202, "_entity_slug": "dte-energy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "FirstEnergy", "Category": "Utilities: Gas and Electric", "Terms & Conditions URL": "See FirstEnergy's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See FirstEnergy's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not applicable in the typical consumer-arbitration sense for many utilities, which are often regulated monopolies subject to state public utility commission oversight rather than private arbitration — recommend confirming this utility's specific dispute-resolution process.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Akron", "HQ State": "Ohio", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Ohio' is a non-DMV US state", "Parent / Ultimate Owner": "FirstEnergy Corp.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: FirstEnergy Corp.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] FirstEnergy, parent of Potomac Edison, is tied to one of the largest utility corruption matters in recent US history, though this pass didn't verify current figures\nWHAT THE TERMS SAY: The row states FirstEnergy has been the subject of one of the largest utility corruption matters in recent US history, involving legislative bribery in Ohio, but this pass did not independently verify the settlement figures or current posture, so none are asserted.\nWHY IT MATTERS: A Maryland/West Virginia household's utility data governance is set by a corporate parent under this cloud, and per the row, that household has no alternative provider.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is substantiated — the FirstEnergy corruption matter, explicitly flagged by the row as unverified pending follow-up. Arbitration opt-out terms are also unstated, and no other company-specific data or fee detail is given for a second or third item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The row explicitly says the corruption matter's figures and current posture were not independently verified this pass.", "Exposure Score (0-100)": 8, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "FirstEnergy  <-  FirstEnergy Corp.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, FirstEnergy takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "FirstEnergy is the parent of Potomac Edison, which serves Maryland and West Virginia customers. FirstEnergy has been the subject of one of the largest utility corruption matters in recent US history involving legislative bribery in Ohio - this pass did not independently verify the settlement figures or current posture, so none are asserted here, and a direct follow-up is recommended before publishing anything on it. The point that does hold without qualification is that a Maryland household's utility data governance is set by a corporate parent under that cloud, and the household has no alternative provider.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Electric-Gas Utilities", "_row_id": 885, "_entity_id": 1204, "_entity_slug": "firstenergy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Xcel Energy", "Category": "Utilities: Gas and Electric", "Terms & Conditions URL": "See Xcel Energy's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Xcel Energy's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not applicable in the typical consumer-arbitration sense for many utilities, which are often regulated monopolies subject to state public utility commission oversight rather than private arbitration — recommend confirming this utility's specific dispute-resolution process.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Minneapolis", "HQ State": "Minnesota", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Minnesota' is a non-DMV US state", "Parent / Ultimate Owner": "Xcel Energy Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Xcel Energy Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-1] Xcel equipment implicated in Colorado's Marshall Fire has produced extensive litigation from households who had no alternative utility to choose\nWHAT THE TERMS SAY: The row states Xcel's equipment was implicated in the Marshall Fire investigation in Colorado, producing extensive litigation from destroyed households, and calls this the dominant risk profile for electric utilities — dwarfing any privacy exposure.\nWHY IT MATTERS: Households allegedly harmed by fire linked to Xcel equipment had no choice of alternative utility provider, and the row states this physical/property risk is more significant than any data issue for this company.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the Marshall Fire litigation item is substantiated and company-specific; arbitration opt-out terms are unstated and no data-sharing specifics beyond the tab's generic boilerplate are given for Xcel, leaving no second or third distinct item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Marshall Fire litigation is clearly described, but data-practice specifics remain generic and unconfirmed.", "Exposure Score (0-100)": 10, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 10/20 (severity3+8, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Xcel Energy  <-  Xcel Energy Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Xcel Energy takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Upper Midwest and Colorado utility. Xcel's equipment was implicated in the Marshall Fire investigation in Colorado, producing extensive litigation from destroyed households — people harmed by a company they had no choice but to buy from. That is the dominant risk profile for electric utilities, and it dwarfs any privacy exposure.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Electric-Gas Utilities", "_row_id": 886, "_entity_id": 1206, "_entity_slug": "xcel-energy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sempra", "Category": "Utilities: Gas and Electric", "Terms & Conditions URL": "See Sempra's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Sempra's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not applicable in the typical consumer-arbitration sense for many utilities, which are often regulated monopolies subject to state public utility commission oversight rather than private arbitration — recommend confirming this utility's specific dispute-resolution process.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Diego", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Sempra", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Sempra). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Sempra's SDG&E and SoCalGas meters collect Fourth-Amendment-relevant data, though California customers get CCPA rights most states lack\nWHAT THE TERMS SAY: The row states Sempra (parent of SDG&E and SoCalGas) meters generate the interval data the Seventh Circuit held to be a Fourth Amendment search in Naperville, that nothing company-specific was confirmed this pass, and that California customers hold CCPA rights most other states' utility customers lack.\nWHY IT MATTERS: The row frames this as evidence that a consumer's utility privacy position is set by their state legislature, not by anything they personally agreed to.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only the generic smart-meter/CCPA item is supported; the row explicitly states nothing Sempra-specific was confirmed this pass, and arbitration opt-out terms are also unstated, leaving no second or third distinct company-specific harm.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row explicitly states nothing company-specific was confirmed this pass.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Sempra  <-  Sempra", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (12 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Sempra takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Parent of San Diego Gas & Electric and SoCalGas. Smart meter interval data was held by the Seventh Circuit in Naperville to constitute a Fourth Amendment search, because appliance-level consumption signatures reveal occupancy, sleep and meal routines and EV charging patterns. Nothing company-specific confirmed this pass. California customers hold CCPA rights that utility customers in most other states do not, which is worth noting as the clearest illustration in this tab that a consumer's utility privacy position is set by their state legislature rather than by anything they agreed to.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Electric-Gas Utilities", "_row_id": 887, "_entity_id": 1207, "_entity_slug": "sempra", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Eversource Energy", "Category": "Utilities: Gas and Electric", "Terms & Conditions URL": "See Eversource Energy's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Eversource Energy's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility serving CT, MA, NH. Customer data governed by state PUC regulations. Connecticut's new neural data protections (SB1295, July 2026) apply to Eversource's Connecticut operations.", "Arbitration / Class Action Waiver": "Regulated utility — disputes governed by CT PURA, MA DPU, NH PUC. No private arbitration clause in consumer-facing terms.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Hartford", "HQ State": "Connecticut", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Connecticut' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Connecticut SOTS CONCORD — service.ct.gov/business/s/onlinebusinesssearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Connecticut's new neural-data protection law now applies to Eversource's Connecticut operations\nWHAT THE TERMS SAY: The row states Connecticut's new neural data protections (SB1295, effective July 2026) apply to Eversource's Connecticut operations, alongside its regulated utility data practices governed by CT PURA, MA DPU, and NH PUC.\nWHY IT MATTERS: This signals an emerging category of legal protection for a new kind of sensitive data in one of Eversource's three states, though the row doesn't specify what Eversource itself currently collects that would trigger it.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one company/jurisdiction-specific item is supported — the new Connecticut neural-data law's applicability; the row's other content (rate/performance scrutiny, generic smart-meter note, monopoly framing) repeats boilerplate shared across this tab's utility rows without Eversource-specific clause detail.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "No private arbitration exists (clear), but Connecticut's new neural-data law's application to Eversource's actual practices isn't detailed.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Eversource Energy  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Eversource Energy takes nothing from the list this tracker checks - but 10 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "New England utility, subject of significant state regulatory scrutiny in Connecticut over rate increases and performance. Its smart meters collect the same interval consumption data described in the Naperville analysis, and as with every utility in this tab, a dissatisfied customer has no alternative provider to move to.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Electric-Gas Utilities", "_row_id": 888, "_entity_id": 1208, "_entity_slug": "eversource-energy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Entergy", "Category": "Utilities: Gas and Electric", "Terms & Conditions URL": "See Entergy's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Entergy's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility. Customer data governed by state PUC regulations. Entergy operates the Grand Gulf nuclear plant and customer data includes nuclear-adjacent community information.", "Arbitration / Class Action Waiver": "Regulated utility — disputes governed by state PSCs (AR, LA, MS, TX). No private arbitration clause.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New Orleans", "HQ State": "Louisiana", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Louisiana' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Louisiana) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Louisiana. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Entergy's meter data doubles as a court-recognized 'search,' and its shutoff/payment-plan records track financial distress in a region customers can't leave\nWHAT THE TERMS SAY: The row states Entergy's meter reports often enough that a court called collecting it a search, and that in high-energy-burden areas across Louisiana, Mississippi, Arkansas, and Texas, shutoff and payment-plan records constitute a financial-distress dataset held by a provider the household cannot leave.\nWHY IT MATTERS: Combining fine-grained usage data with payment-distress records under one monopoly provider means vulnerable households have no alternative if they're uncomfortable with how that data is handled, though the row confirms nothing Entergy-specific this pass.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one substantive item is supported — the meter/shutoff financial-distress combination; the nuclear-adjacent community-data mention is too thin (no specifics on collection, use, or sharing) to support a second distinct item, and no arbitration clause exists to report.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row explicitly states nothing company-specific was confirmed this pass, and the nuclear-adjacent data note is undetailed.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Entergy  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Entergy takes nothing from the list this tracker checks - but 10 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The meter on this utility's customers' homes reports often enough that a court called collecting it a search. Gulf South utility serving Louisiana, Mississippi, Arkansas and Texas, including areas with high energy burden where shutoff and payment-plan records constitute a financial-distress dataset held by a provider the household cannot leave. Nothing company-specific confirmed this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Electric-Gas Utilities", "_row_id": 889, "_entity_id": 1209, "_entity_slug": "entergy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "AES", "Category": "Utilities: Gas and Electric", "Terms & Conditions URL": "See AES's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See AES's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "DMV-headquartered global energy company. US utility subsidiaries' customer data governed by respective state PUC regulations. International operations subject to local data protection laws (GDPR in European operations, LGPD in Brazil).", "Arbitration / Class Action Waiver": "Regulated utility — disputes governed by state/international regulators. AES HQ: Arlington, Virginia (DMV). AES operates in 15 countries. US operations include Indianapolis Power & Light and AES Ohio (formerly Dayton Power & Light).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Arlington", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "The AES Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: The AES Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] AES's own row contradicts itself on whether it has US household customers\nWHAT THE TERMS SAY: The SCARY field states AES has 'No US household relationship' and sells wholesale generation domestically, but the Arbitration field in the same row lists AES's US operations as including Indianapolis Power & Light and AES Ohio (formerly Dayton Power & Light), and the Data Sharing field refers to 'US utility subsidiaries' customer data.'\nWHY IT MATTERS: If IPL and AES Ohio serve individual households, as their names and structure suggest, AES may have direct US consumer relationships this row's own SCARY framing denies, meaning the actual consumer-data picture for AES customers in Indiana and Ohio may be undocumented here.\n(evidence: SCARY | Arbitration / Class Action Waiver | Data Sharing/Selling Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-4] AES directly serves consumers in Puerto Rico and El Salvador, outside this tracker's Mid-Atlantic scope\nWHAT THE TERMS SAY: The row states AES does own utilities in Puerto Rico and El Salvador where it serves consumers directly — a genuine consumer relationship, just not one inside this tracker's Mid-Atlantic scope.\nWHY IT MATTERS: Consumers in those markets have a real AES account relationship that this tracker acknowledges but does not evaluate, leaving their data and terms exposure entirely undocumented here.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Two items are supported (an internal contradiction about US consumer relationships, and an acknowledged-but-unexamined Puerto Rico/El Salvador consumer relationship); no third distinct, sourced harm is available since the row provides no arbitration, fee, or breach detail for any AES entity.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=N; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The row contradicts itself about whether AES has US household customers, and its international consumer relationships are acknowledged but unexamined.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "AES  <-  The AES Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Global power generation and distribution, operating utilities largely outside the US and selling wholesale generation domestically. No US household relationship. AES does own utilities in Puerto Rico and El Salvador where it serves consumers directly — a genuine consumer relationship, just not one inside this tracker's Mid-Atlantic scope, and worth flagging before treating the row as purely wholesale.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Electric-Gas Utilities", "_row_id": 890, "_entity_id": 1211, "_entity_slug": "aes", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "WEC Energy", "Category": "Utilities: Gas and Electric", "Terms & Conditions URL": "See WEC Energy's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See WEC Energy's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility serving WI, IL, MI, MN. Customer data governed by state PUC regulations.", "Arbitration / Class Action Waiver": "Regulated utility — disputes governed by WI PSC, IL CC, MI PSC, MN PUC. No private arbitration clause.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Milwaukee", "HQ State": "Wisconsin", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Wisconsin' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Wisconsin DFI Corporate Records — apps.dfi.wi.gov/apps/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] WEC's interval meters reveal household occupancy and routine, with retention and disclosure rules set by the utility.\nWHAT THE TERMS SAY: The row states interval meter data reveals household occupancy and routine, that retention periods are set by the utility rather than the customer, and that the law-enforcement request policy is rarely published anywhere a ratepayer would find it.\nWHY IT MATTERS: Customers have no confirmed way to learn how long their usage data is kept or when it is handed to law enforcement.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is supported; the tracker states nothing company-specific was confirmed this pass, and arbitration/fees fields contain no substantive company detail beyond the absence of a private arbitration clause.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing, arbitration, and fees are all generic or unconfirmed for WEC specifically; only an industry-wide structural point is stated.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "WEC Energy  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, WEC Energy takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Wisconsin and Illinois utility. Nothing company-specific confirmed this pass. The structural point applies unchanged: interval meter data reveals household occupancy and routine, retention periods are set by the utility rather than the customer, and the law enforcement request policy is rarely published anywhere a ratepayer would find it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Electric-Gas Utilities", "_row_id": 891, "_entity_id": 1212, "_entity_slug": "wec-energy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CenterPoint Energy", "Category": "Utilities: Gas and Electric", "Terms & Conditions URL": "See CenterPoint Energy's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See CenterPoint Energy's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility. Customer data governed by state PUC regulations. CenterPoint faced severe criticism during Hurricane Beryl (July 2024) over power restoration and customer communication failures.", "Arbitration / Class Action Waiver": "Regulated utility — disputes governed by TX PUC, IN IURC, OH PUCO, MN PUC. No private arbitration clause.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] CenterPoint's interval meters produce the appliance-level detail a court found constitutionally significant.\nWHAT THE TERMS SAY: The row states CenterPoint's interval metering produces the appliance-level detail the Naperville court found constitutionally significant.\nWHY IT MATTERS: The same meter data that runs the grid also reveals granular information about activity inside a customer's home.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is supported; the row explicitly records the Hurricane Beryl criticism as a service-reliability issue rather than a data or contract term, and arbitration/fees are not itemized for CenterPoint specifically.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "One specific, company-tied data fact is stated (the Naperville-linked meter data point), but arbitration and fees are not itemized for CenterPoint specifically.", "Exposure Score (0-100)": 8, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "CenterPoint Energy  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, CenterPoint Energy takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Interval metering here produces the appliance-level detail the Naperville court found constitutionally significant. Texas and Midwest utility. CenterPoint drew significant regulatory and legislative scrutiny over storm response and outage communications, which is a service-reliability matter rather than a data one and is recorded as such.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Electric-Gas Utilities", "_row_id": 892, "_entity_id": 1213, "_entity_slug": "centerpoint-energy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "PPL", "Category": "Utilities: Gas and Electric", "Terms & Conditions URL": "See PPL's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See PPL's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not applicable in the typical consumer-arbitration sense for many utilities, which are often regulated monopolies subject to state public utility commission oversight rather than private arbitration — recommend confirming this utility's specific dispute-resolution process.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Allentown", "HQ State": "Pennsylvania", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "PPL Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: PPL Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] PPL's billing system failure produced estimated and erroneous bills at scale, drawing regulatory attention.\nWHAT THE TERMS SAY: The row states PPL faced substantial customer complaints and regulatory attention after a billing system failure produced estimated and erroneous bills at scale.\nWHY IT MATTERS: The row records substantial customer complaints and regulatory attention over this, and calls it a reminder that the utility data most likely to harm you is the reading on your own bill.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[LOCATION_TRACKING · FL-2] PPL's smart-meter reads reveal household occupancy and appliance-usage patterns.\nWHAT THE TERMS SAY: The row states PPL's smart-meter data reveals household occupancy and appliance-usage patterns, with law-enforcement sharing generally requiring a warrant or subpoena under state PUC rules.\nWHY IT MATTERS: Detailed usage data can expose a household's daily routines even though it's collected for billing purposes.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct items are supported; arbitration status is explicitly unconfirmed ('recommend confirming this utility's specific dispute-resolution process') and fees beyond the billing-failure item are not itemized.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The billing-failure finding and smart-meter data practice are stated concretely, but arbitration status is explicitly unconfirmed and fees are otherwise not itemized.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "PPL  <-  PPL Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, PPL takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Pennsylvania and Kentucky utility with a footprint adjacent to this tracker's core region. PPL faced substantial customer complaints and regulatory attention after a billing system failure produced estimated and erroneous bills at scale — a reminder that the utility data most likely to harm you is the reading on your own bill.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Electric-Gas Utilities", "_row_id": 893, "_entity_id": 1215, "_entity_slug": "ppl", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ameren", "Category": "Utilities", "Terms & Conditions URL": "See Ameren's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Ameren's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility serving MO and IL. Customer data governed by state PUC regulations.", "Arbitration / Class Action Waiver": "Regulated utility — disputes governed by MO PSC and IL CC. No private arbitration clause.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "St. Louis", "HQ State": "Missouri", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Missouri' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Missouri SOS Business Search — bsd.sos.mo.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-3] Ameren customers get materially different privacy protection depending on which state they're served in.\nWHAT THE TERMS SAY: The row states Illinois customers hold biometric rights under BIPA that Missouri customers do not, so two halves of the same utility's service territory operate under materially different privacy law.\nWHY IT MATTERS: A Missouri customer has no BIPA-style recourse that an Illinois customer served by the same company would have.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is supported; the tracker states nothing company-specific was confirmed this pass on data sharing or arbitration, leaving the BIPA jurisdictional-disparity note as the sole substantive, company-tied fact.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing and arbitration are both generic or unconfirmed for Ameren specifically; only the cross-state BIPA disparity point is company-tied.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Ameren  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Ameren takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Missouri and Illinois utility. Nothing company-specific confirmed this pass. Worth noting that Illinois customers hold biometric rights under BIPA that Missouri customers do not, so two halves of the same utility's service territory operate under materially different privacy law — a clean illustration of cross-cutting finding #10.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Electric-Gas Utilities", "_row_id": 894, "_entity_id": 1216, "_entity_slug": "ameren", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CMS Energy", "Category": "Utilities: Gas and Electric", "Terms & Conditions URL": "See CMS Energy's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See CMS Energy's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not applicable in the typical consumer-arbitration sense for many utilities, which are often regulated monopolies subject to state public utility commission oversight rather than private arbitration — recommend confirming this utility's specific dispute-resolution process.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Jackson", "HQ State": "Michigan", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Michigan' is a non-DMV US state", "Parent / Ultimate Owner": "CMS Energy Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Michigan LARA Business Entity Search — cofs.lara.state.mi.us/SearchApi/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: CMS Energy Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] CMS Energy's smart-meter reads reveal household occupancy and appliance-usage patterns.\nWHAT THE TERMS SAY: The row states CMS's smart-meter data reveals household occupancy and appliance-usage patterns, with law-enforcement sharing generally requiring a warrant or subpoena under state PUC rules.\nWHY IT MATTERS: Detailed usage data can expose a household's routines even though it's collected only for billing.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-3] Michigan has no comprehensive privacy statute, so CMS customers' only recourse runs through the utility commission.\nWHAT THE TERMS SAY: The row states Michigan has no comprehensive state privacy statute, so a CMS customer's leverage runs through the Public Service Commission rather than any privacy right.\nWHY IT MATTERS: Customers cannot invoke a state privacy law over how CMS handles their meter data; the utility commission is the only avenue.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two items are supported; arbitration is explicitly described as not confirmed in the typical consumer sense, and fees are not itemized.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Smart-meter data practices are stated concretely, but arbitration status is unconfirmed and Michigan's lack of a privacy statute limits what else can be verified.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "CMS Energy  <-  CMS Energy Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, CMS Energy takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Michigan utility, subject alongside DTE to state scrutiny over reliability. Nothing company-specific confirmed this pass on data. The Naperville interval-data analysis applies, and Michigan has no comprehensive state privacy statute, so a customer's leverage runs through the Public Service Commission rather than any privacy right.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Electric-Gas Utilities", "_row_id": 895, "_entity_id": 1218, "_entity_slug": "cms-energy", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Consolidated Edison", "Category": "Utilities: Gas and Electric", "Terms & Conditions URL": "See Consolidated Edison's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Consolidated Edison's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not applicable in the typical consumer-arbitration sense for many utilities, which are often regulated monopolies subject to state public utility commission oversight rather than private arbitration — recommend confirming this utility's specific dispute-resolution process.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: New York, New York (non-US)", "Parent / Ultimate Owner": "Consolidated Edison, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Consolidated Edison, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — active/unresolved matter cited in finding)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Con Edison's meters generate the occupancy-revealing consumption record central to the Naperville ruling.\nWHAT THE TERMS SAY: The row states this utility's meters generate the occupancy-revealing consumption record at issue in the Naperville ruling, alongside standard smart-meter data sharing rules requiring a warrant or subpoena for law-enforcement access.\nWHY IT MATTERS: Consumption data can reveal a household's presence and routine even though it's collected for billing.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is supported; arbitration status is unconfirmed, fees are not itemized, and the row's point about NY DFS cybersecurity rules is protective context rather than a troubling term for Con Edison itself.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The meter-data practice is stated concretely, but arbitration status is unconfirmed and fees are not itemized.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Consolidated Edison  <-  Consolidated Edison, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Consolidated Edison takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "This utility's meters generate the occupancy-revealing consumption record at issue in the Naperville ruling. New York utility. Con Ed customers do at least benefit from an unusually active state regulator and from NY DFS cybersecurity requirements, which produced the GEICO and Travelers penalties documented in the Insurance tabs - a reminder that regulatory geography, not company choice, drives most of the accountability in this tracker.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Electric-Gas Utilities", "_row_id": 896, "_entity_id": 1220, "_entity_slug": "consolidated-edison", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Vistra", "Category": "Energy", "Terms & Conditions URL": "See Vistra's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Vistra's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Regulated utility — customer data (usage patterns, billing, smart-meter reads) governed by state public utility commission regulations, which typically restrict data sharing more than company-level privacy policies. Smart-meter data reveals household occupancy and appliance-usage patterns. Data sharing with law enforcement generally requires a warrant or subpoena under state PUC rules.", "Arbitration / Class Action Waiver": "Not applicable in the typical consumer-arbitration sense for many utilities, which are often regulated monopolies subject to state public utility commission oversight rather than private arbitration — recommend confirming this utility's specific dispute-resolution process.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Power Utilities tab (Pepco, BGE, Dominion Energy Virginia, etc.) for the fullest treatment of DMV-region utility billing/shutoff practices — this company likely serves a different geographic region but may share similar regulatory and billing-dispute patterns.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AUTO_RENEWAL_FEES · FL-1] Vistra sits in a retail-electricity sector flagged for rates resetting far above intro offers\nWHAT THE TERMS SAY: The row states Vistra's retail electricity business sits in a sector with sustained state enforcement over deceptive rate marketing, specifically variable rates that reset far above the introductory offer.\nWHY IT MATTERS: A customer who signs up on a low intro rate can see their bill jump sharply once the promotional period ends.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "[DARK_PATTERN_CONSENT · FL-1] Vistra's retail-energy sector faces state enforcement over door-to-door sales tactics\nWHAT THE TERMS SAY: The row states the retail energy sector, which includes Vistra, has drawn sustained state enforcement over door-to-door sales practices alongside deceptive rate marketing.\nWHY IT MATTERS: The row records door-to-door sales practices as part of the sustained state enforcement in this sector, and calls this the harm a consumer in a deregulated market is most likely to actually encounter.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 1: Overstated corrected) (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[LOCATION_TRACKING · FL-2] Vistra's smart-meter data reveals household occupancy and appliance-usage patterns.\nWHAT THE TERMS SAY: The row states smart-meter data reveals household occupancy and appliance-usage patterns, shared with law enforcement only under a warrant or subpoena per state PUC rules.\nWHY IT MATTERS: Usage data collected for billing can also expose a household's routine.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Retail-market pricing risk and smart-meter data practices are described, but framed as sector-wide patterns rather than confirmed Vistra-specific enforcement actions.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Vistra  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Vistra you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Vistra is primarily a competitive power generator and retail electricity provider in deregulated markets. Retail energy supply is the consumer-facing part, and it is a sector with sustained state enforcement over deceptive rate marketing - variable rates that reset far above the introductory offer, and door-to-door sales practices. That is a pricing and disclosure finding rather than a privacy one, and it is the harm a consumer in a deregulated market is most likely to actually encounter.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Electric-Gas Utilities", "_row_id": 897, "_entity_id": 1221, "_entity_slug": "vistra", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Goldman Sachs", "Category": "Commercial Banks", "Terms & Conditions URL": "See Goldman Sachs's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Goldman Sachs's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Goldman Sachs' Consumer Privacy Notice (required by Gramm-Leach-Bliley Act) discloses sharing personal information with affiliates for marketing, joint marketing with other financial companies, and sharing as permitted by law. Opt-out available for affiliate marketing. Marcus (consumer banking) collects credit, transaction, and device data.", "Arbitration / Class Action Waiver": "MANDATORY pre-dispute arbitration for brokerage clients per FINRA rules (Goldman Sachs & Co. LLC is a FINRA member). Wealth management and Marcus (consumer banking) agreements contain separate arbitration clauses. FINRA Rule 2268 prohibits class action waivers in brokerage customer agreements.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly checking for any retail-facing product (e.g., a Goldman Sachs Marcus-style consumer bank) this company might separately operate.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "The Goldman Sachs Group, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: The Goldman Sachs Group, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] Goldman's Marcus/Apple Card business drew a CFPB action over credit card servicing and dispute handling.\nWHAT THE TERMS SAY: The row states the Marcus consumer bank and the Apple Card partnership drew a CFPB action concerning credit card servicing and dispute handling.\nWHY IT MATTERS: Consumers with Apple Card/Marcus accounts faced servicing and dispute-handling problems significant enough to draw federal regulatory action.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Mandatory FINRA arbitration for Goldman brokerage clients; wealth management and Marcus have separate clauses\nWHAT THE TERMS SAY: The row states mandatory pre-dispute arbitration applies to brokerage clients under FINRA rules, with wealth management and Marcus each containing separate arbitration clauses; FINRA Rule 2268 bars class action waivers in the brokerage agreements specifically.\nWHY IT MATTERS: Customers across Goldman's consumer and brokerage products are steered to arbitration rather than court, though brokerage clients keep the right to bring class claims.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Goldman shares customer data with affiliates for marketing and joint marketing with other financial companies.\nWHAT THE TERMS SAY: The row states Goldman's GLB-required privacy notice discloses sharing personal information with affiliates for marketing and joint marketing with other financial companies, with an opt-out available for affiliate marketing.\nWHY IT MATTERS: Customer data moves beyond the immediate account relationship unless the customer actively opts out.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=N; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms and the CFPB action are clearly stated, but data-privacy specifics beyond GLB boilerplate are unconfirmed this pass.", "Exposure Score (0-100)": 27, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 5/20 (severity2+2, penalty+3) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Goldman Sachs  <-  The Goldman Sachs Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n\nTHE DOCUMENT DOES NOT TAKE: your right to join a class action.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Goldman Sachs you gave up your data shared corporate-wide and your right to sue. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass on data privacy. Goldman's consumer-facing findings are elsewhere: the Marcus consumer bank and the Apple Card partnership drew a CFPB action concerning credit card servicing and dispute handling, and Goldman has since retreated substantially from consumer lending - meaning customers who opened accounts under one strategy had them transferred or wound down under another. Cross-ref the Clarity Money row in Niche Apps & Games, a Goldman acquisition that was shut down.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Financial Svcs Remainder", "_row_id": 898, "_entity_id": 1223, "_entity_slug": "goldman-sachs", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "BlackRock", "Category": "Securities", "Terms & Conditions URL": "See BlackRock's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See BlackRock's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "BlackRock manages $10.5T+ in assets. Its Aladdin platform processes risk analytics across institutional portfolios. Consumer-facing data sharing governed by GLB Act; institutional data governed by enterprise agreements. BlackRock's 2024 acquisition of Global Infrastructure Partners expanded its data footprint into infrastructure assets.", "Arbitration / Class Action Waiver": "MANDATORY pre-dispute arbitration for iShares and BlackRock Fund investors per fund prospectus terms. BlackRock's Aladdin platform (institutional) governed by separate enterprise agreements. FINRA arbitration applies to brokerage-distributed products.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly checking for any retail-facing product (e.g., a Goldman Sachs Marcus-style consumer bank) this company might separately operate.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "BlackRock, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: BlackRock, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] iShares and BlackRock Fund investors are bound to mandatory pre-dispute arbitration under fund prospectus terms.\nWHAT THE TERMS SAY: The row states mandatory pre-dispute arbitration applies to iShares and BlackRock Fund investors per fund prospectus terms, with FINRA arbitration applying separately to brokerage-distributed products.\nWHY IT MATTERS: Fund investors are routed to arbitration rather than court for disputes with BlackRock.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] BlackRock's Aladdin is a concentration point: many firms' risk decisions run through one system\nWHAT THE TERMS SAY: The row states BlackRock's Aladdin risk platform is used by a large share of the institutional market, making it a concentration point where many firms' risk decisions run through one system.\nWHY IT MATTERS: The row records Aladdin as a concentration point of a different kind - a large share of the institutional market runs its risk decisions through one system.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct items are supported this pass; the intermediated-relationship point (consumers reaching BlackRock through retirement plans and fund platforms) is structural context rather than a discrete harm, and fees/data-sale specifics are not itemized.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated for fund investors, but the consumer relationship is largely intermediated through retirement platforms so little else is confirmed.", "Exposure Score (0-100)": 20, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "BlackRock  <-  BlackRock, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using BlackRock you gave up your right to sue. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The world's largest asset manager, whose consumer relationship runs almost entirely through retirement plans and fund platforms rather than directly — the intermediated structure documented in the Franklin Resources and Empower rows. Its Aladdin risk platform is also used by a large share of the institutional market, making it a concentration point of a different kind: many firms' risk decisions run through one system.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Financial Svcs Remainder", "_row_id": 899, "_entity_id": 1225, "_entity_slug": "blackrock", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "KKR", "Category": "Securities", "Terms & Conditions URL": "See KKR's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See KKR's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Primarily institutional. KKR's portfolio companies (including Epicor, BrightSpring Health, Academy Sports) have their own separate data practices not governed by KKR's terms.", "Arbitration / Class Action Waiver": "B2B/institutional — KKR's consumer-facing footprint is minimal. Fund investor agreements contain arbitration provisions per industry practice. Individual investors typically access KKR through intermediary platforms (Schwab, Fidelity) whose own arbitration clauses govern the relationship.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly checking for any retail-facing product (e.g., a Goldman Sachs Marcus-style consumer bank) this company might separately operate.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Consumers dealing with a KKR portfolio company generally can't identify or evaluate the PE owner shaping its decisions.\nWHAT THE TERMS SAY: The row states KKR's portfolio spans healthcare, consumer services, and housing, that consumers dealing with a portfolio company generally cannot identify the owner or factor it into a decision, and that data-handling decisions are made against an eventual sale rather than a long customer relationship.\nWHY IT MATTERS: A private-equity owner's investment horizon, not a brand's reputational interest, drives how a portfolio company treats customer data.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is supported; KKR is classified B2B/institutional with minimal direct consumer footprint, and arbitration and fees are not itemized or directly applicable to individual consumers this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "KKR itself has no confirmed consumer terms this pass; only the structural private-equity ownership point is stated.", "Exposure Score (0-100)": 2, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "KKR  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Private equity ownership is the finding. KKR's portfolio spans healthcare, consumer services and housing, and consumers dealing with a portfolio company generally cannot identify the owner or factor it into a decision. The relevant structural point: private equity holds assets on an investment horizon rather than a brand's reputational one, and data-handling decisions at portfolio companies are made against an eventual sale rather than a long customer relationship.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Financial Svcs Remainder", "_row_id": 900, "_entity_id": 1226, "_entity_slug": "kkr", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Apollo Global Management", "Category": "Securities", "Terms & Conditions URL": "See Apollo Global Management's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Apollo Global Management's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Primarily institutional. Apollo's ownership of Yahoo/AOL (via the 2021 Verizon Media sale) creates indirect consumer data exposure — Yahoo Mail's 3B-account breach history is now under Apollo's portfolio umbrella.", "Arbitration / Class Action Waiver": "B2B/institutional — similar structure to KKR. Apollo's consumer exposure is through portfolio companies (Yahoo/AOL via Verizon Media Group acquisition, Shutterfly, Cox Media). Each portfolio company maintains its own T&C.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly checking for any retail-facing product (e.g., a Goldman Sachs Marcus-style consumer bank) this company might separately operate.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] Apollo owns Athene, an annuity insurer whose reserve investments annuitants cannot see or agree to\nWHAT THE TERMS SAY: The row states Apollo owns Athene, a large annuity provider, so retirement savers hold guaranteed-income products issued by an insurer owned by an alternative asset manager, a structure that has drawn sustained regulatory and academic attention over how such insurers invest their reserves.\nWHY IT MATTERS: The row states the annuitant's security depends on how such insurers invest their reserves - asset choices they cannot see and did not agree to - a structure that has drawn sustained regulatory and academic attention.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] Apollo's ownership of Yahoo/AOL brings Yahoo Mail's 3-billion-account breach history under its portfolio umbrella.\nWHAT THE TERMS SAY: The row states Apollo's 2021 acquisition of Yahoo/AOL (via the Verizon Media sale) means Yahoo Mail's 3-billion-account breach history is now under Apollo's portfolio umbrella.\nWHY IT MATTERS: Consumers whose accounts were exposed in that historical breach now have their data sitting inside an asset manager's portfolio rather than a dedicated consumer company's.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct items are supported; the point about portfolio companies handling data under an investment-resale horizon duplicates the same structural theme as the KKR row and is industry-shared context, not a distinct Apollo-specific harm.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Athene structure and the Yahoo/AOL breach history are stated concretely, but Apollo's own arbitration and fee terms are not confirmed since its footprint is primarily institutional.", "Exposure Score (0-100)": 5, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Apollo Global Management  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Private equity firm that owns Athene, a large annuity provider — meaning retirement savers hold guaranteed-income products issued by an insurer owned by an alternative asset manager. That structure has drawn sustained regulatory and academic attention over how such insurers invest their reserves, because the annuitant's security depends on asset choices they cannot see and did not agree to. Apollo's portfolio companies also hold consumer data across many sectors under an investment holding period rather than a brand's reputational horizon.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Financial Svcs Remainder", "_row_id": 901, "_entity_id": 402, "_entity_slug": "apollo-global-management", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Marsh & McLennan", "Category": "Diversified Financials", "Terms & Conditions URL": "See Marsh & McLennan's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Marsh & McLennan's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Mercer processes employee benefits data (health, retirement, compensation) for corporate clients. As a business associate under HIPAA for health-benefits administration. Data practices governed by client agreements, not consumer T&C.", "Arbitration / Class Action Waiver": "B2B — Marsh McLennan (parent of Marsh, Mercer, Guy Carpenter, Oliver Wyman) serves primarily commercial/institutional clients. Employee benefits participants interact through Mercer but the contractual relationship is between Mercer and the employer.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly checking for any retail-facing product (e.g., a Goldman Sachs Marcus-style consumer bank) this company might separately operate.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] Marsh & McLennan settled a landmark NY AG action over contingent commissions that steered clients to higher-paying insurers.\nWHAT THE TERMS SAY: The row states Marsh & McLennan settled a landmark New York Attorney General action over contingent commission arrangements that steered clients to insurers paying the broker more.\nWHY IT MATTERS: Clients relying on the broker's advice could have been placed with insurers chosen partly for the broker's own compensation rather than the client's best interest.\n(evidence: Major Issues Record; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Mercer handles health and retirement data for employees who never chose Mercer and can't decline\nWHAT THE TERMS SAY: The row states Mercer processes health, retirement, and compensation data for corporate clients, administering plan enrollment, participation, and claims analytics for a very large number of employers' employees, who are not Mercer's customers and cannot decline.\nWHY IT MATTERS: Employees have no direct relationship or contract with Mercer even though it handles their sensitive benefits data.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 1: Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two items are supported; the arbitration and fees fields are B2B and not itemized, yielding no distinct third consumer-facing term.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The contingent-commission settlement and the no-relationship benefits-data structure are both stated concretely, but arbitration and fee terms are not itemized since the relationship is B2B.", "Exposure Score (0-100)": 14, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 11/20 (severity3+8, penalty+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Marsh & McLennan  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Marsh brokers insurance and Mercer administers employee benefits, so the group handles health plan enrolment, retirement participation and claims analytics for a very large number of employers — covering people who are not its customers and cannot decline. This is the same no-relationship structure as ADP and Workday, applied to health and retirement data. Marsh & McLennan also settled a landmark New York Attorney General action over contingent commission arrangements that steered clients to insurers paying the broker more.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Financial Svcs Remainder", "_row_id": 902, "_entity_id": 1227, "_entity_slug": "marsh-mclennan", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "S&P Global", "Category": "Financial Data Services", "Terms & Conditions URL": "See S&P Global's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See S&P Global's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "S&P Global processes financial data across credit, commodities, and market intelligence. The 2022 merger with IHS Markit created one of the largest financial data companies in the world. Data practices governed by enterprise licensing agreements.", "Arbitration / Class Action Waiver": "B2B — S&P Global (parent of S&P Ratings, S&P Dow Jones Indices, Platts, Capital IQ/Market Intelligence) is primarily institutional. Consumer exposure limited to S&P credit ratings and index methodology, which are published information, not contractual services.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly checking for any retail-facing product (e.g., a Goldman Sachs Marcus-style consumer bank) this company might separately operate.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SALE · FL-2] S&P Global sells datasets derived from consumer financial and transaction activity to financial institutions.\nWHAT THE TERMS SAY: The row states S&P Global owns substantial datasets derived from consumer financial and transaction activity, which it sells to financial institutions, and that nobody in that chain has a relationship with the individuals whose behavior the data describes.\nWHY IT MATTERS: Consumers whose transaction behavior underlies these datasets have no relationship with, visibility into, or consent mechanism for S&P Global's use of it.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item is supported; arbitration and fees are not itemized for this largely institutional business, and the IQVIA comparison in the row is another company's finding, not S&P's own.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The consumer-data-sale practice is stated concretely, but S&P has no consumer contract and other fields are not applicable or itemized.", "Exposure Score (0-100)": 10, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (data_sold_or_shared_for_value+8) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "S&P Global  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Ratings, indices and data analytics. The consumer-relevant part is the data business: S&P Global owns substantial datasets derived from consumer financial and transaction activity, sold to financial institutions. Nobody in that chain has a relationship with the individuals whose behaviour the data describes — the same structural invisibility documented in the IQVIA row for health data.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Financial Svcs Remainder", "_row_id": 903, "_entity_id": 1228, "_entity_slug": "s-p-global", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fiserv", "Category": "Financial Data Services", "Terms & Conditions URL": "fiserv.com/en/about-fiserv/legal.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "fiserv.com/en/about-fiserv/legal/privacy-notice.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SERIOUS, DIRECTLY CONSUMER-RELEVANT FINDINGS given how many small banks/credit unions rely on Fiserv's 'invisible' backend infrastructure: (1) A February 2026 lawsuit (FiCare Federal Credit Union v. Fiserv, Florida) alleges Fiserv's 'Virtual Branch Next' online banking platform contained security flaws the company had KNOWN ABOUT FOR YEARS, allowing hackers 'shockingly easy' access — attackers took control of credit union customers' accounts and STOLE MONEY DIRECTLY; the complaint further alleges Fiserv then tried to CHARGE the credit union ADDITIONAL FEES for a security upgrade after the breach. (2) A SEPARATE, brand-new breach (May 2026): the Everest ransomware/extortion group (also responsible for the Citizens Bank, AT&T, and Sweden's national power grid incidents documented elsewhere) claimed responsibility for compromising Fiserv — as of this research, Fiserv had not publicly confirmed the incident's scope, though given Fiserv's role powering core banking systems, digital banking, and the widely-used 'Clover' point-of-sale system, the potential consumer impact could be extensive.", "Arbitration / Class Action Waiver": "B2B — Fiserv provides payment processing, core banking, and merchant services infrastructure. Consumers interact with Fiserv indirectly through their bank or merchant. Clover (Fiserv's POS system for small businesses) has its own merchant ToS.", "Fees / Billing Flags": "The FEE-FOR-SECURITY-UPGRADE-AFTER-A-BREACH-IT-CAUSED allegation is a particularly notable, distinct billing practice worth flagging — charging a victim institution for fixing a vulnerability the vendor already knew about.", "Notes": "This is a genuinely important 'invisible infrastructure' finding similar to Synchrony Financial, Apex Clearing, and Green Dot documented elsewhere in this tracker — a consumer with an account at ANY small bank or credit union using Fiserv's Virtual Branch Next platform, or a merchant using Fiserv's Clover point-of-sale system, could be affected without ever having heard of Fiserv directly.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Brookfield", "HQ State": "Wisconsin", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Wisconsin' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Wisconsin DFI Corporate Records — apps.dfi.wi.gov/apps/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-1] A pending lawsuit alleges Fiserv knew of Virtual Branch Next security flaws for years, letting hackers steal customer funds directly.\nWHAT THE TERMS SAY: The row states a February 2026 lawsuit (FiCare Federal Credit Union v. Fiserv, Florida) alleges Fiserv's 'Virtual Branch Next' online banking platform had security flaws the company had known about for years, allowing 'shockingly easy' hacker access through which attackers took control of credit union customers' accounts and stole money directly.\nWHY IT MATTERS: If proven, customers of any bank or credit union running this platform could have had funds stolen through a flaw the vendor allegedly knew about but did not fix.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-1] The same lawsuit alleges Fiserv then tried to charge the breached credit union extra fees for a security upgrade.\nWHAT THE TERMS SAY: The row states the lawsuit's complaint further alleges Fiserv tried to charge the credit union additional fees for a security upgrade after the breach it allegedly caused.\nWHY IT MATTERS: A victim institution would be asked to pay for fixing a vulnerability the vendor is alleged to have known about for years.\n(evidence: Fees; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[NO_DISCLOSURE_THICK_FOG · FL-2] A ransomware group claims it compromised Fiserv in May 2026, but Fiserv has not confirmed the incident's scope.\nWHAT THE TERMS SAY: The row states the Everest ransomware/extortion group claimed responsibility for compromising Fiserv, and that as of this research Fiserv had not publicly confirmed the incident's scope, despite Fiserv's role powering core banking, digital banking, and the Clover point-of-sale system.\nWHY IT MATTERS: Given Fiserv's reach into small banks, credit unions, and Clover merchants, an unconfirmed breach of this scale could affect many consumers who have never heard of Fiserv.\n(evidence: Data Sharing; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "One incident gives detailed, if still-alleged, facts about a known flaw and a retaliatory fee; a second, potentially larger breach claim remains unconfirmed by Fiserv.", "Exposure Score (0-100)": 7, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 4/20 (severity2+2, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Fiserv  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Fiserv you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Fiserv's findings are directly consumer-relevant because of how many banks and credit unions run on its infrastructure - a very large share of American community banks' core processing, card issuing and online banking is Fiserv underneath. That means a consumer's bank could be flawless and their exposure would still run through a vendor they have never heard of and cannot evaluate. Fiserv also owns Clover, the point-of-sale system in a great many small businesses. This is the AMCA and CDK pattern applied to retail banking, and it is one of the most consequential concentration points in this tracker.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Financial Svcs Remainder", "_row_id": 904, "_entity_id": 1229, "_entity_slug": "fiserv", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cognizant Technology", "Category": "Information Technology Services", "Terms & Conditions URL": "cognizant.com/us/en/legal/terms-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "cognizant.com/us/en/legal/privacy-statement", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Cognizant is referenced elsewhere in this tracker as a CALL-CENTER SERVICES PROVIDER named alongside Papa John's in a privacy case where a California federal judge granted summary judgment FOR the defendants (Papa John's and Cognizant) on wiretapping claims — a rare instance of a company winning outright on the merits in this specific category of litigation, in contrast to many other companies in this tracker facing ongoing or settled tracking-technology claims.", "Arbitration / Class Action Waiver": "B2B — Cognizant is an IT services and consulting firm. No direct consumer products. Employee-facing arbitration governed by employment agreements.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The Papa John's/Cognizant summary-judgment WIN is worth flagging as a genuine counter-example to the broader tracking-litigation trend documented throughout this tracker — not every case results in a settlement or plaintiff-favorable ruling.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Teaneck", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NJ Business Records Service — businessrecords.nj.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Cognizant experienced a significant ransomware incident affecting client-facing operations.\nWHAT THE TERMS SAY: The row states Cognizant experienced a significant ransomware incident affecting client-facing operations.\nWHY IT MATTERS: Clients whose customer-service operations run through Cognizant could have had those operations disrupted or exposed.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Outsourced call-center work means a consumer's account file may be read by a different company in a different country.\nWHAT THE TERMS SAY: The row states Cognizant is a call-center and IT services provider, meaning the person reading a customer's account file works for a different company in a different country under a contract the consumer cannot see.\nWHY IT MATTERS: Consumers have no visibility into who is handling their account data or under what terms once customer service is outsourced.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two items are supported; Cognizant's referenced litigation history includes a summary-judgment win for the company (not a troubling term), and as a B2B services provider it has no consumer-facing fee or arbitration terms itemized.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The ransomware incident is stated as fact, but Cognizant has no direct consumer terms and its only litigation reference this pass ended in a win for the company.", "Exposure Score (0-100)": 14, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Cognizant Technology  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Cognizant appears elsewhere in this tracker as a call-centre and IT services provider, and that is the row's substance: outsourced customer service means the person reading your account file works for a different company in a different country under a contract you cannot see. Cognizant also experienced a significant ransomware incident affecting client-facing operations. Offshore business process outsourcing is a genuine and underexamined layer in the consumer data chain.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Financial Svcs Remainder", "_row_id": 905, "_entity_id": 1230, "_entity_slug": "cognizant-technology", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "ADP", "Category": "Diversified Outsourcing Services", "Terms & Conditions URL": "adp.com/about-adp/legal.aspx", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "adp.com/about-adp/privacy.aspx", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "ADP processes payroll for millions of American employees across thousands of employers — meaning most individual exposure comes indirectly, through an EMPLOYER'S choice to use ADP, rather than a direct consumer account relationship. No specific named recent lawsuit or breach independently confirmed this pass, though ADP's central role in payroll data (SSNs, bank account/direct-deposit info, salary data) for a very large share of US employees makes it a significant 'invisible infrastructure' player similar to Fiserv (this same tab).", "Arbitration / Class Action Waiver": "NOT VERIFIED THIS PASS — ADP's services are primarily B2B (employer payroll processing). Individual employees interact with ADP's portal to view paystubs and tax forms, but the contractual relationship is between ADP and the employer, not ADP and the employee. The arbitration clause in ADP's Terms of Use may not bind individual employees who never separately agreed to them.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Fiserv row (this same tab) for the shared 'invisible payroll/financial infrastructure provider' risk category.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-4] ADP holds SSNs, bank details, and salary data for employees who never chose ADP and cannot opt out.\nWHAT THE TERMS SAY: The row states ADP processes payroll data (Social Security numbers, bank/direct-deposit information, salary data) for a very large share of American employees, none of whom are its customers — the employer chose the vendor, and the employee cannot decline, switch, or read the contract.\nWHY IT MATTERS: An employee has no contractual relationship with ADP yet must trust it with their most sensitive financial identifiers.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] It's unverified whether ADP's arbitration clause can even bind employees who never separately agreed to it.\nWHAT THE TERMS SAY: The row states ADP's arbitration terms are not verified this pass, and that the arbitration clause in ADP's Terms of Use may not bind individual employees who never separately agreed to them, since the contract is between ADP and the employer.\nWHY IT MATTERS: Employees may be unknowingly subject to — or possibly protected from — an arbitration clause they never signed.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two items found; this pass explicitly duplicates the fuller ADP analysis in the Payroll/RealEstate & Finance tab, and no breach or fee specifics are confirmed here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No specific lawsuit or breach is confirmed this pass, arbitration enforceability against employees is explicitly unverified, and the row is flagged as a cross-tab duplicate.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "ADP  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, ADP takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Duplicate of the ADP row in Payroll, RealEstate & Finance - see that row for the full analysis. The core finding bears repeating: ADP processes payroll for a very large share of American employees, none of whom are its customers. You supply the Social Security number and the bank account; your employer chose the vendor; you cannot decline, switch or read the contract. TRACKER NOTE: confirmed cross-tab duplicate, flag for the dedup pass described in the project guide.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Financial Svcs Remainder", "_row_id": 906, "_entity_id": 521, "_entity_slug": "adp", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "U.S. Bancorp", "Category": "Commercial Banks", "Terms & Conditions URL": "See U.S. Bancorp's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See U.S. Bancorp's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "GLB Act-governed Consumer Privacy Notice. Shares information with affiliates, service providers, and joint marketing partners. U.S. Bank's Elan Financial Services subsidiary issues credit cards for hundreds of smaller banks — the arbitration clause in Elan's cardholder agreement governs those relationships too.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. U.S. Bank Consumer Deposit Account Agreement. 60-day opt-out via written notice. U.S. Bancorp is the 5th-largest US bank by assets. The arbitration clause covers checking, savings, CDs, and the U.S. Bank mobile app.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly checking for any retail-facing product (e.g., a Goldman Sachs Marcus-style consumer bank) this company might separately operate.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Minneapolis", "HQ State": "Minnesota", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 60, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] U.S. Bank faced CFPB enforcement over employees opening unauthorized accounts to hit sales goals.\nWHAT THE TERMS SAY: The row states U.S. Bank has faced CFPB enforcement over employees opening unauthorized accounts to meet sales goals.\nWHY IT MATTERS: The row calls this the harm a U.S. Bank customer is most likely to actually experience - employees opening unauthorised accounts to meet sales goals, the same sales-incentive failure it documents elsewhere.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] U.S. Bank's deposit agreement imposes mandatory arbitration with a class action waiver and a 60-day opt-out\nWHAT THE TERMS SAY: The row states U.S. Bank's Consumer Deposit Account Agreement contains mandatory binding arbitration with a class action waiver, covering checking, savings, CDs, and the mobile app, with a 60-day opt-out available via written notice.\nWHY IT MATTERS: Customers who do not send the written opt-out notice within the 60-day window are locked into arbitration and give up the right to join a class action.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] U.S. Bank's GLB framework permits more internal data sharing than most customers assume, with an opt-out mailed once a year.\nWHAT THE TERMS SAY: The row states U.S. Bank shares information with affiliates, service providers, and joint marketing partners under the Gramm-Leach-Bliley framework, which the row characterizes as permitting considerably more internal sharing than customers assume, with an opt-out notice mailed once a year.\nWHY IT MATTERS: A customer who misses the annual mailed notice stays opted in to affiliate data sharing by default.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Arbitration terms, the opt-out window, the affiliate-sharing framework, and the CFPB enforcement action are all stated with specifics rather than hedges.", "Exposure Score (0-100)": 31, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 22, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 22/30 (forced_arbitration+12, class_action_waiver+9, optout_60d+1) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 5/20 (severity2+2, penalty+3) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "U.S. Bancorp  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using U.S. Bancorp you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A major national bank subject to the Gramm-Leach-Bliley affiliate-sharing framework, which permits considerably more internal data sharing than customers assume with an opt-out mailed once a year. U.S. Bank has also faced CFPB enforcement over employees opening unauthorised accounts to meet sales goals — the same sales-incentive failure documented in the Fifth Third row and, most famously, at Wells Fargo. That is the harm a customer is most likely to actually experience here.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Financial Svcs Remainder", "_row_id": 907, "_entity_id": 1231, "_entity_slug": "u-s-bancorp", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "StoneX", "Category": "Diversified Financials", "Terms & Conditions URL": "See StoneX's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See StoneX's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "StoneX processes trading data across commodities, forex, equities, and fixed income. Primarily institutional/sophisticated investor clientele.", "Arbitration / Class Action Waiver": "MANDATORY pre-dispute arbitration per FINRA rules (StoneX Financial Inc. is a FINRA member). Covers forex, futures, and securities brokerage. FINRA Rule 2268 prohibits class action waivers.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly checking for any retail-facing product (e.g., a Goldman Sachs Marcus-style consumer bank) this company might separately operate.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] StoneX's forex, futures, and securities brokerage accounts carry mandatory pre-dispute FINRA arbitration.\nWHAT THE TERMS SAY: The row states mandatory pre-dispute arbitration applies under FINRA rules to StoneX Financial Inc.'s forex, futures, and securities brokerage accounts, and that FINRA Rule 2268 prohibits class action waivers.\nWHY IT MATTERS: The row states StoneX has no retail consumer relationship, though it does serve some self-directed traders through acquired platforms - worth verifying before treating the row as purely institutional; FINRA Rule 2268 prohibits class action waivers.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item found; StoneX's row is classified B2B/no consumer relationship, with only a caveat about some self-directed retail traders through acquired platforms — that arbitration clause is the sole consumer-relevant term stated.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=N; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The FINRA arbitration terms are stated clearly, but StoneX is classified as primarily institutional with a caveat about some retail exposure worth verifying.", "Exposure Score (0-100)": 18, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "StoneX  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Financial services for institutional and commercial clients in commodities and markets, including hedging for agricultural producers and mid-sized businesses. No retail consumer relationship, though it does serve some self-directed traders through acquired platforms — worth verifying before treating the row as purely institutional.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Financial Svcs Remainder", "_row_id": 908, "_entity_id": 1232, "_entity_slug": "stonex", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Jefferies Financial", "Category": "Diversified Financials", "Terms & Conditions URL": "See Jefferies Financial's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Jefferies Financial's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Investment banking and brokerage. Primarily institutional. GLB Act privacy notice for brokerage clients.", "Arbitration / Class Action Waiver": "MANDATORY pre-dispute arbitration per FINRA rules (Jefferies LLC is a FINRA member). FINRA Rule 2268 prohibits class action waivers for brokerage clients.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly checking for any retail-facing product (e.g., a Goldman Sachs Marcus-style consumer bank) this company might separately operate.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Jefferies' brokerage clients are bound to mandatory pre-dispute FINRA arbitration.\nWHAT THE TERMS SAY: The row states mandatory pre-dispute arbitration applies under FINRA rules to Jefferies LLC's brokerage clients, and that FINRA Rule 2268 prohibits class action waivers for those clients.\nWHY IT MATTERS: Brokerage clients are routed to arbitration for disputes with Jefferies, though they keep the right to bring class claims.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item found; Jefferies is classified B2B/no consumer relationship, and its M&A-advisory role in transactions that move consumer data between corporate parents is structural context involving other tracked companies' deals, not a distinct term of Jefferies' own.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=N; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The FINRA arbitration terms are stated clearly, but Jefferies has no retail consumer relationship and no other terms are itemized.", "Exposure Score (0-100)": 18, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Jefferies Financial  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Investment bank serving institutional clients with no retail consumer relationship. Jefferies' relevance to this tracker is as an advisor on the mergers that move consumer data between corporate parents — the Albertsons, Kellanova and Discover transactions documented elsewhere all ran through banks in this category.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Financial Svcs Remainder", "_row_id": 909, "_entity_id": 1233, "_entity_slug": "jefferies-financial", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Intercontinental Exchange", "Category": "Securities", "Terms & Conditions URL": "See Intercontinental Exchange's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Intercontinental Exchange's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "ICE processes real-time trading data, mortgage origination data, and fixed-income pricing. Parent of the NYSE. Data practices governed by exchange rules and institutional agreements.", "Arbitration / Class Action Waiver": "B2B — ICE operates exchanges (NYSE, ICE Futures) and data services. Consumer exposure through ICE Mortgage Technology (Encompass platform used by lenders) — consumers interact indirectly. ICE's 2020 attempted acquisition of eBay failed.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly checking for any retail-facing product (e.g., a Goldman Sachs Marcus-style consumer bank) this company might separately operate.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Atlanta", "HQ State": "Georgia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Georgia SOS eCorp — ecorp.sos.ga.gov/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-4] A homebuyer's complete financial file passes through ICE's mortgage-technology systems under contracts the buyer never sees.\nWHAT THE TERMS SAY: The row states ICE owns mortgage technology infrastructure, including systems (Encompass) that process a large share of US mortgage originations, so a homebuyer's complete financial file passes through ICE systems under contracts between lenders and ICE.\nWHY IT MATTERS: A mortgage applicant has no direct relationship with ICE even though their financial file runs through its systems, and the row notes this is unverified rather than confirmed clean.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one item found; the SCARY field explicitly says nothing was confirmed this pass and recommends a follow-up, so this is inferred structural context rather than a confirmed company-specific practice.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The row explicitly states nothing was confirmed this pass; the mortgage-technology concentration point is inferred structural context pending a follow-up.", "Exposure Score (0-100)": 5, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Intercontinental Exchange  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. ICE owns exchanges and, more relevantly here, mortgage technology infrastructure including systems that process a large share of US mortgage originations - so a homebuyer's complete financial file passes through ICE systems under contracts between lenders and ICE. Same invisible-infrastructure structure as Fiserv. Unverified rather than clean, and worth a follow-up given the homebuilder and mortgage rows elsewhere in this tracker.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Financial Svcs Remainder", "_row_id": 910, "_entity_id": 1234, "_entity_slug": "intercontinental-exchange", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Arthur J. Gallagher", "Category": "Diversified Financials", "Terms & Conditions URL": "See Arthur J. Gallagher's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Arthur J. Gallagher's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Processes commercial insurance placement data. Employee benefits administration through Gallagher's consulting arm.", "Arbitration / Class Action Waiver": "B2B — insurance brokerage serving commercial/institutional clients. No direct consumer products.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly checking for any retail-facing product (e.g., a Goldman Sachs Marcus-style consumer bank) this company might separately operate.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Rolling Meadows", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Gallagher has disclosed a prior breach through that brokerage relationship, but scope is unconfirmed this pass\nWHAT THE TERMS SAY: The tracker states Gallagher has historically disclosed a significant breach affecting a large number of individuals through its employee-benefits administration/brokerage relationship with employers, but flags the scope as not independently confirmed this pass.\nWHY IT MATTERS: Gallagher is an insurance broker and benefits consultant handling employee benefits data on behalf of employers, a no-relationship structure in which the individuals whose data it holds are not its customers; the tracker records nothing confirmed this pass and recommends a direct follow-up to confirm scope before publishing.\n(evidence: SCARY; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Gallagher is a B2B insurance brokerage/benefits consultant with no direct consumer Terms of Service; fees are not itemized this pass and the only substantive item, the historical breach disclosure, is itself flagged as needing a direct follow-up to confirm scope.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Fees are not itemized, no consumer contract exists, and even the SCARY breach disclosure is explicitly flagged as unconfirmed pending follow-up.", "Exposure Score (0-100)": 9, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Arthur J. Gallagher  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass in this period. Gallagher is an insurance broker and benefits consultant handling employee benefits data on behalf of employers - the same no-relationship structure as Marsh & McLennan and ADP. Gallagher has historically disclosed a significant breach affecting a large number of individuals through that brokerage relationship. Recommend a direct follow-up to confirm scope before publishing.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Financial Svcs Remainder", "_row_id": 911, "_entity_id": 1235, "_entity_slug": "arthur-j-gallagher", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fannie Mae", "Category": "Diversified Financials", "Terms & Conditions URL": "See Fannie Mae's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Fannie Mae's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Fannie Mae processes mortgage performance data for ~30% of all US mortgages. Desktop Underwriter (DU) automated underwriting system processes borrower income, credit, and asset data. Data practices governed by FHFA oversight, not consumer T&C. DMV-headquartered GSE.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Fannie Mae (Federal National Mortgage Association) is a government-sponsored enterprise. Its Single-Family Selling Guide and Servicing Guide govern lender relationships, not consumer relationships. Consumers' disputes are with their mortgage servicer, not with Fannie Mae directly. Fannie Mae HQ: Washington DC (DMV).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly checking for any retail-facing product (e.g., a Goldman Sachs Marcus-style consumer bank) this company might separately operate.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Washington", "HQ State": "District of Columbia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Washington, District of Columbia (DC/MD/VA)", "Parent / Ultimate Owner": "Federal National Mortgage Association (GSE)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): DC DLCP CorpOnline — corponline.dcra.dc.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Federal National Mortgage Association (GSE)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Fannie Mae holds loan-level borrower data no borrower selected and cannot leave\nWHAT THE TERMS SAY: The tracker states Fannie Mae processes mortgage performance data for ~30% of all US mortgages and that its Desktop Underwriter automated underwriting system processes borrower income, credit, and asset data, with data practices governed by FHFA oversight rather than consumer T&C; it adds that a homeowner generally does not know whether Fannie holds their loan.\nWHY IT MATTERS: A borrower has no direct relationship with Fannie Mae, cannot select or leave it, and deals only with a separate mortgage servicer, yet Fannie holds detailed financial data on a very large share of American mortgage holders.\n(evidence: SCARY, Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Fannie Mae is a government-sponsored enterprise with no consumer Terms of Service; arbitration is explicitly ruled out and fees are not itemized this pass, leaving only the structural data-concentration item described in SCARY/Data Sharing.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Data-holding practices are described in structural terms with no formal consumer terms of service, and fees/other fields are not itemized this pass.", "Exposure Score (0-100)": 5, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Fannie Mae  <-  Federal National Mortgage Association (GSE)", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Fannie Mae holds or guarantees a very large share of US residential mortgages, which means loan-level borrower data - income, credit, property, payment history - sits with a government-sponsored enterprise that no borrower selected and cannot leave. A homeowner generally does not know whether Fannie holds their loan, and the servicer they deal with is a different company again. Honest structural row.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Financial Svcs Remainder", "_row_id": 912, "_entity_id": 1237, "_entity_slug": "fannie-mae", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Freddie Mac", "Category": "Diversified Financials", "Terms & Conditions URL": "See Freddie Mac's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Freddie Mac's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Freddie Mac processes mortgage performance data for ~25% of all US mortgages. Loan Prospector (LP) automated underwriting system. Data practices governed by FHFA oversight. DMV-headquartered GSE.", "Arbitration / Class Action Waiver": "NO MANDATORY ARBITRATION — Freddie Mac (Federal Home Loan Mortgage Corporation) is a GSE with the same structure as Fannie Mae. Consumer disputes are with the mortgage servicer. Freddie Mac HQ: McLean, Virginia (DMV).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly checking for any retail-facing product (e.g., a Goldman Sachs Marcus-style consumer bank) this company might separately operate.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "McLean", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: McLean, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "Federal Home Loan Mortgage Corporation (GSE)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Federal Home Loan Mortgage Corporation (GSE)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Freddie Mac holds loan-level data on a very large share of US mortgages, with no homeowner relationship\nWHAT THE TERMS SAY: The tracker states Freddie Mac processes mortgage performance data for ~25% of all US mortgages under FHFA oversight and runs the Loan Prospector automated underwriting system, and that it holds or guarantees loan-level data - income, credit, property, payment history - on a very large share of American mortgages; together with Fannie Mae the tracker calls this the largest concentration of household financial data in the country, held under federal conservatorship rather than by a company the borrower chose.\nWHY IT MATTERS: Homeowners generally cannot find out whether Freddie Mac holds their loan without using a lookup tool most people never hear about, yet it holds detailed financial data on a large share of American households.\n(evidence: SCARY, Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Freddie Mac is a government-sponsored enterprise with no consumer Terms of Service; arbitration is explicitly ruled out and fees are not itemized this pass, leaving only the structural data-concentration item described in SCARY/Data Sharing.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Data-holding practices are described in structural terms with no formal consumer terms of service, and fees/other fields are not itemized this pass.", "Exposure Score (0-100)": 5, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Freddie Mac  <-  Federal Home Loan Mortgage Corporation (GSE)", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Freddie Mac holds or guarantees loan-level data — income, credit, property, payment history — on a very large share of American mortgages, and the homeowner has no relationship with it, did not select it, and generally cannot find out whether it holds their loan without using a lookup tool most people never hear about. Together with Fannie Mae it constitutes the largest concentration of household financial data in the country, held by government-sponsored enterprises under federal conservatorship rather than by any company a borrower chose.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Financial Svcs Remainder", "_row_id": 913, "_entity_id": 1239, "_entity_slug": "freddie-mac", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Union Pacific", "Category": "Railroads", "Terms & Conditions URL": "up.com/aboutup/legal/index.htm", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "up.com/aboutup/legal/privacy/index.htm", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Union Pacific operates as a FREIGHT railroad (not passenger rail, which is Amtrak, documented elsewhere in this tracker) — meaning it has virtually NO direct individual consumer customer relationship or Terms of Service that ordinary people would encounter. A historical Illinois BIPA (biometric privacy) class action against Union Pacific was allowed to proceed (2021 ruling) — an EMPLOYEE-facing biometric-timekeeping claim, not a consumer matter.", "Arbitration / Class Action Waiver": "Not applicable — no meaningful direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "MAJOR PENDING STRUCTURAL DEVELOPMENT: Union Pacific and Norfolk Southern (this same tab) have proposed merging to create 'America's FIRST TRANSCONTINENTAL RAILROAD' — a combined network spanning 50,000+ miles across 43 states, which would consolidate the US freight rail industry from 4 major carriers (with BNSF and CSX) down to effectively 3. The US Surface Transportation Board initially REJECTED the merger application (Jan 2026) as incomplete, and ordered the companies to publicly release EMPLOYMENT DATA they had tried to mark 'highly confidential' (July 2026 ruling) — while this merger doesn't directly involve individual consumer data, it represents one of the largest corporate consolidations referenced anywhere in this entire tracker, and freight-rail concentration can indirectly affect consumer goods prices/availability nationwide.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Union Pacific is a freight railroad with no consumer Terms of Service; the only litigation mentioned (a 2021 Illinois BIPA biometric-timekeeping claim allowed to proceed) is expressly noted as an employee matter, not a consumer one, and the SCARY field describes only physical hazmat exposure to non-customers rather than a contractual term.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms of service exist, and the one litigation item cited is explicitly an employee-facing matter, not consumer-facing.", "Exposure Score (0-100)": 8, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 6/30 (biometric_collection+6) | Contract 0/20 (none) | Record 2/20 (severity1+0, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Union Pacific  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Freight railroad with no passenger service and no consumer contract. Its consumer relevance is physical rather than contractual: hazardous materials move through communities along its lines under Federal Railroad Administration rules, and residents affected by a derailment have no relationship with the company at all — the same non-customer harm pattern as the Norfolk Southern row.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Transport & Logistics", "_row_id": 914, "_entity_id": 1240, "_entity_slug": "union-pacific", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Norfolk Southern", "Category": "Railroads", "Terms & Conditions URL": "norfolksouthern.com/en/about-us/legal", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "norfolksouthern.com/en/about-us/legal/privacy-policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Same freight-railroad structure as Union Pacific (this same tab) — no meaningful direct consumer relationship. Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not applicable — no meaningful direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Union Pacific row (this same tab) for the major pending merger between these two companies, which would create the first US transcontinental railroad — a significant industry-consolidation event even though it doesn't directly implicate individual consumer privacy.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Norfolk Southern is a freight railroad with no consumer Terms of Service; the East Palestine derailment referenced in the SCARY field is explicitly noted as a safety/environmental matter, not a data-privacy or contract-terms issue.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist and no data-privacy or contractual findings are confirmed; the only public-relevance item cited is a safety incident outside this tracker's scope.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Norfolk Southern  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass - Norfolk Southern is a freight railroad with no passenger service and no consumer terms. Its genuine public relevance is the East Palestine, Ohio derailment and the resulting environmental and community health response, which is a safety and regulatory matter rather than a data one and is recorded here as such so a future reader does not mistake this row for a clean record in every sense. Honest B2B entry on the terms-of-service question.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Transport & Logistics", "_row_id": 915, "_entity_id": 1241, "_entity_slug": "norfolk-southern", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CSX", "Category": "Railroads", "Terms & Conditions URL": "See CSX's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See CSX's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "This company operates primarily as a B2B freight/logistics carrier or broker (moving goods for OTHER BUSINESSES) rather than serving individual consumers directly — no meaningful consumer Terms of Service relationship exists for most ordinary people, similar to Union Pacific/Norfolk Southern (this same tab).", "Arbitration / Class Action Waiver": "Not applicable — no meaningful direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Included for Fortune 500 completeness; this company does not fit this tracker's core purpose of auditing consumer-facing Terms & Conditions, since ordinary individuals have no direct account relationship with it.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — CSX is a B2B freight carrier with no consumer Terms of Service; the SCARY field describes only physical/regulatory encounters (crossings, hazmat routing) rather than any contractual or data-privacy term.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist and the tracker records no data-privacy or contractual findings for this row.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "CSX  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Freight railroad whose network runs through much of this tracker's Mid-Atlantic core — Virginia, Maryland, DC. No consumer relationship. Rail crossings, blocked-crossing complaints and hazmat routing are the ways households actually encounter CSX, all governed by federal regulation rather than any agreement.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Transport & Logistics", "_row_id": 916, "_entity_id": 1242, "_entity_slug": "csx", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "J.B. Hunt Transport Services", "Category": "Trucking, Truck Leasing", "Terms & Conditions URL": "See J.B. Hunt Transport Services's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See J.B. Hunt Transport Services's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B freight/logistics. Processes commercial shipping data. J.B. Hunt 360 platform connects shippers with carriers — data governed by commercial agreements.", "Arbitration / Class Action Waiver": "Primarily B2B — J.B. Hunt is a trucking/intermodal company serving commercial shippers. No significant consumer-facing digital products.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Included for Fortune 500 completeness; this company does not fit this tracker's core purpose of auditing consumer-facing Terms & Conditions, since ordinary individuals have no direct account relationship with it.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Lowell", "HQ State": "Arkansas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Arkansas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Arkansas) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Arkansas. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — J.B. Hunt is a B2B trucking/intermodal carrier with no consumer Terms of Service; its final-mile delivery role is contractually with the retailer, not the consumer, so the tracker records no direct consumer-facing term.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the only consumer-adjacent touchpoint (final-mile delivery) runs through a retailer's contract, not J.B. Hunt's.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "J.B. Hunt Transport Services  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Trucking and intermodal carrier contracting with shippers. No consumer relationship, though its final-mile delivery arm does place drivers at residential doors on behalf of retailers — where the consumer's contract is with the retailer and the person at the door works for someone else entirely. Small-business relevant as a freight provider.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Transport & Logistics", "_row_id": 917, "_entity_id": 1243, "_entity_slug": "j-b-hunt-transport-services", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "C.H. Robinson Worldwide", "Category": "Transportation and Logistics", "Terms & Conditions URL": "See C.H. Robinson Worldwide's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See C.H. Robinson Worldwide's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "This company operates primarily as a B2B freight/logistics carrier or broker (moving goods for OTHER BUSINESSES) rather than serving individual consumers directly — no meaningful consumer Terms of Service relationship exists for most ordinary people, similar to Union Pacific/Norfolk Southern (this same tab).", "Arbitration / Class Action Waiver": "Not applicable — no meaningful direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Included for Fortune 500 completeness; this company does not fit this tracker's core purpose of auditing consumer-facing Terms & Conditions, since ordinary individuals have no direct account relationship with it.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — C.H. Robinson is a B2B freight brokerage matching shippers to carriers with no consumer Terms of Service; the SCARY field describes only its asset-light brokerage structure between businesses, not a consumer-facing term.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist and no data-privacy or contractual findings are confirmed for this row.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "C.H. Robinson Worldwide  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Freight brokerage arranging shipping between businesses, with no assets of its own — it matches shippers to carriers. Small-business relevant: a small manufacturer or distributor shipping goods likely books through a broker like this. No consumer relationship, and the brokerage model means neither party in a shipment necessarily knows who else touched it.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Transport & Logistics", "_row_id": 918, "_entity_id": 1244, "_entity_slug": "c-h-robinson-worldwide", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ryder System", "Category": "Transportation and Logistics", "Terms & Conditions URL": "See Ryder System's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Ryder System's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "This company operates primarily as a B2B freight/logistics carrier or broker (moving goods for OTHER BUSINESSES) rather than serving individual consumers directly — no meaningful consumer Terms of Service relationship exists for most ordinary people, similar to Union Pacific/Norfolk Southern (this same tab).", "Arbitration / Class Action Waiver": "Not applicable — no meaningful direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Included for Fortune 500 completeness; this company does not fit this tracker's core purpose of auditing consumer-facing Terms & Conditions, since ordinary individuals have no direct account relationship with it.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Ryder is a B2B truck-leasing and fleet-management company with no consumer Terms of Service; the telematics tracking it operates applies to drivers employed by lessee businesses, not to individual consumers, so no consumer-facing term is confirmed this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the fleet telematics tracking described applies to lessee-employed drivers, not consumers.", "Exposure Score (0-100)": 4, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Ryder System  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Commercial truck leasing and fleet management. Genuinely small-business relevant — a contractor or distributor leasing vehicles is a Ryder customer — and its fleet telematics track vehicle location and driver behaviour continuously, so an employee driving a leased truck is monitored by a company that is neither their employer nor a party to their employment.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Transport & Logistics", "_row_id": 919, "_entity_id": 1245, "_entity_slug": "ryder-system", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "GXO Logistics", "Category": "Transportation and Logistics", "Terms & Conditions URL": "See GXO Logistics's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See GXO Logistics's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "This company operates primarily as a B2B freight/logistics carrier or broker (moving goods for OTHER BUSINESSES) rather than serving individual consumers directly — no meaningful consumer Terms of Service relationship exists for most ordinary people, similar to Union Pacific/Norfolk Southern (this same tab).", "Arbitration / Class Action Waiver": "Not applicable — no meaningful direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Included for Fortune 500 completeness; this company does not fit this tracker's core purpose of auditing consumer-facing Terms & Conditions, since ordinary individuals have no direct account relationship with it.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — GXO is a B2B contract-logistics and warehousing operator with no consumer Terms of Service; the worker-productivity monitoring described applies to its own workforce, not consumers, so no consumer-facing term is confirmed this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; consumer order data is described as passing through GXO's systems under contracts the consumer never sees, with no specific practice detailed.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "GXO Logistics  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Contract logistics and warehousing operated on behalf of retailers and manufacturers. Consumer order data passes through GXO's fulfilment systems under contracts the consumer never sees. GXO also deploys warehouse automation and worker-productivity monitoring, so the most closely tracked people in its operations are its own workforce.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Transport & Logistics", "_row_id": 920, "_entity_id": 1246, "_entity_slug": "gxo-logistics", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Expeditors International of Washington", "Category": "Transportation and Logistics", "Terms & Conditions URL": "See Expeditors International of Washington's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Expeditors International of Washington's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "This company operates primarily as a B2B freight/logistics carrier or broker (moving goods for OTHER BUSINESSES) rather than serving individual consumers directly — no meaningful consumer Terms of Service relationship exists for most ordinary people, similar to Union Pacific/Norfolk Southern (this same tab).", "Arbitration / Class Action Waiver": "Not applicable — no meaningful direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Included for Fortune 500 completeness; this company does not fit this tracker's core purpose of auditing consumer-facing Terms & Conditions, since ordinary individuals have no direct account relationship with it.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2022", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Expeditors' 2022 ransomware attack shut down operations for weeks and drew customer litigation\nWHAT THE TERMS SAY: The tracker states Expeditors suffered a major ransomware attack in 2022 that shut down operations for weeks and generated substantial litigation from customers over resulting losses.\nWHY IT MATTERS: Business customers relying on Expeditors for freight forwarding and customs brokerage absorbed real commercial losses from an extended outage, and some pursued litigation over it.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Expeditors is a B2B freight forwarder and customs broker with no consumer Terms of Service; only one substantive item, the 2022 ransomware attack and resulting customer litigation, is stated in the tracker.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "No consumer terms exist, but the tracker documents a specific, dated cyber incident with confirmed commercial consequences and litigation.", "Exposure Score (0-100)": 5, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 5/20 (severity1+0, breach+3, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Expeditors International of Washington  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Global freight forwarding and customs brokerage for business shippers. Expeditors suffered a major ransomware attack in 2022 that shut down operations for weeks and generated substantial customer litigation over resulting losses — a supply-chain continuity event, and one of the clearer cases of a B2B cyber incident producing direct, quantified commercial harm to customers.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Transport & Logistics", "_row_id": 921, "_entity_id": 1247, "_entity_slug": "expeditors-international-of-washington", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Boeing", "Category": "Aerospace & Defense", "Terms & Conditions URL": "boeing.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "boeing.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Boeing HQ: Arlington, VA (DMV). B2B for both defense and commercial aviation. Boeing's Connected Crew and Connected Fleet platforms process airline operational data. The MAX crisis exposed data-integrity issues in the MCAS certification process.", "Arbitration / Class Action Waiver": "B2B/government contractor for defense; commercial aviation sold to airlines, not consumers. Boeing's consumer touchpoint is its website and the Boeing Store. HQ moved from Chicago to Arlington, Virginia (DMV) in 2022. The 737 MAX crisis (346 deaths, $2.5B DOJ settlement) was resolved through government enforcement, not consumer arbitration.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Boeing's safety record is a matter of significant public concern, but is a fundamentally DIFFERENT category of issue (aviation safety/engineering) than the data-privacy/consumer-terms focus of this tracker — individuals are affected as AIRLINE PASSENGERS, not as Boeing account holders.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Arlington", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Arlington, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "The Boeing Company", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: The Boeing Company). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Boeing experienced a significant ransomware incident affecting parts and distribution operations\nWHAT THE TERMS SAY: The tracker states Boeing experienced a significant ransomware incident affecting its parts and distribution operations; Boeing has no consumer terms of service since it sells aircraft to airlines and governments, not individual consumers.\nWHY IT MATTERS: Boeing sells aircraft to airlines and governments rather than to passengers and no consumer terms of service exist, so nothing consumer-facing was confirmed this pass on data privacy; the tracker records the ransomware incident so a blank privacy row is not read as a clean record generally.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Boeing has no consumer Terms of Service; the tracker explicitly separates its aviation-safety and MAX-crisis accountability (a different, non-data-privacy category resolved through government enforcement) from this tracker's scope, leaving only the stated ransomware incident as a tracker-relevant item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "No consumer terms exist, but the tracker documents a specific cyber incident and a resolved DOJ settlement, both explicitly outside this tracker's data-privacy/terms focus.", "Exposure Score (0-100)": 6, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 6, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 6/20 (severity1+0, breach+3, penalty+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Boeing  <-  The Boeing Company", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass on data privacy - Boeing sells aircraft to airlines and governments, not to passengers, and no consumer terms of service exist. Boeing did experience a significant ransomware incident affecting parts and distribution operations. The row is recorded honestly as B2B on the terms question, with the explicit note that Boeing's substantial public accountability issues concern aircraft safety certification and manufacturing quality - matters governed by the FAA and by criminal and civil proceedings, not by anything in this tracker's columns, and a blank privacy row should not be read as a clean record generally.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Aerospace & Defense", "_row_id": 922, "_entity_id": 1249, "_entity_slug": "boeing", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "RTX", "Category": "Aerospace & Defense", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a defense/aerospace contractor", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company sells primarily to GOVERNMENTS and other businesses (military hardware, aircraft components, industrial systems) rather than to individual consumers — it has no direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — RTX sells to governments and airlines with no consumer Terms of Service; its Collins Aerospace unit's proximity to passenger-processing IT is explicitly noted as a supplier role to carriers, not a party to any passenger contract, so no company-specific consumer term is stated.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist and no data-privacy or contractual findings are confirmed for this row.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "RTX  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Aerospace and defence manufacturer selling to governments and airlines. No consumer terms exist. RTX's Collins Aerospace unit supplies airport and airline IT systems — including passenger processing — so it sits closer to the traveller data documented in the Global Airlines tab than its defence profile suggests, though always as a supplier to the carrier rather than a party to any passenger contract.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Aerospace & Defense", "_row_id": 923, "_entity_id": 1250, "_entity_slug": "rtx", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Lockheed Martin", "Category": "Aerospace & Defense", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a defense/aerospace contractor", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "B2B/government contractor. Processes classified and controlled-unclassified information (CUI) under DFARS 252.204-7012 cybersecurity requirements. Lockheed Martin HQ: Bethesda, MD — one of the largest employers in the DMV corridor.", "Arbitration / Class Action Waiver": "B2B/government contractor — no consumer-facing products or services. Lockheed Martin's website ToS are minimal. Disputes are governed by the Federal Acquisition Regulation (FAR) and Defense Federal Acquisition Regulation Supplement (DFARS). HQ: Bethesda, Maryland (DMV).", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Bethesda", "HQ State": "Maryland", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Bethesda, Maryland (DC/MD/VA)", "Parent / Ultimate Owner": "Lockheed Martin Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Maryland SDAT Business Entity Search — egov.maryland.gov/businessexpress/entitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Lockheed Martin Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Lockheed Martin is a B2B/government contractor with minimal website terms and no consumer-facing products; disputes are governed by FAR/DFARS, and the only data category mentioned (personnel/clearance data on employees and subcontractors) is not a consumer matter.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; disputes are governed by FAR/DFARS rather than any consumer-facing agreement.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Lockheed Martin  <-  Lockheed Martin Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The largest US defence contractor, selling to the US and allied governments. No consumer relationship and no consumer terms. Recorded as an honest completeness row — but note that defence primes hold extensive personnel and clearance data on employees and subcontractors, a genuine individual-data category governed by federal contract security requirements rather than consumer privacy law.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Aerospace & Defense", "_row_id": 924, "_entity_id": 1252, "_entity_slug": "lockheed-martin", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "General Dynamics", "Category": "Aerospace & Defense", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a defense/aerospace contractor", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "B2B/government contractor. HQ: Reston, VA (DMV). General Dynamics IT (GDIT) operates significant federal IT infrastructure including cloud and cybersecurity services for federal agencies.", "Arbitration / Class Action Waiver": "B2B/government contractor — no direct consumer products (Gulfstream jets are B2B high-net-worth). FAR/DFARS govern disputes. HQ: Reston, Virginia (DMV).", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Reston", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Reston, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "General Dynamics Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: General Dynamics Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] General Dynamics IT unit processes citizen records for federal agencies without those citizens being customers\nWHAT THE TERMS SAY: The tracker notes General Dynamics IT (GDIT) holds large federal IT contracts processing citizen records for government agencies, with no contractual relationship between GDIT and the citizens whose data it handles.\nWHY IT MATTERS: GDIT's customer is the government agency it contracts with, not the citizens whose records it processes -- the tracker puts this in the same civil-liberties category as Booz Allen and Leidos, since the people whose data GDIT handles are not its customers.\n(evidence: SCARY; Stated in tracker (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — General Dynamics is primarily a B2B/government defense contractor with no direct-consumer Terms of Service (Gulfstream jets are sold B2B to high-net-worth buyers); only the GDIT federal-records-processing item is a substantive, company-specific fact in the tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "No consumer terms exist, but the tracker names a specific data-processing role (GDIT federal IT/citizen records) rather than only a blank B2B entry.", "Exposure Score (0-100)": 3, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "General Dynamics  <-  General Dynamics Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Defence and aerospace, with two consumer-adjacent exceptions worth naming: Gulfstream sells business jets to individuals, and GDIT holds large federal IT contracts processing citizen records for government agencies. The latter puts it in the same civil-liberties category as Booz Allen and Leidos — the people whose data it handles are not its customers.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Aerospace & Defense", "_row_id": 925, "_entity_id": 1254, "_entity_slug": "general-dynamics", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Northrop Grumman", "Category": "Aerospace & Defense", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a defense/aerospace contractor", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "B2B/government contractor. HQ: Falls Church, VA (DMV). Processes defense, intelligence, and space-systems data under DFARS cybersecurity requirements.", "Arbitration / Class Action Waiver": "B2B/government contractor — no consumer-facing products. FAR/DFARS govern disputes. HQ: Falls Church, Virginia (DMV).", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Falls Church", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Falls Church, Virginia (DC/MD/VA)", "Parent / Ultimate Owner": "Northrop Grumman Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Northrop Grumman Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Northrop Grumman is a B2B/government defense contractor with no consumer Terms of Service; the tracker explicitly frames its surveillance-adjacent space/sensor work as a policy question rather than a data-terms finding, leaving no substantive tracker-scope item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the tracker itself labels the surveillance-adjacent context a policy question rather than a terms-of-service finding.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Northrop Grumman  <-  Northrop Grumman Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Defence and space systems for the US government. No consumer relationship. Its space and sensor work supports surveillance capabilities whose subjects are members of the public, which is a policy question rather than a terms-of-service one, but it is the honest reason this row is not simply blank.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Aerospace & Defense", "_row_id": 926, "_entity_id": 1256, "_entity_slug": "northrop-grumman", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "L3Harris Technologies", "Category": "Aerospace & Defense", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a defense/aerospace contractor", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "B2B/government contractor. Processes defense communications, electronic warfare, and intelligence data.", "Arbitration / Class Action Waiver": "B2B/government contractor — no consumer-facing products. FAR/DFARS govern disputes.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Melbourne", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — L3Harris is a B2B/government defense contractor with no consumer Terms of Service; the tracker notes only that it supplies communications and surveillance technology to law enforcement and defense customers, a context note rather than a specific contractual or data-practice finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist and nothing consumer-facing is confirmed this pass beyond a general note about its law-enforcement/defense customer base.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "L3Harris Technologies  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass, and no consumer terms exist. Worth recording that L3Harris supplies communications and surveillance technology to law enforcement as well as defence customers, which places part of its work in the same civil-liberties category as Motorola Solutions, Booz Allen, Leidos and CACI - people affected are members of the public, not customers. Honest B2B entry with that qualification.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Aerospace & Defense", "_row_id": 927, "_entity_id": 1257, "_entity_slug": "l3harris-technologies", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Huntington Ingalls Industries", "Category": "Aerospace & Defense", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a defense/aerospace contractor", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company sells primarily to GOVERNMENTS and other businesses (military hardware, aircraft components, industrial systems) rather than to individual consumers — it has no direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Huntington Ingalls is a B2B/government shipbuilder with no consumer Terms of Service; the tracker's only substantive point is an analogy to the Ahold Delhaize finding about large regional employers, which is context about employee-data exposure elsewhere in the tracker, not a company-specific finding here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the only related point is a cross-reference to another company's employer-data finding, not a fact about this company.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Huntington Ingalls Industries  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Military shipbuilder and the largest industrial employer in Virginia, with the Newport News yard directly inside this tracker's core region. No consumer relationship — but as the Ahold Delhaize finding showed, a large regional employer's exposure is an employee-data question, and tens of thousands of Virginia households are connected to this company through work rather than purchase.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Aerospace & Defense", "_row_id": 928, "_entity_id": 1258, "_entity_slug": "huntington-ingalls-industries", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Textron", "Category": "Aerospace & Defense", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a defense/aerospace contractor", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company sells primarily to GOVERNMENTS and other businesses (military hardware, aircraft components, industrial systems) rather than to individual consumers — it has no direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Providence", "HQ State": "Rhode Island", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Providence, Rhode Island (non-US)", "Parent / Ultimate Owner": "Textron Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): RI SOS Corporate Database — business.sos.ri.gov/CorpWeb/CorpSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Textron Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Textron's aviation and vehicle lines (Cessna, Beechcraft, Bell, E-Z-GO) reach individual owners, but the tracker notes purchases and data run through dealers rather than Textron directly, and no specific consumer-facing term or data practice is stated for this row.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms are located; the tracker notes purchases and data run through dealers rather than through Textron directly.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Textron  <-  Textron Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Manufacturer of Cessna and Beechcraft aircraft, Bell helicopters, and E-Z-GO golf and utility vehicles. The aviation lines reach individual owners, making this one of the few genuinely consumer-adjacent rows in the defence tab, though the purchase runs through dealers and the data with them.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Aerospace & Defense", "_row_id": 929, "_entity_id": 1260, "_entity_slug": "textron", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "TransDigm", "Category": "Aerospace & Defense", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a defense/aerospace contractor", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company sells primarily to GOVERNMENTS and other businesses (military hardware, aircraft components, industrial systems) rather than to individual consumers — it has no direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] TransDigm has been repeatedly flagged by the DoD Inspector General for excess pricing on spare parts\nWHAT THE TERMS SAY: The tracker states TransDigm has been the repeated subject of Department of Defense Inspector General findings on excess pricing for aerospace spare parts.\nWHY IT MATTERS: This is described as a taxpayer-cost issue rather than a consumer harm, since TransDigm sells to manufacturers and maintenance operators, not individual consumers, but it means the row is not a clean record on pricing practices.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — TransDigm is a B2B aerospace-components supplier with no consumer Terms of Service; only the DoD Inspector General excess-pricing findings are a substantive, company-specific fact, and the tracker itself frames this as a taxpayer-cost issue rather than a consumer one.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "No consumer terms exist, but the tracker documents a specific, repeated regulatory finding (DoD IG excess-pricing) rather than only a blank B2B entry.", "Exposure Score (0-100)": 3, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 3, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 3/20 (severity1+0, penalty+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "TransDigm  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Aerospace components sold to manufacturers and maintenance operators. TransDigm has been the repeated subject of Department of Defense Inspector General findings on excess pricing for spare parts — a taxpayer-cost issue rather than a consumer one, recorded so the row is not read as clean.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Aerospace & Defense", "_row_id": 930, "_entity_id": 1261, "_entity_slug": "transdigm", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Howmet Aerospace", "Category": "Aerospace & Defense", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a defense/aerospace contractor", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company sells primarily to GOVERNMENTS and other businesses (military hardware, aircraft components, industrial systems) rather than to individual consumers — it has no direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B/government-facing (aerospace fasteners and metal components) with no consumer account relationship or Terms of Service; the only non-boilerplate content is corporate-lineage trivia (Arconic/Alcoa spinout), which is not a troubling term.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or Terms of Service exists for this company.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Howmet Aerospace  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Engineered metal products and fastening systems for aerospace and industrial customers. No consumer relationship. Spun out of Arconic, itself split from Alcoa — a corporate lineage worth noting for anyone tracing historical records across name changes.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Aerospace & Defense", "_row_id": 931, "_entity_id": 1262, "_entity_slug": "howmet-aerospace", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Amentum", "Category": "Business Services", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a defense/aerospace contractor", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company sells primarily to GOVERNMENTS and other businesses (military hardware, aircraft components, industrial systems) rather than to individual consumers — it has no direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B/government-services (formed from Amentum-Jacobs merger) with no consumer account relationship or Terms of Service; the individuals affected by its work are members of the public, not customers, so no consumer-terms finding applies.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or Terms of Service exists for this company.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Amentum  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Engineering and technical services under government contracts, formed through the merger of Amentum with Jacobs' government services business. Its workforce holds security clearances and its contracts touch federal systems, so like the other government services firms in this tracker the individuals affected by its work are members of the public rather than customers.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Aerospace & Defense", "_row_id": 932, "_entity_id": 1263, "_entity_slug": "amentum", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "General Electric", "Category": "Aerospace & Defense", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a defense/aerospace contractor", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company sells primarily to GOVERNMENTS and other businesses (military hardware, aircraft components, industrial systems) rather than to individual consumers — it has no direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] GE's own brand no longer identifies who actually made your appliance or light bulb\nWHAT THE TERMS SAY: GE split into GE Aerospace, GE Vernova and GE HealthCare; GE-branded appliances and light bulbs sold today are made under license by entirely different companies (Haier and Savant).\nWHY IT MATTERS: A consumer researching 'GE' after a problem with a GE-branded appliance will find a corporate record that has nothing to do with the actual manufacturer, a brand-licensing accountability gap.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Company is B2B/government-facing aerospace with no consumer account relationship; the only company-specific substantive item is the GE brand-licensing accountability gap noted in SCARY.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer Terms of Service exist for GE itself; the finding is a brand-accountability gap, not a disclosed term.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "General Electric  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "GE no longer exists as the conglomerate most people remember — it split into GE Aerospace, GE Vernova and GE HealthCare, two of which appear separately in this tracker. The GE-branded appliances and light bulbs sold today are made under licence by entirely different companies (Haier and Savant). A consumer researching 'GE' after a problem with their refrigerator will find a corporate record that has nothing to do with the manufacturer, which is a brand-licensing accountability gap worth naming.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Aerospace & Defense", "_row_id": 933, "_entity_id": 1264, "_entity_slug": "general-electric", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Caterpillar", "Category": "Construction and Farm Machinery", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is primarily a B2B industrial equipment manufacturer", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial/commercial equipment (heavy machinery, elevators, industrial automation, HVAC systems) sold primarily to OTHER BUSINESSES rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would encounter.", "Arbitration / Class Action Waiver": "Primarily B2B — Caterpillar sells construction/mining equipment to businesses and dealers. Consumer exposure through Cat-branded merchandise and the Cat app (equipment monitoring). Website ToS contain arbitration provisions.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Irving", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Caterpillar Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Caterpillar Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Caterpillar telematics report a contractor's machine location and hours to two companies\nWHAT THE TERMS SAY: Caterpillar's connected-machine telematics stream location, utilisation and diagnostic data from equipment back to Caterpillar and the dealer.\nWHY IT MATTERS: A small contractor's machine reports its working hours and whereabouts to two companies under a dealer agreement the operator may never have read.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Caterpillar's website terms contain arbitration provisions, with no further detail confirmed\nWHAT THE TERMS SAY: The tracker states that Caterpillar's website Terms of Service contain arbitration provisions, and separately notes consumer exposure through Cat-branded merchandise and the Cat app (equipment monitoring); it does not say which of those the provisions cover.\nWHY IT MATTERS: Users of Caterpillar's consumer-facing app or merchandise site may be bound to arbitration, though the tracker does not confirm scope, class-action waiver status, or an opt-out.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — row text too thin; queued for research pass", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Core business is B2B/dealer-based; arbitration provisions and telematics data flows are mentioned but not itemized in detail.", "Exposure Score (0-100)": 22, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Caterpillar  <-  Caterpillar Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Construction and mining equipment sold through independent dealers. Caterpillar's connected-machine telematics stream location, utilisation and diagnostic data from equipment back to the manufacturer and dealer — so a small contractor's machine reports its working hours and whereabouts to two companies, under a dealer agreement the operator may never have read. Small-business relevant, no consumer relationship.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Industrial Machinery", "_row_id": 934, "_entity_id": 1266, "_entity_slug": "caterpillar", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Honeywell", "Category": "Industrial Machinery", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is primarily a B2B industrial equipment manufacturer", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Honeywell Home products (thermostats, security) collect household temperature, occupancy, and security-event data. Smart-thermostat data reveals household presence/absence patterns similar to utility smart-meter data.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Honeywell Home ToS (consumer products: thermostats, security cameras, air purifiers). 30-day opt-out. Honeywell Home (Resideo Technologies, spun off 2018) uses the Honeywell brand under license — check whether the consumer ToS are Resideo's or Honeywell's.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Charlotte", "HQ State": "North Carolina", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'North Carolina' is a non-DMV US state", "Parent / Ultimate Owner": "Honeywell International Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NC SOS Business Registration Search — sosnc.gov/online_services/search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Honeywell International Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Honeywell Home locks thermostat and camera buyers into arbitration unless they opt out in 30 days\nWHAT THE TERMS SAY: Honeywell Home Terms of Service (covering thermostats, security cameras, and air purifiers) mandate binding arbitration with a class-action waiver, with a 30-day window to opt out.\nWHY IT MATTERS: Consumers who miss the 30-day opt-out window lose the right to sue or join a class action over disputes with their connected home devices.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Honeywell Home devices collect occupancy and temperature patterns from inside the house\nWHAT THE TERMS SAY: Honeywell Home products (thermostats, security systems) collect household temperature, occupancy, and security-event data.\nWHY IT MATTERS: Occupancy and temperature patterns can reveal when a home is empty; the tracker notes this resembles reasoning a court applied to utility smart-meter data in a separate, unrelated utility company's case.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[OTHER · FL-4] Unclear whether Honeywell or Resideo's terms actually govern Honeywell-branded home products\nWHAT THE TERMS SAY: Honeywell Home products are licensed to Resideo Technologies following a 2018 spin-off, and it is unconfirmed this pass whether the applicable consumer Terms of Service are Resideo's or Honeywell's.\nWHY IT MATTERS: A consumer may not know which company's terms and privacy practices actually govern their smart-home device.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated, but data-sharing detail is thin and the responsible corporate entity (Honeywell vs. Resideo) is unconfirmed.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Honeywell  <-  Honeywell International Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Honeywell you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass on data, but Honeywell is worth more than a boilerplate B2B entry because of residential connected products: Honeywell-branded thermostats and home security systems transmit occupancy and temperature patterns supporting the same inferences the Seventh Circuit found constitutionally significant in the smart meter case documented in the Power Utilities tab. Honeywell Home products were licensed to Resideo following a spin-off, so the brand on the thermostat and the company behind it may differ. Recommend a follow-up on connected residential product data flows.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Industrial Machinery", "_row_id": 935, "_entity_id": 1268, "_entity_slug": "honeywell", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "3M", "Category": "Chemicals", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is primarily a B2B industrial equipment manufacturer", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial/commercial equipment (heavy machinery, elevators, industrial automation, HVAC systems) sold primarily to OTHER BUSINESSES rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would encounter.", "Arbitration / Class Action Waiver": "3M's consumer products (Post-it, Scotch, Command) are purchased at retail — no digital consumer platform requiring T&C acceptance. 3M's website ToS are minimal. The earplug litigation ($6B+ settlement, 2023) was governed by product-liability law, not website T&C.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "St. Paul", "HQ State": "Minnesota", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Minnesota' is a non-DMV US state", "Parent / Ultimate Owner": "3M Company", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: 3M Company). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — 3M is B2B/retail-purchase with minimal website Terms of Service and no digital consumer platform; the PFAS and earplug litigation are explicitly noted as environmental and product-liability matters resolved outside any Terms-of-Service framework, not a ToS finding for this row.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No meaningful consumer terms exist; the row explicitly states data privacy is not confirmed and directs the major accountability matters to a non-ToS category.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "3M  <-  3M Company", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass on data privacy, and no meaningful consumer terms exist. Recorded with the explicit note that 3M's major public accountability matters - the PFAS settlements and the earplug litigation - are environmental and product liability questions rather than terms-of-service ones, and a blank privacy row should not be read as a clean record generally. Honest B2B entry on the terms question.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Industrial Machinery", "_row_id": 936, "_entity_id": 1270, "_entity_slug": "3m", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Illinois Tool Works", "Category": "Industrial Machinery", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is primarily a B2B industrial equipment manufacturer", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial/commercial equipment (heavy machinery, elevators, industrial automation, HVAC systems) sold primarily to OTHER BUSINESSES rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would encounter.", "Arbitration / Class Action Waiver": "B2B — diversified manufacturer. No significant consumer-facing digital products.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Glenview", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] ITW's decentralized brands often leave buyers unaware that ITW is the parent company\nWHAT THE TERMS SAY: ITW operates dozens of decentralised business units selling into small-business trades (welding, food equipment, automotive aftermarket), and a buyer often deals with a brand without knowing ITW is the parent.\nWHY IT MATTERS: A small-business buyer may be unable to identify or hold accountable the actual parent company behind a branded product.\n(evidence: SCARY; Stated in tracker (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Company is B2B with no significant consumer-facing digital products; the only substantive item is the brand-transparency note in SCARY.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; only an indirect brand-transparency issue is noted.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Illinois Tool Works  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Diversified industrial manufacturer operating dozens of decentralised business units, several of which sell into small-business trades (welding, food equipment, automotive aftermarket). No consumer relationship, but the decentralised structure means a buyer often deals with a brand without knowing ITW is the parent.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Industrial Machinery", "_row_id": 937, "_entity_id": 1271, "_entity_slug": "illinois-tool-works", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Parker-Hannifin", "Category": "Industrial Machinery", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is primarily a B2B industrial equipment manufacturer", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial/commercial equipment (heavy machinery, elevators, industrial automation, HVAC systems) sold primarily to OTHER BUSINESSES rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would encounter.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cleveland", "HQ State": "Ohio", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Ohio' is a non-DMV US state", "Parent / Ultimate Owner": "Parker-Hannifin Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Parker-Hannifin Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row states plainly that no consumer relationship and no consumer terms exist, with no other substantive content beyond a description of the industrial/aerospace business.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or terms exist; explicitly described as an 'honest completeness row'.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Parker-Hannifin  <-  Parker-Hannifin Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Motion and control technologies for industrial and aerospace customers. No consumer relationship and no consumer terms. An honest completeness row.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Industrial Machinery", "_row_id": 938, "_entity_id": 1273, "_entity_slug": "parker-hannifin", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Emerson Electric", "Category": "Industrial Machinery", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is primarily a B2B industrial equipment manufacturer", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial/commercial equipment (heavy machinery, elevators, industrial automation, HVAC systems) sold primarily to OTHER BUSINESSES rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would encounter.", "Arbitration / Class Action Waiver": "B2B — Emerson provides process automation and commercial HVAC. Consumer exposure through Emerson's Sensi smart thermostat brand.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "St. Louis", "HQ State": "Missouri", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Missouri' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Missouri SOS Business Search — bsd.sos.mo.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Company is B2B process automation and commercial HVAC; consumer exposure through the Sensi thermostat brand is only briefly noted with no clause detail, and SCARY explicitly frames Emerson's risk as operational-technology/critical-infrastructure security rather than consumer privacy.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms are described; Sensi consumer exposure is mentioned only in passing with no clause content, and the arbitration opt-out window is explicitly not stated.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Emerson Electric  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Industrial automation and process control, plus the Ridgid and InSinkErator-adjacent tool lines historically associated with the brand. Emerson's automation systems run critical infrastructure including water treatment and energy facilities, which places it in the same critical-infrastructure security category as the Kinder Morgan row rather than in consumer privacy.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Industrial Machinery", "_row_id": 939, "_entity_id": 1274, "_entity_slug": "emerson-electric", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Stanley Black & Decker", "Category": "Industrial Machinery", "Terms & Conditions URL": "See Stanley Black & Decker's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Stanley Black & Decker's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a company-specific data-privacy lawsuit or breach; as a manufacturer of consumer-purchased products (appliances/tires/power tools), this company sells DIRECTLY to individual consumers, though typically through retail purchase rather than an ongoing account relationship — recommend checking against the broader 'right to repair' regulatory trend documented for Deere (this same tab), which increasingly applies to appliance and tool manufacturers under new state laws (California, Colorado, Minnesota, New York, Oregon, Washington).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard product-warranty terms likely apply rather than an ongoing service arbitration clause.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See Deere row (this same tab) for the broader right-to-repair regulatory context that increasingly applies to consumer appliance/tool manufacturers like this one.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New Britain", "HQ State": "Connecticut", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Connecticut' is a non-DMV US state", "Parent / Ultimate Owner": "Stanley Black & Decker, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Connecticut SOTS CONCORD — service.ct.gov/business/s/onlinebusinesssearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Stanley Black & Decker, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Category note: connected tool platforms log tool location and usage, showing where a contractor's crew works\nWHAT THE TERMS SAY: Connected tool platforms register products to a user account and, in commercial versions, log tool location and usage.\nWHY IT MATTERS: On a jobsite that means a contractor's tools report where the crew is working; the tracker records this as a category note about connected tool platforms rather than a confirmed Stanley-specific term, and notes power tools are sold through retailers so the transaction and its data belong to the store.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data-sharing and arbitration fields are both explicitly 'Not independently confirmed this pass'; only the connected-tool telematics fact in SCARY is a substantive, company-specific item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Sells directly to consumers at retail, but data-privacy and arbitration specifics are unconfirmed this pass; only the connected-tool data flow is substantiated.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent", "Entity Type": "Company", "Ownership Path": "Stanley Black & Decker  <-  Stanley Black & Decker, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Stanley Black & Decker you gave up your physical movements. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Power tools sold through retailers, so the transaction and its data belong to the store. The category note that matters: connected tool platforms register products to a user account and, in commercial versions, log tool location and usage — on a jobsite that means a contractor's tools report where the crew is working. Stanley also owns Craftsman and DeWalt, so a buyer choosing between them is choosing one company.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Industrial Machinery", "_row_id": 940, "_entity_id": 1276, "_entity_slug": "stanley-black-decker", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Deere (John Deere)", "Category": "Construction and Farm Machinery", "Terms & Conditions URL": "deere.com/en/legal/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "deere.com/en/privacy-and-data/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MAJOR, DIRECTLY CONSUMER/FARMER-RELEVANT 'RIGHT TO REPAIR' FINDINGS — TWO SEPARATE CASES: (1) A PRIVATE CLASS ACTION (filed 2022): alleged Deere withheld repair software and conspired with its authorized-dealer network to force farmers into using only Deere-approved repair services, allowing 'supracompetitive' pricing. Deere agreed to a $99 MILLION settlement (April 2026, pending final court approval), covering farmers who paid Deere/authorized dealers for large agricultural equipment repairs since Jan 2018, PLUS a 10-year commitment to make diagnostic/repair tools available — Deere maintains 'no finding of wrongdoing.' (2) A SEPARATE, government-brought FTC LAWSUIT (filed Jan 2025, with 5 state attorneys general) specifically alleging Deere's practices 'driven up equipment repair costs for farmers while depriving [them] of the ability to make timely repairs' — a federal judge denied Deere's motion to dismiss (June 2025), and Deere ultimately SETTLED this SEPARATE case too (July 8, 2026), agreeing to provide the SAME diagnostic software, manuals, and parts-pairing tools available to authorized dealers for the next 10 YEARS, plus $1 million toward state legal costs.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass for standard consumer purchase agreements; the remedies in both settlements specifically focus on compelling ACCESS to repair tools rather than a traditional arbitration-clause dispute.", "Fees / Billing Flags": "The CORE ALLEGATION IN BOTH CASES IS DIRECTLY ABOUT FEES/PRICING: farmers forced into higher-cost authorized-dealer repairs instead of cheaper independent or self-service options — a direct, quantifiable consumer-cost harm.", "Notes": "This 'right to repair' pattern is part of a BROADER, ACCELERATING STATE LEGISLATIVE TREND — as of Jan 1, 2026, California, Colorado, Minnesota, New York, Oregon, and Washington all require manufacturers of covered products to provide fair-terms access to repair parts/tools/documentation, with 33+ additional right-to-repair bills introduced in just the first few weeks of one recent legislative session — worth flagging as a genuinely significant, rapidly evolving consumer-rights area likely to affect many OTHER manufacturers in this tracker (electronics, appliances, vehicles) beyond Deere specifically.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Moline", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Deere & Company", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Deere & Company). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Farmers allege they can't repair Deere equipment they own without dealer software\nWHAT THE TERMS SAY: Deere's software locks and diagnostic restrictions have been the central case in the right-to-repair movement; farmers allege they cannot fix equipment they own outright without authorized-dealer software. A private class action produced a $99 million settlement (pending final court approval, April 2026) plus a 10-year commitment to make diagnostic/repair tools available; a separate FTC lawsuit with five state attorneys general settled in July 2026 with the same 10-year commitment to provide diagnostic software, manuals, and parts-pairing tools, plus $1 million toward state legal costs.\nWHY IT MATTERS: Farmers were allegedly forced into costlier authorized-dealer repairs instead of cheaper independent or self-service options; Deere maintains no finding of wrongdoing in the private settlement.\n(evidence: Data Sharing/Selling Flags, Fees / Billing Flags, SCARY; Stated in tracker (fidelity pass 1: Hedge lost corrected))", "Top Troubling #2": "[OTHER · FL-4] Who owns the yield data a Deere tractor collects on a farmer's own land is unresolved\nWHAT THE TERMS SAY: Deere equipment also generates detailed farm operational and yield data, which the tracker flags as a separate, underexamined question of who owns agronomic data generated on a farmer's own land.\nWHY IT MATTERS: Farmers may not control or benefit from agronomic data their own equipment generates, though the tracker does not confirm any specific data-ownership term.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Two distinct company-specific harms are documented (the repair-software lock and the farm-data ownership question); a third would require treating the state legislative trend or the AGCO/Farm-Bureau MOU as Deere-specific findings, which they are not.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The repair-restriction litigation is documented with specific settlement amounts and dates, but the farm-data ownership question is explicitly called unconfirmed and underexamined.", "Exposure Score (0-100)": 17, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 4/20 (termination_or_confiscation+4) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Deere (John Deere)  <-  Deere & Company", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Deere (John Deere) you gave up your right to keep what you paid for. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The John Deere finding is not privacy but repair, and it is one of the sharpest ownership questions in this tracker: Deere's software locks and diagnostic restrictions have been the central case in the right-to-repair movement, with farmers arguing they cannot fix equipment they own outright without authorised dealer software. That is a terms-and-conditions finding in the purest sense - a purchased physical object whose usability is governed by a licence. Deere signed a memorandum of understanding with the American Farm Bureau Federation on repair access, and the FTC and state legislatures have engaged the issue. Deere equipment also generates detailed farm operational and yield data, which raises a separate and underexamined question about who owns agronomic data generated on a farmer's own land.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Industrial Machinery", "_row_id": 941, "_entity_id": 1278, "_entity_slug": "deere-john-deere", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cummins", "Category": "Industrial Machinery", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is primarily a B2B industrial equipment manufacturer", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial/commercial equipment (heavy machinery, elevators, industrial automation, HVAC systems) sold primarily to OTHER BUSINESSES rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would encounter.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Columbus", "HQ State": "Indiana", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Indiana' is a non-DMV US state", "Parent / Ultimate Owner": "Cummins Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Indiana SOS INBiz — inbiz.in.gov/BOS/Home/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Cummins Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-3] Cummins settled a Clean Air Act case over emissions defeat devices in RAM trucks\nWHAT THE TERMS SAY: Cummins agreed to a major Clean Air Act settlement over emissions defeat devices in RAM trucks, resolved through EPA enforcement rather than any consumer contract.\nWHY IT MATTERS: Individual truck owners were affected by the alleged emissions defeat devices, but they had no consumer-contract recourse — the matter was resolved by regulators instead; the tracker notes this so the row is not read as clean.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Company is B2B (engines/power systems sold to manufacturers and fleets) with no consumer relationship; the Clean Air Act settlement is the only substantive company-specific item, and the tracker itself frames it as regulatory rather than a consumer-terms matter.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the emissions settlement is known only via regulatory enforcement, not any disclosure regime.", "Exposure Score (0-100)": 3, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 3, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 3/20 (severity1+0, penalty+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Cummins  <-  Cummins Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Engines and power systems sold to vehicle manufacturers and fleet operators. Cummins agreed to a major Clean Air Act settlement over emissions defeat devices in RAM trucks — a consumer-affecting matter, since the vehicles were owned by individuals, but resolved through EPA enforcement rather than any consumer contract. Worth recording so the row is not read as clean.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Industrial Machinery", "_row_id": 942, "_entity_id": 1280, "_entity_slug": "cummins", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Paccar", "Category": "Motor Vehicles & Parts", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is primarily a B2B industrial equipment manufacturer", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial/commercial equipment (heavy machinery, elevators, industrial automation, HVAC systems) sold primarily to OTHER BUSINESSES rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would encounter.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Paccar trucks stream owner-operators' location and driving behavior to the manufacturer\nWHAT THE TERMS SAY: Modern Kenworth, Peterbilt and DAF trucks generate continuous telematics, so an independent driver's location and driving behaviour flow to the manufacturer and the fleet software provider.\nWHY IT MATTERS: Independent owner-operators — many of whom buy Paccar trucks through dealers — have detailed location and driving-behavior data collected by parties beyond their direct control.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Company is B2B with no consumer relationship or terms; only the truck telematics data-flow fact in SCARY is a substantive, company-specific item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the telematics data flow is described in SCARY context only, not via any disclosure regime.", "Exposure Score (0-100)": 4, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Paccar  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Manufacturer of Kenworth, Peterbilt and DAF commercial trucks sold through dealers to fleet operators, including many small owner-operators. Modern trucks generate continuous telematics, so an independent driver's location and driving behaviour flow to the manufacturer and fleet software provider — the commercial-vehicle version of the connected-car findings in the Auto Apps tab.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Industrial Machinery", "_row_id": 943, "_entity_id": 1281, "_entity_slug": "paccar", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Rockwell Automation", "Category": "Electronics, Electrical Equip.", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is primarily a B2B industrial equipment manufacturer", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial/commercial equipment (heavy machinery, elevators, industrial automation, HVAC systems) sold primarily to OTHER BUSINESSES rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would encounter.", "Arbitration / Class Action Waiver": "B2B — industrial automation. No consumer-facing products.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Milwaukee", "HQ State": "Wisconsin", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Wisconsin' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Wisconsin DFI Corporate Records — apps.dfi.wi.gov/apps/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Pure B2B industrial automation company with no consumer-facing products; SCARY explicitly frames Rockwell's risk as recurring CISA industrial-control-system advisories, i.e. operational-technology security, not consumer data or terms.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship exists; the only risk noted is industrial-control-system security, outside this tracker's consumer-terms scope.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Rockwell Automation  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Industrial control systems for manufacturers. Rockwell's products are a recurring subject of CISA industrial control system advisories, which is the relevant risk register here — operational technology security rather than consumer data. No consumer relationship.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Industrial Machinery", "_row_id": 944, "_entity_id": 1282, "_entity_slug": "rockwell-automation", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Xylem", "Category": "Industrial Machinery", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is primarily a B2B industrial equipment manufacturer", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial/commercial equipment (heavy machinery, elevators, industrial automation, HVAC systems) sold primarily to OTHER BUSINESSES rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would encounter.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — B2B water-technology manufacturer with no consumer relationship or terms; the substantive content in SCARY is context about downstream utility customers (documented in the DC Water, WSSC and Fairfax Water rows), which per instructions is not a Xylem-specific finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or terms exist; smart-metering data flows discussed belong to utility customer rows, not Xylem itself.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Xylem  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Water technology sold to utilities and industrial customers, including smart water metering. That places Xylem directly upstream of the DC Water, WSSC and Fairfax Water rows: the interval consumption data those utilities hold is generated by equipment from companies like this one, and the collection frequency is a procurement decision made years before any customer sees a bill.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Industrial Machinery", "_row_id": 945, "_entity_id": 1283, "_entity_slug": "xylem", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Vertiv", "Category": "Electronics, Electrical Equip.", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is primarily a B2B industrial equipment manufacturer", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial/commercial equipment (heavy machinery, elevators, industrial automation, HVAC systems) sold primarily to OTHER BUSINESSES rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would encounter.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row explicitly states Vertiv holds no consumer data and has no consumer relationship, describing itself as an honest infrastructure entry with no substantive finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or data holdings exist; explicitly described as an 'honest infrastructure row'.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Vertiv  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Data centre power and cooling infrastructure. Vertiv holds no consumer data but keeps running the facilities described in the Equinix row — the buildings where most of the data in this tracker physically sits. An honest infrastructure row.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Industrial Machinery", "_row_id": 946, "_entity_id": 1284, "_entity_slug": "vertiv", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Otis Worldwide", "Category": "Industrial Machinery", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is primarily a B2B industrial equipment manufacturer", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial/commercial equipment (heavy machinery, elevators, industrial automation, HVAC systems) sold primarily to OTHER BUSINESSES rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would encounter.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Farmington", "HQ State": "Connecticut", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Otis Worldwide Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Connecticut SOTS CONCORD — service.ct.gov/business/s/onlinebusinesssearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Otis Worldwide Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Otis elevators can log which floor you go to, and building occupants aren't party to anything\nWHAT THE TERMS SAY: Otis connected-elevator systems continuously report usage and fault data, and some destination-dispatch deployments log which floor an individual travels to.\nWHY IT MATTERS: This building-occupancy data is held by an equipment vendor under a service contract with the building owner, while the individual occupant whose floor selections are logged is party to nothing.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Company sells and services elevators/escalators under long-term contracts with building owners, not occupants, so only one company-specific substantive item exists — the destination-dispatch occupancy logging noted in SCARY.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Building occupants have no contract or disclosure regime with Otis at all, despite floor-level usage data being logged.", "Exposure Score (0-100)": 7, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Otis Worldwide  <-  Otis Worldwide Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Elevators and escalators, sold and serviced under long-term contracts with building owners. Otis connected-elevator systems report usage and fault data continuously, and in some deployments include destination-dispatch systems that log which floor an individual travels to — building occupancy data held by an equipment vendor, with the occupant party to nothing.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Industrial Machinery", "_row_id": 947, "_entity_id": 1286, "_entity_slug": "otis-worldwide", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "AGCO", "Category": "Construction and Farm Machinery", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is primarily a B2B industrial equipment manufacturer", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial/commercial equipment (heavy machinery, elevators, industrial automation, HVAC systems) sold primarily to OTHER BUSINESSES rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would encounter.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Duluth", "HQ State": "Georgia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Georgia' is a non-DMV US state", "Parent / Ultimate Owner": "AGCO Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Georgia SOS eCorp — ecorp.sos.ga.gov/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: AGCO Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row documents a cooperative right-to-repair memorandum of understanding with the American Farm Bureau Federation — a positive counterpoint to the Deere row, not an adverse practice — and states no consumer relationship, so no troubling item is present.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or terms exist; the repair MOU is a cooperative practice, not a disclosed consumer term.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "AGCO  <-  AGCO Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Agricultural equipment sold through dealers. AGCO signed a right-to-repair memorandum of understanding with the American Farm Bureau Federation, which is the more cooperative counterpart to the John Deere row's software-lock dispute — a genuine and reportable difference between two competitors on whether a farmer can fix equipment they own.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Industrial Machinery", "_row_id": 948, "_entity_id": 1288, "_entity_slug": "agco", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Oshkosh", "Category": "Construction and Farm Machinery", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is primarily a B2B industrial equipment manufacturer", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial/commercial equipment (heavy machinery, elevators, industrial automation, HVAC systems) sold primarily to OTHER BUSINESSES rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would encounter.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — No consumer relationship exists; the row notes that municipal vehicles increasingly carry cameras and telematics as general context, but states no specific Oshkosh practice, term, or data flow to evaluate as a company-specific finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or terms exist; municipal camera/telematics procurement is noted only generally, without company-specific detail.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Oshkosh  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Specialty vehicles for municipal, defence and commercial customers, including the USPS Next Generation Delivery Vehicle contract. No consumer relationship, though its products — fire apparatus, refuse trucks, mail vehicles — operate in residential neighbourhoods daily and increasingly carry cameras and telematics procured by the municipality, not the resident.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Industrial Machinery", "_row_id": 949, "_entity_id": 1289, "_entity_slug": "oshkosh", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Whirlpool", "Category": "Electronics, Electrical Equip.", "Terms & Conditions URL": "See Whirlpool's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Whirlpool's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a company-specific data-privacy lawsuit or breach; as a manufacturer of consumer-purchased products (appliances/tires/power tools), this company sells DIRECTLY to individual consumers, though typically through retail purchase rather than an ongoing account relationship — recommend checking against the broader 'right to repair' regulatory trend documented for Deere (this same tab), which increasingly applies to appliance and tool manufacturers under new state laws (California, Colorado, Minnesota, New York, Oregon, Washington).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard product-warranty terms likely apply rather than an ongoing service arbitration clause.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See Deere row (this same tab) for the broader right-to-repair regulatory context that increasingly applies to consumer appliance/tool manufacturers like this one.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Benton Harbor", "HQ State": "Michigan", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Michigan' is a non-DMV US state", "Parent / Ultimate Owner": "Whirlpool Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Michigan LARA Business Entity Search — cofs.lara.state.mi.us/SearchApi/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Whirlpool Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Whirlpool connected appliances report your household routine to a company account\nWHAT THE TERMS SAY: Connected Whirlpool, Maytag, KitchenAid and JennAir appliances register to a user account and transmit usage telemetry, such as a washing machine or refrigerator reporting cycle times.\nWHY IT MATTERS: Appliance usage telemetry functions as an occupancy and household-routine signal, though the tracker does not itemize it as sold or shared with third parties.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] Whirlpool's authorized-repair network decides whether your appliance is worth fixing\nWHAT THE TERMS SAY: Whirlpool's authorised service network and parts availability determine whether an appliance is economically repairable, described as the domestic-scale version of the right-to-repair question.\nWHY IT MATTERS: An appliance can become effectively disposable if authorized repair is unavailable or uneconomical, though the tracker does not confirm specific restrictive repair terms.\n(evidence: SCARY, Notes; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data-sharing and arbitration fields are both explicitly 'Not independently confirmed this pass'; only the SCARY field's appliance-telemetry and repair-economics observations are substantive and company-specific.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Sells directly to consumers at retail, but data-privacy and arbitration specifics are unconfirmed this pass; only appliance telemetry and repair-network facts are substantiated.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Whirlpool  <-  Whirlpool Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Whirlpool takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Whirlpool, Maytag, KitchenAid and JennAir are one company, so a buyer choosing between them for reliability is choosing one manufacturer. Connected appliances register to an account and transmit usage telemetry — a washing machine or refrigerator reporting cycle times is an occupancy and household-routine signal. The more common consumer friction is warranty and repair, where Whirlpool's authorised service network and parts availability determine whether an appliance is economically repairable, which is the right-to-repair question in domestic form.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Industrial Machinery", "_row_id": 950, "_entity_id": 1291, "_entity_slug": "whirlpool", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Goodyear Tire & Rubber", "Category": "Motor Vehicles & Parts", "Terms & Conditions URL": "See Goodyear Tire & Rubber's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Goodyear Tire & Rubber's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a company-specific data-privacy lawsuit or breach; as a manufacturer of consumer-purchased products (appliances/tires/power tools), this company sells DIRECTLY to individual consumers, though typically through retail purchase rather than an ongoing account relationship — recommend checking against the broader 'right to repair' regulatory trend documented for Deere (this same tab), which increasingly applies to appliance and tool manufacturers under new state laws (California, Colorado, Minnesota, New York, Oregon, Washington).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard product-warranty terms likely apply rather than an ongoing service arbitration clause.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See Deere row (this same tab) for the broader right-to-repair regulatory context that increasingly applies to consumer appliance/tool manufacturers like this one.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Goodyear's tire/fleet telematics extend retail data into continuous vehicle data, unconfirmed\nWHAT THE TERMS SAY: Retail tire sales/service tie a named person to a specific vehicle and its mileage, and the tracker notes Goodyear's connected tire and fleet telematics products extend that into continuous vehicle data.\nWHY IT MATTERS: If active, telematics could let Goodyear or partners collect ongoing vehicle data tied to an identified owner, though the tracker treats this as unverified and does not itself specify location tracking for Goodyear's own products.\n(evidence: SCARY; Tracker says unconfirmed (fidelity pass 1: Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration and fees are both explicitly not confirmed this pass ('standard product-warranty terms likely apply', 'not itemized'); only the SCARY telematics note is substantive, and even that is flagged unverified rather than clean.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=N; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data sharing, arbitration, and fees are all unconfirmed or unstated this pass; only a hedged telematics note exists.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Goodyear Tire & Rubber  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your biometric identifiers.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Goodyear Tire & Rubber takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Goodyear is consumer-facing through retail tire sales and service, where the transaction ties a named person to a specific vehicle and its mileage - and connected tire and fleet telematics products extend that into continuous vehicle data. Cross-ref the Auto Apps tab and the Allstate/Arity finding in Insurance for what happens to vehicle movement data once it leaves the vehicle. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Industrial Machinery", "_row_id": 951, "_entity_id": 1292, "_entity_slug": "goodyear-tire-rubber", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Dow", "Category": "Chemicals", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Primarily B2B — Dow produces chemicals/plastics sold to manufacturers. Consumer exposure through Dow-branded consumer products is minimal (Great Stuff foam sealant).", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Midland", "HQ State": "Michigan", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Michigan' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Michigan LARA Business Entity Search — cofs.lara.state.mi.us/SearchApi/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-1] Dow's consumer-relevant exposure runs through breast-implant and PFAS litigation, not any signed term\nWHAT THE TERMS SAY: The tracker names the legacy Dow Corning breast implant matter and PFAS-related claims as Dow's consumer-relevant exposure, explicitly noting this runs through product-liability and environmental litigation rather than through anything a consumer signs.\nWHY IT MATTERS: Consumers affected by these matters have no ToS or account relationship with Dow to reference; any recourse runs through litigation rather than a service agreement, and no consumer terms exist here.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Dow is a B2B chemicals manufacturer with no direct consumer account relationship or Terms of Service; only the litigation context is substantive, and the tracker states it explicitly does not arise from any consumer-signed agreement.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=?; litigation=Y; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist for this B2B manufacturer; the only content is litigation context unrelated to any signed agreement.", "Exposure Score (0-100)": 2, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity1+0, litigation+2) | flags stated 16/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Dow  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 80.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Bulk chemicals and materials sold to manufacturers. Dow's consumer-relevant exposure runs through product liability and environmental litigation — including the legacy Dow Corning breast implant matter and PFAS-related claims — rather than through anything a consumer signs. No consumer terms exist.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 952, "_entity_id": 1293, "_entity_slug": "dow", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sherwin-Williams", "Category": "Chemicals", "Terms & Conditions URL": "See Sherwin-Williams's own published terms of service (retail paint stores)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Sherwin-Williams's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Sherwin-Williams ColorSnap app collects color preferences, room photos, and purchase history. The company-owned store model means SW directly collects purchase data rather than receiving it through a retailer intermediary.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Sherwin-Williams website ToS. 30-day opt-out. Consumer-facing through 4,800+ company-owned stores and the SW ColorSnap app. Product-liability claims (lead paint) governed by separate litigation.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, focused on the retail store loyalty program rather than the company's broader industrial chemical operations.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cleveland", "HQ State": "Ohio", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Ohio' is a non-DMV US state", "Parent / Ultimate Owner": "The Sherwin-Williams Company", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: The Sherwin-Williams Company). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Sherwin-Williams' website ToS impose mandatory binding arbitration with a 30-day opt-out\nWHAT THE TERMS SAY: The tracker states Sherwin-Williams' website Terms of Service impose MANDATORY binding arbitration with a class action waiver and a 30-day opt-out; it separately records that the company is consumer-facing through 4,800+ company-owned stores and the SW ColorSnap app, and that product-liability (lead paint) claims are governed by separate litigation.\nWHY IT MATTERS: Anyone bound by the website terms who does not opt out within 30 days gives up court for arbitration.\n(evidence: Arbitration; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[CLASS_ACTION_WAIVER · FL-3] The same clause waives customers' right to join a class action against Sherwin-Williams\nWHAT THE TERMS SAY: The tracker states the mandatory arbitration clause includes a class action waiver.\nWHY IT MATTERS: Consumers with small individual claims cannot band together against Sherwin-Williams; each must arbitrate alone.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] ColorSnap app photographs and processes images of customers' home interiors, plus purchase history\nWHAT THE TERMS SAY: The ColorSnap app collects color preferences, room photos, and purchase history, and Sherwin-Williams' company-owned store model means it directly collects this purchase data itself rather than through a retailer intermediary.\nWHY IT MATTERS: Photos of a customer's home interior are a sensitive data category; the tracker flags this as worth watching alongside biometric and image-analysis findings elsewhere, though nothing company-specific is confirmed this pass.\n(evidence: Data Sharing, SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated, but the ColorSnap data-collection detail and lead-paint litigation remain thinly verified this pass.", "Exposure Score (0-100)": 31, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 4, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 4/20 (severity2+2, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Sherwin-Williams  <-  The Sherwin-Williams Company", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Sherwin-Williams you gave up your right to sue and your right to join a class action. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Sherwin-Williams is one of the few genuinely consumer-facing companies in this tab, operating a large network of company-owned paint stores plus a loyalty and colour-matching app. Colour visualiser features that let a customer photograph a room and preview paint are image-processing on interior photographs of a home, which is a category worth flagging given the biometric and image-analysis findings elsewhere in this tracker. Nothing company-specific confirmed this pass; unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 953, "_entity_id": 1295, "_entity_slug": "sherwin-williams", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "PPG Industries", "Category": "Chemicals", "Terms & Conditions URL": "See PPG Industries's own published terms of service (retail paint stores)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See PPG Industries's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B chemicals/materials manufacturer — sells to industrial customers and manufacturers, not consumers. No consumer data collection through the core business.", "Arbitration / Class Action Waiver": "PPG sells paints (PPG, Glidden, Olympic) through retail channels. Consumer digital footprint through PPG's color-matching app and online paint ordering.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, focused on the retail store loyalty program rather than the company's broader industrial chemical operations.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Pittsburgh", "HQ State": "Pennsylvania", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] PPG's colour app processes home-interior photos, its one real consumer data touchpoint\nWHAT THE TERMS SAY: PPG's core business is B2B trade/architectural coatings sold through distribution and company stores; the tracker states its colour-visualiser app performs image processing on photographs customers take of their home interiors, calling this 'the one genuine consumer data touchpoint.'\nWHY IT MATTERS: This is the one place PPG holds identifiable consumer data (photos of someone's home), though the tracker doesn't detail how that image data is stored or used.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — PPG is primarily a B2B coatings manufacturer with no consumer arbitration or fee terms located this pass; only the colour-visualiser app represents a genuine, but thinly detailed, consumer data touchpoint.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=N; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Primarily a B2B manufacturer with no arbitration or fee terms located; only a thin, unconfirmed app data touchpoint is noted.", "Exposure Score (0-100)": 3, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "PPG Industries  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Industrial and architectural coatings. PPG sells through trade distribution and company stores serving contractors, so a homeowner encounters it mostly through a painter rather than directly. Its colour-visualiser app performs image processing on photographs of a customer's home interior, which is the one genuine consumer data touchpoint.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 954, "_entity_id": 1296, "_entity_slug": "ppg-industries", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Eastman Chemical", "Category": "Chemicals", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "B2B — specialty chemicals/materials. No consumer-facing products.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Kingsport", "HQ State": "Tennessee", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Tennessee' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Tennessee SOS Business Search — tnbear.tn.gov/Ecommerce/FilingSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] Eastman's recyclability marketing claims have drawn FTC-style scrutiny, separate from any consumer term\nWHAT THE TERMS SAY: The tracker notes Eastman's molecular recycling operations have drawn scrutiny over recyclability claims, describing it as a marketing-substantiation question of the kind the FTC pursues.\nWHY IT MATTERS: If Eastman's recyclability marketing overstates what its process achieves, that is a consumer-protection concern, though the tracker is clear it never appears in a terms of service and Eastman has no consumer-facing products.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Eastman is a B2B specialty-chemicals manufacturer with no consumer terms; the only substantive item is scrutiny over recyclability marketing claims, a consumer-protection question separate from any signed agreement.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=?; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist for this B2B manufacturer; only a marketing-substantiation scrutiny note is present.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 16/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Eastman Chemical  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 80.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Specialty chemicals and materials, including plastics used in consumer packaging. Eastman's molecular recycling operations have drawn scrutiny over recyclability claims, which is a marketing-substantiation question of the kind the FTC pursues — a consumer-protection issue that never appears in a terms of service.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 955, "_entity_id": 1297, "_entity_slug": "eastman-chemical", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Celanese", "Category": "Chemicals", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "B2B — specialty chemicals. No consumer-facing products.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Irving", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Celanese is a B2B specialty-chemicals producer with no consumer relationship or terms; the tracker notes chemical-plant safety regulation, not data, as the sector's real risk, and states nothing company-specific.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms or disclosure regime exists; this is a B2B company with no individual-consumer relationship.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 17/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Celanese  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 83.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Engineered materials and acetyl chemicals for industrial customers. No consumer relationship. An honest completeness row; the meaningful risk in this sector is chemical plant safety regulation, not data.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 956, "_entity_id": 1298, "_entity_slug": "celanese", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "International Paper", "Category": "Packaging, Containers", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Memphis", "HQ State": "Tennessee", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Tennessee SOS Business Search — tnbear.tn.gov/Ecommerce/FilingSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] International Paper is a defendant in significant antitrust litigation over containerboard pricing\nWHAT THE TERMS SAY: The tracker states International Paper is a defendant in significant antitrust litigation over containerboard pricing.\nWHY IT MATTERS: The tracker notes containerboard pricing raises input costs for every small business that ships anything - a genuine small-business harm arriving through commodity pricing rather than through data.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — International Paper sells packaging/containerboard to commercial customers with no consumer terms; the only substantive item is antitrust litigation affecting small-business shipping costs, not a consumer-facing clause.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=N; litigation=Y; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; only antitrust litigation context is noted, which doesn't run through any consumer agreement.", "Exposure Score (0-100)": 2, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity1+0, litigation+2) | flags stated 17/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "International Paper  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 83.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Packaging and containerboard for commercial customers. International Paper is worth noting for a different reason: it is a defendant in significant antitrust litigation over containerboard pricing, which raises input costs for every small business that ships anything — a genuine small-business harm arriving through commodity pricing rather than through data.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 957, "_entity_id": 1299, "_entity_slug": "international-paper", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ecolab", "Category": "Chemicals", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "B2B — water treatment, hygiene, infection prevention for commercial/institutional clients. Consumer exposure through Ecolab's residential pest control brand (Terminix-adjacent). Limited consumer-digital footprint.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "St. Paul", "HQ State": "Minnesota", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Minnesota' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Ecolab's hygiene-monitoring systems aggregate client business data those clients may not know about\nWHAT THE TERMS SAY: The tracker states Ecolab's cleaning, sanitation, and water-treatment systems monitor hygiene compliance at client sites (restaurants, hospitals, hotels), giving it detailed operational data about those businesses, including many small ones, that the tracker says they may not realize is being aggregated.\nWHY IT MATTERS: Many of Ecolab's clients are small businesses that may lack visibility into how much operational data Ecolab collects about their sites, though the tracker doesn't specify further downstream use.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Ecolab is a B2B hygiene/water-treatment company with no individual-consumer terms; only its aggregation of client operational data is substantive, and the tracker doesn't detail further use.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=?; affiliates=?; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No individual-consumer terms exist; only a noted, thinly detailed client-data aggregation practice appears.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 15/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Ecolab  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 76.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Cleaning, sanitation and water treatment for commercial and institutional customers, including restaurants, hospitals and hotels across this tracker. Ecolab's systems monitor hygiene compliance at client sites, so it holds detailed operational data about businesses — including many small ones — that those businesses may not realise is being aggregated.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 958, "_entity_id": 1300, "_entity_slug": "ecolab", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Air Products & Chemicals", "Category": "Chemicals", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Allentown", "HQ State": "Pennsylvania", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Air Products and Chemicals, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Air Products and Chemicals, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Air Products is a B2B industrial-gas supplier with no consumer relationship; it supplies hospitals' medical gas but holds no patient data and is not a HIPAA covered entity, per the tracker.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms or disclosure regime exists; this is a B2B company with no individual-consumer relationship.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 17/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Air Products & Chemicals  <-  Air Products and Chemicals, Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 83.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Industrial gases supplied to manufacturing, energy and healthcare customers. Its medical gas business supplies hospitals, so it sits in the healthcare supply chain without being a HIPAA covered entity or holding any patient data. Genuinely no consumer relationship.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 959, "_entity_id": 1302, "_entity_slug": "air-products-chemicals", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Westlake", "Category": "Chemicals", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Westlake is a B2B petrochemicals/building-products manufacturer with no consumer terms; its building products reach consumers only through retailers who own the transaction and any data.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms or disclosure regime exists; this is a B2B company with no individual-consumer relationship.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 17/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Westlake  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 83.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Petrochemicals and building products. Westlake's building products reach consumers through home improvement retailers, but the transaction and any data belong to the retailer. No consumer terms are published.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 960, "_entity_id": 1303, "_entity_slug": "westlake", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Corning", "Category": "Electronics, Electrical Equip.", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Corning", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Corning has no direct consumer account relationship despite its glass and fiber being physically present in consumers' phones and networks; the tracker keeps this row specifically to note that contrast, not to flag a term.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms or disclosure regime exists; this is a B2B company with no individual-consumer relationship.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 17/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Corning  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 83.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Corning makes the cover glass on a very large share of the world's smartphones and the optical fibre carrying internet traffic under the streets, selling entirely to manufacturers and network operators. It is simultaneously invisible to consumers and physically present in their hands and beneath their feet. No consumer relationship exists, and this row is worth keeping precisely for that contrast.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 961, "_entity_id": 1304, "_entity_slug": "corning", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Nucor", "Category": "Metals", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Charlotte", "HQ State": "North Carolina", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ: Charlotte, North Carolina (non-US)", "Parent / Ultimate Owner": "Nucor Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NC SOS Business Registration Search — sosnc.gov/online_services/search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Nucor Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Nucor is a B2B steel producer with no consumer relationship; the tracker notes it as a large electricity ratepayer via its electric-arc mini-mills, which is a utility-sector link rather than a data or terms issue.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms or disclosure regime exists; this is a B2B company with no individual-consumer relationship.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 17/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Nucor  <-  Nucor Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 83.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The largest US steel producer, selling to construction, automotive and manufacturing customers. No consumer relationship. Nucor's electric-arc mini-mill model makes it a significant electricity consumer, which links it to the utility rows in this tracker as a ratepayer rather than as a data holder.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 962, "_entity_id": 1306, "_entity_slug": "nucor", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Steel Dynamics", "Category": "Metals", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Fort Wayne", "HQ State": "Indiana", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Indiana' is a non-DMV US state", "Parent / Ultimate Owner": "Steel Dynamics, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Indiana SOS INBiz — inbiz.in.gov/BOS/Home/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Steel Dynamics, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Steel Dynamics' scrap recycling of end-of-life goods raises an unresolved consumer data-destruction question\nWHAT THE TERMS SAY: The tracker notes Steel Dynamics' metals recycling arm handles end-of-life vehicles and appliances, and flags that shredded consumer goods can still contain storage media, calling the data-destruction question in the recycling chain 'genuinely underexamined.'\nWHY IT MATTERS: If storage media from scrapped consumer goods isn't wiped before shredding, personal data could be exposed, though the tracker treats this as an open question rather than a confirmed incident.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Steel Dynamics is a B2B steel/recycling company with no consumer terms; only the recycling-chain data-destruction question is substantive, and the tracker itself flags it as underexamined rather than confirmed.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=?; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist for this B2B recycler; the only item is a flagged-but-unconfirmed data-destruction question in its scrap chain.", "Exposure Score (0-100)": 3, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 16/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Steel Dynamics  <-  Steel Dynamics, Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 80.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Steel production and metals recycling for industrial customers. Its scrap recycling arm handles end-of-life vehicles and appliances, which is worth flagging alongside the LKQ row: shredded consumer goods can still contain storage media, and the data-destruction question in the recycling chain is genuinely underexamined.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 963, "_entity_id": 1308, "_entity_slug": "steel-dynamics", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "United States Steel", "Category": "Metals", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Pittsburgh", "HQ State": "Pennsylvania", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "United States Steel Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: United States Steel Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — US Steel is a B2B steel producer with no consumer terms; the tracker's only note is the Nippon Steel acquisition's national-security review, which is unrelated to consumer data or contracts.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms or disclosure regime exists; this is a B2B company with no individual-consumer relationship.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 17/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "United States Steel  <-  United States Steel Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 83.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Integrated steel producer, subject of a heavily contested acquisition by Nippon Steel that turned on national security review rather than any commercial or consumer question. No consumer relationship exists.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 964, "_entity_id": 1310, "_entity_slug": "united-states-steel", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cleveland-Cliffs", "Category": "Metals", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cleveland", "HQ State": "Ohio", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Ohio' is a non-DMV US state", "Parent / Ultimate Owner": "Cleveland-Cliffs Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Cleveland-Cliffs Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Cleveland-Cliffs is a B2B iron-ore/steel producer selling mainly to automotive manufacturers, with no consumer relationship or terms noted.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms or disclosure regime exists; this is a B2B company with no individual-consumer relationship.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 17/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Cleveland-Cliffs  <-  Cleveland-Cliffs Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 83.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Iron ore and steel for industrial customers, principally automotive. No consumer relationship. Its supply position means disruptions surface as vehicle availability and price rather than as any consumer data event.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 965, "_entity_id": 1312, "_entity_slug": "cleveland-cliffs", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Alcoa", "Category": "Metals", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Pittsburgh", "HQ State": "Pennsylvania", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Alcoa Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alcoa Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Alcoa is a B2B aluminum producer with no consumer terms; the tracker notes its smelters' utility negotiations can indirectly shift costs to residential ratepayers, but says this has no contractual expression.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms or disclosure regime exists; this is a B2B company with no individual-consumer relationship.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 17/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Alcoa  <-  Alcoa Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 83.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Aluminium and alumina production. No consumer relationship. Alcoa's operations are energy-intensive enough that its smelters negotiate directly with utilities, which occasionally shifts costs onto residential ratepayers — an indirect consumer effect with no contractual expression.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 966, "_entity_id": 1314, "_entity_slug": "alcoa", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Reliance", "Category": "Metals", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Reliance is a B2B metals distributor serving fabricators and small machine shops, with no consumer relationship or terms; it is noted as small-business relevant as a supplier rather than as a data holder.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms or disclosure regime exists; this is a B2B company with no individual-consumer relationship.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 17/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Reliance  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 83.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Metals service centre distributor supplying fabricators and manufacturers, including a large number of small machine shops and fabrication businesses. No consumer relationship, but genuinely small-business relevant as a supplier.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 967, "_entity_id": 1315, "_entity_slug": "reliance", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Mosaic", "Category": "Chemicals", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Tampa", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "The Mosaic Company", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: The Mosaic Company). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-1] Mosaic's Florida phosphogypsum stacks are a documented environmental liability\nWHAT THE TERMS SAY: The tracker states Mosaic's Florida phosphogypsum stacks, a byproduct of its phosphate/potash operations, are a documented environmental liability.\nWHY IT MATTERS: This is an environmental/regulatory risk rather than a consumer data or contract issue, since Mosaic sells to agricultural distributors and has no individual-consumer relationship.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Mosaic is a B2B crop-nutrients producer with no consumer terms; the only substantive item is a documented environmental liability unrelated to any consumer agreement.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist for this B2B producer; only an environmental liability unrelated to any agreement is noted.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 15/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Mosaic  <-  The Mosaic Company", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 76.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Phosphate and potash crop nutrients sold to agricultural distributors. No consumer relationship. Mosaic's Florida phosphogypsum stacks are a documented environmental liability — again recorded so a blank privacy row is not read as a blank record.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 968, "_entity_id": 1317, "_entity_slug": "mosaic", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Freeport-McMoRan", "Category": "Mining, Crude-Oil Production", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Phoenix", "HQ State": "Arizona", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Arizona' is a non-DMV US state", "Parent / Ultimate Owner": "Freeport-McMoRan Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Arizona Corporation Commission eCorp — ecorp.azcc.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Freeport-McMoRan Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Freeport-McMoRan is a B2B copper/gold miner with no consumer relationship; the tracker links it to electrification demand only as a commodity input, not a data or terms issue.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms or disclosure regime exists; this is a B2B company with no individual-consumer relationship.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 17/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Freeport-McMoRan  <-  Freeport-McMoRan Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 83.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Copper and gold mining. No consumer relationship. Copper demand from electrification links this company to the utility and EV rows elsewhere in the tracker, but only as a commodity input.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 969, "_entity_id": 1319, "_entity_slug": "freeport-mcmoran", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Newmont", "Category": "Mining, Crude-Oil Production", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Denver", "HQ State": "Colorado", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Colorado' is a non-DMV US state", "Parent / Ultimate Owner": "Newmont Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Colorado SOS Business Search — sos.state.co.us/biz/BusinessEntityCriteria. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Newmont Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Newmont is a B2B gold miner selling into commodity markets, with no consumer relationship or terms; the tracker calls it 'an honest completeness row' with nothing further to flag.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=N; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=N; liabcap=N; contentlic=N; confiscation=N; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms or disclosure regime exists; this is a B2B company with no individual-consumer relationship.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 17/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Newmont  <-  Newmont Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 83.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Gold mining selling into commodity markets. No consumer relationship and no consumer terms. An honest completeness row.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 970, "_entity_id": 1321, "_entity_slug": "newmont", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Owens Corning", "Category": "Building Materials, Glass", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Owens Corning has no direct consumer contract; roofing/insulation warranty claims run through the installer, not the maker\nWHAT THE TERMS SAY: Owens Corning sells building materials to contractors and distributors rather than directly to consumers, so there is no Terms of Service between the company and a homeowner; warranty claims, the most common consumer friction point in this category, run through a dealer network instead of the manufacturer.\nWHY IT MATTERS: A homeowner with a roofing or insulation problem must resolve it with the installer rather than Owens Corning directly, adding a layer to getting a warranty issue addressed.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Row is B2B with no direct consumer Terms of Service; only the warranty/dealer-network structural note in the SCARY field is substantive enough to report.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer disclosure regime exists because Owens Corning has no direct consumer contract.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Owens Corning  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Insulation, roofing and composites sold through building products distribution to contractors. Homeowners encounter the brand on a roof or in an attic but contract with the installer, so warranty claims — the most common consumer friction in this category — run through a dealer network rather than the manufacturer.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 971, "_entity_id": 1322, "_entity_slug": "owens-corning", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Avery Dennison", "Category": "Packaging, Containers", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "B2B — labels, packaging materials. No consumer-facing products.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mentor", "HQ State": "Ohio", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Ohio' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Avery Dennison's RFID retail tags stay readable after purchase unless a retailer deactivates them\nWHAT THE TERMS SAY: Avery Dennison is a major supplier of RFID inlays used in retail inventory and apparel tagging; the tracker notes these tags remain readable after purchase unless deactivated, though the deployment and deactivation decision belongs to the retailer rather than the label maker.\nWHY IT MATTERS: A purchased garment could still be scanned after leaving the store, though the tracker attributes the deployment decision to retailers rather than to Avery Dennison itself.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Row is B2B with no direct consumer Terms of Service; only the RFID tag-readability note raises a consumer-relevant question, and even that is a retailer deployment decision rather than an Avery Dennison practice.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No direct consumer relationship or disclosure regime; the RFID note flags a third-party retailer decision, not an Avery Dennison practice.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Avery Dennison  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Labelling and functional materials. Worth one specific note: Avery Dennison is a major supplier of RFID inlays used in retail inventory and apparel tagging, and RFID tags embedded in clothing remain readable after purchase unless deactivated — a genuine and rarely discussed consumer privacy question, though the deployment decision belongs to the retailer rather than to the label maker.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 972, "_entity_id": 1323, "_entity_slug": "avery-dennison", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Packaging Corp. of America", "Category": "Packaging, Containers", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[PENDING_LITIGATION · FL-3] Packaging Corp. of America is a co-defendant in the containerboard antitrust litigation\nWHAT THE TERMS SAY: The tracker notes Packaging Corp. of America is a co-defendant in the containerboard antitrust litigation documented in the International Paper row, alongside its core B2B packaging business with no direct consumer relationship.\nWHY IT MATTERS: The tracker records this as an antitrust matter documented in the International Paper row; PCA supplies containerboard and corrugated packaging to commercial customers and the row states no consumer relationship exists.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Row is B2B with no direct consumer Terms of Service; the antitrust co-defendant note is the only substantive item, and full detail is documented in the International Paper row rather than repeated here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer disclosure regime; only a brief cross-referenced litigation note exists for this company.", "Exposure Score (0-100)": 2, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity1+0, litigation+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Packaging Corp. of America  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Containerboard and corrugated packaging for commercial customers, and a co-defendant in the containerboard antitrust litigation noted in the International Paper row. No consumer relationship.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 973, "_entity_id": 1324, "_entity_slug": "packaging-corp-of-america", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Graphic Packaging", "Category": "Packaging, Containers", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Atlanta", "HQ State": "Georgia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Georgia' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Georgia SOS eCorp — ecorp.sos.ga.gov/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no direct consumer Terms of Service and no company-specific privacy, arbitration, fee, or litigation finding is stated; the SCARY note is a generic structural observation about packaging manufacturers rather than a finding specific to Graphic Packaging.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or disclosure regime, and no company-specific finding located.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Graphic Packaging  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Paperboard packaging produced for consumer products companies. The packaging in a shopper's hand is this company's product, but the contract and the data belong to the brand that filled it. No consumer terms exist.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 974, "_entity_id": 1325, "_entity_slug": "graphic-packaging", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Crown", "Category": "Packaging, Containers", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no direct consumer Terms of Service; the only litigation noted (asbestos liability inherited via acquisition) is explicitly flagged in the tracker as unrelated to this tracker's terms/privacy focus, so no consumer-relevant troubling item is reported.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer disclosure regime; the one litigation note is off-topic legacy product-liability exposure, not a terms/privacy finding.", "Exposure Score (0-100)": 2, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity1+0, litigation+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Crown  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Metal cans and closures for beverage and food producers. No consumer relationship. Crown is also a defendant in long-running asbestos liability litigation inherited through acquisition — a legacy exposure unrelated to anything in this tracker's columns.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 975, "_entity_id": 1326, "_entity_slug": "crown", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Berry Global", "Category": "Packaging, Containers", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Evansville", "HQ State": "Indiana", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Indiana SOS INBiz — inbiz.in.gov/BOS/Home/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no direct consumer Terms of Service and no company-specific privacy, arbitration, fee, or litigation finding is stated; the SCARY note is only a generic structural observation about packaging plus a merger mention.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or disclosure regime, and no company-specific finding located.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Berry Global  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Plastic packaging and engineered materials, merging with Amcor. No consumer relationship. As with the other packaging rows, the consumer holds the product and contracts with the brand.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 976, "_entity_id": 1327, "_entity_slug": "berry-global", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ball", "Category": "Packaging, Containers", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no direct consumer Terms of Service; the only note (a 2024 aerospace divestiture creating search-continuity confusion) is an informational aside rather than a consumer privacy, arbitration, fee, or litigation finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or disclosure regime; no company-specific privacy or terms finding exists.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Ball  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Aluminium beverage packaging. Ball sold its aerospace business in 2024 to focus on packaging, so a reader searching its historical defence work will find a company that no longer does it — the same search-continuity problem flagged in the Expand Energy and APA rows.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 977, "_entity_id": 1328, "_entity_slug": "ball", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Westinghouse Air Brake Technologies", "Category": "Industrial Machinery", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B chemicals/materials/mining company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "This company manufactures industrial chemicals, raw materials, packaging components, or mined commodities sold to OTHER MANUFACTURERS rather than individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to. (Corning is a partial exception — while its Gorilla Glass and other materials reach consumers embedded in phones/cookware, Corning itself has no direct consumer account relationship for these components.)", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no direct consumer Terms of Service; the tracker states Wabtec holds no consumer data, so despite its role in rail-transit safety infrastructure there is no data-sharing, arbitration, fee, or litigation finding to report.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship, no data held, and no disclosure regime applicable to this company's rail-safety business.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Westinghouse Air Brake Technologies  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Wabtec makes rail braking, control and monitoring systems sold to freight railroads and transit agencies — including the systems behind positive train control. It holds no consumer data, but its equipment governs passenger safety on transit systems many people in this tracker's region use daily, under FRA regulation rather than any consumer contract.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Chemicals & Materials", "_row_id": 978, "_entity_id": 1329, "_entity_slug": "westinghouse-air-brake-technologies", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Walt Disney", "Category": "Entertainment", "Terms & Conditions URL": "disneytermsofuse.com", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "disneyprivacycenter.com", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "MAJOR, VERY RECENT BIOMETRIC LAWSUIT (filed May 2026): alleges Disney secretly deployed FACIAL RECOGNITION technology at Disneyland/California Adventure park ENTRANCES (starting April 28, 2026) to prevent ticket fraud/re-entry — converting visitors' faces into numerical codes matched against photos taken at ticket purchase, WITHOUT clear consent, including children's biometric data. Disney claims participation is 'optional' via alternative lanes marked with a silhouette-and-slash icon, but the lawsuit argues this signage is 'unclear and easy to miss,' preventing meaningful informed consent — especially given Disney ALSO collects biometric data elsewhere in its parks (fingerprints for 'MagicBand' access, facial images via the 'Disney PhotoPass' program). The complaint specifically questions Disney's 30-day retention claim as 'illogical' since the same facial data is compared against ticket/annual-pass purchases that remain active far longer than 30 days, and references Disney's own 2024 'massive data breach' as evidence of the ongoing hacking risk this biometric database represents. SEPARATELY, Disney is already documented elsewhere in this tracker (Consumer Apps tab) for its $10 MILLION FTC COPPA SETTLEMENT (finalized Dec 2025) over mislabeling children's YouTube videos to enable improper ad-targeting data collection.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass for park-admission Terms of Use specifically — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "GIVEN DISNEY'S ENORMOUS CONSUMER REACH (tens of millions of theme-park visitors annually, plus streaming/media properties), the facial-recognition finding is arguably one of the most directly relevant biometric-privacy findings in this ENTIRE 800+ company tracker — worth flagging prominently given how many families visit Disney parks specifically WITH children, the population the lawsuit specifically highlights as inadequately protected by the current opt-out signage.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] Disney allegedly deployed park-entrance facial recognition without clear consent, including on children\nWHAT THE TERMS SAY: A May 2026 lawsuit alleges Disney secretly deployed facial recognition at Disneyland/California Adventure entrances starting April 28, 2026, converting visitors' faces into numeric codes matched against ticket-purchase photos without clear consent; Disney says an opt-out lane exists but the suit calls its signage unclear and easy to miss, and disputes Disney's 30-day retention claim as inconsistent with active ticket/annual-pass records.\nWHY IT MATTERS: Families, including those with children, may be biometrically scanned at park entry without realizing an alternative existed, and the stated 30-day retention window is itself contested as inconsistent with how long the matched purchase data stays active.\n(evidence: Data Sharing/Selling Flags; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[REGULATORY_PENALTY · FL-2] Disney paid a $10 million FTC settlement for mislabeling kids' YouTube videos to enable ad-targeting\nWHAT THE TERMS SAY: The tracker states Disney reached a $10 million FTC COPPA settlement, finalized December 2025, over mislabeling children's YouTube videos in a way that enabled improper ad-targeting data collection.\nWHY IT MATTERS: Children's viewing data was used to enable targeted advertising in violation of federal child-privacy law, a confirmed and finalized regulatory finding.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[LOCATION_TRACKING · FL-2] Disney's MagicBand and finger-geometry entry systems build a continuous in-park location trace\nWHAT THE TERMS SAY: The tracker notes Disney has used finger-geometry scanning at park entry for years, and its MagicBand and app systems generate a continuous in-park location trace tied to a named family; Disney separately collects facial images through its PhotoPass program.\nWHY IT MATTERS: A family's in-park movements are continuously logged and tied to a named family, and the tracker notes the same entry and payment systems are collecting biometric identifiers from minors.\n(evidence: SCARY; Stated in tracker (fidelity pass 1: Overstated corrected) (fidelity pass 2 (strict): Overstated corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=Y; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Substantial biometric and breach history is documented, but the central facial-recognition claims are still allegations and arbitration/fee terms remain unconfirmed.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 18, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 18/30 (data_sold_or_shared_for_value+8, biometric_collection+6, precise_location_tracking+4) | Contract 0/20 (none) | Record 16/20 (severity3+8, breach+3, penalty+3, litigation+2) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nBIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Walt Disney  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (10 of 13): your content used as AI training data; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Walt Disney you gave up your personal data sold onward, your biometric identifiers, and your physical movements. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The May 2026 biometric lawsuit is the current finding, and Disney occupies an unusual position in this tracker because its customer base is disproportionately families with young children - which means facial and fingerprint systems deployed for park entry and payment convenience are collecting biometric identifiers from minors. Disney parks have used finger-geometry scanning at entry for years, and MagicBand and app systems generate a continuous in-park location trace tied to a named family. Cross-ref the ESPN+ row in Home Security & Entertainment for the streaming side. Allegations, not findings.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Entertainment & Leisure", "_row_id": 979, "_entity_id": 1330, "_entity_slug": "walt-disney", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Warner Bros. Discovery (Max/HBO)", "Category": "Entertainment", "Terms & Conditions URL": "See the Max/HBO Max row (Home Security & Entertainment tab) for the streaming-service-specific entry", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "See Max row for privacy policy details", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "This is the CORPORATE PARENT of Max/HBO Max, already documented in the Home Security & Entertainment tab — no additional corporate-level finding independently confirmed this pass beyond what's noted there.", "Arbitration / Class Action Waiver": "Same as Max/HBO Max row.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Max (HBO Max) row (Home Security & Entertainment tab) for the primary consumer-facing streaming service under this same corporate parent.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] WBD's repeated streaming reorganizations move subscriber data between corporate entities without new consent\nWHAT THE TERMS SAY: The tracker notes Warner Bros. Discovery has repeatedly restructured, spun off, and renamed its streaming products, and each reorganization moves subscriber data between corporate entities without obtaining a new consent.\nWHY IT MATTERS: A subscriber's data can end up controlled by a different corporate entity than the one they originally signed up with, with no additional opt-in required.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — This row largely refers to the Max/HBO Max row for the full corporate finding; only the data-shifting-on-reorganization point is a new, company-specific fact stated here, and the Video Privacy Protection Act note is general industry context rather than a specific WBD practice.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row largely defers to the Max/HBO Max row for confirmed detail; fees and arbitration are not itemized here.", "Exposure Score (0-100)": 17, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 5/20 (unilateral_modification+5) | Record 8/20 (severity3+8) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Warner Bros. Discovery (Max/HBO)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Warner Bros. Discovery (Max/HBO) you gave up your data shared corporate-wide and your right to be consulted before terms change. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Corporate parent of Max, documented elsewhere in this tracker. The parent-level note worth recording is that streaming services sit squarely within the Video Privacy Protection Act, which provides statutory damages without proof of harm - the reason this category generates so much litigation. WBD has also repeatedly restructured, spun off and renamed its streaming products, and each reorganisation moves subscriber data between corporate entities without a new consent.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Entertainment & Leisure", "_row_id": 980, "_entity_id": 1331, "_entity_slug": "warner-bros-discovery-max-hbo", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fox Corporation", "Category": "Entertainment", "Terms & Conditions URL": "fox.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "fox.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach for Fox's own streaming/digital properties; note Fox Corporation (broadcast/cable/Tubi) is a SEPARATE company from 21st Century Fox's former film studio assets (now part of Disney) following a 2019 corporate split.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, particularly checking Fox's free ad-supported streaming service Tubi for any tracking-technology litigation similar to that documented for other streaming services throughout this tracker.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Fox's news-site reading data forms a political profile with no meaningful consent step\nWHAT THE TERMS SAY: Fox's consumer data relationship runs through its streaming apps and website tracking; the tracker notes ordinary browsing on Fox's news properties generates a political-profile inference with no consent step that would make it legible to the reader.\nWHY IT MATTERS: Political-viewing inferences are an especially sensitive data category, and consumers have no clear way to see or control the profile being built from ordinary browsing.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No company-specific breach, lawsuit, or clause is confirmed this pass for Fox; the row itself says verification is thin, so only the general political-profiling risk noted in the SCARY field is reported.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed this pass; the row itself flags thin verification and recommends follow-up.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Fox Corporation  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Fox Corporation takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Fox operates broadcast, cable news and sports properties, and the consumer data relationship runs through streaming apps and website tracking rather than through broadcast itself. News site reading data is a political profile - the most sensitive inference category in this tracker outside health - and it is generated by ordinary browsing with no consent step that would make it legible. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Entertainment & Leisure", "_row_id": 981, "_entity_id": 321, "_entity_slug": "fox-corporation", "_issuer": "Fox Corporation", "_issuer_slug": "fox-corporation", "_ticker": "FOXA", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Live Nation Entertainment", "Category": "Entertainment", "Terms & Conditions URL": "See the Ticketmaster/Live Nation row (Consumer Apps tab)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "See Ticketmaster/Live Nation row for privacy policy details", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "This is the SAME company already extensively documented in the Ticketmaster/Live Nation row (Consumer Apps tab), including the April 2026 federal jury verdict finding Live Nation/Ticketmaster illegally monopolized the live entertainment market and the 'robbing them blind' internal-communications finding — no additional finding to add here.", "Arbitration / Class Action Waiver": "See Ticketmaster/Live Nation row.", "Fees / Billing Flags": "See Ticketmaster/Live Nation row.", "Notes": "See the Ticketmaster/Live Nation row (Consumer Apps tab) for the full, extensively-documented findings already captured for this company.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Live Nation/Ticketmaster's 2024 Snowflake-linked breach reached a very large number of ticket buyers\nWHAT THE TERMS SAY: The tracker states the 2024 Snowflake-linked breach reached a very large number of Live Nation/Ticketmaster ticket buyers; the full detail is documented in the Ticketmaster/Live Nation row (Consumer Apps tab).\nWHY IT MATTERS: A very large number of ticket buyers were caught in the 2024 Snowflake-linked breach, which the row records as its data-breach finding.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[OTHER · FL-3] Live Nation's dominance of promotion and ticketing means concertgoers generally can't avoid the relationship\nWHAT THE TERMS SAY: The tracker notes Live Nation's combined dominance of concert promotion and ticketing means a concertgoer generally cannot avoid the relationship to attend a show, removing the market-based check that would normally let consumers choose a different provider.\nWHY IT MATTERS: Without a practical alternative, consumers can't opt out of Live Nation's data practices or contract terms even if they object to them.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[PENDING_LITIGATION · FL-3] Live Nation is the subject of a DOJ antitrust action over its market dominance\nWHAT THE TERMS SAY: The tracker notes Live Nation is the subject of a Department of Justice antitrust action, which it characterizes as a competition finding rather than a privacy one.\nWHY IT MATTERS: The antitrust case reinforces the market-power concern above, though it does not itself concern data or terms practices.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach and antitrust action are confirmed, but arbitration and fee terms are not stated in this row and instead point to the Ticketmaster/Live Nation row.", "Exposure Score (0-100)": 13, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 13/20 (severity3+8, breach+3, litigation+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Live Nation Entertainment  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Live Nation Entertainment takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same company already documented extensively in the Ticketmaster rows. The short version: the 2024 Snowflake-linked breach reached a very large number of ticket buyers, and Live Nation's dominance of both promotion and ticketing means a concertgoer generally cannot avoid the relationship if they want to attend the show - which removes the market response consumer protection assumes exists. Live Nation is also the subject of a Department of Justice antitrust action, which is a competition finding rather than a privacy one.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Entertainment & Leisure", "_row_id": 982, "_entity_id": 1332, "_entity_slug": "live-nation-entertainment", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "MGM Resorts International", "Category": "Hotels, Casinos, Resorts", "Terms & Conditions URL": "mgmresorts.com/en/terms-of-use.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "mgmresorts.com/en/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "TWO SEPARATE MAJOR BREACHES, NOW FULLY SETTLED: (1) A 2019 breach exposed personal information of approximately 10.6 MILLION guests — including celebrities and business leaders — with stolen data later appearing on public hacking forums. (2) A SEPARATE, more disruptive September 2023 attack (attributed to the Scattered Spider/ALPHV threat actors, the same group later linked to the Qantas/Hawaiian Airlines/WestJet cluster and Erie Insurance documented elsewhere in this tracker) encrypted portions of MGM's data infrastructure via ransomware, disrupting hotel reservations, slot machines, and payment processing across MGM's Las Vegas properties (Bellagio, Mandalay Bay, MGM Grand, Aria, Cosmopolitan, Vdara) for DAYS — MGM's stock fell over 4% following disclosure. Both incidents were consolidated into ONE federal class action, resulting in a $45 MILLION SETTLEMENT (final approval June 18, 2025) — offering reimbursement up to $15,000 for documented losses plus one year of financial-account monitoring; cash payments were distributed starting Dec 12, 2025. Notably, MGM REFUSED to pay the 2023 ransom demand (unlike Caesars, this same tab, which reportedly did pay) — plaintiffs argue MGM's refusal, despite advance industry warnings about the same threat actor targeting Caesars weeks earlier, directly contributed to the customer data exposure that followed.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual guest/loyalty-program agreements, separate from this specific completed settlement.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The MGM-vs-Caesars contrast (one refused to pay ransom and faced prolonged data exposure/operational disruption, the other reportedly paid and avoided broader disclosure) is a genuinely instructive real-world illustration of the difficult trade-offs companies face during ransomware incidents — worth flagging both approaches without endorsing either, since paying ransoms is itself ethically and legally contested.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] MGM's 2019 breach (~10.6M guests) and 2023 ransomware attack settled together for $45M\nWHAT THE TERMS SAY: A 2019 breach exposed personal data of about 10.6 million MGM guests, later posted on hacking forums; a separate September 2023 ransomware attack (Scattered Spider/ALPHV) encrypted MGM systems and disrupted reservations, slot machines, and payments for days. Both were consolidated into one federal class action settled for $45 million (final approval June 18, 2025), offering up to $15,000 per documented loss plus one year of financial-account monitoring, with payments starting December 12, 2025.\nWHY IT MATTERS: Guests can claim documented-loss reimbursement and monitoring, but the underlying data, including celebrities' and executives' information, was already circulating on hacking forums before the settlement resolved.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity pass 1: Overstated corrected) (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] MGM's casino loyalty program tracks gambling volume and patterns, a financial-behavior dataset\nWHAT THE TERMS SAY: The tracker notes casino loyalty programs, including MGM's, track gambling volume and patterns, financial-behavior data with obvious potential for harm to people with gambling problems.\nWHY IT MATTERS: This behavioral data carries particular risk for consumers vulnerable to problem gambling if exposed or misused.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The 2019/2023 breach-and-settlement story and the casino loyalty gambling-data risk are the two distinct harms this row states; no arbitration or fee detail is confirmed here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach and settlement are thoroughly confirmed, but arbitration and fee terms for the underlying guest/loyalty agreements are not confirmed this pass.", "Exposure Score (0-100)": 14, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "MGM Resorts International  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, MGM Resorts International takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Two separate major breaches, now settled - and the 2023 incident is the most instructive social-engineering case in this tracker after the Salesforce campaign: attackers reportedly used publicly available employee information and a phone call to a help desk to obtain access, taking down slot machines, hotel key cards, reservation systems and ATMs across MGM properties. Casinos also hold an unusually sensitive dataset - loyalty programmes track gambling volume and patterns, which is financial-behaviour data with obvious potential for harm to people with gambling problems.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Entertainment & Leisure", "_row_id": 983, "_entity_id": 1333, "_entity_slug": "mgm-resorts-international", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Caesars Entertainment", "Category": "Hotels, Casinos, Resorts", "Terms & Conditions URL": "caesars.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "caesars.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "CONFIRMED 2023 BREACH via SOCIAL ENGINEERING (a social-media-account-focused attack, occurring weeks before the related MGM Resorts attack documented in this same tab, both attributed to the Scattered Spider/ALPHV threat actors): hackers stole Caesars' REWARDS-PROGRAM MEMBER DATABASE. Unlike MGM, Caesars REPORTEDLY PAID A RANSOM to the attackers specifically to protect customer data from being publicly leaked — a real-world illustration of the 'pay to avoid disclosure' strategy, in contrast to MGM's refusal (documented in that row) which led to a more prolonged, publicly visible operational disruption. The Nevada Gaming Control Board and Nevada's governor were reported to be actively monitoring the situation given the coordinated, industry-targeted nature of both attacks.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual guest/rewards-program agreements.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the MGM Resorts row (this same tab) for the direct comparison between the two companies' different responses to the SAME coordinated attack campaign — worth reading both rows together as one connected story about the Las Vegas hospitality industry's 2023 security crisis.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Caesars' 2023 breach exposed Social Security and driver's license numbers from its Rewards database\nWHAT THE TERMS SAY: Caesars was breached in 2023 through social engineering of an outsourced IT support vendor; the exposed Caesars Rewards loyalty database included driver's license and Social Security numbers for a large number of members. Caesars reportedly paid a ransom to keep the data from being publicly leaked.\nWHY IT MATTERS: Exposure of SSNs and driver's license numbers creates identity-theft risk for affected members, and paying the ransom doesn't guarantee the data wasn't already copied or won't surface later.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Caesars Rewards loyalty data is, in the tracker's words, a gambling-behaviour record\nWHAT THE TERMS SAY: The tracker states the Caesars Rewards database exposed in the 2023 incident contained loyalty data including driver's licence and Social Security numbers for a large number of members, and that casino loyalty data is a gambling-behaviour record.\nWHY IT MATTERS: Beyond the identity-theft exposure from driver's licence and Social Security numbers, the tracker classes the exposed loyalty data itself as a record of gambling behaviour.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The breach/ransom-payment story and the gambling-behavior-data structural risk are the two distinct harms this row states; no arbitration, fee, or additional litigation detail is confirmed here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach and exposed data types are confirmed, but arbitration and fee terms for guest/rewards agreements are not confirmed this pass.", "Exposure Score (0-100)": 8, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Caesars Entertainment  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Caesars Entertainment takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Caesars was breached in 2023 through social engineering of an outsourced IT support vendor, and reporting indicates Caesars paid a substantial ransom while MGM did not - two competitors, same period, same technique, opposite decisions, and neither set of customers had any say. The Caesars Rewards database exposed in that incident contained loyalty data including driver's licence and Social Security numbers for a large number of members. Casino loyalty data is a gambling-behaviour record.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Entertainment & Leisure", "_row_id": 984, "_entity_id": 1334, "_entity_slug": "caesars-entertainment", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Las Vegas Sands", "Category": "Hotels, Casinos, Resorts", "Terms & Conditions URL": "sands.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "sands.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a company-specific breach or lawsuit; recommend checking against the same Scattered Spider/ALPHV Las Vegas hospitality-industry attack campaign documented for MGM Resorts and Caesars Entertainment (this same tab), given the shared geographic/industry exposure.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See MGM Resorts and Caesars Entertainment rows (this same tab) for the well-documented 2023 Las Vegas casino-industry attack campaign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Las Vegas Sands suffered a historical state-attributed cyberattack aimed at destroying systems, not stealing data\nWHAT THE TERMS SAY: The tracker states Las Vegas Sands historically experienced a destructive, state-attributed cyberattack aimed at damaging systems rather than stealing data, a different category from most breaches in this tracker that involve data taken for resale.\nWHY IT MATTERS: Even without reported data theft, systems being deliberately damaged by a nation-state-attributed actor shows a distinct risk profile from typical financially-motivated breaches.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Sands' casino loyalty programs hold gambling-behavior data with elevated harm potential\nWHAT THE TERMS SAY: The tracker notes casino loyalty programs anywhere, including Sands', hold gambling volume and pattern data, financial-behavior information with potential for harm to people with gambling problems.\nWHY IT MATTERS: This behavioral data carries particular risk for problem gamblers if exposed, though no Sands-specific breach of this data is confirmed this pass.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No company-specific 2023-era breach or lawsuit is confirmed this pass for Sands, only a historical destructive cyberattack and a generic casino-loyalty-data risk; Sands also sold its Las Vegas properties, so current US consumer exposure is limited.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No company-specific breach or lawsuit is confirmed this pass, and US consumer exposure is now largely historical since Sands sold its Las Vegas properties.", "Exposure Score (0-100)": 11, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Las Vegas Sands  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Las Vegas Sands takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Sands sold its Las Vegas properties and now operates primarily in Macau and Singapore, so a US consumer's exposure is largely historical. Historically it experienced a destructive state-attributed cyberattack aimed at damaging systems rather than stealing data — a category distinction worth preserving, since most findings in this tracker involve data taken for resale. Casino loyalty programmes anywhere hold gambling volume and pattern data, which is financial-behaviour information with obvious potential for harm to people with gambling problems.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Entertainment & Leisure", "_row_id": 985, "_entity_id": 1335, "_entity_slug": "las-vegas-sands", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Lululemon athletica", "Category": "Specialty Retailers: Apparel", "Terms & Conditions URL": "shop.lululemon.com/help/legal/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "shop.lululemon.com/help/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] Lululemon's app ties studio location and class attendance to purchase history\nWHAT THE TERMS SAY: The Lululemon app and membership programme collect workout data, class attendance, and studio location alongside purchase history, per the tracker, the same fitness-adjacent inference surface as gym apps but held by a retailer rather than a gym.\nWHY IT MATTERS: Combining location and behavioral fitness data with purchase history builds a detailed profile of a person's routines and whereabouts.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Lululemon's apparel size history carries unprotected body-measurement inference\nWHAT THE TERMS SAY: The tracker notes apparel size history carries body-measurement inference, which is health-adjacent and entirely unprotected data.\nWHY IT MATTERS: Body-measurement inferences drawn from size history are sensitive but fall outside typical health-privacy protections, leaving them without special safeguards.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[RETENTION_PERIOD · FL-2] What happened to Mirror's camera and biometric data after Lululemon shut the product down is unresolved\nWHAT THE TERMS SAY: Lululemon acquired and then shut down Mirror, a connected home-fitness device with camera and biometric capability; the tracker flags that product's data disposition on shutdown as an open follow-up item, not yet confirmed.\nWHY IT MATTERS: Users of a discontinued camera/biometric device may not know what happened to data already collected, and the tracker hasn't yet confirmed the answer.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Some fitness/location/purchase data practices are described concretely, but the shut-down Mirror device's data disposition remains an open, unconfirmed follow-up.", "Exposure Score (0-100)": 19, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 4, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 13/30 (biometric_collection+6, precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 4/20 (termination_or_confiscation+4) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRICS → MD: sensitive data — sale BANNED outright, opt-in consent to collect (MODPA); VA: opt-in consent required (VCDPA); DC: biometric data is covered by the breach-notice law only\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "App / Service", "Ownership Path": "Lululemon athletica  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Lululemon athletica you gave up your biometric identifiers, your physical movements, and your right to keep what you paid for. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The Lululemon app and membership programme collect workout data, class attendance and studio location alongside purchase history — the same fitness-adjacent inference surface documented across the gym rows, held by a retailer rather than a gym. Apparel size history also carries body-measurement inference, which is health-adjacent and entirely unprotected. Lululemon acquired and then shut down Mirror, the connected home fitness device, which had camera and biometric capability; that product's data disposition on shutdown is worth a follow-up.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Entertainment & Leisure", "_row_id": 986, "_entity_id": 1336, "_entity_slug": "lululemon-athletica", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ross Stores", "Category": "Specialty Retailers: Apparel", "Terms & Conditions URL": "See the Ross Dress for Less row (Retail & Fintech tab)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "See Ross Dress for Less row for privacy policy details", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "This is the SAME company already documented in the Ross Dress for Less row (Retail & Fintech tab) — no additional finding to add here.", "Arbitration / Class Action Waiver": "See Ross Dress for Less row.", "Fees / Billing Flags": "See Ross Dress for Less row.", "Notes": "See the Ross Dress for Less row (Retail & Fintech tab) for the entry already captured for this company.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Off-price retail's non-loyalty advantage is offset by in-store Wi-Fi and camera analytics with no notice\nWHAT THE TERMS SAY: The tracker notes off-price retailers like Ross benefit from a low share of loyalty-program enrollment, limiting identified data collection, but this is offset by in-store Wi-Fi and camera analytics that measure shoppers who never identified themselves and never saw a notice.\nWHY IT MATTERS: On the tracker's structural point, in-store Wi-Fi and camera analytics measure shoppers who never identified themselves and never saw a notice; the primary assessment sits in the Ross Dress for Less row (Retail & Fintech tab).\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — This row largely refers to the Ross Dress for Less row (Retail & Fintech tab) for the full assessment; only the in-store Wi-Fi/camera-analytics structural note is a distinct, row-specific fact stated here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Row defers to the Ross Dress for Less row for confirmed detail; only a general structural note about in-store tracking is stated here.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "App / Service", "Ownership Path": "Ross Stores  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Ross Stores takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "See the Ross Dress for Less row in Retail & Fintech for the primary assessment. The structural point worth repeating: off-price retail's high share of non-loyalty transactions is a real if incidental privacy advantage, offset by in-store Wi-Fi and camera analytics that measure shoppers who never identified themselves and never saw a notice.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Entertainment & Leisure", "_row_id": 987, "_entity_id": 1337, "_entity_slug": "ross-stores", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Keurig Dr Pepper", "Category": "Beverages", "Terms & Conditions URL": "keurigdrpepper.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "keurigdrpepper.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach; Keurig specifically sells CONNECTED COFFEE MAKERS with companion apps — a distinctive consumer-electronics/IoT product category for a beverage company — worth checking that app's specific data practices given the smart-home-device privacy concerns documented for other connected products throughout this tracker.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass, specifically on the Keurig smart coffee maker companion app.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[REGULATORY_PENALTY · FL-1] Keurig settled FTC allegations over recyclability claims for its K-Cup pods\nWHAT THE TERMS SAY: The tracker states Keurig settled FTC allegations over recyclability claims for K-Cup pods.\nWHY IT MATTERS: The tracker lists this among the more substantiated consumer issues for Keurig, though it is historical and the recyclability claims were settled allegations rather than adjudicated findings.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[OTHER · FL-4] Keurig faced antitrust litigation over lockout technology blocking rival K-Cup pods\nWHAT THE TERMS SAY: The tracker notes Keurig separately faced antitrust litigation over lockout technology designed to block competitors' pods from working in its machines, the same razor-and-blade lock-in the tracker describes in the John Deere repair row, applied to coffee.\nWHY IT MATTERS: Lockout technology can force consumers who already bought a Keurig machine to keep buying Keurig-brand pods rather than a cheaper or preferred competitor's pod.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] Keurig's connected brewers and auto-delivery subscriptions tie consumption patterns to an account\nWHAT THE TERMS SAY: The tracker notes Keurig sells connected coffee makers with companion apps, and that connected brewers plus subscription auto-delivery tie consumption patterns and household routine to an account, a distinctive IoT data surface for a beverage company the tracker recommends following up on directly.\nWHY IT MATTERS: Detailed household consumption and routine data accumulates in an account whose specific handling practices the tracker has not yet independently verified.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The FTC settlement and antitrust lockout litigation are stated as historical fact, but the connected-brewer app's current data practices are explicitly unconfirmed and flagged for follow-up.", "Exposure Score (0-100)": 19, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nAUTO-RENEWAL / FEES → Route through each state's general consumer-protection act (MD CPA, VA CPA, DC CPPA) rather than the privacy statutes", "Entity Type": "Company", "Ownership Path": "Keurig Dr Pepper  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Keurig Dr Pepper you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Connected brewers and subscription auto-delivery tie consumption patterns and household routine to an account. The more substantiated consumer issues are historical: Keurig settled FTC allegations over recyclability claims for K-Cup pods, and separately faced antitrust litigation over lockout technology designed to block competitors' pods from its machines — the same razor-and-blade lock-in the John Deere repair row describes, applied to coffee.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Entertainment & Leisure", "_row_id": 988, "_entity_id": 1338, "_entity_slug": "keurig-dr-pepper", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Charter Communications (Spectrum)", "Category": "Telecommunications", "Terms & Conditions URL": "See Charter Spectrum row (Internet Providers tab)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "See Charter Spectrum row for privacy policy details", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "This is the SAME company already documented in the Charter Spectrum row (Internet Providers tab), recently UPDATED with a major April/May 2026 ShinyHunters breach affecting 13-42 million records — no additional finding to add here.", "Arbitration / Class Action Waiver": "See Charter Spectrum row.", "Fees / Billing Flags": "See Charter Spectrum row.", "Notes": "See the Charter Spectrum row (Internet Providers tab) for the full corporate-level finding, including the significant 2026 breach.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] FTC's 6(b) study of six ISPs, Charter among them, found sorting of customers by race, orientation\nWHAT THE TERMS SAY: The tracker notes Charter Spectrum is one of six ISPs the FTC compelled records from under 6(b) orders, and that the study's findings included sorting customers into sensitive categories such as race and sexual orientation — the source does not confirm this practice was Charter's specifically as opposed to a finding across the six-ISP study collectively.\nWHY IT MATTERS: Categorizing customers by race or sexual orientation creates a real risk of discriminatory targeting or exposure of characteristics customers never chose to disclose in that context.\n(evidence: SCARY; Stated in tracker (fidelity pass 1: Cross-ref leak corrected))", "Top Troubling #2": "[CONFIRMED_BREACH · FL-2] Charter Spectrum's April/May 2026 ShinyHunters breach affected 13-42 million records\nWHAT THE TERMS SAY: The tracker states Charter Spectrum was recently updated with a major April/May 2026 breach attributed to ShinyHunters, affecting between 13 and 42 million records; full detail is in the Charter Spectrum row (Internet Providers tab).\nWHY IT MATTERS: The tracker records the breach as affecting between 13 and 42 million records and points to the Charter Spectrum row (Internet Providers tab) for the full corporate-level finding.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[LOCATION_TRACKING · FL-2] FTC's 6(b) study of six ISPs, including Charter, found real-time location shared with third parties\nWHAT THE TERMS SAY: The tracker notes the same FTC 6(b) study — covering Charter Spectrum as one of six ISPs studied — found that real-time location data was shared with third parties; the source does not confirm this was Charter's own practice specifically rather than a finding across the six-ISP study.\nWHY IT MATTERS: Real-time location sharing with outside parties means a customer's whereabouts can be tracked by companies beyond their ISP, not necessarily obvious to the customer.\n(evidence: SCARY; Stated in tracker (fidelity pass 1: Cross-ref leak corrected))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The FTC 6(b) findings and 2026 breach are both confirmed and specific, but this row defers to the Charter Spectrum row for full detail and doesn't itemize arbitration or fees.", "Exposure Score (0-100)": 16, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 11, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 11/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 5/20 (severity2+2, breach+3) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Charter Communications (Spectrum)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Charter Communications (Spectrum) you gave up your physical movements and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same company documented in the Charter Spectrum row of Internet Providers - one of six ISPs the FTC compelled records from under 6(b) orders, whose findings included sorting customers into sensitive categories by race and sexual orientation and sharing real-time location with third parties. Recorded here as a cross-reference rather than re-researched.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Telecom & Consumer Svc", "_row_id": 989, "_entity_id": 1339, "_entity_slug": "charter-communications-spectrum", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Lumen Technologies", "Category": "Telecommunications", "Terms & Conditions URL": "See Lumen Technologies's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Lumen Technologies's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-2] Lumen's backbone network sees a huge share of internet traffic but sits almost entirely outside consumer privacy law\nWHAT THE TERMS SAY: The tracker states Lumen operates backbone network infrastructure carrying a large share of internet traffic; because backbone operators have no direct consumer relationship, they are almost entirely outside consumer privacy law, which the tracker itself calls out as the finding.\nWHY IT MATTERS: A company positioned to observe enormous volumes of internet traffic is not subject to the disclosure and consent rules that apply to consumer-facing services, leaving a regulatory gap.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Nothing consumer-facing is confirmed this pass for Lumen; the only substantive point is the structural observation that backbone network operators fall outside consumer privacy law entirely, which is itself the row's stated finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing consumer-facing is confirmed this pass, and the backbone business itself has no consumer disclosure regime by design.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Lumen Technologies  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Lumen Technologies takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass. Lumen operates backbone network infrastructure carrying a large share of internet traffic, plus the CenturyLink and Quantum Fiber consumer brands documented in the Internet Providers tab. Backbone operators occupy the most privileged observation position in the entire internet, above any individual ISP, and are almost entirely outside consumer privacy law because they have no consumer relationship. That gap is the finding.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Telecom & Consumer Svc", "_row_id": 990, "_entity_id": 1340, "_entity_slug": "lumen-technologies", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Motorola Solutions", "Category": "Network and Other Communications Equipment", "Terms & Conditions URL": "See Motorola Solutions's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Motorola Solutions's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Chicago", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Motorola Solutions, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Motorola Solutions, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[BIOMETRICS · FL-2] Motorola's police tech processes data of non-customers who did not consent and generally can't find out\nWHAT THE TERMS SAY: Motorola Solutions sells public safety technology — police radio systems, body cameras, license plate recognition and video analytics — to government agencies rather than to individual consumers.\nWHY IT MATTERS: The people whose data these systems collect are members of the public, not Motorola's customers, so they never consented and generally cannot find out what is held about them.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data Sharing, Arbitration, and Fees fields are all unconfirmed this pass ('Not independently confirmed' / 'Not itemized'); only the SCARY entry — a structural note about non-consenting-public surveillance — is substantive, and it describes a single distinct issue rather than three.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer-facing terms exist for the people whose data is collected, and the tracker states they generally cannot find out what is held.", "Exposure Score (0-100)": 12, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 10/30 (biometric_collection+6, precise_location_tracking+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Motorola Solutions  <-  Motorola Solutions, Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass, and the honest entry here is more interesting than a null: Motorola Solutions sells public safety technology - police radio systems, body cameras, licence plate recognition and video analytics - to government agencies. The people whose data it processes are members of the public who are not customers, did not consent and generally cannot find out what is held. Recommend treating this as a civil-liberties row rather than a consumer terms row in any future analysis.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Telecom & Consumer Svc", "_row_id": 991, "_entity_id": 1342, "_entity_slug": "motorola-solutions", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Altria", "Category": "Tobacco", "Terms & Conditions URL": "See Altria's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Altria's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Tracker: nothing confirmed for Altria; tobacco companies' age-verified marketing collects ID documents\nWHAT THE TERMS SAY: Nothing confirmed this pass for Altria. The tracker records that tobacco companies operate age-verified direct marketing programmes that collect identity documents and build detailed consumer databases — a category with heavy regulatory history under the tobacco Master Settlement Agreement's marketing restrictions. Altria also held a substantial stake in JUUL, whose marketing to minors produced extensive litigation.\nWHY IT MATTERS: Consumers enrolling in such programmes hand over identity documents that are built into detailed consumer databases, in a category with heavy regulatory history under the tobacco Master Settlement Agreement's marketing restrictions; the tracker records this honestly as a marketing-regulation row rather than a privacy one.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data Sharing, Arbitration, and Fees fields are unconfirmed this pass; the SCARY item describes shared tobacco-industry marketing practice rather than an Altria-specific confirmed incident, and the JUUL litigation mentioned belongs to JUUL's own finding, not this row, so only one item is offered.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No Altria-specific practice is confirmed this pass; only general tobacco-industry context is available.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Altria  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Altria takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Tobacco companies operate age-verified direct marketing programmes that collect identity documents and build detailed consumer databases - a category with heavy regulatory history under the tobacco Master Settlement Agreement's marketing restrictions. Altria also held a substantial stake in JUUL, whose marketing to minors produced extensive litigation. Recorded honestly as a marketing-regulation row rather than a privacy one.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Telecom & Consumer Svc", "_row_id": 992, "_entity_id": 1343, "_entity_slug": "altria", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Philip Morris", "Category": "Tobacco", "Terms & Conditions URL": "See Philip Morris's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Philip Morris's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Philip Morris's connected heated-tobacco devices can transmit usage data on a health behaviour\nWHAT THE TERMS SAY: Newer heated tobacco products register to a user account and can transmit usage data, so a consumption pattern for a health behaviour flows to Philip Morris.\nWHY IT MATTERS: This creates an ongoing behavioural health data stream to the manufacturer that the tracker says has no clear regulatory home.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[OTHER · FL-2] Age-verified tobacco marketing collects ID documents into detailed consumer databases\nWHAT THE TERMS SAY: Age-verified direct marketing collects identity documents and builds detailed consumer databases, a practice with regulatory history under the tobacco Master Settlement Agreement's marketing restrictions.\nWHY IT MATTERS: Consumers verifying their age to purchase hand over identity documents that become part of detailed consumer databases, which the tracker places under the tobacco Master Settlement Agreement's marketing restrictions.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Data Sharing, Arbitration, and Fees fields are all unconfirmed this pass; only two distinct SCARY-derived items are substantive enough to include, with no third distinct harm stated.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing confirmed this pass beyond the SCARY field's device and marketing context.", "Exposure Score (0-100)": 11, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Philip Morris  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Philip Morris takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Age-verified direct marketing collects identity documents and builds detailed consumer databases under the tobacco Master Settlement Agreement's marketing restrictions. The newer exposure is connected devices: heated tobacco products register to a user account and can transmit usage data, so a consumption pattern for a health behaviour flows to the manufacturer — a data category with no clear regulatory home.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Telecom & Consumer Svc", "_row_id": 993, "_entity_id": 1344, "_entity_slug": "philip-morris", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Universal Health Services", "Category": "Health Care: Medical Facilities", "Terms & Conditions URL": "uhsinc.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "uhsinc.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Universal Health Services (UHS) is the PARENT COMPANY of Talkspace, already extensively documented in the Retirement & Telehealth tab of this tracker (following Talkspace's 2026 acquisition by UHS for $835 million) — including the finding that Talkspace's CEO described the company's 8 billion words of therapy-session data as 'one of the largest mental health data banks in the world.' UHS itself operates 119 outpatient and 346 inpatient behavioral health facilities nationally; no additional UHS-corporate-level breach or lawsuit independently confirmed this pass beyond the Talkspace acquisition context.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected for individual patient agreements.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the Talkspace row (Retirement & Telehealth tab) for the fullest treatment of this parent-subsidiary relationship and its significant mental-health-data implications, now that Talkspace's entire data set sits within UHS's broader corporate structure.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "King of Prussia", "HQ State": "Pennsylvania", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): PA Business Entity Search — file.dos.pa.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] UHS ransomware attack knocked hospital IT systems offline, forcing paper patient records\nWHAT THE TERMS SAY: UHS experienced a major ransomware attack that took hospital IT systems offline across its US facilities, forcing clinical staff to paper records — a patient-safety event, not just a data one.\nWHY IT MATTERS: Behavioural health records are the most sensitive category in healthcare and UHS holds them at scale across 119 outpatient and 346 inpatient facilities, so a systems outage of this kind directly affects patient care.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] UHS now owns Talkspace's 8-billion-word therapy data bank after the 2026 acquisition\nWHAT THE TERMS SAY: UHS is the parent company of Talkspace following its 2026 acquisition for $835 million; Talkspace's CEO described the company's 8 billion words of therapy-session data as 'one of the largest mental health data banks in the world,' and that data set now sits within UHS's corporate structure.\nWHY IT MATTERS: A very large volume of sensitive mental-health data is now consolidated under a parent that also runs hundreds of behavioural health facilities directly (fuller treatment in the tracker's Retirement & Telehealth tab).\n(evidence: Data Sharing/Selling Flags | Notes; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and Fees fields are unconfirmed this pass; only two distinct company-level facts (the ransomware incident and the Talkspace data-bank acquisition) are substantive, and no additional UHS-corporate-level breach or lawsuit is independently confirmed beyond those.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The ransomware incident and Talkspace acquisition are stated as fact, but no other UHS-corporate breach or lawsuit is independently confirmed this pass.", "Exposure Score (0-100)": 14, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 11/20 (severity3+8, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Universal Health Services  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Universal Health Services takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "UHS is the parent of Talkspace, whose findings are documented in the Retirement & Telehealth tab and are among the most serious in this tracker. UHS separately operates a large network of inpatient behavioural health facilities and experienced a major ransomware attack that took hospital IT systems offline across its US facilities, forcing clinical staff to paper records - a patient-safety event rather than only a data one. Behavioural health records are the most sensitive category in healthcare and UHS holds them at scale.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Telecom & Consumer Svc", "_row_id": 994, "_entity_id": 1345, "_entity_slug": "universal-health-services", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Auto-Owners Insurance", "Category": "Insurance: Property and Casualty (Mutual)", "Terms & Conditions URL": "See Auto-Owners Insurance's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Auto-Owners Insurance's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Auto-Owners' claims files sit across thousands of independent agency systems, not one perimeter\nWHAT THE TERMS SAY: As a mutual insurer distributing exclusively through independent agencies, Auto-Owners' policyholder data — including claims files with photographs, medical records and recorded statements — sits primarily in thousands of small agency systems rather than behind a corporate perimeter.\nWHY IT MATTERS: That distributed-agent security surface is invisible to a policyholder who chooses an insurer based on price, per the tracker (the same structure it notes in the New York Life, Cincinnati Financial and Ameriprise rows).\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data Sharing, Arbitration, and Fees fields are all unconfirmed this pass; only the SCARY structural item is substantive, so a single item is offered rather than padding to three.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing consumer-facing is independently confirmed this pass beyond the structural distribution-model note.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Auto-Owners Insurance  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Auto-Owners Insurance you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Mutual insurer distributing exclusively through independent agencies, which means policyholder data — including claims files with photographs, medical records and recorded statements — sits primarily in thousands of small agency systems rather than behind a corporate perimeter. That distributed-agent surface is the same one documented in the New York Life, Cincinnati Financial and Ameriprise rows, and it is invisible to the policyholder choosing an insurer on price.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Telecom & Consumer Svc", "_row_id": 995, "_entity_id": 1346, "_entity_slug": "auto-owners-insurance", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Mass Mutual", "Category": "Insurance: Life, Health (Mutual)", "Terms & Conditions URL": "See Mass Mutual's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Mass Mutual's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] A MassMutual member's data exposure ran three organizations deep to an undisclosed subcontractor\nWHAT THE TERMS SAY: Via a Cigna vendor relationship, a MassMutual benefit plan member's exposure ran three organisations deep to a subcontractor that was never disclosed by name.\nWHY IT MATTERS: Members cannot know or consent to a subcontractor two layers removed from the insurer they signed up with holding their data.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — This row is flagged by the tracker itself as a cross-tab duplicate under a spelling variant, with the full Cigna-subcontractor finding detailed only in the Life-Health-Dental tab; Arbitration and Fees fields are unconfirmed here, so only one thin item is offered rather than three.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "This entry is a cross-tab duplicate placeholder; full detail sits in another tab.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Mass Mutual  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Mass Mutual you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Duplicate of the MassMutual row in Life-Health-Dental - see that row for the Cigna vendor cross-reference, where a MassMutual benefit plan member's exposure ran three organisations deep to a subcontractor nobody disclosed by name. TRACKER NOTE: this is a confirmed cross-tab duplicate under a spelling variant and should be flagged for the dedup pass described in the project guide.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Telecom & Consumer Svc", "_row_id": 996, "_entity_id": 1347, "_entity_slug": "mass-mutual", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "PNC", "Category": "Commercial Banks", "Terms & Conditions URL": "See PNC's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See PNC's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] GLBA permits more affiliate sharing than PNC customers assume; opt-out mailed once, rarely exercised\nWHAT THE TERMS SAY: As a major regional bank, PNC holds one of the most complete behavioural records that exists about a person; the Gramm-Leach-Bliley framework permits considerably more affiliate sharing than customers assume, with an opt-out mailed once and rarely exercised.\nWHY IT MATTERS: The tracker records nothing confirmed for PNC this pass — unverified rather than clean — but notes the structural point that a bank holds the most complete behavioural record that exists about a person, and that the Gramm-Leach-Bliley framework permits considerably more affiliate sharing than customers assume, with an opt-out mailed once and rarely exercised.\n(evidence: SCARY; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data Sharing, Arbitration, and Fees fields are all explicitly unconfirmed this pass ('Unverified rather than clean'); only the general GLBA affiliate-sharing structural note is available, and it is shared banking-industry context rather than a PNC-specific confirmed incident, so a single item is offered.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Tracker explicitly records this as 'Unverified rather than clean' with nothing PNC-specific confirmed.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "PNC  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using PNC you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. PNC is a major regional bank with substantial Mid-Atlantic presence, and the structural note recorded in the Citizens Financial row applies: a bank holds the most complete behavioural record that exists about a person, and the Gramm-Leach-Bliley framework permits considerably more affiliate sharing than customers assume, with an opt-out mailed once and rarely exercised. Unverified rather than clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Telecom & Consumer Svc", "_row_id": 997, "_entity_id": 1348, "_entity_slug": "pnc", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Blackstone", "Category": "Diversified Financials", "Terms & Conditions URL": "See Blackstone's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Blackstone's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Blackstone's PE ownership puts tenant, pet-sitting and patient data under an investor's horizon\nWHAT THE TERMS SAY: Blackstone holds very large residential real estate and healthcare portfolios; consumer data such as tenant records, pet-sitting access details, and patient files sits inside portfolio companies governed by an asset manager's investment horizon rather than a consumer brand's reputational one.\nWHY IT MATTERS: That is a genuinely different accountability structure for consumer data, and it is invisible to the consumer interacting with what looks like an ordinary landlord, service, or provider.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data Sharing, Arbitration, and Fees fields are unconfirmed at the Blackstone parent level this pass; only the SCARY structural ownership point is substantive, and Rover's own specific findings belong to that company's row (Gig Economy tab), not this one.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed at the Blackstone parent level; the point is structural rather than an itemized practice.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Blackstone  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Blackstone takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass at the parent level, and the finding is what Blackstone owns: it is the parent of Rover, documented in the Gig Economy tab, and holds very large residential real estate and healthcare portfolios. Private equity ownership means consumer data - tenant records, pet-sitting access details, patient files - sits inside portfolio companies governed by an asset manager's investment horizon rather than a consumer brand's reputational one. That is a genuinely different accountability structure and it is invisible to the consumer.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Telecom & Consumer Svc", "_row_id": 998, "_entity_id": 1349, "_entity_slug": "blackstone", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Accenture", "Category": "Information Technology Services", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Accenture operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] Accenture staff abroad can handle consumer data under contracts consumers never see\nWHAT THE TERMS SAY: Accenture builds and operates the systems that hold other companies' customer records; a consumer's data can be handled by Accenture personnel in several countries under a contract the consumer will never see, and no notification obligation attaches to Accenture directly.\nWHY IT MATTERS: If something goes wrong, the consumer has no direct relationship with, visibility into, or notice obligation from the company actually processing their data.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Accenture has no direct consumer relationship or Terms of Service (Arbitration/Fees marked not applicable); only the SCARY infrastructure-exposure point is offered as a single item.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist at all for ordinary people; the row is included only for Fortune 500 completeness.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Accenture  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Global consulting and IT services. Accenture builds and operates the systems that hold other companies' customer records, which places it in the same invisible-infrastructure category as Fiserv and Cognizant: a consumer's data can be handled by Accenture personnel in several countries under a contract the consumer will never see, and no notification obligation attaches to Accenture directly.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Business Services", "_row_id": 999, "_entity_id": 1350, "_entity_slug": "accenture", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Booz Allen Hamilton", "Category": "Information Technology Services", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "B2B/government contractor. DMV-headquartered. Booz Allen's AI/ML practice processes government data under DFARS and agency-specific security requirements. Edward Snowden was a Booz Allen contractor when he disclosed NSA surveillance programs (2013).", "Arbitration / Class Action Waiver": "B2B/government contractor. HQ: McLean, Virginia (DMV). Booz Allen provides management consulting, analytics, and digital solutions to defense, intelligence, and civil agencies. No consumer products.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "McLean", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Virginia' is DC/MD/VA", "Parent / Ultimate Owner": "Booz Allen Hamilton Holding Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Booz Allen Hamilton Holding Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Edward Snowden was a Booz Allen contractor when he disclosed NSA surveillance programs in 2013\nWHAT THE TERMS SAY: Edward Snowden was a Booz Allen contractor when he disclosed NSA surveillance programs in 2013; Booz Allen's AI/ML practice processes government data under DFARS and agency-specific security requirements.\nWHY IT MATTERS: Booz Allen's work includes intelligence and defence systems and its AI/ML practice processes government data under DFARS and agency-specific security requirements, so the individuals whose data passes through its work are members of the public rather than customers — no consent, no notice, no ability to inquire.\n(evidence: Data Sharing/Selling Flags; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[NO_DISCLOSURE_THICK_FOG · FL-4] People affected by Booz Allen's intel work are the public, not customers—no consent, no notice\nWHAT THE TERMS SAY: Booz Allen is a government consulting and technology contractor whose work includes intelligence and defence systems; the individuals whose data passes through this work are members of the public rather than customers, with no consent, no notice, and no ability to inquire.\nWHY IT MATTERS: There is no consumer relationship or disclosure mechanism at all for the people actually affected by this data processing.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Fees and consumer Arbitration terms are not applicable (no consumer products); two distinct structural/historical facts are offered rather than a third, since no additional company-specific consumer-facing item is stated.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; nothing consumer-facing is confirmed this pass.", "Exposure Score (0-100)": 2, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Booz Allen Hamilton  <-  Booz Allen Hamilton Holding Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass. Booz Allen is a government consulting and technology contractor whose work includes intelligence and defence systems, so the individuals whose data passes through its work are members of the public rather than customers - no consent, no notice, no ability to inquire. Recorded as a civil-liberties row rather than a consumer terms row, the same category as Motorola Solutions in F500 Telecom & Consumer Svc.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Business Services", "_row_id": 1000, "_entity_id": 1352, "_entity_slug": "booz-allen-hamilton", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Leidos", "Category": "Information Technology Services", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "B2B/government contractor. DMV-headquartered. Leidos operates significant federal IT infrastructure including the FAA's NextGen air traffic control modernization and CDC data systems.", "Arbitration / Class Action Waiver": "B2B/government contractor. HQ: Reston, Virginia (DMV). Leidos provides IT, engineering, and science services to defense and federal civilian agencies. No consumer products. FAR/DFARS govern disputes.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Reston", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Virginia' is DC/MD/VA", "Parent / Ultimate Owner": "Leidos Holdings, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Leidos Holdings, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] A veteran's benefits data may sit with contractor Leidos, not the agency they applied to\nWHAT THE TERMS SAY: Leidos operates significant federal IT infrastructure, including FAA air traffic control modernization and CDC data systems, and holds large federal contracts covering health and benefits systems that process citizen records.\nWHY IT MATTERS: Government contractors sit outside consumer privacy law and inside federal contract terms the individual never sees, so a veteran or beneficiary has no direct visibility into or recourse over how their data is handled.\n(evidence: Data Sharing/Selling Flags | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No consumer products or terms exist (Arbitration/Fees marked not applicable); only the single federal-contractor data-custody point is substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; nothing consumer-facing is confirmed this pass.", "Exposure Score (0-100)": 2, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Leidos  <-  Leidos Holdings, Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass. Leidos holds large federal contracts including health and benefits systems processing citizen records - meaning a veteran's or beneficiary's data may sit with a contractor rather than the agency they applied to. Government contractors are outside consumer privacy law entirely and inside federal contract terms the individual never sees. Civil-liberties row rather than a consumer terms row.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Business Services", "_row_id": 1001, "_entity_id": 1354, "_entity_slug": "leidos", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CACI International", "Category": "Information Technology Services", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "CACI International operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-3] CACI faced historical litigation over contractor conduct in overseas detention\nWHAT THE TERMS SAY: CACI is a federal technology and services contractor with no consumer relationship; historical litigation concerning contractor conduct in overseas detention is a matter of public record, though it is a human-rights question rather than a consumer-terms one.\nWHY IT MATTERS: The tracker notes this specifically so a blank consumer-privacy row for CACI is not mistaken for a clean record generally.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No consumer products or terms exist; only the single litigation-context item is offered, since it is the sole substantive fact in an otherwise 'nothing confirmed' row.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer-facing terms exist for this federal contractor.", "Exposure Score (0-100)": 8, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "CACI International  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass. CACI is a government technology and services contractor, and the row is recorded honestly as a federal contractor with no consumer relationship - the same category as Booz Allen and Leidos. Historical litigation concerning contractor conduct in overseas detention is a matter of public record but is a human rights question rather than a consumer terms one, and it is noted only so a future reader does not read a blank privacy row as a clean record generally.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Business Services", "_row_id": 1002, "_entity_id": 1355, "_entity_slug": "caci-international", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "DXC Technology", "Category": "Information Technology Services", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "DXC Technology operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Ashburn", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Virginia' is DC/MD/VA", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] DXC staff operate insurance and healthcare systems with consumer records under contracts consumers can't see\nWHAT THE TERMS SAY: DXC runs IT outsourcing for client systems, including insurance and healthcare platforms; its staff operate systems containing consumer records under contracts the consumer cannot see.\nWHY IT MATTERS: A consumer has no visibility into or relationship with the vendor actually handling their insurance or healthcare data.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[OTHER · FL-1] DXC's client disputes over service failures can affect whether an insurer processes your claim\nWHAT THE TERMS SAY: DXC has been the subject of significant client disputes over service failures — a commercial matter, but one that determines whether a consumer's insurer can process a claim.\nWHY IT MATTERS: A vendor-level commercial dispute the consumer never sees can directly delay or block their own insurance claim.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — No consumer terms or products exist directly (Arbitration/Fees marked not applicable); two distinct structural/commercial points are offered rather than three, since no third distinct fact is stated.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer-facing terms exist; DXC is included only for completeness.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "DXC Technology  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "IT outsourcing running client systems, including insurance and healthcare platforms. Its staff operate systems containing consumer records under contracts the consumer cannot see. DXC has also been the subject of significant client disputes over service failures — a commercial matter, but one that determines whether a consumer's insurer can process a claim.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Business Services", "_row_id": 1003, "_entity_id": 1356, "_entity_slug": "dxc-technology", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Kyndryl", "Category": "Information Technology Services", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Kyndryl operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2021", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] Kyndryl runs the mainframes behind many banks and insurers, an invisible layer over your data\nWHAT THE TERMS SAY: Kyndryl, spun out of IBM in 2021, runs mainframes and data centres for banks, insurers, and government agencies; much of the core processing behind institutions in this tracker physically runs on infrastructure Kyndryl manages.\nWHY IT MATTERS: This is another layer between a consumer and the company they believe holds their data, with no direct relationship or disclosure to the consumer.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No consumer terms or relationship exists (Arbitration/Fees not applicable); only the single infrastructure-layer point is substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer-facing terms exist; Kyndryl has no direct consumer relationship.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Kyndryl  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The IT infrastructure services business spun out of IBM in 2021, running mainframes and data centres for banks, insurers and government agencies. Much of the core processing behind institutions in this tracker physically runs on infrastructure Kyndryl manages, which makes it another layer between a consumer and the company they think holds their data.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Business Services", "_row_id": 1004, "_entity_id": 1357, "_entity_slug": "kyndryl", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Concentrix", "Category": "Information Technology Services", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Concentrix operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] The person reading your bank file may work for Concentrix overseas, unseen by you\nWHAT THE TERMS SAY: Concentrix is one of the largest customer-experience outsourcing firms in the world; when a consumer calls their bank, insurer, or airline, the person accessing their account file frequently works for Concentrix in another country under a contract the consumer has never seen.\nWHY IT MATTERS: Outsourced customer service puts a consumer's account details in front of a third-party workforce abroad with no direct accountability to the consumer.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No consumer terms or relationship exists directly with Concentrix; only the single outsourced-access structural point is substantive this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer-facing terms exist; nothing is confirmed this pass beyond the structural note.", "Exposure Score (0-100)": 2, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Concentrix  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass, and the honest entry is more useful than a null: Concentrix is one of the largest customer-experience outsourcing firms in the world, which means when you call your bank, your insurer or your airline, the person reading your account file frequently works for Concentrix in another country under a contract you have never seen. Outsourced customer service is a genuine and underexamined layer in the consumer data chain - cross-ref the Cognizant row in F500 Financial Svcs Remainder.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Business Services", "_row_id": 1005, "_entity_id": 1358, "_entity_slug": "concentrix", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Manpower", "Category": "Diversified Outsourcing Services", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Manpower operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Staffing firms hold job seekers' background-check and drug-screening records; nothing confirmed for Manpower\nWHAT THE TERMS SAY: Staffing firms like Manpower hold job seeker data — resumes, background check results, drug screening, work authorisation documents, and placement history — for people who are not their customers and often not their employees either.\nWHY IT MATTERS: In this triangular relationship the worker generating the most sensitive data has no leverage to negotiate over how it is held or used.\n(evidence: SCARY; Inferred from tracker text (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data Sharing, Arbitration, and Fees fields are unconfirmed this pass ('Not applicable' / 'No confirmed finding'); only the single structural job-seeker-data point is substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing Manpower-specific is confirmed this pass; only shared staffing-industry structural context is available.", "Exposure Score (0-100)": 5, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Manpower  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. Staffing firms hold job seeker data - resumes, background check results, drug screening, work authorisation documents and placement history - for people who are not their customers and often not their employees either, in a triangular relationship where the worker has the least leverage. That is the same structure documented in the TaskRabbit and Vismo rows: the person generating the most sensitive data has no ability to negotiate over it.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Business Services", "_row_id": 1006, "_entity_id": 1359, "_entity_slug": "manpower", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Interpublic", "Category": "Advertising, Marketing", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Interpublic operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SALE · FL-2] Interpublic assembles consumer profiles from purchased data, with no consumer relationship at all\nWHAT THE TERMS SAY: Interpublic owns media buying, data, and identity-resolution businesses that assemble consumer profiles from purchased data sources — location data sold by app SDKs, ISP sensitive-category segments the FTC described, and retail loyalty records all flow toward companies in this category. Interpublic has agreed to be acquired by Omnicom, consolidating two of the largest such operations.\nWHY IT MATTERS: No consumer has any relationship with Interpublic and no privacy policy names it, yet it sits at the demand side of nearly every data-sharing practice documented elsewhere in this tracker.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Data Sharing, Arbitration, and Fees are marked not applicable (no direct consumer relationship or ToS); only the single demand-side data-aggregation point is offered.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or privacy policy names Interpublic at all, per the tracker.", "Exposure Score (0-100)": 16, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Interpublic  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Advertising holding companies are the demand side of everything this tracker documents from the supply side. Interpublic owns media buying, data and identity-resolution businesses whose function is assembling consumer profiles from purchased data sources - so the location data sold by app SDKs, the ISP sensitive-category segments the FTC described, and the retail loyalty records all flow toward companies in this category. Interpublic agreed to be acquired by Omnicom, consolidating two of the largest such operations. No consumer has any relationship with either, and no privacy policy names them.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Business Services", "_row_id": 1007, "_entity_id": 1360, "_entity_slug": "interpublic", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Omnicom", "Category": "Advertising, Marketing", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Omnicom operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Omnicom-Interpublic consolidates ad data consumers can't name or request access to\nWHAT THE TERMS SAY: Omnicom is the acquiring party in the Omnicom-Interpublic combination, creating one of the largest advertising and marketing data operations in the world; data documented elsewhere in this tracker as 'shared with third parties' or 'used for advertising purposes' ends up with a small number of holding companies consumers cannot name, have no relationship with, and cannot make a data request to in any practical way.\nWHY IT MATTERS: The tracker frames this opacity as not incidental but the market's design — consumers structurally cannot exercise data rights against the companies actually assembling their profiles.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No consumer relationship or terms exist directly with Omnicom (Arbitration/Fees not applicable); only the single market-consolidation/opacity point is substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or privacy policy names Omnicom, per the tracker's own framing of this as by-design opacity.", "Exposure Score (0-100)": 6, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Omnicom  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The acquiring party in the Omnicom-Interpublic combination, creating one of the largest advertising and marketing data operations in the world. The structural point belongs in both rows: everything documented across this tracker as data being 'shared with third parties' or 'used for advertising purposes' ends up in the hands of a small number of holding companies that consumers cannot name, have no relationship with, and cannot make a data request to in any practical way. That opacity is not incidental - it is the market's design.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Business Services", "_row_id": 1008, "_entity_id": 1361, "_entity_slug": "omnicom", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cintas", "Category": "Diversified Outsourcing Services", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Cintas operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Primarily B2B — Cintas provides uniforms, cleaning, and fire protection to businesses. No significant consumer-facing products.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mason", "HQ State": "Ohio", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Ohio' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Ohio SOS Business Search — businesssearch.ohiosos.gov. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Cintas holds employee sizing records via uniform contracts employees never chose\nWHAT THE TERMS SAY: Uniform rental services involve recurring on-site access to client premises and employee sizing records — a small but genuine workforce-data holding by a vendor the employee never selected.\nWHY IT MATTERS: Employees have their sizing and access data held by a third-party vendor chosen by their employer, with no say in the arrangement.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No direct consumer relationship or terms exist (B2B uniform/facility services); only the single minor workforce-data point is stated, consistent with the tracker's own lowest severity rating (1) for this row.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer-facing terms exist; Cintas serves businesses, not consumers directly.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Cintas  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Uniform rental, facility services and safety supplies for businesses. Small-business relevant as a supplier. Uniform services involve recurring on-site access to client premises and employee sizing records, which is a small but genuine workforce-data holding by a vendor the employee never selected.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Business Services", "_row_id": 1009, "_entity_id": 1362, "_entity_slug": "cintas", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Aramark", "Category": "Diversified Outsourcing Services", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Aramark operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Aramark's campus and prison commissary systems tie purchases to an individual account for captive populations\nWHAT THE TERMS SAY: Aramark provides food service and facilities management under contract at hospitals, universities, stadiums and correctional facilities, serving captive populations who did not choose the vendor and frequently cannot go elsewhere; campus and prison commissary systems tie purchases to an individual account, and correctional commissary pricing in particular has drawn sustained scrutiny.\nWHY IT MATTERS: The people Aramark serves under these contracts did not choose the vendor and frequently cannot go elsewhere, and campus and prison commissary systems tie their purchases to an individual account; correctional commissary pricing in particular has drawn sustained scrutiny.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — No consumer terms exist directly with Aramark (Arbitration/Fees not applicable); only the single captive-population commissary-account point is substantive this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing consumer-facing is independently confirmed this pass; only the structural commissary-account note is available.", "Exposure Score (0-100)": 2, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Aramark  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing consumer-facing confirmed this pass. Aramark provides food service and facilities management under contract at hospitals, universities, stadiums and correctional facilities - so the people it serves are captive populations who did not choose the vendor and frequently cannot go elsewhere. Campus and prison commissary systems tie purchases to an individual account, and correctional commissary pricing in particular has drawn sustained scrutiny. Honest structural row.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Business Services", "_row_id": 1010, "_entity_id": 1363, "_entity_slug": "aramark", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Jacobs Solutions", "Category": "Diversified Outsourcing Services", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Jacobs Solutions operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Dallas", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row states Jacobs has no consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to; its work is B2B/government engineering with no consumer-facing clause or practice to extract.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer Terms of Service exists for this company, per the row's own text.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Jacobs Solutions  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Engineering and professional services for government and industrial clients, including water infrastructure and transit systems used daily across this tracker's region. No consumer relationship, but its designs govern facilities the public uses without any contractual relationship to the designer.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Engineering & Construct", "_row_id": 1011, "_entity_id": 1364, "_entity_slug": "jacobs-solutions", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "AECOM", "Category": "Engineering & Construction", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "AECOM operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Dallas", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row states AECOM has no consumer account relationship or Terms of Service; it designs infrastructure for public agencies, so its outputs are public infrastructure rather than a consumer product with terms.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer Terms of Service exists for this company, per the row's own text.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "AECOM  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Infrastructure engineering for public agencies. AECOM designs and manages transit, water and transportation projects — including work for authorities in the DMV — so its outputs are public infrastructure rather than consumer products. No consumer terms exist.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Engineering & Construct", "_row_id": 1012, "_entity_id": 1365, "_entity_slug": "aecom", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fluor", "Category": "Engineering & Construction", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Fluor operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row states Fluor has no consumer relationship; the government contract disputes and restatement issues it mentions are explicitly framed as investor and taxpayer matters, not consumer terms or data practices.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer Terms of Service exists for this company, per the row's own text.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Fluor  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Engineering, procurement and construction for industrial and government clients. No consumer relationship. Fluor's history includes significant government contract disputes and restatement issues, which are investor and taxpayer matters rather than consumer ones.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Engineering & Construct", "_row_id": 1013, "_entity_id": 1366, "_entity_slug": "fluor", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Quanta Services", "Category": "Engineering & Construction", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Quanta Services operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Quanta's crews work on residential property under the utility's authority, not the homeowner's own agreement\nWHAT THE TERMS SAY: The row states Quanta builds infrastructure for utilities and pipeline operators, including installing grid equipment such as smart meters, and that its crews work on residential property under the utility's authority rather than under any agreement with the homeowner.\nWHY IT MATTERS: A homeowner has no contract with the company whose crews and equipment are physically present on their property, so they have no direct terms of their own to consent to or dispute.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Row is B2B with no consumer terms; only this one structural observation, that work occurs on private property without a homeowner agreement, is substantive enough to report.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the noted practice is structural context rather than a documented policy.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Quanta Services  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Infrastructure construction for utilities and pipeline operators — the contractor that physically installs the grid equipment described in the Power Utilities tab, including smart meters. No consumer relationship, though its crews work on residential property under the utility's authority rather than the homeowner's agreement.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Engineering & Construct", "_row_id": 1014, "_entity_id": 1367, "_entity_slug": "quanta-services", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "EMCOR", "Category": "Engineering & Construction", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "EMCOR operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no consumer relationship; the occupancy-sensing and access-control point is speculative ('increasingly include') about industry trends generally, not a stated EMCOR-specific practice or clause.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer Terms of Service exists for this company, per the row's own text.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "EMCOR  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Mechanical and electrical construction and facilities services for commercial buildings. Small-business relevant as a contractor; no consumer relationship. Building systems it installs increasingly include occupancy sensing and access control, which generates data about the people inside under the building owner's terms.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Engineering & Construct", "_row_id": 1015, "_entity_id": 1368, "_entity_slug": "emcor", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "MasTec", "Category": "Engineering & Construction", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "MasTec operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Coral Gables", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] MasTec crews survey and record household premises during installs it has no consumer contract to govern\nWHAT THE TERMS SAY: The row states MasTec builds telecom, utility and energy infrastructure and that its crews perform residential installations, described as 'the point at which a household's premises are surveyed and recorded.'\nWHY IT MATTERS: A household's property is surveyed and recorded during installation even though the resident has no direct contractual relationship with MasTec defining how that information is used.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Row is B2B with no consumer terms; only the residential-installation survey/record point rises above generic B2B boilerplate.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the noted practice is structural context rather than a documented policy.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "MasTec  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Builds infrastructure for telecom, utility and energy clients — including the fibre and wireless networks behind the Internet Providers tab. No consumer relationship, but its crews are the ones performing residential installations, which is the point at which a household's premises are surveyed and recorded.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Engineering & Construct", "_row_id": 1016, "_entity_id": 1369, "_entity_slug": "mastec", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Comfort Systems USA", "Category": "Engineering & Construction", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Comfort Systems USA operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no consumer relationship; the only specific point raised, occupancy-sensing building controls, is explicitly a cross-reference to findings already flagged in the Carrier and Honeywell rows, not a Comfort Systems-specific finding.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer Terms of Service exists for this company, per the row's own text.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Comfort Systems USA  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Commercial HVAC installation and service. Small-business relevant as a contractor for any organisation with a facility; no consumer relationship. Connected building controls it installs raise the same occupancy-inference question flagged in the Carrier and Honeywell rows.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Engineering & Construct", "_row_id": 1017, "_entity_id": 1370, "_entity_slug": "comfort-systems-usa", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Peter Kiewit Sons'", "Category": "Engineering & Construction", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Peter Kiewit Sons' operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[NO_DISCLOSURE_THICK_FOG · FL-4] Kiewit's private ownership means minimal disclosure, so the lack of findings reflects opacity, not a clean record\nWHAT THE TERMS SAY: The row states Peter Kiewit Sons' is employee-owned and privately held, and that private ownership means minimal public disclosure of any kind, so the absence of findings here reflects opacity rather than examination.\nWHY IT MATTERS: Because the company discloses little publicly, an outside observer cannot tell an actually clean record apart from one that simply hasn't been examined.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Row is B2B with no consumer terms; the one substantive point is the tracker's own note that Kiewit's opacity, not a confirmed clean record, explains the lack of findings.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Private ownership means minimal public disclosure of any kind, per the row's own text.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Peter Kiewit Sons'  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Construction and engineering contractor, employee-owned and privately held, working on public and industrial projects. Private ownership means minimal public disclosure of any kind, so absence of findings here reflects opacity rather than examination. No consumer relationship.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Engineering & Construct", "_row_id": 1018, "_entity_id": 1371, "_entity_slug": "peter-kiewit-sons", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Builders FirstSource", "Category": "Building Materials, Glass", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Builders FirstSource operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Irving", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Builders FirstSource, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Builders FirstSource, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no consumer relationship; its customers are professional homebuilders documented elsewhere in the tracker, not homebuyers, and no consumer-facing practice is described.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer Terms of Service exists for this company, per the row's own text.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Builders FirstSource  <-  Builders FirstSource, Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Supplies building materials and manufactured components to professional homebuilders — its customers are the builders documented in the F500 Homebuilders tab, not homebuyers. Genuinely small-business relevant to contractors; no consumer relationship.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Engineering & Construct", "_row_id": 1019, "_entity_id": 1373, "_entity_slug": "builders-firstsource", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "United Rentals", "Category": "Specialty Retailers: Other", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B/institutional services company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "United Rentals operates primarily as a B2B/government/institutional services provider (IT consulting, engineering, staffing, advertising, wholesale distribution) rather than serving individual consumers directly — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[LOCATION_TRACKING · FL-2] United Rentals telematics track rented equipment's location throughout the hire, even on the customer's own property\nWHAT THE TERMS SAY: The row states United Rentals telematics-tracks its fleet, so rented equipment reports its location back to the rental company throughout the hire, including while sitting on a customer's private property, and that walk-in rental creates a limited consumer relationship involving a driver's licence scan and a card on file.\nWHY IT MATTERS: A renter's equipment location is continuously reported to the company for the full rental period, including while parked on the renter's own property, without this being described as something the customer separately agrees to.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one substantive, company-specific item is present; arbitration terms are noted as not stated and no other distinct data or fee practice is described.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "A limited consumer relationship and a specific tracking practice are described, but arbitration terms and other details are not stated.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (precise_location_tracking+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "PRECISE LOCATION → VA: sale of precise geolocation data banned from Jul 1, 2026 (VCDPA amendment); MD: sensitive data (within 1,750 ft) — sale banned, opt-in consent", "Entity Type": "Company", "Ownership Path": "United Rentals  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using United Rentals you gave up your physical movements. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Predominantly equipment rental to contractors, making it genuinely small-business relevant. Walk-in rental creates a limited consumer relationship involving a driver's licence scan and a card on file. United Rentals also telematics-tracks its fleet, so rented equipment reports its location back to the rental company throughout the hire — including while sitting on a customer's private property.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Engineering & Construct", "_row_id": 1020, "_entity_id": 1374, "_entity_slug": "united-rentals", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sysco", "Category": "Wholesalers: Food and Grocery", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Sysco operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "B2B — foodservice distribution to restaurants, hospitals, schools. No consumer-facing products.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no consumer terms; the purchasing-history data described concerns restaurant business customers, not individual consumers, matching the row's own 'no consumer-facing products' classification.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer Terms of Service exists for this company, per the row's own text.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Sysco  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The largest US foodservice distributor, supplying restaurants, schools, hospitals and senior facilities — including a great many small independent operators across the DMV. No consumer relationship, but highly small-business relevant: Sysco's ordering platform holds a restaurant's complete purchasing history, which is effectively its recipe costs, margins and menu strategy in data form, and that is the operator's most commercially sensitive information.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Wholesalers Remainder", "_row_id": 1021, "_entity_id": 1375, "_entity_slug": "sysco", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "US Foods", "Category": "Wholesalers: Food and Grocery", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "US Foods operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "B2B — foodservice distribution. No consumer-facing products.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Rosemont", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no consumer terms; the order-history data described concerns restaurant business customers, and the row's point about no consumer-style deletion right applies to business customer data, not individual consumers.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer Terms of Service exists for this company, per the row's own text.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "US Foods  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Foodservice distributor competing directly with Sysco and holding the same category of data about its restaurant customers — order history that reveals cost structure and volume. For a small restaurant, switching distributors means that history sits with a company it no longer does business with, and no consumer-style deletion right applies to business customer data.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Wholesalers Remainder", "_row_id": 1022, "_entity_id": 1376, "_entity_slug": "us-foods", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Performance Food", "Category": "Wholesalers: Food and Grocery", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Performance Food operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "B2B — foodservice distribution. HQ: Richmond, Virginia (DMV). No consumer-facing products.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Richmond", "HQ State": "Virginia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "DMV", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Virginia' is DC/MD/VA", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Virginia SCC Clerk's Information System — cis.scc.virginia.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp. DMV ENTITY: this company is headquartered in the DC/MD/VA corridor, so local service and local small-claims venue are realistic options.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no consumer terms; the described data (restaurant order history) and business lines (Vistar vending/concessions distribution) involve business customers, not individual consumers.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer Terms of Service exists for this company, per the row's own text.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Performance Food  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Foodservice and convenience distribution, including the Vistar arm that supplies vending and theatre concessions. Same customer-data profile as Sysco and US Foods. Small-business relevant; no consumer relationship.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Wholesalers Remainder", "_row_id": 1023, "_entity_id": 1377, "_entity_slug": "performance-food", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "United Natural Foods", "Category": "Wholesalers: Food and Grocery", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "United Natural Foods operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Providence", "HQ State": "Rhode Island", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Rhode Island' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): RI SOS Corporate Database — business.sos.ri.gov/CorpWeb/CorpSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] UNFI's 2025 cyber incident disrupted deliveries to grocery stores nationwide\nWHAT THE TERMS SAY: The row states UNFI is the primary supplier to Whole Foods and that its 2025 cyber incident disrupted deliveries to grocery stores nationwide.\nWHY IT MATTERS: A security failure at a B2B distributor reached consumers as empty shelves rather than as leaked personal records, illustrating that supply-chain security is a food-access issue even without a direct consumer contract.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Row is B2B with no consumer terms; only the confirmed 2025 cyber incident is a substantive, company-specific fact, and no consumer data-handling clauses are described.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the one confirmed fact is an operational incident, not a policy disclosure.", "Exposure Score (0-100)": 3, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 3, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 3/20 (severity1+0, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "United Natural Foods  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Natural and organic distributor and the primary supplier to Whole Foods. UNFI's 2025 cyber incident disrupted deliveries to grocery stores nationwide — the clearest illustration in this tab that a B2B failure reaches consumers as empty shelves rather than as leaked records, and that supply-chain security is a food-access question.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Wholesalers Remainder", "_row_id": 1024, "_entity_id": 1378, "_entity_slug": "united-natural-foods", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Albertsons", "Category": "Food & Drug Stores", "Terms & Conditions URL": "See Safeway (Albertsons) row (Car Rental & Grocery-Restaurant tab)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "See Safeway (Albertsons) row for privacy policy details", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "This is the SAME parent company already documented in the Safeway (Albertsons) row — including the $5.95 million settlement over unsolicited marketing texts continuing after opt-out, and the data-driven pricing/promotional practices Albertsons itself disclosed in SEC filings — no additional finding to add here.", "Arbitration / Class Action Waiver": "See Safeway (Albertsons) row.", "Fees / Billing Flags": "See Safeway (Albertsons) row.", "Notes": "See the Safeway (Albertsons) row (Car Rental & Grocery-Restaurant tab) for the full corporate-level finding already captured for this company.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Boise", "HQ State": "Idaho", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Idaho' is a non-DMV US state", "Parent / Ultimate Owner": "Albertsons Companies, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Non-US entity (Idaho) — no US registered agent unless separately qualified", "Registered Agent Address / Service Notes": "HQ is in Idaho. A foreign company generally has NO US registered agent unless it has qualified to do business in a US state or has a US subsidiary. For correspondence: identify the US-qualified affiliate (if any) and look that entity up on the relevant state registry. Service on a foreign parent may require the Hague Service Convention, which is slower and more formal than domestic service.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DARK_PATTERN_CONSENT · FL-2] Albertsons paid $5.95M to settle marketing texts that kept coming after customers opted out\nWHAT THE TERMS SAY: The row states Albertsons faced a $5.95 million settlement over unsolicited marketing texts continuing after opt-out.\nWHY IT MATTERS: A customer who opted out of marketing texts kept receiving them anyway, meaning the opt-out mechanism did not reliably work as represented.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Albertsons runs 22 grocery banners on shared loyalty data, mixing pharmacy records with purchase history\nWHAT THE TERMS SAY: The row states Albertsons operates 22 grocery banners including Safeway, Vons, Jewel-Osco and Acme on shared loyalty infrastructure, so switching banners changes the sign on the building and nothing else, and that its in-store pharmacies place prescription records alongside purchase history.\nWHY IT MATTERS: A customer who switches to a different Albertsons-owned banner thinking they're changing companies stays inside the same data system, one that combines prescription records with everyday grocery purchase history.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — This row is flagged in the tracker itself as a confirmed cross-tab duplicate of the Safeway (Albertsons) row; only the two items restated directly in this row's own text are used, and no third distinct item is present here.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Specific confirmed facts are stated (the settlement, the shared-banner loyalty infrastructure), but full arbitration and fee terms are only available in the referenced Safeway row.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 5, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 5/20 (severity2+2, penalty+3) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Albertsons  <-  Albertsons Companies, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Albertsons you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Duplicate of the Safeway row in Car Rental & Grocery-Restaurant - see that row for the full analysis. The core finding: Albertsons operates 22 grocery banners including Safeway, Vons, Jewel-Osco and Acme on shared loyalty infrastructure, so switching banners changes the sign on the building and nothing else, and its in-store pharmacies place prescription records alongside purchase history. TRACKER NOTE: confirmed cross-tab duplicate, flag for the dedup pass described in the project guide.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Wholesalers Remainder", "_row_id": 1025, "_entity_id": 1380, "_entity_slug": "albertsons", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "TD Synnex", "Category": "Wholesalers: Electronics and Office Equipment", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "TD Synnex operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Fremont", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "TD SYNNEX Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: TD SYNNEX Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no consumer terms; it distributes to resellers and integrators with no consumer-facing data practice described beyond generic supply-chain exposure.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer Terms of Service exists for this company, per the row's own text.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "TD Synnex  <-  TD SYNNEX Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Technology products distributor selling to resellers and integrators — the layer between manufacturers and the IT vendor a small business actually hires. No consumer relationship, but its distribution position means a compromise here would propagate into thousands of small-business IT environments.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Wholesalers Remainder", "_row_id": 1026, "_entity_id": 1382, "_entity_slug": "td-synnex", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ingram Micro", "Category": "Wholesalers: Electronics and Office Equipment", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Ingram Micro operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Irvine", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Ingram Micro Holding Corporation", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Ingram Micro Holding Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Ingram Micro suffered a significant 2025 ransomware attack that disrupted its ordering systems globally\nWHAT THE TERMS SAY: The row states Ingram Micro suffered a significant ransomware attack in 2025 that disrupted its ordering systems globally.\nWHY IT MATTERS: Because Ingram sits between manufacturers and the resellers that serve small businesses, an outage here stalls hardware procurement for organisations that have never heard of the company.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Row is B2B with no consumer terms; only the confirmed 2025 ransomware incident is a substantive, company-specific fact.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the one confirmed fact is an operational incident, not a policy disclosure.", "Exposure Score (0-100)": 3, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 3, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 3/20 (severity1+0, breach+3) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Ingram Micro  <-  Ingram Micro Holding Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Technology distributor that suffered a significant ransomware attack in 2025 disrupting its ordering systems globally. Because Ingram sits between manufacturers and the resellers that serve small businesses, an outage here stalls hardware procurement for organisations that have never heard of the company. No consumer relationship.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Wholesalers Remainder", "_row_id": 1027, "_entity_id": 1384, "_entity_slug": "ingram-micro", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Arrow Electronics", "Category": "Wholesalers: Electronics and Office Equipment", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Arrow Electronics operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Centennial", "HQ State": "Colorado", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Colorado' is a non-DMV US state", "Parent / Ultimate Owner": "Arrow Electronics, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Colorado SOS Business Search — sos.state.co.us/biz/BusinessEntityCriteria. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Arrow Electronics, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no consumer terms; its relevance is described only as generic supply-chain infrastructure, with no company-specific practice or incident stated.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer Terms of Service exists for this company, per the row's own text.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Arrow Electronics  <-  Arrow Electronics, Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Electronic components distributor supplying manufacturers. No consumer relationship. Its position matters only as supply-chain infrastructure — component shortages routed through distributors like Arrow are what turn into consumer product delays.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Wholesalers Remainder", "_row_id": 1028, "_entity_id": 1386, "_entity_slug": "arrow-electronics", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Avnet", "Category": "Wholesalers: Electronics and Office Equipment", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Avnet operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Phoenix", "HQ State": "Arizona", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Arizona' is a non-DMV US state", "Parent / Ultimate Owner": "Avnet, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Arizona Corporation Commission eCorp — ecorp.azcc.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Avnet, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B with no consumer terms; the row states it is a competitor to Arrow with the same purely industrial customer base, with no additional company-specific fact.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer Terms of Service exists for this company, per the row's own text.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Avnet  <-  Avnet, Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Electronic components distributor, competitor to Arrow, with the same purely industrial customer base. No consumer relationship and no consumer terms.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Wholesalers Remainder", "_row_id": 1029, "_entity_id": 1388, "_entity_slug": "avnet", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ferguson", "Category": "Wholesalers: Diversified", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Ferguson operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Ferguson's homeowner showrooms capture renovation project scope and property details, not just a purchase\nWHAT THE TERMS SAY: The row states Ferguson primarily distributes plumbing and HVAC to trade customers, but its showrooms serve homeowners directly on renovation projects, a channel described as a genuine limited consumer relationship that captures project scope and property details rather than just a purchase.\nWHY IT MATTERS: A homeowner visiting a showroom for a renovation project has project and property details captured as part of a relationship the row itself calls only 'limited,' with no further terms described.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one substantive, company-specific item is present; arbitration terms are noted as not stated and no other distinct practice is described.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "A limited consumer relationship and a specific data-capture point are described, but arbitration and fee terms are not stated.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Ferguson  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Ferguson takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Plumbing and HVAC distribution, primarily to trade customers but with showrooms serving homeowners directly on renovation projects. That showroom channel is a genuine limited consumer relationship, capturing project scope and property details rather than just a purchase.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Wholesalers Remainder", "_row_id": 1030, "_entity_id": 1389, "_entity_slug": "ferguson", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Genuine Parts", "Category": "Wholesalers: Diversified", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Genuine Parts operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Genuine Parts (parent of NAPA Auto Parts) has consumer exposure through NAPA stores. NAPA's website ToS may contain arbitration provisions. Genuine Parts also owns Motion Industries (B2B).", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Atlanta", "HQ State": "Georgia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Georgia' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Georgia SOS eCorp — ecorp.sos.ga.gov/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] NAPA (Genuine Parts) purchase history can reconstruct a vehicle's make, model, age and mechanical condition.\nWHAT THE TERMS SAY: The tracker states that NAPA purchase history reconstructs a vehicle's make, model, age and mechanical condition, and calls this directly useful to the insurance and advertising markets.\nWHY IT MATTERS: Insurers or advertisers could use inferred vehicle condition data to target or price a customer, though the tracker only asserts the data is 'useful' for this, not that it has actually been sold; the same inference is separately documented for AutoZone and Advance Auto Parts, noted here only as context for other companies.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] NAPA's consumer-facing website terms may include arbitration provisions, though this is unconfirmed.\nWHAT THE TERMS SAY: The tracker states NAPA's website Terms of Service 'may contain' arbitration provisions, without confirming the actual clause.\nWHY IT MATTERS: If confirmed, NAPA customers could be routed into arbitration rather than court for disputes.\n(evidence: Arbitration; Tracker says unconfirmed (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Genuine Parts is primarily a B2B distributor; only two items are substantive because arbitration language for its consumer-facing NAPA stores is hedged ('may contain') and the Fees field is not applicable.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=N; aitrain=?; location=N; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "NAPA consumer exposure is acknowledged but its arbitration terms are hedged ('may contain') and not independently confirmed.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Genuine Parts  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your biometric identifiers; your physical movements.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Genuine Parts takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Owner of NAPA Auto Parts, which is consumer-facing through retail stores, and of industrial parts distribution. NAPA purchase history reconstructs a vehicle's make, model, age and mechanical condition — the same inference documented in the AutoZone and Advance Auto Parts rows, and directly useful to the insurance and advertising markets described in the Insurance tab.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Wholesalers Remainder", "_row_id": 1031, "_entity_id": 1390, "_entity_slug": "genuine-parts", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "WESCO International", "Category": "Wholesalers: Diversified", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "WESCO International operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — WESCO is a pure B2B electrical/industrial distributor with no consumer relationship or Terms of Service; the SCARY field only notes it as an upstream utility-grid equipment supplier, which is context rather than a distinct practice.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms, disclosure regime, or data practice is described for this company.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 12/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "WESCO International  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 66.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Electrical and industrial supply distributor serving contractors and facility operators. Small-business relevant as a supplier to electrical trades; no consumer relationship. WESCO also distributes utility grid equipment, placing it upstream of the utility rows in this tracker.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Wholesalers Remainder", "_row_id": 1032, "_entity_id": 1391, "_entity_slug": "wesco-international", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "W.W. Grainger", "Category": "Wholesalers: Diversified", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "W.W. Grainger operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "B2B — industrial distribution. Limited consumer exposure through Grainger.com (some small-business/individual purchases). Website ToS contain arbitration provisions.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Lake Forest", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] Grainger.com's website Terms of Service contain arbitration provisions covering its limited individual/small-business purchasers.\nWHAT THE TERMS SAY: The tracker states Grainger has limited consumer exposure through Grainger.com for individual purchases, and that its website Terms of Service contain arbitration provisions.\nWHY IT MATTERS: Individuals buying directly from Grainger.com, not just business accounts, are subject to arbitration terms for disputes.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Grainger's account purchase data is detailed enough to infer a buyer's headcount, facility size and operating tempo.\nWHAT THE TERMS SAY: The tracker notes Grainger's account data includes purchase patterns detailed enough to infer headcount, facility size and operating tempo for the buyer.\nWHY IT MATTERS: A small business or nonprofit buying facility supplies may not realize its purchase history reveals this much about its operations.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two distinct items are stated; Grainger's opt-out window is marked 'N/A - no consumer contract' even though the Arbitration field says its website ToS contain arbitration provisions, leaving that detail unresolved, and Fees is marked not applicable.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration is confirmed for Grainger.com but its scope is limited and the opt-out field contradicts the Arbitration field's 'consumer exposure' statement.", "Exposure Score (0-100)": 21, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 10/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "W.W. Grainger  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 60.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "MRO and industrial supply distributor. Grainger is one of the most small-business-relevant companies in this entire tracker — a nonprofit or small operator buying facility supplies is very likely a Grainger customer — and its account data includes purchase patterns detailed enough to infer headcount, facility size and operating tempo. No consumer relationship exists.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Wholesalers Remainder", "_row_id": 1033, "_entity_id": 1392, "_entity_slug": "w-w-grainger", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fastenal", "Category": "Wholesalers: Diversified", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Fastenal operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "B2B — industrial distribution. No significant consumer-facing products.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Winona", "HQ State": "Minnesota", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Minnesota' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Minnesota SOS Business Search — mblsportal.sos.state.mn.us/Business/Search. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Fastenal's on-site vending and inventory systems record which employee withdrew which item and when, inside customer facilities.\nWHAT THE TERMS SAY: The tracker states Fastenal operates on-site vending and inventory systems inside customer facilities that record which employee withdrew which item and when.\nWHY IT MATTERS: This is workplace behavioural data held by a supplier rather than the employer, which the tracker calls an underexamined category.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Fastenal is a pure B2B distributor with no consumer relationship or terms; the vending-system item concerns workplace data at customer facilities rather than a Fastenal consumer practice, and no other field yields a second distinct, substantive finding.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist; the only substantive item is a structural workplace-data note, not a disclosed consumer policy.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 12/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Fastenal  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 66.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Industrial and construction supply distributor operating on-site vending and inventory systems inside customer facilities. Those systems record which employee withdrew which item and when, which is workplace behavioural data held by a supplier rather than the employer — an underexamined category, and the reason this row is more interesting than a distribution business normally would be.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Wholesalers Remainder", "_row_id": 1034, "_entity_id": 1393, "_entity_slug": "fastenal", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ace Hardware", "Category": "Wholesalers: Diversified", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Ace Hardware operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Ace disclosed a late-2023 cyber incident that took down central systems for days, blocking member orders.\nWHAT THE TERMS SAY: The tracker states Ace disclosed a cyber incident in late 2023 that took down its central systems for days, leaving member retailers unable to order inventory or process some transactions.\nWHY IT MATTERS: An outage of this length shows how fragile the co-op's shared technology backbone is, though the tracker does not confirm whether any customer data was exposed.\n(evidence: SCARY; Stated in tracker (fidelity pass 1: Overstated corrected) (fidelity pass 2 (strict): Wrong corrected))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Ace Rewards loyalty and purchase data is split between roughly 5,000 independently owned stores and the central co-op, with security varying store by store.\nWHAT THE TERMS SAY: The tracker states Ace is a retailer-owned cooperative of about 5,000 independently owned stores, and that the loyalty and purchase data behind an Ace Rewards card sits partly with a local owner-operator and partly with the co-op, with security capability varying store by store.\nWHY IT MATTERS: As the tracker puts it, 'Ace Hardware' is not one company a consumer can hold accountable but thousands of small businesses under a shared brand, so protection of rewards data depends on which store a customer used.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — The Arbitration/Class Action Waiver and Fees fields are both marked not applicable for this row, leaving only the two structural findings from the SCARY field as substantive, distinct harms.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=Y; biometric=N; aitrain=?; location=N; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=?; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The row's own fields are internally inconsistent about whether a consumer relationship exists, and the 2023 cyber incident is disclosed without full scope details.", "Exposure Score (0-100)": 6, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 9/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Ace Hardware  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nTHE DOCUMENT DOES NOT TAKE: your biometric identifiers; your physical movements; your right to sue; your right to join a class action; your right to stop paying by inaction.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your content used as AI training data; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ace Hardware you gave up your data shared corporate-wide. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Ace is a retailer-owned cooperative of roughly 5,000 independently owned stores, which means the loyalty and purchase data behind an Ace Rewards card sits partly with a local owner-operator and partly with the co-op, and security capability varies store by store. Ace disclosed a cyber incident in late 2023 that took down its central systems for days, leaving member retailers unable to order inventory or process some transactions. For a consumer, the practical effect is that 'Ace Hardware' is not one company you can hold accountable but thousands of small businesses under a shared brand.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Wholesalers Remainder", "_row_id": 1035, "_entity_id": 1394, "_entity_slug": "ace-hardware", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Graybar Electric", "Category": "Wholesalers: Diversified", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Graybar Electric operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Graybar is a pure B2B, employee-owned distributor with no consumer relationship or terms; the SCARY field describes its ownership structure and reduced public disclosure, not a specific harmful practice.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms, disclosure regime, or data practice is described; the company also discloses less publicly due to its employee-owned structure.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 12/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Graybar Electric  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 66.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Employee-owned distributor of electrical and communications products to contractors. The employee ownership is a genuine structural difference from its peers — no external shareholder pressure — though it also means far less public disclosure of any kind. Small-business relevant as a supplier; no consumer relationship.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Wholesalers Remainder", "_row_id": 1036, "_entity_id": 1395, "_entity_slug": "graybar-electric", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "LKQ", "Category": "Wholesalers: Diversified", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "LKQ operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Unconfirmed: LKQ salvage handles vehicles whose infotainment systems retain contacts and location history\nWHAT THE TERMS SAY: The tracker states LKQ's salvage operations mean it handles vehicles whose infotainment systems retain paired phone contacts, call logs and location history, and that salvage/resale is the point where such data most often escapes without anyone noticing.\nWHY IT MATTERS: A previous owner's personal data could leave with a salvaged vehicle without being wiped, though the tracker explicitly flags this as an unconfirmed, recommended follow-up rather than a confirmed LKQ practice.\n(evidence: SCARY; Tracker says unconfirmed (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Nothing is confirmed this pass ('Nothing confirmed this pass'); LKQ is primarily a B2B parts distributor, and the single item above is explicitly flagged in the tracker as an unconfirmed follow-up recommendation rather than a stated fact.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=?; affiliates=?; biometric=N; aitrain=N; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing is confirmed this pass; the only item is an explicitly unconfirmed follow-up recommendation about salvage-vehicle infotainment data.", "Exposure Score (0-100)": 5, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 9/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "LKQ  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. LKQ distributes recycled and aftermarket vehicle parts, primarily to repair shops rather than consumers, and its salvage operations mean it handles vehicles - and any data left in them. Vehicle infotainment systems retain paired phone contacts, call logs and location history, and salvage and resale is the point at which that data most often escapes without anyone noticing. Recommend a follow-up on data wiping practice in the vehicle salvage chain; it is a genuine gap.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Wholesalers Remainder", "_row_id": 1037, "_entity_id": 1396, "_entity_slug": "lkq", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Jabil", "Category": "Semiconductors and Other Electronic Components", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Jabil operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "St. Petersburg", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Florida' is a non-DMV US state", "Parent / Ultimate Owner": "Jabil Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Jabil Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Jabil is a pure B2B contract manufacturer holding only client design and production data, not consumer data; the SCARY field's note about being upstream of connected consumer devices is supply-chain context, not a Jabil-specific practice.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms, disclosure regime, or data practice is described for this company.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 12/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Jabil  <-  Jabil Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 66.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Contract electronics manufacturer building products designed and branded by other companies. Jabil holds its clients' product designs and production data, not consumer data — but it manufactures a substantial share of the connected consumer devices documented elsewhere in this tracker, so its security posture is upstream of theirs.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Wholesalers Remainder", "_row_id": 1038, "_entity_id": 1398, "_entity_slug": "jabil", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Flex", "Category": "Semiconductors and Other Electronic Components", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Flex operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Austin", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Flex Ltd.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Flex Ltd.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Flex is explicitly described as occupying 'the same structural position as Jabil' — a pure B2B contract manufacturer with no consumer relationship; no distinct, company-specific practice is stated.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms, disclosure regime, or data practice is described for this company.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 12/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Flex  <-  Flex Ltd.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 66.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Contract electronics manufacturer, same structural position as Jabil. No consumer relationship. Worth noting that contract manufacturers are a recognised supply-chain security concern precisely because they sit inside the production process for devices consumers later trust by default.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Wholesalers Remainder", "_row_id": 1039, "_entity_id": 1400, "_entity_slug": "flex", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sanmina", "Category": "Semiconductors and Other Electronic Components", "Terms & Conditions URL": "No consumer-facing Terms of Service identified — this is a B2B wholesale/distribution company", "T&C Direct PDF?": "N/A", "Privacy Policy URL": "No consumer-facing Privacy Policy identified", "Privacy Direct PDF?": "N/A", "Data Sharing/Selling Flags": "Sanmina operates as a wholesale distributor or contract manufacturer selling to OTHER BUSINESSES (restaurants, retailers, hospitals, electronics companies) rather than directly to individual consumers — it has no meaningful direct consumer account relationship or Terms of Service that an ordinary person would ever encounter or agree to.", "Arbitration / Class Action Waiver": "Not applicable — no consumer relationship exists.", "Fees / Billing Flags": "Not applicable.", "Notes": "Included for Fortune 500 completeness per the original request, but does not fit this tracker's core purpose (companies whose Terms & Conditions ordinary consumers actually agree to).", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Jose", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'California' is a non-DMV US state", "Parent / Ultimate Owner": "Sanmina Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): California SOS bizfileOnline — bizfileonline.sos.ca.gov/search/business. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Sanmina Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Sanmina is a pure B2B contract manufacturer with no consumer relationship; its only distinctive note (upstream of medical-device makers documented in other rows) is an explicit cross-reference to other companies' findings, not a Sanmina-specific fact.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=N; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms, disclosure regime, or data practice is described for this company.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 12/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Sanmina  <-  Sanmina Corporation", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 66.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Contract electronics manufacturer serving communications, medical and industrial customers. Its medical device manufacturing places it upstream of the connected-device questions raised in the Boston Scientific and GE HealthCare rows. No consumer relationship.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Wholesalers Remainder", "_row_id": 1040, "_entity_id": 1402, "_entity_slug": "sanmina", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Dell Technologies", "Category": "Computers, Office Equipment", "Terms & Conditions URL": "dell.com/en-us/dt/corporate/policies/terms-of-sale.htm", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "dell.com/en-us/dt/corporate/privacy.htm", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "HISTORICAL CONFIRMED BREACH (2024): Dell disclosed a breach of its 'Dell Premier' business-customer portal, exposing names and physical addresses (NOT financial/payment data) of approximately 49 MILLION customer records — Dell sells directly to consumers (laptops, desktops) as well as businesses, giving it a genuine direct-to-consumer relationship distinct from many other companies in this Misc Remainder tab.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. Dell ToS, AAA rules. 30-day opt-out. Dell's April 2024 partner-portal breach (~49M records scraped via unsecured API over ~3 weeks) means the arbitration clause directly affects breach victims. Dell stated no financial/email/phone data was involved — only names, addresses, and hardware-order information.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Unlike most other companies in this final batch, Dell has a GENUINE direct-to-consumer sales relationship (individuals buy computers directly from Dell.com) — worth treating with more weight than the purely B2B companies also included in this tab.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Round Rock", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.bleepingcomputer.com/news/security/dell-api-abused-to-steal-49-million-customer-records-in-data-breach/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Dell Technologies Inc. (Michael Dell, chairman/CEO)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Dell Technologies Inc. (Michael Dell, chairman/CEO)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] Dell's 2024 Premier portal breach exposed roughly 49 million customer records' names, addresses and hardware/order details.\nWHAT THE TERMS SAY: Dell disclosed a breach of its Dell Premier business-customer portal exposing names and physical addresses (not financial or payment data) for approximately 49 million customer records, reportedly scraped via an unsecured API over about three weeks.\nWHY IT MATTERS: A customer's address paired with their exact hardware order history is, as the tracker notes, a ready-made targeting package for tech-support scams.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Dell requires mandatory binding arbitration under AAA rules, with only a 30-day window to opt out.\nWHAT THE TERMS SAY: Dell's Terms of Service impose mandatory binding arbitration under AAA rules with a 30-day opt-out window, which the tracker notes directly affects victims of the 2024 breach.\nWHY IT MATTERS: Breach victims wanting to pursue a claim are funneled into individual arbitration unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CLASS_ACTION_WAIVER · FL-3] Dell's arbitration clause bundles in a class-action waiver, blocking breach victims from banding together.\nWHAT THE TERMS SAY: The same Dell ToS clause that mandates arbitration also waives class actions, per the tracker.\nWHY IT MATTERS: Even with tens of millions of records exposed, affected customers cannot pursue a collective claim and must arbitrate individually.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=N; aitrain=?; location=N; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=N; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The breach scale and arbitration terms are clearly stated, but the exposure method is only 'reportedly' confirmed and Fees are not itemized.", "Exposure Score (0-100)": 44, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 0/30 (none) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Dell Technologies  <-  Dell Technologies Inc. (Michael Dell, chairman/CEO)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your biometric identifiers; your physical movements.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Dell Technologies you gave up your right to sue and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Dell disclosed a breach exposing customer records at very large scale - reporting cited on the order of 49 million purchase records including names, physical addresses and hardware and order information. Dell's characterisation was that no financial or payment information, email addresses or phone numbers were involved. The exposure route was reportedly a partner portal accessed through registered accounts, which is the same authorisation-abuse structure as the Salesforce campaign: legitimate access used illegitimately, no exploit required. A customer address plus a hardware list is a targeting package for technical support scams.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Misc Remainder", "_row_id": 1041, "_entity_id": 1404, "_entity_slug": "dell-technologies", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "UPS", "Category": "Mail, Package and Freight Delivery", "Terms & Conditions URL": "ups.com/us/en/help-center/legal-terms-conditions.page", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "ups.com/us/en/help-center/legal-terms-conditions/privacy-notice.page", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "UPS processes 24.3M packages daily. UPS My Choice tracks delivery preferences, home address, and package-receipt patterns. UPS Capital provides package-value insurance. The combination of shipping data + financial data creates detailed consumer purchasing profiles.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. UPS Technology Agreement / ups.com ToS. 30-day opt-out. Covers UPS.com, UPS My Choice, UPS Capital, and all digital shipping services. UPS processes shipping address, package-content descriptions, and tracking data — the arbitration clause covers disputes over this data.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "See the FedEx row (Travel & Transit Apps tab) for a directly comparable competitor's recent major breach — worth a direct follow-up on whether UPS has faced a similar incident.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Atlanta", "HQ State": "Georgia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Georgia' is a non-DMV US state", "Parent / Ultimate Owner": "United Parcel Service, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Georgia SOS eCorp — ecorp.sos.ga.gov/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: United Parcel Service, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] UPS combines shipping, delivery-preference and insurance data into what the tracker calls detailed consumer purchasing profiles.\nWHAT THE TERMS SAY: UPS My Choice tracks delivery preferences, home address and package-receipt patterns, and UPS Capital adds package-value insurance data; the tracker states this combination creates detailed consumer purchasing profiles.\nWHY IT MATTERS: A profile like this reveals a household's shopping habits and routine, not just its shipping address.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] UPS imposes mandatory binding arbitration with a class-action waiver across UPS.com, My Choice, Capital and other digital shipping services, with a 30-day opt-out.\nWHAT THE TERMS SAY: The UPS Technology Agreement / ups.com Terms of Service mandate binding arbitration and a class-action waiver, covering disputes over shipping, address and tracking data, with a 30-day opt-out window.\nWHY IT MATTERS: Disputes over how UPS handles a customer's shipping and address data go to individual arbitration rather than court.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[CONFIRMED_BREACH · FL-2] UPS has previously disclosed incidents affecting its package-tracking and address look-up tools, though scope and dates are unspecified.\nWHAT THE TERMS SAY: The tracker states UPS 'has historically disclosed incidents affecting package tracking and its address look-up tools' without further detail.\nWHY IT MATTERS: Without specifics, customers cannot tell how much of their shipping or address data may have been exposed in past incidents.\n(evidence: SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=N; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated, but past incidents are mentioned only vaguely and fees are not itemized.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "UPS  <-  United Parcel Service, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your biometric identifiers.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using UPS you gave up your right to sue and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Shipping records map sender, recipient, address, timing and often contents category — a relationship graph and a household routine in one dataset. UPS has historically disclosed incidents affecting package tracking and its address look-up tools, and its Store franchise network handles notarisation and mailbox services that involve identity documents. Cross-ref the FedEx row for the Salesforce-campaign exposure on the other major carrier.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Misc Remainder", "_row_id": 1042, "_entity_id": 1406, "_entity_slug": "ups", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "GE Vernova", "Category": "Energy", "Terms & Conditions URL": "See GE Vernova's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See GE Vernova's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected where a direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cambridge", "HQ State": "Massachusetts", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Massachusetts' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Massachusetts SOC Corporate Search — corp.sec.state.ma.us/corpweb/corpsearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — GE Vernova is B2B energy equipment sold to utilities; the row explicitly states it holds no household data itself, and arbitration is only hedged as 'expected' rather than confirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or terms are described; arbitration is only hedged as expected, not confirmed.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 9/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "GE Vernova  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Energy equipment and grid technology sold to utilities. GE Vernova's grid software and control systems sit inside the utilities documented in this tracker, which makes it part of the critical-infrastructure security perimeter without holding any household's data itself.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Misc Remainder", "_row_id": 1043, "_entity_id": 1407, "_entity_slug": "ge-vernova", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "EOG Resources", "Category": "Mining, Crude-Oil Production", "Terms & Conditions URL": "See EOG Resources's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See EOG Resources's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "B2B — E&P company. No consumer-facing products.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — EOG is a pure upstream oil-and-gas producer with no consumer-facing products; the row's brief mention of individual-data exposure for royalty owners is an explicit cross-reference to 'other E&P rows' rather than a detailed EOG-specific fact.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or terms are described for this company.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 11/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "EOG Resources  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 63.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Oil and gas exploration and production. No consumer relationship or consumer terms. As with the other E&P rows, its individual-data exposure concerns mineral rights and royalty owners rather than customers.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Misc Remainder", "_row_id": 1044, "_entity_id": 1408, "_entity_slug": "eog-resources", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CDW", "Category": "Information Technology Services", "Terms & Conditions URL": "See CDW's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See CDW's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Primarily B2B — CDW is an IT solutions provider for businesses and government. Limited consumer exposure through CDW.com small-business/individual sales.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Lincolnshire", "HQ State": "Illinois", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Illinois' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Illinois SOS Business Entity Search — apps.ilsos.gov/businessentitysearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] As an IT reseller, CDW holds a client's full hardware and software inventory — effectively a map of that client's attack surface.\nWHAT THE TERMS SAY: The tracker describes CDW as a technology reseller for businesses, government, education and small organisations that often use it as their de facto IT department, and notes that a reseller in that position holds a client's full hardware and software inventory.\nWHY IT MATTERS: That inventory is, in the tracker's words, a map of the client's attack surface, even though CDW's own consumer-facing terms are otherwise unconfirmed this pass.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — CDW is primarily a B2B reseller with only limited, undetailed consumer exposure through CDW.com; the client-inventory item is the only distinct, substantive finding, and fees/arbitration specifics are not itemized this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Primarily B2B with only limited, undetailed consumer exposure; the one substantive item concerns client inventory data, not a disclosed consumer term.", "Exposure Score (0-100)": 3, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "CDW  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Technology products and services reseller serving businesses, government and education — including a large number of small organisations that use CDW as their de facto IT department. No consumer relationship, but genuinely small-business relevant, and a reseller in that position holds a client's full hardware and software inventory, which is a map of their attack surface.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Misc Remainder", "_row_id": 1045, "_entity_id": 1409, "_entity_slug": "cdw", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Carrier Global", "Category": "Industrial Machinery", "Terms & Conditions URL": "See Carrier Global's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Carrier Global's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach. Carrier Global primarily serves institutional/business customers or, where it does reach individual consumers (e.g., waste/recycling collection service, apparel brands, RVs), typically through a simpler transactional relationship (a monthly service bill or a retail purchase) rather than an ongoing account relationship comparable to a bank or social media platform.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected where a direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Palm Beach Gardens", "HQ State": "Florida", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Carrier Global Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Florida Sunbiz — search.sunbiz.org/Inquiry/CorporationSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Carrier Global Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] Carrier's connected HVAC/thermostat products transmit occupancy and temperature patterns that can reveal when a home is empty or residents are asleep.\nWHAT THE TERMS SAY: The tracker notes Carrier's residential smart thermostats transmit occupancy and temperature data, and cites the Seventh Circuit's smart-meter ruling as an example of such patterns being treated as constitutionally significant.\nWHY IT MATTERS: This kind of household-routine data is sensitive even though Carrier's own consumer terms are otherwise unconfirmed this pass.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[OTHER · FL-4] Carrier's building access and monitoring systems generate data about building occupants who never agreed to any Carrier terms.\nWHAT THE TERMS SAY: The tracker states Carrier sells building access and monitoring systems that generate data about occupants who are 'party to nothing.'\nWHY IT MATTERS: Tenants or employees in a monitored building may have data collected about them without ever being a party to any contract with Carrier.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Arbitration and any breach or lawsuit are explicitly unconfirmed this pass ('not independently confirmed'), so only the two product-category data findings from the SCARY field are substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=N; aitrain=N; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration and any breach or litigation are both explicitly unconfirmed; only general product-category risk is described.", "Exposure Score (0-100)": 5, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "Carrier Global  <-  Carrier Global Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your content used as AI training data; your biometric identifiers.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Carrier Global takes nothing from the list this tracker checks - but 11 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "HVAC and building systems, increasingly connected. A residential smart thermostat transmits occupancy and temperature patterns supporting the same inferences the Seventh Circuit found constitutionally significant in the smart meter case — when a house is empty, when people sleep, when routines change. Carrier also owns Kidde and its residential fire safety lines, and building access and monitoring systems it sells generate data about occupants who are party to nothing.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Misc Remainder", "_row_id": 1046, "_entity_id": 1411, "_entity_slug": "carrier-global", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Waste Management", "Category": "Waste Management", "Terms & Conditions URL": "See Waste Management's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Waste Management's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "WM processes service-address data, pickup schedules, and increasingly, recycling-bin-content analysis through computer vision. Smart-bin sensors track fill levels and contamination rates by household.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. WM.com ToS. 30-day opt-out. Waste Management's consumer-facing digital products include the WM app (scheduling pickups, viewing routes) and WM Recycle Right (AI-powered contamination detection in recycling bins).", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Houston", "HQ State": "Texas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Texas' is a non-DMV US state", "Parent / Ultimate Owner": "Waste Management, Inc. (d/b/a WM)", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Texas SOS SOSDirect / Taxable Entity Search — mycpa.cpa.state.tx.us/coa. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Waste Management, Inc. (d/b/a WM)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-3] WM's mandatory arbitration clause with a class-action waiver covers disputes over its app and AI-powered Recycle Right data collection.\nWHAT THE TERMS SAY: WM.com's Terms of Service mandate binding arbitration with a class-action waiver and a 30-day opt-out window, covering the WM app and WM Recycle Right.\nWHY IT MATTERS: Customers who want to dispute how the company handles their household data are funneled into individual arbitration rather than court.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] WM uses computer vision on recycling-bin contents; smart-bin sensors track contamination rates by household\nWHAT THE TERMS SAY: The tracker states WM processes recycling-bin-content analysis through computer vision, and separately that smart-bin sensors track fill levels and contamination rates by household; WM Recycle Right is described as AI-powered contamination detection in recycling bins.\nWHY IT MATTERS: This turns curbside bins into a household-level data collection point most customers likely don't think about.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "[OTHER · FL-2] Truck-mounted cameras photograph the curb, street and driveway on a non-optional, municipally-franchised waste route.\nWHAT THE TERMS SAY: The tracker states WM's route telematics and increasingly truck-mounted cameras photograph the curb and, incidentally, the street and driveway, and that municipal franchise contracts make WM non-optional for most households.\nWHY IT MATTERS: Consumers cannot decline the service or opt out of the camera pass, since the provider is set by municipal contract rather than customer choice.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=N; aitrain=Y; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Arbitration terms are clearly stated but fee practices are unitemized and the extent of data-sharing beyond internal service delivery is unclear.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 8/30 (ai_training_on_user_data+5, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Waste Management  <-  Waste Management, Inc. (d/b/a WM)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nTHE DOCUMENT DOES NOT TAKE: your biometric identifiers.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Waste Management you gave up your content used as AI training data, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Residential waste service with billing and address data, plus route telematics and increasingly truck-mounted cameras that photograph the curb and, incidentally, the street and driveway. Municipal franchise contracts make the provider non-optional for most households, so this is a service you cannot decline and a camera pass you cannot opt out of.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Misc Remainder", "_row_id": 1047, "_entity_id": 1413, "_entity_slug": "waste-management", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Republic Services", "Category": "Waste Management", "Terms & Conditions URL": "See Republic Services's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Republic Services's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach. Republic Services primarily serves institutional/business customers or, where it does reach individual consumers (e.g., waste/recycling collection service, apparel brands, RVs), typically through a simpler transactional relationship (a monthly service bill or a retail purchase) rather than an ongoing account relationship comparable to a bank or social media platform.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected where a direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Scottsdale", "HQ State": "Arizona", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Arizona' is a non-DMV US state", "Parent / Ultimate Owner": "Republic Services, Inc.", "Years Referenced in Finding (heuristic)": "2023", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Arizona Corporation Commission eCorp — ecorp.azcc.gov/EntitySearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Republic Services, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-2] Republic Services reportedly runs the same non-optional municipal-franchise route telematics and curbside camera systems as Waste Management.\nWHAT THE TERMS SAY: The row states Republic uses 'the same non-optional municipal franchise structure as Waste Management, with the same route telematics and curbside camera systems,' stated by comparison rather than independently detailed for Republic.\nWHY IT MATTERS: As with Waste Management, customers cannot decline the service or the camera pass because the provider is set by municipal contract.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Arbitration is explicitly unconfirmed this pass ('expected' only) and fees are not itemized; the only substantive item is the route-telematics/camera note, which is itself framed as a comparison to the separately-documented Waste Management row rather than an independently confirmed Republic-specific fact.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=N; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Arbitration and any breach or lawsuit are both explicitly unconfirmed this pass; the only detailed content is inferred by comparison to the Waste Management row.", "Exposure Score (0-100)": 2, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Republic Services  <-  Republic Services, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your biometric identifiers.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Republic Services takes nothing from the list this tracker checks - but 12 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same non-optional municipal franchise structure as Waste Management, with the same route telematics and curbside camera systems. Republic is worth recording separately for its 2023 Teamsters strikes and resulting service disruptions — a labour matter, but the way most customers actually experienced the company's decisions, and one no term of service addresses.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Misc Remainder", "_row_id": 1048, "_entity_id": 1415, "_entity_slug": "republic-services", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "SpaceX", "Category": "Aerospace & Defense", "Terms & Conditions URL": "See the Starlink row (Internet Providers tab)", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "See Starlink row for privacy policy details", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "SpaceX is the PARENT COMPANY of Starlink, already documented in the Internet Providers tab — including the notable finding that residential Starlink customer data may be used for AI training by default (unlike Enterprise/Government customers, who are auto-opted-out), and Starlink's use of ICC arbitration (unusual, not the AAA standard used by most other companies in this tracker). SpaceX's OTHER primary business (launching rockets, government/commercial satellite contracts) has no direct consumer relationship.", "Arbitration / Class Action Waiver": "See Starlink row.", "Fees / Billing Flags": "See Starlink row.", "Notes": "See the Starlink row (Internet Providers tab) for the fullest treatment of SpaceX's actual consumer-facing product.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[AI_TRAINING · FL-2] Residential Starlink data may be used for AI training by default; Enterprise/Government are auto-opted-out\nWHAT THE TERMS SAY: Per the tracker's Starlink documentation, residential Starlink customer data may be used for AI training by default, unlike Enterprise/Government tiers which are automatically opted out.\nWHY IT MATTERS: Households get a weaker privacy default than SpaceX's institutional customers for the same underlying service.\n(evidence: Notes; Inferred from tracker text (fidelity pass 2 (strict): Hedge lost corrected))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] Starlink uses ICC arbitration, not the AAA standard used by most other companies in this tracker\nWHAT THE TERMS SAY: The row notes Starlink's use of ICC arbitration as unusual compared to the AAA rules typical elsewhere in the tracker.\nWHY IT MATTERS: ICC arbitration is a less familiar venue than the AAA process used elsewhere in the tracker, which the tracker flags as an unusual choice for a consumer dispute.\n(evidence: Arbitration; Stated in tracker (fidelity pass 1: Overstated corrected) (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — SpaceX's own launch and government/commercial satellite business has no direct consumer relationship; the two items above both derive from Starlink, SpaceX's only consumer-facing product, and no third distinct item is stated.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=N; aitrain=Y; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "SpaceX is privately held with minimal public disclosure (no SEC filings, earnings calls, or analyst scrutiny), and this row's own findings are limited to a pointer to the Starlink row.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 5/30 (ai_training_on_user_data+5) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING → No Mid-Atlantic statute names model training; MD purpose-limitation/minimization and VA purpose-specification duties are the closest hooks — argue secondary use\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "SpaceX  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your right to take them to court. Disputes go to private arbitration.\n\nTHE DOCUMENT DOES NOT TAKE: your biometric identifiers.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using SpaceX you gave up your content used as AI training data and your right to sue. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "See the Starlink row in Internet Providers for the consumer-facing analysis, including the tiering finding that the stronger privacy commitments attach to Enterprise and Government tiers rather than to households. SpaceX is also privately held, which means substantially less public disclosure than a listed company of comparable scale - no SEC filings, no earnings calls, no analyst scrutiny. Absence of findings here reflects that opacity.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Misc Remainder", "_row_id": 1049, "_entity_id": 1416, "_entity_slug": "spacex", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Corteva", "Category": "Food Production", "Terms & Conditions URL": "See Corteva's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Corteva's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected where a direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Indianapolis", "HQ State": "Indiana", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Indiana' is a non-DMV US state", "Parent / Ultimate Owner": "Corteva, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Indiana SOS INBiz — inbiz.in.gov/BOS/Home/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Corteva, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] Corteva's digital agronomy platforms collect detailed field-level farm data, raising an unresolved question of who owns a grower's own yield data.\nWHAT THE TERMS SAY: The tracker states Corteva's digital agronomy platforms collect detailed field-level farm data, raising a real and underexamined ownership question for growers over who owns the yield data generated on their own land.\nWHY IT MATTERS: Growers using these platforms may not control or own data describing their own operations; the tracker notes this parallels a separately-documented finding for John Deere, mentioned here only as context.\n(evidence: SCARY; Inferred from tracker text (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Corteva has no direct consumer relationship or consumer terms; only the grower data-ownership note from the SCARY field is a distinct, company-specific concern, and arbitration/fees are both unconfirmed or not itemized this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=N; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=N; litigation=N; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer relationship or terms exist; the single item is a grower data-ownership question raised in the SCARY field, not a confirmed policy.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 9/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Corteva  <-  Corteva, Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Agricultural seed and crop protection. No consumer relationship. Corteva's digital agronomy platforms do collect detailed field-level farm data, which raises a real and underexamined ownership question for growers — who owns the yield data generated on your own land — that parallels the John Deere finding.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Misc Remainder", "_row_id": 1050, "_entity_id": 1418, "_entity_slug": "corteva", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Medline", "Category": "Medical Devices", "Terms & Conditions URL": "See Medline's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Medline's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected where a direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B (medical supply manufacturer/distributor to healthcare providers) with no direct consumer relationship; Data Sharing, Arbitration, and Finding Type fields all confirm no consumer terms exist to assess.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=N; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer-facing terms exist to review; only B2B commercial agreements with business customers apply.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Medline  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Medical supply manufacturer and distributor to healthcare providers, including many small practices and long-term care facilities. No consumer relationship, but it sits inside the healthcare supply chain alongside the Owens & Minor and Henry Schein rows, and supply disruption is a patient-care issue rather than a data one.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Misc Remainder", "_row_id": 1051, "_entity_id": 1419, "_entity_slug": "medline", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Solventum", "Category": "Medical Products and Equipment", "Terms & Conditions URL": "See Solventum's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Solventum's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected where a direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2024", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B (healthcare business separated from 3M in 2024: wound care, dental, health information systems) with no direct consumer relationship; the health information software line sits in the HIPAA business-associate perimeter but still has no consumer terms to assess.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=N; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer-facing terms exist to review; the company's own record should not be conflated with 3M's per the tracker note.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Solventum  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The healthcare business separated from 3M in 2024 — wound care, dental and health information systems. The health information software line is the notable part: it processes clinical documentation for providers, which places it inside the HIPAA business-associate perimeter even though it has no consumer relationship. Do not conflate its record with 3M's.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Misc Remainder", "_row_id": 1052, "_entity_id": 1420, "_entity_slug": "solventum", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fidelity National Information", "Category": "Financial Data Services", "Terms & Conditions URL": "See Fidelity National Information's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Fidelity National Information's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach. Fidelity National Information primarily serves institutional/business customers or, where it does reach individual consumers (e.g., waste/recycling collection service, apparel brands, RVs), typically through a simpler transactional relationship (a monthly service bill or a retail purchase) rather than an ongoing account relationship comparable to a bank or social media platform.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected where a direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] FIS and Fiserv together provide core banking infrastructure to a large share of US banks and credit unions\nWHAT THE TERMS SAY: The tracker states FIS is the other half of the finding recorded in the Fiserv row: together, FIS and Fiserv provide core processing, card issuing and digital banking infrastructure to a very large share of American banks and credit unions.\nWHY IT MATTERS: A consumer's own bank can be flawless and their data exposure still runs through FIS, a company they have never heard of, cannot evaluate, and have no relationship with.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one substantive item found; Data Sharing and Arbitration fields both state no specific lawsuit, breach, or arbitration terms were independently confirmed this pass.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=?", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The structural infrastructure role is clearly stated, but Data Sharing and Arbitration are both marked not independently confirmed this pass.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No flag-specific hook stated in tracker text. Baseline rights still apply to any MD/VA resident: access, correct, delete, portability (MODPA / VCDPA). DC residents: no comprehensive statute — CPPA only.", "Entity Type": "Company", "Ownership Path": "Fidelity National Information  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Fidelity National Information takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "FIS is the other half of the finding recorded in the Fiserv row: together they provide core processing, card issuing and digital banking infrastructure to a very large share of American banks and credit unions. A consumer's bank can be flawless and their exposure still runs through FIS, a company they have never heard of, cannot evaluate and have no relationship with. TRACKER NOTE: FIS should not be confused with Fidelity Investments or Fidelity National Financial - three unrelated companies with confusingly similar names, all appearing in or adjacent to this tracker.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Misc Remainder", "_row_id": 1053, "_entity_id": 1421, "_entity_slug": "fidelity-national-information", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "International Flavors & Fragrances", "Category": "Chemicals", "Terms & Conditions URL": "See International Flavors & Fragrances's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See International Flavors & Fragrances's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "B2B — flavors and fragrances sold to CPG manufacturers. No consumer-facing products.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B (flavors and fragrances sold to CPG manufacturers) with no consumer-facing products; the tracker itself frames the label-disclosure gap as a regulatory question rather than a data one.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=N; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist to review; the only notable gap raised (fragrance trade-secret non-disclosure) is a regulatory issue, not a data one.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "International Flavors & Fragrances  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Flavour and fragrance ingredients sold to food, beverage and consumer products manufacturers. No consumer relationship. IFF's formulations are in products consumers use daily while remaining entirely invisible on the label, since fragrance composition is generally protected as trade secret — a disclosure gap that is a regulatory question rather than a data one.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Misc Remainder", "_row_id": 1054, "_entity_id": 1422, "_entity_slug": "international-flavors-fragrances", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Mohawk Industries", "Category": "Home Equipment, Furnishings", "Terms & Conditions URL": "See Mohawk Industries's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Mohawk Industries's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach. Mohawk Industries primarily serves institutional/business customers or, where it does reach individual consumers (e.g., waste/recycling collection service, apparel brands, RVs), typically through a simpler transactional relationship (a monthly service bill or a retail purchase) rather than an ongoing account relationship comparable to a bank or social media platform.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected where a direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Calhoun", "HQ State": "Georgia", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Georgia' is a non-DMV US state", "Parent / Ultimate Owner": "Mohawk Industries, Inc.", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Georgia SOS eCorp — ecorp.sos.ga.gov/BusinessSearch. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Mohawk Industries, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — The tracker explicitly states no consumer terms exist for Mohawk: consumers encounter the product but contract with the installer or retailer, so warranty friction runs through a dealer rather than the manufacturer.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer terms exist per the tracker; the consumer-facing relationship runs through a dealer, not Mohawk.", "Exposure Score (0-100)": 2, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Mohawk Industries  <-  Mohawk Industries, Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Flooring manufacturer selling through retailers and contractors. Consumers encounter the product but contract with the installer or store, so warranty friction — the main consumer complaint in this category — runs through a dealer rather than the manufacturer. No consumer terms exist.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Misc Remainder", "_row_id": 1055, "_entity_id": 1424, "_entity_slug": "mohawk-industries", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "VF", "Category": "Apparel", "Terms & Conditions URL": "See VF's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See VF's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "VF Corporation's Dec 2023 ALPHV/BlackCat ransomware breach exposed ~35.5M consumers' data. VF stated no SSNs, bank accounts, or payment cards were compromised. VF's loyalty programs across 5 major brands collectively create a cross-brand purchase profile that individual brand interactions don't reveal.", "Arbitration / Class Action Waiver": "MANDATORY binding arbitration with class action waiver. VF's website ToS cover all VF brands (The North Face, Vans, Timberland, Dickies, Supreme). 30-day opt-out. A consumer buying from thenorthface.com is bound by VF Corporation's arbitration clause, not a brand-specific one.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Denver", "HQ State": "Colorado", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.securityweek.com/vf-corp-says-data-breach-resulting-from-ransomware-attack-impacts-35-million/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Colorado' is a non-DMV US state", "Parent / Ultimate Owner": "VF Corporation", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): Colorado SOS Business Search — sos.state.co.us/biz/BusinessEntityCriteria. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: VF Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-02-15 (6mo — severity 5 routine cadence)", "Top Troubling #1": "[CONFIRMED_BREACH · FL-2] VF's Dec 2023 ransomware breach exposed data for roughly 35.5 million consumers across its brand family.\nWHAT THE TERMS SAY: The Dec 2023 ALPHV/BlackCat ransomware attack exposed approximately 35.5 million consumers' data; VF stated no SSNs, bank accounts, or payment cards were compromised, per the tracker.\nWHY IT MATTERS: Tens of millions of shoppers across North Face, Vans, Timberland, Dickies and Supreme had personal data compromised, and the breach also disrupted holiday order fulfillment.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[FORCED_ARBITRATION · FL-3] One arbitration clause in VF's corporate ToS binds shoppers across five separate-feeling brands.\nWHAT THE TERMS SAY: VF's website terms impose mandatory binding arbitration with a class-action waiver across all VF brands (The North Face, Vans, Timberland, Dickies, Supreme), with a 30-day opt-out window.\nWHY IT MATTERS: A consumer buying from thenorthface.com is bound by VF Corporation's arbitration clause, not a brand-specific one, and loses the right to sue or join a class action unless they opt out within 30 days.\n(evidence: Arbitration; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Loyalty programs across five VF brands quietly merge into one cross-brand purchase profile.\nWHAT THE TERMS SAY: VF's loyalty programs across its five major brands collectively create a cross-brand purchase profile that individual brand interactions don't reveal, per the tracker.\nWHY IT MATTERS: A shopper who thinks they have separate relationships with North Face, Vans, Timberland, Dickies and Supreme is actually building one consolidated purchase history under a single parent company.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from tracker text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=Y; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The breach, arbitration terms, and cross-brand data sharing are all clearly stated and specific in the tracker.", "Exposure Score (0-100)": 48, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 24, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 24/30 (forced_arbitration+12, class_action_waiver+9, optout_30d+3) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 20/20 (severity5+20) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "VF  <-  VF Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using VF you gave up your data shared corporate-wide, your right to sue, and your right to join a class action. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "VF Corporation - The North Face, Vans, Timberland, Dickies - disclosed a major breach affecting a very large number of consumers, with reporting citing on the order of 35 million records, that disrupted order fulfilment during the holiday season. The multi-brand structure is the note: a customer with accounts at what feel like four unrelated outdoor and apparel brands has one profile with one parent, and one incident reaches all of them.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Misc Remainder", "_row_id": 1056, "_entity_id": 1426, "_entity_slug": "vf", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "THOR Industries", "Category": "Motor Vehicles & Parts", "Terms & Conditions URL": "See THOR Industries's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See THOR Industries's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach. THOR Industries primarily serves institutional/business customers or, where it does reach individual consumers (e.g., waste/recycling collection service, apparel brands, RVs), typically through a simpler transactional relationship (a monthly service bill or a retail purchase) rather than an ongoing account relationship comparable to a bank or social media platform.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected where a direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Data breach", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-08-17 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[OTHER · FL-4] THOR's RV buyers' financing dossier and data live with the dealer, not the manufacturer.\nWHAT THE TERMS SAY: THOR sells RVs through independent dealers; the tracker states the purchase, its financing dossier, and any associated data sit with the dealer rather than THOR directly, comparing the structure to the dealer-network exposure documented in the (separate) CDK breach in the F500 Auto & Dealerships tab.\nWHY IT MATTERS: A consumer's financial and personal data tied to an RV purchase is held by a dealer network THOR doesn't directly control, creating the same third-party exposure pattern that made another company's breach consequential — though no breach specific to THOR itself is confirmed here.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one substantive item found; Data Sharing and Arbitration fields are both unconfirmed this pass, and the SCARY field states THOR has no direct consumer relationship — the CDK comparison is another company's finding, not a confirmed breach of THOR itself.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data Sharing and Arbitration are both marked not confirmed this pass, and THOR itself has no direct consumer relationship or terms.", "Exposure Score (0-100)": 8, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "THOR Industries  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Recreational vehicle manufacturer selling through independent dealers. The purchase, its financing dossier and any data sit with the dealer, mirroring the structure that made CDK's breach so consequential in the F500 Auto & Dealerships tab. No direct consumer relationship.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "No", "_tab": "F500 Misc Remainder", "_row_id": 1057, "_entity_id": 1427, "_entity_slug": "thor-industries", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "SpartanNash", "Category": "Wholesalers: Food and Grocery", "Terms & Conditions URL": "See SpartanNash's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See SpartanNash's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach. SpartanNash primarily serves institutional/business customers or, where it does reach individual consumers (e.g., waste/recycling collection service, apparel brands, RVs), typically through a simpler transactional relationship (a monthly service bill or a retail purchase) rather than an ongoing account relationship comparable to a bank or social media platform.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected where a direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2025", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] SpartanNash supplies US military commissaries, whose purchases are tied to a military ID\nWHAT THE TERMS SAY: SpartanNash is a major supplier to US military commissaries, so its operations touch service member households whose commissary purchases are tied to a military ID, per the tracker.\nWHY IT MATTERS: Service member households have documented elevated exposure to identity theft and targeted financial predation, so purchase data tied to a military ID carries added risk if mishandled.\n(evidence: SCARY; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-4] SpartanNash's 2025 acquisition by C&S Wholesale Grocers will move its customer and supplier data to a new private parent.\nWHAT THE TERMS SAY: SpartanNash agreed to be acquired by C&S Wholesale Grocers in 2025, which the tracker notes will move that customer and supplier data to a new private parent.\nWHY IT MATTERS: Customers and suppliers whose data was collected under SpartanNash's practices have no say as that data moves under new private ownership with potentially different practices.\n(evidence: SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two substantive items found; Arbitration and Fees fields are both unconfirmed/not itemized this pass, so no third distinct consumer harm is documented.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The SCARY field gives specific, concrete facts, but Arbitration and Fees remain unconfirmed this pass.", "Exposure Score (0-100)": 9, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "SpartanNash  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using SpartanNash you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Food distributor and grocery retailer that is also a major supplier to US military commissaries, so its operations touch service member households — a population with documented elevated exposure to identity theft and targeted financial predation, and one whose commissary purchases are tied to a military ID. SpartanNash agreed to be acquired by C&S Wholesale Grocers in 2025, which will move that customer and supplier data to a new private parent.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Misc Remainder", "_row_id": 1058, "_entity_id": 1428, "_entity_slug": "spartannash", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "ABM Industries", "Category": "Diversified Outsourcing Services", "Terms & Conditions URL": "See ABM Industries's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See ABM Industries's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected where a direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'New York' is a non-DMV US state", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): NY DOS Corporation & Business Entity Database — apps.dos.ny.gov/publicInquiry. Search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand. Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B (janitorial, parking, facility services under contract to building owners) with no direct consumer relationship; the license-plate-recognition item referenced is a finding about a separate company (Colonial Parking/SP+), not ABM, and ABM's workplace-monitoring exposure is procured by its clients, not ABM's own customers.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=N; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer-facing terms exist to review; ABM's data practices are governed by B2B commercial agreements with building owners.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "ABM Industries  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Janitorial, parking and facility services under contract to building owners. Its parking operations sit adjacent to the licence plate recognition finding in the Colonial Parking/SP+ row, and its janitorial workforce is subject to workplace monitoring systems procured by the client — in both cases the people generating data are not ABM's customers.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Misc Remainder", "_row_id": 1059, "_entity_id": 1429, "_entity_slug": "abm-industries", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "APi", "Category": "Engineering & Construction", "Terms & Conditions URL": "See APi's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See APi's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected where a direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B (fire safety, security, and specialty services for commercial/industrial clients) with no direct consumer relationship; camera and access-control recordings are governed by the building owner's policy, not APi's own consumer terms.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=N; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer-facing terms exist to review; APi's data practices are governed by B2B commercial agreements with client businesses.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "APi  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Fire safety, security and specialty services for commercial and industrial clients. Small-business relevant as a contractor. Its security installations include camera and access control systems whose recordings are governed by the building owner's policy, not the occupants'.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Misc Remainder", "_row_id": 1060, "_entity_id": 1430, "_entity_slug": "api", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Andersons", "Category": "Food Production", "Terms & Conditions URL": "See Andersons's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See Andersons's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected where a direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B (agricultural commodity trading, grain merchandising, plant nutrients serving farmers and processors) with no consumer relationship; the tracker notes any individual-level data concerns grower accounts, which sit outside consumer privacy law.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=N; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer-facing terms exist to review; Andersons' data practices concern grower accounts outside consumer privacy law.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "Andersons  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Agricultural commodity trading, grain merchandising and plant nutrients serving farmers and processors. No consumer relationship. Its individual-level data concerns grower accounts, which sit outside consumer privacy law entirely.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Misc Remainder", "_row_id": 1061, "_entity_id": 1431, "_entity_slug": "andersons", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "American Financial", "Category": "Insurance: Property and Casualty (Stock)", "Terms & Conditions URL": "See American Financial's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See American Financial's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "Not independently confirmed this pass with a specific named data-privacy lawsuit or breach. American Financial primarily serves institutional/business customers or, where it does reach individual consumers (e.g., waste/recycling collection service, apparel brands, RVs), typically through a simpler transactional relationship (a monthly service bill or a retail purchase) rather than an ongoing account relationship comparable to a bank or social media platform.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected where a direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Data Sharing and Arbitration fields are both unconfirmed this pass; the SCARY field's multi-decade annuity retention point is explicitly cross-referenced to other life-insurer rows (not a finding about American Financial specifically), and the annuity sales-practice scrutiny it describes is framed as a generic industry/regulatory pattern rather than a company-specific term.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Data Sharing and Arbitration are both unconfirmed, and the only SCARY content is either cross-referenced to other rows or generic industry context.", "Exposure Score (0-100)": 2, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ENTITY-LEVEL EXEMPTION LIKELY → MODPA and VCDPA exempt GLBA-regulated financial institutions and HIPAA covered entities at the ENTITY level (retrieved 2026-08-29). For a bank, credit union, insurer, lender or health provider the state-privacy hooks below may NOT apply; the working routes are the GLBA privacy notice opt-outs, HIPAA rights via HHS OCR, and the general consumer-protection acts. Confirm the exemption before citing.", "Entity Type": "Company", "Ownership Path": "American Financial  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, American Financial takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "American Financial Group writes specialty property and casualty lines and annuities through Great American. The annuity business carries the multi-decade retention profile noted across the life insurer rows, and annuity sales practices to older buyers are a recurring focus of state insurance regulators and FINRA — suitability rather than privacy, but the harm that actually reaches customers in this product category.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Misc Remainder", "_row_id": 1062, "_entity_id": 1432, "_entity_slug": "american-financial", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "XPO", "Category": "Transportation and Logistics", "Terms & Conditions URL": "See XPO's own published terms of service", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See XPO's own published privacy policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "B2B company — no direct consumer data collection. Data practices governed by commercial agreements with business customers, not consumer privacy policies.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected where a direct consumer relationship exists.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not applicable to consumer notice - B2B row", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "0 of 3 identified — Row is B2B (less-than-truckload freight carrier serving business shippers) with no consumer relationship; where residential delivery occurs, the tracker states the consumer's contract is with the retailer that arranged shipment, not XPO.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=N; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No consumer-facing terms exist to review; XPO's relationship is with business shippers, not consumers.", "Exposure Score (0-100)": 0, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "N/A — no consumer relationship; state privacy statutes give the resident no request rights against this entity", "Entity Type": "Company", "Ownership Path": "XPO  <-  Not determined this pass", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Less-than-truckload freight carrier serving business shippers, including many small businesses moving palletised goods. No consumer relationship — though residential delivery of large items does occur, in which case the consumer's contract is with the retailer that arranged the shipment rather than with XPO.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "F500 Misc Remainder", "_row_id": 1063, "_entity_id": 1433, "_entity_slug": "xpo", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Bend", "Category": "Wellness/Fitness (stretching app)", "Terms & Conditions URL": "bend.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "bend.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Developed by Bowery Digital (operating as 'Bend Health & Fitness, Inc.'). Its own App Store privacy label discloses data 'may be used to TRACK YOU ACROSS APPS AND WEBSITES owned by other companies' — a genuine cross-app tracking disclosure for what looks like a simple stretching-routine app. Bend also integrates with Apple Health, letting it sync a user's broader health/activity data if enabled. No specific named lawsuit or breach independently confirmed this pass.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Free and paid ('Member') tiers; specific subscription pricing not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification beyond the app-store privacy label; the cross-app tracking disclosure is worth flagging given how innocuous a stretching app seems on its surface.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] A basic stretching app discloses it may track users across other companies' apps and websites.\nWHAT THE TERMS SAY: Bend's own App Store privacy label discloses that data 'may be used to TRACK YOU ACROSS APPS AND WEBSITES owned by other companies,' per the tracker.\nWHY IT MATTERS: Users of what looks like a simple stretching-routine app are subject to the same cross-app ad-tracking disclosure typically associated with social networks or ad-tech companies.\n(evidence: Data Sharing | SCARY; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Bend can sync a user's broader Apple Health data, not just stretching activity, when the integration is enabled.\nWHAT THE TERMS SAY: Bend integrates with Apple Health, letting it sync a user's broader health/activity data if enabled, per the tracker.\nWHY IT MATTERS: A user who enables the integration may be sharing more sensitive health data with a cross-app-tracking company than the stretching-app use case suggests.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two substantive items found; Arbitration is not confirmed this pass and subscription pricing is not itemized, so no third distinct item is documented.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The App Store privacy label discloses concrete tracking practices, but Arbitration terms and subscription pricing remain unconfirmed this pass.", "Exposure Score (0-100)": 9, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "App / Service", "Ownership Path": "Bend  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Bend you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A simple stretching-routine app discloses that your data 'may be used to track you across apps and websites owned by other companies' — the same cross-app tracking language you'd expect from a social network or ad-tech company, attached here to an app whose whole purpose is showing you how to touch your toes.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Phone List Follow-Ups", "_row_id": 1064, "_entity_id": 1434, "_entity_slug": "bend", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "InnerNow (Chopra Enterprises)", "Category": "Meditation/Wellness", "Terms & Conditions URL": "innernow.com/policies/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "innernow.com/policies/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "InnerNow is operated by Chopra Enterprises Corporation (the wellness company associated with Deepak Chopra) — its own App Store privacy label discloses data 'used to track you across apps and websites owned by other companies,' AND separately discloses collecting Health & Fitness data, Contact Info, User Content, and Identifiers all LINKED TO THE USER'S IDENTITY. This is the same general wellness/meditation-app data-sharing risk category documented for Calm and Headspace elsewhere in this tracker (Consumer Apps tab).", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Free with in-app purchases; annual subscription with a 7-day free trial mentioned in App Store listing.", "Notes": "See the Calm/Headspace rows (Consumer Apps tab) for the fullest treatment of the shared meditation-app data-sharing risk pattern that applies here too — InnerNow's identity-linked Health & Fitness data collection is a notable specific data point given how personal that category can be.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "AI-written Aug 2026 (R8) — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "2022", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] InnerNow's privacy label discloses tracking users across other companies' apps and websites.\nWHAT THE TERMS SAY: InnerNow's own App Store privacy label discloses that data is 'used to track you across apps and websites owned by other companies,' per the tracker.\nWHY IT MATTERS: Meditation and wellness app users are subject to third-party ad-tracking disclosures typically associated with non-wellness platforms.\n(evidence: Data Sharing; Stated in tracker (fidelity-verified OK, 2 passes))", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] InnerNow collects Health & Fitness data, contacts, user content and identifiers all linked to your identity.\nWHAT THE TERMS SAY: InnerNow's privacy label separately discloses collecting Health & Fitness data, Contact Info, User Content, and Identifiers, all linked to the user's identity, per the tracker.\nWHY IT MATTERS: Health & Fitness data from a meditation app is tied directly to an identifiable user rather than being anonymized or aggregated.\n(evidence: Data Sharing; Stated in tracker (fidelity pass 2 (strict): Overstated corrected))", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 identified — Only two substantive items found; the SCARY field explicitly states 'nothing confirmed this pass' beyond generic wellness-app industry context (a Mozilla review, cross-referenced to the Wellness & Meditation Apps tab and the Calm/Headspace rows), and Arbitration remains unconfirmed.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The App Store privacy label gives concrete disclosures, but Arbitration is unconfirmed and the SCARY field itself states nothing company-specific was confirmed this pass.", "Exposure Score (0-100)": 9, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 7, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 7/30 (shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "InnerNow (Chopra Enterprises)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using InnerNow (Chopra Enterprises) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Nothing confirmed this pass. InnerNow sits in the meditation and wellness app category where Mozilla's 2022 review gave 29 of 32 apps a warning label and concluded the sector was worse than any other product category for privacy and security - the spine documented in the Wellness & Meditation Apps tab. Celebrity-affiliated wellness apps also blur the line between content and health guidance, and check-in and mood features collect emotional-state data users experience as part of the practice rather than as collection. Recommend a follow-up on the app's third-party SDK inventory, which is where Mozilla located most of the category's exposure.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Phone List Follow-Ups", "_row_id": 1065, "_entity_id": 1435, "_entity_slug": "innernow-chopra-enterprises", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CloZ (AI Stylist/Digital Wardrobe)", "Category": "Fashion/Lifestyle", "Terms & Conditions URL": "See app's published Terms of Use (French-market app; exact URL not independently confirmed this pass)", "T&C Direct PDF?": "NOT CONFIRMED", "Privacy Policy URL": "See app's published Privacy Policy", "Privacy Direct PDF?": "NOT CONFIRMED", "Data Sharing/Selling Flags": "CloZ is an AI-powered personal stylist app that digitizes a user's wardrobe from photos of their real clothing to generate outfit suggestions — meaning it necessarily processes photos of the user's actual belongings and, often, themselves wearing those items. No specific named lawsuit or breach independently confirmed this pass; this app appears to be primarily France-market-facing based on listing language.", "Arbitration / Class Action Waiver": "Not independently confirmed this pass — standard binding arbitration + class action waiver expected.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recommend a direct follow-up given thin verification this pass; the photo-based wardrobe-digitization feature is a distinctive data category (personal photos of belongings/self) worth understanding retention practices for specifically.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-08-04", "Provenance (who determined this)": "Original tracker build — origin not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Unspecified", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "No HQ data on file - cannot classify", "Parent / Ultimate Owner": "Not determined this pass", "Years Referenced in Finding (heuristic)": "No year mentioned in SCARY text", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — HQ state unknown", "Registered Agent Address / Service Notes": "Registered agent NOT yet determined. HQ state is not on file for this row, so the correct state registry cannot be identified. Fill HQ State first, then look up the agent on that state's business-entity registry.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-02-15 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-2] CloZ's AI stylist ingests photos of your actual clothes and often yourself wearing them, with retention largely unverified.\nWHAT THE TERMS SAY: To function, CloZ requires uploading photos of the user's actual clothing, and often themselves wearing those items, into its AI wardrobe-digitization system; the tracker notes very little independently verifiable information on how long those photos are kept or who else might see them.\nWHY IT MATTERS: A wardrobe app becomes a photo library of a user's closet and potentially themselves, with retention and third-party access largely unconfirmed.\n(evidence: Data Sharing | SCARY; Tracker says unconfirmed (fidelity-verified OK, 2 passes))", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — Only one substantive item found; Arbitration is not confirmed this pass, Fees are not itemized, and no specific breach or lawsuit is confirmed — only the photo-retention concern is substantive.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=N; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Retention and third-party access practices for uploaded photos are explicitly described as unverified, and Arbitration/Fees fields are unconfirmed.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 3, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 3/30 (sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BREACH / SENSITIVE EXPOSURE → DC: breach notice \"most expedient time possible\", AG notice at 50+ residents, CPPA PRIVATE RIGHT OF ACTION; MD/VA: state breach-notice laws + AG complaint", "Entity Type": "Company", "Ownership Path": "CloZ (AI Stylist/Digital Wardrobe)  <-  Not determined this pass", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, CloZ (AI Stylist/Digital Wardrobe) takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "To use CloZ as designed, you upload photos of your actual clothes — and often yourself wearing them — into an AI system, with very little independently verifiable information available about how long those photos are kept or who else might see them. A wardrobe app quietly becomes a photo library of your closet and, potentially, you.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Phone List Follow-Ups", "_row_id": 1066, "_entity_id": 1436, "_entity_slug": "cloz-ai-stylist-digital-wardrobe", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Samsung Electronics America (Samsung TVs / Tizen)", "Category": "Smart TV Platform", "Terms & Conditions URL": "samsung.com/us/Legal/SamsungLegal-SmartTV/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "samsung.com/us/account/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Samsung's ACR product is branded Viewing Information Services. Texas AG Ken Paxton sued Samsung on 15 December 2025 (announced 18 December) alleging it used ACR to identify on-screen content -- broadcast, streaming apps, game consoles and anything cast or mirrored from a phone -- and monetised the resulting profile without informed consent. The state alleged the consent flow was a dark pattern requiring as many as 200 clicks across nested menus to reach the relevant privacy disclosure. Samsung SETTLED FIRST, on 26 February 2026: it must stop collecting or processing ACR viewing data from Texas consumers without express prior consent, and must rebuild the on-screen setup flow so the choice is prominent rather than buried. NO MONETARY PENALTY was assessed -- the remedy is entirely forward-looking conduct and UI. Samsung denies its practices violated any regulation. Reporting indicates Samsung emailed Smart TV customers in May 2026 confirming ACR collects viewing history, a Personalized Service ID and the IP address, while stating it does not collect the video itself.", "Arbitration / Class Action Waiver": "Not verified this pass. Samsung has historically used arbitration with an opt-out in its US mobile terms; the Smart TV / Samsung Account terms were not fetched this pass and MUST NOT be assumed to match. Flagged for Tranche 2. Note that the Texas settlement is an AG action and was never subject to any consumer arbitration clause -- that is precisely why it reached a remedy.", "Fees / Billing Flags": "Not itemized this pass. Note the structural fee point: the panel is sold at or below cost and the operating system is the profit centre, so \"fees\" for a smart TV are largely paid in viewing data rather than dollars.", "Notes": "Samsung is the volume leader in US TV sales, which makes the 26 February 2026 settlement the single most consequential ACR remedy so far -- but it binds Samsung only as to TEXAS consumers. A Maryland, Virginia or DC household gets no benefit from it and must still switch Viewing Information Services off by hand. That asymmetry is the reportable story for a Mid-Atlantic readership.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Ridgefield Park", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.texasattorneygeneral.gov/news/releases", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Samsung Electronics Co., Ltd. (KRX: 005930)", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Samsung Electronics Co., Ltd. (KRX: 005930)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "[REGULATORY_ACTION_PRIVACY · FL-1] Texas alleged Samsung buried the ACR privacy disclosure roughly 200 clicks deep; Samsung settled on 26 Feb 2026\nWHAT THE TERMS SAY: The Texas AG alleged Samsung steered consumers into enabling ACR through unclear setup disclosures and made opting out difficult across fragmented, multi-step menus -- as many as 200 clicks to reach the disclosure. The February 2026 settlement requires express prior consent before ACR collection or processing for Texas consumers, plus clear and conspicuous disclosure and consent screens.\nWHY IT MATTERS: No monetary penalty was assessed, and the order reaches Texas consumers only -- an identical Samsung TV in Maryland still ships with the same default.\n(evidence: Texas AG press release and settlement coverage, Feb-Mar 2026)", "Top Troubling #2": "[DATA_SALE · FL-1] The screen itself is the sensor: ACR reads game consoles, HDMI inputs and phone casting, not just the TV apps\nWHAT THE TERMS SAY: The Texas complaints describe ACR capturing what is on screen regardless of source -- broadcasts, streaming apps, game consoles, and content cast or mirrored from a phone -- with the resulting profile sold into ad targeting.\nWHY IT MATTERS: A privacy-chosen device plugged into the HDMI port is fingerprinted by the panel it is plugged into, so choosing a private streaming stick does not escape the TV underneath it.\n(evidence: Texas AG filings, December 2025)", "Top Troubling #3": "[DARK_PATTERN_CONSENT · FL-2] Samsung ships ACR on by default and confirms it collects viewing history, a service ID and IP address\nWHAT THE TERMS SAY: Reporting on Samsung customer emails in May 2026 states ACR collects viewing history, a Personalized Service ID and the IP address; Samsung says the video itself is not collected and that the opt-out has always been available.\nWHY IT MATTERS: An always-available opt-out that nobody is shown is functionally different from a choice, which is the exact defect the Texas consent screen is meant to cure.\n(evidence: Samsung customer notice reporting, May 2026; secondary)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The conduct, the dates, the remedy and the absence of a fine are all documented in a signed state settlement.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Samsung Electronics America (Samsung TVs / Tizen)  <-  Samsung Electronics Co., Ltd. (KRX: 005930)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Samsung Electronics America (Samsung TVs / Tizen) you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Texas sued Samsung in December 2025 alleging its TVs run software that can grab a screenshot of your display roughly TWICE EVERY SECOND -- and that Samsung buried the disclosure so deep it took around 200 CLICKS through nested menus to reach it. Samsung settled on 26 February 2026 and must now get express consent from Texas viewers. It paid NO FINE. And the order covers TEXAS ONLY: the identical television sold in Maryland, Virginia or DC still ships with Viewing Information Services enabled, so a DMV household gets none of the protection Texans just won and has to go turn it off themselves.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1067, "_entity_id": 1438, "_entity_slug": "samsung-electronics-america-samsung-tvs-tizen", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "LG Electronics U.S.A. (LG TVs / webOS)", "Category": "Smart TV Platform", "Terms & Conditions URL": "lg.com/us/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "lg.com/us/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "LG's ACR feature is branded Live Plus. LG was one of five manufacturers sued by Texas on 15 December 2025 over ACR collection without meaningful consent. LG settled on 11 May 2026, formalised as an Agreed Final Judgment in State of Texas v. LG Electronics U.S.A., Inc. The core requirement matches Samsung's: express consent before ACR collection, plus a pop-up disclosure on LG televisions explaining how viewing data may be collected and used, with a clear opt-out. As with Samsung, NO MONETARY FINE was assessed. LG also operates LG Ad Solutions, the in-house advertising arm built on the Alphonso acquisition, which is the commercial destination for the viewing signal -- meaning the manufacturer and the ad-tech buyer are the same corporate group.", "Arbitration / Class Action Waiver": "Not verified this pass. LG US terms were not fetched; do not assume a clause either way. Queued for Tranche 2.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "LG is the second of the five Texas defendants to fold, and the second to pay nothing. Two settlements with zero dollars attached is itself the finding: the enforcement price of a decade of undisclosed viewing collection has so far been a UI change. Worth pairing with the Vizio 2017 FTC number ($2.2M) to show the trend line is DOWN, not up.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Englewood Cliffs", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.texasattorneygeneral.gov/news/releases", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "LG Electronics Inc. (KRX: 066570)", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: LG Electronics Inc. (KRX: 066570)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "[REGULATORY_ACTION_PRIVACY · FL-1] LG signed an Agreed Final Judgment with Texas on 11 May 2026 requiring express consent before Live Plus collects viewing data\nWHAT THE TERMS SAY: State of Texas v. LG Electronics U.S.A., Inc. was resolved by Agreed Final Judgment on 11 May 2026, requiring express consent before ACR collection and a pop-up disclosure on LG televisions explaining how viewing data may be collected and used, with a clear opt-out.\nWHY IT MATTERS: Like the Samsung order it carries no monetary penalty and binds LG only as to Texas consumers.\n(evidence: Texas AG / National Law Review coverage of the LG judgment, May 2026)", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] LG both collects the viewing signal and owns the ad business that monetises it\nWHAT THE TERMS SAY: LG operates LG Ad Solutions, its in-house connected-TV advertising arm, alongside the Live Plus ACR feature on its own panels.\nWHY IT MATTERS: When the collector and the buyer sit inside one corporate group, an \"we do not sell your data to third parties\" style assurance can be literally true while the data is still fully monetised in-house.\n(evidence: Structural reading of LG corporate disclosures; not independently confirmed against LG contract text this pass)", "Top Troubling #3": "[DARK_PATTERN_CONSENT · FL-2] Live Plus is enabled through the setup flow rather than affirmatively chosen\nWHAT THE TERMS SAY: Texas alleged the five manufacturers, LG among them, obtained ACR enablement through setup disclosures that did not amount to informed consent; the settlement remedy is a prominent pop-up, which implies the prior disclosure was not prominent.\nWHY IT MATTERS: The remedy describes the defect: consumers outside Texas still meet the pre-settlement flow.\n(evidence: Texas AG filings Dec 2025 and the May 2026 judgment)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "A signed Agreed Final Judgment with a named case caption fixes the date, the parties and the obligation.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "LG Electronics U.S.A. (LG TVs / webOS)  <-  LG Electronics Inc. (KRX: 066570)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using LG Electronics U.S.A. (LG TVs / webOS) you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "LG became the SECOND TV manufacturer to settle with Texas over secret viewing-data collection -- on 11 May 2026 -- and like Samsung it paid NOTHING. The remedy is a pop-up. Meanwhile LG owns BOTH ends of the pipe: Live Plus on the panel collects what you watch, and LG Ad Solutions, LG's own advertising business, sells against it. So a promise not to sell your data to outsiders can be perfectly true while your viewing history is still fully monetised -- it just never has to leave the building.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1068, "_entity_id": 1440, "_entity_slug": "lg-electronics-u-s-a-lg-tvs-webos", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sony Electronics (Bravia TVs / Google TV + Samba)", "Category": "Smart TV Platform", "Terms & Conditions URL": "electronics.sony.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "sony.com/en_us/SCA/legal/privacy-policy.html", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Sony is STILL LITIGATING the December 2025 Texas ACR suit -- it did not settle alongside Samsung (Feb 2026) and LG (May 2026). Sony's Bravia sets run Google TV, so the platform telemetry layer is governed by Google's Usage & Diagnostics regime, while the content-recognition layer on select models is supplied by SAMBA TV, a third-party ACR vendor whose entire business is selling viewing measurement to brands. Sony therefore sits at a three-way seam: Sony's own terms, Google's OS terms, and Samba's separate collection -- three controllers behind one screen.", "Arbitration / Class Action Waiver": "Not verified this pass. Sony Electronics US terms not fetched. Note separately that Sony subsidiary Crunchyroll carries its own active VPPA litigation (see the Streaming Services v59 tab) -- the same ultimate parent appears twice in this workbook for two unrelated video-privacy exposures.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The Sony row is the clearest illustration of why 'TV manufacturer' is the wrong unit of analysis. Sony builds the panel, Google supplies the operating system, and Samba TV supplies the content recognition. Turning off one does not turn off the others, and each has its own policy, its own retention and its own opt-out path.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Diego", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.texasattorneygeneral.gov/news/releases", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Sony Group Corporation (NYSE: SONY)", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Sony Group Corporation (NYSE: SONY)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "[REGULATORY_ACTION_PRIVACY · FL-1] Sony is one of three Texas ACR defendants still litigating after Samsung and LG settled\nWHAT THE TERMS SAY: Texas sued Samsung, LG, Sony, Hisense and TCL on 15 December 2025 over ACR collection. Samsung settled 26 February 2026 and LG on 11 May 2026; Sony, Hisense and TCL remained in litigation. Texas DTPA penalties sought run to $10,000 per violation and $250,000 per violation affecting a consumer aged 65 or older.\nWHY IT MATTERS: An unsettled defendant is under no consent obligation at all, so Sony sets currently offer less protection than the Samsung and LG sets the same state already reached.\n(evidence: Texas AG filings and settlement coverage, Dec 2025 - May 2026)", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Three separate controllers sit behind one Bravia screen: Sony, Google TV and Samba TV\nWHAT THE TERMS SAY: Sony Bravia sets run Google TV, so platform and diagnostics telemetry falls under Google Usage & Diagnostics, while content recognition on select models is provided by third-party ACR vendor Samba TV under its own service disclosures.\nWHY IT MATTERS: Disabling Sony-branded settings does not disable the Google layer or the Samba layer, and a consumer has no single switch that reaches all three.\n(evidence: Sony/Samba support documentation and ACR configuration reporting, 2025-2026; secondary)", "Top Troubling #3": "[DATA_SALE · FL-2] Samba TV's product is selling TV-viewing measurement to brands, and Sony panels are one of its supply sources\nWHAT THE TERMS SAY: Samba TV is described in ACR reporting as powering Sony's content-recognition system and selling viewing data to brands that want to measure whether a TV ad drove a purchase.\nWHY IT MATTERS: The commercial purpose is outcome attribution -- linking what you watched to what you later bought -- which is a materially more identifying use than \"improving recommendations\".\n(evidence: ACR vendor reporting, 2025-2026; not confirmed against a Sony-Samba contract)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Texas action against Sony is documented and dated, but the Sony/Google/Samba division of responsibility is reconstructed from support pages rather than from a contract.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Sony Electronics (Bravia TVs / Google TV + Samba)  <-  Sony Group Corporation (NYSE: SONY)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Sony Electronics (Bravia TVs / Google TV + Samba) you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Sony is one of THREE manufacturers -- with Hisense and TCL -- that did NOT settle with Texas and is still fighting the ACR case, meaning its sets carry no consent obligation at all while Samsung's and LG's now do. And a Sony Bravia is not one privacy decision, it is three: Sony makes the panel, GOOGLE supplies the operating system that logs usage and diagnostics, and SAMBA TV -- a company whose actual product is selling proof to advertisers that a TV ad led you to buy something -- supplies the content recognition on select models. Switching off the Sony-branded setting leaves the other two running.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1069, "_entity_id": 1442, "_entity_slug": "sony-electronics-bravia-tvs-google-tv-samba", "_issuer": "Sony Group Corporation", "_issuer_slug": "sony-group-corporation", "_ticker": "SONY", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "TCL Technology (TCL TVs / Roku TV + Google TV)", "Category": "Smart TV Platform", "Terms & Conditions URL": "tclusa.com/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "tclusa.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "TCL is a December 2025 Texas ACR defendant and has NOT settled. TCL's US sets ship on two different operating systems depending on model line -- Roku TV and Google TV -- so the ACR layer on a TCL panel is usually operated by ROKU (branded Smart TV Experience, which covers over-the-air viewing and HDMI-connected content) or by Google, not by TCL itself. That split matters legally: the entity capturing the viewing signal may not be the entity named on the bezel, and the consumer's opt-out lives in the OS menu rather than in a TCL setting.", "Arbitration / Class Action Waiver": "Not verified this pass. Note that a consumer bringing a claim over a TCL Roku TV may find the operative arbitration clause is ROKU's, accepted at OS setup, rather than TCL's -- a mismatch worth checking before filing anything.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "TCL is also a low-price volume leader, which compounds the structural point: the cheaper the panel, the more of the manufacturer's margin comes from the platform rather than the hardware. Buying the budget set is frequently buying the more advertising-dependent set.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Huizhou", "HQ State": "China (Guangdong)", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": "https://www.texasattorneygeneral.gov/news/releases", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "PRC-domiciled parent; US consumer sales via TCL North America", "Parent / Ultimate Owner": "TCL Technology Group Corporation (SZSE: 000100)", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: TCL Technology Group Corporation (SZSE: 000100)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "[REGULATORY_ACTION_PRIVACY · FL-1] TCL is an unsettled defendant in the December 2025 Texas ACR action\nWHAT THE TERMS SAY: Texas sued TCL alongside Samsung, LG, Sony and Hisense on 15 December 2025 alleging ACR collection and monetisation without meaningful consent. TCL had not settled as of this pass. Texas DTPA penalties sought run to $10,000 per violation and $250,000 per violation affecting a consumer aged 65 or older.\nWHY IT MATTERS: TCL owners have neither the Samsung nor the LG consent remedy and no court has yet ruled on the merits.\n(evidence: Texas AG filings, Dec 2025; settlement status reporting through mid-2026)", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] The ACR on most TCL sets is operated by Roku or Google, not by TCL\nWHAT THE TERMS SAY: TCL US models ship on Roku TV or Google TV depending on line; Roku-powered sets including many TCL models run ACR through Roku's Smart TV Experience, which covers over-the-air viewing and content playing through HDMI.\nWHY IT MATTERS: The company you would complain to about your viewing data is probably not the company whose name is on the television.\n(evidence: Roku and TCL configuration documentation, 2025-2026; secondary)", "Top Troubling #3": "[DATA_SALE · FL-3] Budget panels are sold thin because the operating system is the margin\nWHAT THE TERMS SAY: Industry reporting on the connected-TV market describes sets being sold at or below hardware cost because platform advertising generates the return.\nWHY IT MATTERS: Price shopping for a television is, structurally, shopping for how much advertising infrastructure you are installing.\n(evidence: CTV market reporting, 2024-2026; general industry finding rather than a TCL-specific disclosure)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The Texas action is documented; the OS-split analysis is inferred from configuration guides rather than from TCL contract text.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "TCL Technology (TCL TVs / Roku TV + Google TV)  <-  TCL Technology Group Corporation (SZSE: 000100)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using TCL Technology (TCL TVs / Roku TV + Google TV) you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "TCL is still fighting the Texas ACR case -- no consent order, no remedy. But the sharper problem is that on most TCL sets sold in the US, TCL is NOT the one watching: the panel runs Roku TV or Google TV, and it is ROKU'S Smart TV Experience -- which explicitly covers antenna broadcasts and anything plugged into an HDMI port -- that does the content recognition. So the company named on the bezel, the company you would write to, and the company holding your viewing history are three different answers, and the opt-out is buried in an operating system menu you never associated with the brand you bought.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1070, "_entity_id": 1444, "_entity_slug": "tcl-technology-tcl-tvs-roku-tv-google-tv", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Hisense (Hisense TVs / Google TV + Roku TV + VIDAA)", "Category": "Smart TV Platform", "Terms & Conditions URL": "hisense-usa.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "hisense-usa.com/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Hisense is a December 2025 Texas ACR defendant and has NOT settled. Hisense US sets ship on Google TV or Roku TV depending on line, and Hisense additionally operates its own smart-TV platform, VIDAA, used on some models and licensed to other brands. Hisense also owns the TOSHIBA television brand licence for several markets, so a set badged Toshiba may be a Hisense platform decision. That licensing web means the Hisense privacy posture reaches further than the Hisense nameplate does.", "Arbitration / Class Action Waiver": "Not verified this pass. Additional complication: a PRC-domiciled ultimate parent means a US consumer judgment may be practically difficult to enforce against the group even where the US operating subsidiary is properly served. Treat the US subsidiary as the only realistic defendant.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "VIDAA is the reason Hisense deserves its own row rather than a footnote under Google or Roku: unlike TCL, Hisense runs an in-house OS on part of its range, so on those models Hisense IS the platform operator and the ACR controller, not a tenant.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Qingdao", "HQ State": "China (Shandong)", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "Global", "Primary Source URL": "https://www.texasattorneygeneral.gov/news/releases", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "PRC-domiciled parent; US consumer sales via Hisense USA", "Parent / Ultimate Owner": "Hisense Group Holdings Co., Ltd.", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Hisense Group Holdings Co., Ltd.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "[REGULATORY_ACTION_PRIVACY · FL-1] Hisense is an unsettled defendant in the December 2025 Texas ACR action\nWHAT THE TERMS SAY: Texas named Hisense among five manufacturers alleged to have collected and monetised ACR viewing data without meaningful consent; Hisense had not settled as of this pass. Texas DTPA penalties sought run to $10,000 per violation and $250,000 per violation affecting a consumer aged 65 or older.\nWHY IT MATTERS: Hisense owners have no consent order and no adjudicated merits ruling to rely on.\n(evidence: Texas AG filings, Dec 2025; settlement status through mid-2026)", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] On VIDAA models Hisense is itself the platform operator, not a Google or Roku tenant\nWHAT THE TERMS SAY: Hisense ships Google TV and Roku TV on parts of its US range and operates its own VIDAA smart-TV platform on other models, with VIDAA also licensed to additional brands.\nWHY IT MATTERS: Which company holds your viewing history depends on which Hisense model you bought, and the box does not make that obvious.\n(evidence: Platform configuration reporting, 2025-2026; secondary)", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-3] A PRC-domiciled ultimate parent narrows the practical enforcement route\nWHAT THE TERMS SAY: Hisense Group Holdings is domiciled in the PRC; US consumer sales run through Hisense USA.\nWHY IT MATTERS: Serving and collecting against the US subsidiary is realistic; reaching the group parent generally is not, which affects what a small-claims or class remedy can actually deliver.\n(evidence: Corporate structure; general enforcement observation, not a finding about Hisense conduct)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The regulatory action is dated and specific; the VIDAA and Toshiba-licence structure is drawn from market reporting rather than from Hisense contract text.", "Exposure Score (0-100)": 31, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 15, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 15/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Hisense (Hisense TVs / Google TV + Roku TV + VIDAA)  <-  Hisense Group Holdings Co., Ltd.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Hisense (Hisense TVs / Google TV + Roku TV + VIDAA) you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Hisense is still fighting the Texas ACR case, and it is the one defendant that is ALSO its own platform: alongside Google TV and Roku TV models, Hisense runs its own VIDAA operating system -- and licenses VIDAA to other brands. Hisense also holds the TOSHIBA TV brand licence in several markets. So buying a set that says Toshiba, or a set from a brand you have never heard of, can still mean handing your viewing history to Hisense's platform. And the ultimate parent sits in China, which means that even where a US claim succeeds against the American subsidiary, collecting against the group behind it is a different and much harder problem.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1071, "_entity_id": 1446, "_entity_slug": "hisense-hisense-tvs-google-tv-roku-tv-vidaa", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Vizio (Walmart) / SmartCast + Inscape", "Category": "Smart TV Platform", "Terms & Conditions URL": "vizio.com/en/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "vizio.com/en/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Vizio is the origin case for the entire ACR category. The FTC and the New Jersey AG settled with Vizio in February 2017 for $2.2 million: from February 2014 Vizio sold over 11 million smart TVs with ACR installed and enabled BY DEFAULT, disclosed only through a pop-up that timed out after about a minute referring to programme offers and suggestions, and sold the resulting viewing data to third parties. Per the FTC complaint, Vizio facilitated appending DEMOGRAPHICS to that viewing data -- sex, age, income, marital status, household size, education level, home ownership and home value. A consolidated class action settled in October 2018 for $17 million covering roughly 16 million purchasers between February 2014 and February 2017. By November 2021 it was reported that Vizio made more profit from selling customer data than from selling televisions. Walmart completed its acquisition of Vizio on 3 December 2024 for about $2.3 billion ($11.50 per share), explicitly to obtain SmartCast -- then over 19 million active accounts -- and the Inscape data arm, feeding Walmart Connect, Walmart's retail-media advertising business.", "Arbitration / Class Action Waiver": "Not verified this pass -- and this is a live gap, because the operative terms may now be Walmart-group terms. Vizio was delisted from the NYSE on the closing date and is reported as part of the Walmart U.S. segment, so the contracting entity and its dispute terms should be re-fetched before any consumer relies on the older Vizio-standalone position.", "Fees / Billing Flags": "Not itemized this pass. The commercial model is the finding: Vizio hardware has been sold thin against platform advertising revenue, and Walmart bought the company for the platform rather than the panels.", "Notes": "This is the highest-severity row on the tab and the one that anchors the whole category. It is also the only ACR case with an actual dollar remedy, and the numbers are worth putting side by side: $2.2M FTC (2017) and $17M class (2018) against Samsung and LG settling in 2026 for zero. Separately, the Walmart deal is the reason to re-read the row annually: viewing data joined to a grocery-and-general-merchandise purchase history is a materially different dataset than viewing data alone, and no consumer consented to that join at the time they bought the TV.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Irvine", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://corporate.walmart.com/news/2024/12/03/walmart-completes-acquisition-of-vizio", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Walmart Inc. (NYSE: WMT) — wholly owned since 2024-12-03", "Years Referenced in Finding (heuristic)": "2014, 2017, 2018, 2021, 2024", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Walmart Inc. (NYSE: WMT) — wholly owned since 2024-12-03). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 5 accelerated cadence)", "Top Troubling #1": "[DATA_SALE · FL-1] The FTC found Vizio shipped 11 million TVs with tracking on by default and let buyers append income, education and home value to the viewing data\nWHAT THE TERMS SAY: Per the 2017 FTC and New Jersey settlement, Vizio sold over 11 million sets from February 2014 with ACR enabled by default, gave only a brief timed pop-up referring to programme offers and suggestions, sold viewing data to third parties, and facilitated appending demographics including sex, age, income, marital status, household size, education level, home ownership and home value.\nWHY IT MATTERS: That combination converts second-by-second viewing into a household-level marketing profile, which is exactly what the ACR consent fights since 2025 have been about.\n(evidence: FTC v. Vizio complaint and settlement, February 2017)", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-1] Walmart bought Vizio in December 2024 for the viewing data, and can now join it to shopping history\nWHAT THE TERMS SAY: Walmart completed a roughly $2.3 billion acquisition of Vizio on 3 December 2024, citing SmartCast and its 19 million-plus active accounts, with Inscape supplying targeting data into Walmart Connect, the retailer’s advertising business.\nWHY IT MATTERS: Nobody who bought a Vizio before December 2024 agreed to have their viewing history sit inside the same company as their grocery receipts.\n(evidence: Walmart corporate announcement, 2024-12-03, and deal coverage)", "Top Troubling #3": "[REGULATORY_ACTION_PRIVACY · FL-2] A $17 million class settlement in 2018 covered roughly 16 million Vizio purchasers\nWHAT THE TERMS SAY: A consolidated class action settled in October 2018 for $17 million, covering approximately 16 million people who bought Vizio smart TVs between February 2014 and February 2017.\nWHY IT MATTERS: It remains the only ACR matter to have produced meaningful consumer compensation; the 2026 Texas settlements produced none.\n(evidence: Class settlement coverage, October 2018)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "FTC complaint, class settlement and acquisition close are all public, dated and quantified.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 20/20 (severity5+20, litigation+2) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Vizio (Walmart) / SmartCast + Inscape  <-  Walmart Inc. (NYSE: WMT) — wholly owned since 2024-12-03", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Vizio (Walmart) / SmartCast + Inscape you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Vizio is the case that started all of this -- and the enforcement trend since has gone BACKWARDS. In 2017 the FTC caught Vizio shipping 11 MILLION televisions with tracking ON BY DEFAULT, disclosed by a pop-up that vanished after about a minute, and found Vizio let buyers attach your INCOME, EDUCATION, MARITAL STATUS, HOME OWNERSHIP AND HOME VALUE to your second-by-second viewing. That cost $2.2M, plus $17M to a class of ~16 million people. By 2021 Vizio was reportedly making more money selling your data than selling you the TV. Then in December 2024 WALMART BOUGHT THE COMPANY FOR $2.3 BILLION -- explicitly for SmartCast and the Inscape data arm -- which means the record of what plays on that screen now lives inside the same company as your grocery receipts. And in 2026, Samsung and LG settled nearly identical allegations for ZERO DOLLARS.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1072, "_entity_id": 1448, "_entity_slug": "vizio-walmart-smartcast-inscape", "_issuer": "Walmart Inc.  — wholly owned since 2024-12-03", "_issuer_slug": "walmart-inc-wholly-owned-since-2024-12-03", "_ticker": "WMT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Roku (Roku OS, Roku players, Roku TV)", "Category": "Smart TV Platform", "Terms & Conditions URL": "roku.com/legal/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "roku.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Michigan AG Dana Nessel sued Roku on 29 April 2025 in the Eastern District of Michigan (Nessel v. Roku, Inc., No. 2:25-cv-11221) alleging violations of COPPA and the Michigan Consumer Protection Act. The complaint alleges Roku collected children's device identifiers, IP addresses, cookies, account and browsing information, PRECISE GEOLOCATION and VISUAL AND AUDIO INFORMATION, inside and outside the Kids and Family section; that Roku does not offer dedicated child profiles the way Netflix and Disney+ do, so children are subject to the same tracking as adults; and that Roku partnered with third-party web trackers and data brokers, some of which the FTC had itself sued over location tracking. In an April 2026 ruling the court DISMISSED the video-privacy counts (Michigan's VPPA and Preservation of Personal Privacy Act theories) but held that COPPA's express parens patriae provision gives the AG standing, and ALLOWED THE COPPA CLAIMS TO PROCEED. Roku has said it strongly disagrees with the allegations. Separately, Roku's ACR feature -- branded Smart TV Experience -- covers over-the-air broadcast viewing and content playing through HDMI, not just Roku apps.", "Arbitration / Class Action Waiver": "Roku’s consumer Terms of Use have historically carried binding arbitration with a class-action waiver and a dispute-resolution opt-out; the current clause and any opt-out window were NOT fetched this pass and must be re-read before relying on a window. Note the structural point: the arbitration clause did not stop a state AG, which is why the Michigan action reached a merits ruling at all.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Roku is the load-bearing row for the whole tab, because Roku OS is not only on Roku hardware -- it is the platform on many TCL, Hisense, Philips, Sharp, onn and other sets. A consumer who has never bought a Roku-branded product can still be a Roku data subject. The April 2026 split ruling is also the single most useful precedent in this workbook for the children's-data hook: video-privacy theories failed, COPPA survived.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Jose", "HQ State": "California", "CEO": null, "Ticker": "ROKU", "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (ROKU). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.michigan.gov/ag", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Roku, Inc.", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Roku, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-1] Michigan alleges Roku has no child profiles at all, so children get adult-grade tracking including precise location and voice\nWHAT THE TERMS SAY: The Michigan AG complaint alleges Roku lacks dedicated children’s profiles -- a standard feature on Netflix and Disney+ -- and collects children’s device identifiers, IP addresses, cookies, account and browsing data, precise geolocation and visual and audio information both inside and outside the Kids and Family section.\nWHY IT MATTERS: Without a child profile there is no technical boundary to enforce, so a parental control that does not exist cannot be misconfigured -- it simply never applied.\n(evidence: Nessel v. Roku, No. 2:25-cv-11221 (E.D. Mich.), complaint filed 2025-04-29)", "Top Troubling #2": "[REGULATORY_ACTION_PRIVACY · FL-1] In April 2026 the court threw out the video-privacy claims but let the COPPA claims go forward\nWHAT THE TERMS SAY: The court held that COPPA’s express parens patriae provision gives the Michigan AG standing to sue in federal court on behalf of children and that the alleged collection could identify individuals, while dismissing the state video-privacy theories.\nWHY IT MATTERS: It establishes the practical route for Mid-Atlantic households: the children’s-privacy hook survives where the video-viewing hook did not.\n(evidence: April 2026 opinion in Nessel v. Roku; Troutman/MediaPost coverage)", "Top Troubling #3": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Roku's ACR watches antenna and HDMI sources, and Roku OS runs on TVs that carry other brands' names\nWHAT THE TERMS SAY: Roku's Smart TV Experience performs content recognition on over-the-air viewing and on content playing through HDMI, and Roku OS ships on TVs sold under numerous third-party brands.\nWHY IT MATTERS: People who never chose Roku are Roku data subjects, and the tracking reaches devices they plugged in rather than apps they opened.\n(evidence: Roku configuration documentation and OS licensing reporting, 2025-2026)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "A live federal docket with a dated ruling fixes both the allegations and what survived them.", "Exposure Score (0-100)": 62, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 19, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 19/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 6/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nVIDEO PRIVACY (VPPA) → 18 U.S.C. § 2710 gives a private right of action with $2,500 statutory damages per violation and is NOT preempted by state law; scope is before the Supreme Court in Salazar v. Paramount Global (cert granted 2026-01-26), so consumer standing may widen or narrow within the year\nCHILDREN’S DATA → Federal COPPA (amended rule, compliance 2026-04-22) now requires SEPARATE verifiable parental consent before a child’s data goes to advertisers or AI training, and bans indefinite retention; MD bars targeted advertising to consumers a controller knows are under 18; state AGs have express COPPA parens patriae standing (confirmed in the Roku ruling)\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Roku (Roku OS, Roku players, Roku TV)  <-  Roku, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Roku (Roku OS, Roku players, Roku TV) you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, and your right to join a class action. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Michigan's Attorney General sued Roku in April 2025 alleging it collects children's PRECISE LOCATION, VOICE RECORDINGS, IP addresses and browsing identifiers -- and that Roku, unlike Netflix or Disney+, offers NO CHILD PROFILES AT ALL, so a seven-year-old gets adult-grade tracking with no boundary to switch on. The state also alleges Roku worked with trackers and brokers the FTC had already sued over location tracking. In April 2026 a federal judge threw out the video-privacy counts but let the CHILDREN'S PRIVACY claims proceed. And you do not have to own a Roku to be affected: Roku OS runs on TCL, Hisense, Philips, Sharp and Walmart onn televisions, and its content recognition covers antenna broadcasts and anything you plug into an HDMI port.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1073, "_entity_id": 1450, "_entity_slug": "roku-roku-os-roku-players-roku-tv", "_issuer": "Roku, Inc.", "_issuer_slug": "roku-inc", "_ticker": "ROKU", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Amazon Fire TV (Fire TV OS, Fire TV Stick, Fire TV Omni)", "Category": "Smart TV Platform", "Terms & Conditions URL": "amazon.com/gp/help/customer/display.html?nodeId=508088", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "amazon.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Fire TV OS ships ACR-equivalent viewing collection enabled from first boot and is licensed onto third-party sets -- notably Insignia (Best Buy), Toshiba (US brand licence) and, since Panasonic's US re-entry, Panasonic. Amazon was NOT among the five manufacturers Texas sued in December 2025, which is a notable absence rather than a clean bill of health: the Texas action targeted panel makers, and Amazon's exposure sits on the OS side. Amazon's consumer conditions of use notably ABANDONED mandatory arbitration in 2021 after mass individual arbitration filings, which makes Amazon one of the few large consumer platforms where a class action is procedurally available.", "Arbitration / Class Action Waiver": "Amazon dropped its mandatory consumer arbitration clause from its Conditions of Use in 2021 and directs disputes to Washington state and federal courts. That is a genuine consumer advantage over every other platform on this tab and should be recorded as such -- it is why Amazon customers can and do bring class actions that Roku, Netflix and Samsung customers cannot. The specific current clause was not re-fetched this pass; confirm before relying on it.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recording an advantage as an advantage, per the schema guide's instruction to say so when a company looks better than its peers: on the dispute-rights axis Amazon scores well precisely because it removed its arbitration clause. That does not extend to the data axis, where Fire TV is a full-participation ACR platform.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Seattle", "HQ State": "Washington", "CEO": null, "Ticker": "AMZN", "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AMZN). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Amazon.com, Inc.", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Amazon.com, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Fire TV viewing signal joins the largest first-party retail purchase graph in the country\nWHAT THE TERMS SAY: Fire TV OS collects viewing and app-usage telemetry under the Amazon privacy notice, within the same corporate entity that holds Amazon retail purchase history, Prime Video viewing, Alexa voice interactions and Ring device data.\nWHY IT MATTERS: The join is internal, so no data ever has to be \"sold\" for a household-level profile spanning shopping, watching, speaking and doorstep video to exist.\n(evidence: Amazon privacy notice structure; affiliate-sharing inference, not a fetched contract clause)", "Top Troubling #2": "[DARK_PATTERN_CONSENT · FL-3] Fire TV OS is licensed onto sets sold under Insignia, Toshiba and Panasonic badges\nWHAT THE TERMS SAY: Fire TV OS runs on Amazon hardware and is licensed to third-party manufacturers including Best Buy’s Insignia brand, the US Toshiba TV licence and Panasonic’s US range.\nWHY IT MATTERS: A shopper avoiding Amazon hardware can still buy an Amazon platform without ever seeing the word Amazon on the box.\n(evidence: TV platform licensing reporting, 2024-2026)", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Amazon removed mandatory arbitration in 2021, which is a real and unusual consumer advantage\nWHAT THE TERMS SAY: Amazon amended its Conditions of Use in 2021 to drop mandatory consumer arbitration and route disputes to courts in Washington.\nWHY IT MATTERS: Class actions remain procedurally available against Amazon while they are foreclosed against most competitors on this tab -- a genuine point in Amazon’s favour.\n(evidence: Conditions of Use change reporting, 2021; not re-fetched this pass)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Amazon publishes a privacy notice but does not itemise Fire TV viewing collection as a discrete, separately-controllable disclosure the way Samsung and LG now must in Texas.", "Exposure Score (0-100)": 17, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 5/20 (unilateral_modification+5) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Amazon Fire TV (Fire TV OS, Fire TV Stick, Fire TV Omni)  <-  Amazon.com, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Amazon Fire TV (Fire TV OS, Fire TV Stick, Fire TV Omni) you gave up your data shared corporate-wide and your right to be consulted before terms change. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Fire TV is the ACR platform that Texas did NOT sue -- it went after panel makers, and Amazon's exposure is on the operating-system side. Fire TV OS is also licensed onto Insignia (Best Buy's house brand), the US Toshiba badge and Panasonic's US range, so you can carefully avoid buying Amazon hardware and end up running Amazon's platform anyway. The genuinely unusual part, and it counts in Amazon's favour: Amazon DROPPED mandatory arbitration from its consumer terms in 2021 after being buried in individual filings, so unlike Roku, Netflix or Samsung customers, Fire TV owners can still bring a class action.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1074, "_entity_id": 1451, "_entity_slug": "amazon-fire-tv-fire-tv-os-fire-tv-stick-fire-tv-omni", "_issuer": "Amazon.com, Inc.", "_issuer_slug": "amazon-com-inc", "_ticker": "AMZN", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google TV / Chromecast (Google TV OS)", "Category": "Smart TV Platform", "Terms & Conditions URL": "policies.google.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Google TV is the operating system on Sony Bravia, on parts of the TCL and Hisense ranges, and on Chromecast with Google TV hardware. Its telemetry layer is governed by Usage & Diagnostics under the general Google privacy policy rather than by a TV-specific notice, which means the switch a viewer needs is not labelled as a viewing-data control. Google is separately the subject of the Rodriguez v. Google jury verdict (see the Google Ecosystem tab) in which a jury found Google continued collecting app activity from users who had turned Web & App Activity OFF -- a finding about whether Google's own privacy toggles do what they say, which bears directly on how much weight to give a Google TV opt-out.", "Arbitration / Class Action Waiver": "Google does not impose mandatory consumer arbitration in its general US Terms of Service and has litigated consumer privacy class actions to jury verdict. Recorded as an advantage on the dispute-rights axis.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The reason this row matters more than its severity suggests: a Google TV opt-out is only as good as Google's opt-out infrastructure generally, and in September 2025 a jury found that infrastructure did not work as described for Web & App Activity. Cross-reference the Rodriguez row before advising anyone to rely on a Google TV toggle.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": "GOOGL", "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (GOOGL). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alphabet Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Google TV telemetry is governed by a general privacy policy, not a TV-specific viewing notice\nWHAT THE TERMS SAY: Google TV platform and diagnostics collection runs under Usage & Diagnostics within the general Google privacy policy rather than under a distinct smart-TV viewing disclosure.\nWHY IT MATTERS: A viewer looking for a \"viewing data\" setting will not find one under that name, which is the same discoverability defect Texas attacked at Samsung.\n(evidence: Google TV configuration documentation, 2025-2026)", "Top Troubling #2": "[UNILATERAL_CHANGES · FL-2] A jury has already found that a Google privacy toggle did not stop the collection it described\nWHAT THE TERMS SAY: In Rodriguez v. Google LLC a federal jury returned a $425.7 million verdict on 3 September 2025, finding Google collected activity from non-Google apps after users disabled Web & App Activity.\nWHY IT MATTERS: It is direct evidence about the reliability of Google opt-out controls generally, which is the mechanism a Google TV owner would be told to rely on.\n(evidence: Rodriguez v. Google LLC, N.D. Cal., verdict 2025-09-03)", "Top Troubling #3": "[DATA_SALE · FL-3] Sony was sued by Texas over ACR on panels running Google TV\nWHAT THE TERMS SAY: Sony Bravia sets run Google TV and Sony is an unsettled defendant in the December 2025 Texas ACR action, with third-party vendor Samba TV supplying content recognition on select models.\nWHY IT MATTERS: The manufacturer carries the legal exposure while the platform collects the telemetry, and neither arrangement is visible to the buyer.\n(evidence: Texas AG filings and Sony/Samba configuration reporting)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Google publishes extensive general policies but no discrete Google TV viewing-data disclosure, so the boundary between OS telemetry and manufacturer ACR is not stated anywhere a consumer would look.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 10/20 (severity3+8, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "Company", "Ownership Path": "Google TV / Chromecast (Google TV OS)  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Google TV / Chromecast (Google TV OS) you gave up your physical movements, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Google TV runs on Sony Bravia sets, on much of TCL's and Hisense's range, and on Chromecast -- but there is no Google TV privacy policy. Its collection sits under general Usage & Diagnostics in the company-wide policy, so a viewer hunting for a \"viewing data\" switch will not find one under that name. Worse for anyone told to just opt out: in September 2025 a federal jury returned a $425.7 MILLION verdict finding Google kept collecting app activity from people who had already switched Web & App Activity OFF. The remedy being recommended for Google TV is the same class of control a jury has already found did not work.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1075, "_entity_id": 1452, "_entity_slug": "google-tv-chromecast-google-tv-os", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Apple TV (tvOS set-top box)", "Category": "Smart TV Platform", "Terms & Conditions URL": "apple.com/legal/internet-services/terms/site.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "apple.com/legal/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "No ACR finding identified for the tvOS set-top box: Apple does not operate an automatic content recognition product on Apple TV hardware, was not named in the December 2025 Texas action, and does not sell a TV-viewing measurement product to brands the way Samba TV, Inscape and LG Ad Solutions do. That is a real and specific point in Apple's favour on this tab and is recorded as such. It is narrow, though: it says nothing about the Apple TV+ SERVICE, about Apple's Personalized Ads business, or about the Siri litigation -- all of which are separate rows on the Apple Ecosystem tab.", "Arbitration / Class Action Waiver": "Apple does not impose mandatory consumer arbitration in its US media services terms. Recorded as an advantage.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Included deliberately as the counter-example. The schema guide requires saying so when a company looks better than its peers, and on the specific question this tab asks -- does the device fingerprint your screen and sell the result -- the Apple TV box currently answers no. Buying a cheap 'dumb' panel and driving it from an Apple TV is, on the present evidence, the lowest-ACR mainstream configuration available. Do not generalise that to Apple's other products.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cupertino", "HQ State": "California", "CEO": null, "Ticker": "AAPL", "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AAPL). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Apple Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Apple Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[NO_ADVERSE_FINDING · FL-1] No ACR product, no Texas action, and no viewing-measurement business identified on Apple TV hardware\nWHAT THE TERMS SAY: Apple does not operate an automatic content recognition system on tvOS hardware, was not among the five manufacturers Texas sued in December 2025, and sells no TV audience-measurement product comparable to Samba TV or Inscape.\nWHY IT MATTERS: On the narrow question this tab exists to answer, the Apple TV box is currently the cleanest mainstream option -- which is itself a finding worth publishing.\n(evidence: Absence across Texas AG filings and ACR vendor reporting, 2025-2026)", "Top Troubling #2": "[SCOPE_LIMITATION · FL-3] The clean result covers the box only, not Apple TV+, Apple advertising or Siri\nWHAT THE TERMS SAY: This row concerns tvOS hardware and its content-recognition posture; Apple TV+ as a service, Apple Personalized Ads and the Siri litigation are assessed separately.\nWHY IT MATTERS: A reader who takes \"Apple TV is clean\" as a statement about Apple generally will get the wrong answer -- the Siri class action settled for $95 million.\n(evidence: Scope note; see Apple Ecosystem (deep) tab)", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=?; datasale=N; affiliates=N; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "The absence is well-evidenced: Apple is missing from the defendant list of the largest ACR action to date and from the ACR vendor market.", "Exposure Score (0-100)": 10, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 0/20 (severity1+0) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand", "Entity Type": "Company", "Ownership Path": "Apple TV (tvOS set-top box)  <-  Apple Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to be made whole. Their liability is capped, often at what you paid.\n  2. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your data shared corporate-wide; your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (7 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Apple TV (tvOS set-top box) you gave up your right to meaningful compensation and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The most useful thing on this tab is a negative finding. Apple does NOT run automatic content recognition on the Apple TV box, was NOT among the five manufacturers Texas sued in December 2025, and does not sell TV viewing measurement to advertisers the way Samba TV, Inscape or LG Ad Solutions do. On the specific question of whether the device fingerprints your screen and sells the result, the answer here is currently no -- which makes a cheap non-smart panel driven by an Apple TV the lowest-tracking mainstream setup available today. That is a statement about this box and nothing else: Apple settled the Siri eavesdropping class action for $95 million.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1076, "_entity_id": 1453, "_entity_slug": "apple-tv-tvos-set-top-box", "_issuer": "Apple Inc.", "_issuer_slug": "apple-inc", "_ticker": "AAPL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Samba TV", "Category": "ACR / Viewing-Data Vendor", "Terms & Conditions URL": "samba.tv/legal/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "samba.tv/legal/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Samba TV is a third-party ACR supplier embedded in televisions sold by other manufacturers, described in ACR reporting as powering Sony's content-recognition system on select models. Its product is selling TV-viewing measurement to brands that want to know whether a television advertisement led a household to buy something. The consumer relationship is effectively invisible: nobody buys a Samba TV product, agrees to Samba TV terms at a point of sale, or thinks of Samba TV as a company they deal with, yet the collection is on their panel and the opt-out is branded under the manufacturer's menu (Sony's is labelled Samba Interactive TV).", "Arbitration / Class Action Waiver": "Not verified this pass. Note the practical problem this row exists to flag: a consumer wanting to enforce anything against Samba TV must first discover that Samba TV exists, which the purchase flow does not tell them.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This row exists because the tracker's Cross-Cutting Finding #1 is the shared-vendor pattern, and Samba is that pattern applied to televisions. One vendor, many manufacturer badges, one point of failure, and no consumer-facing brand to complain to.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Samba TV, Inc.", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Samba TV, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SALE · FL-1] Samba TV sells outcome attribution: proof that a TV ad you saw preceded a purchase you made\nWHAT THE TERMS SAY: Samba TV supplies ACR on select third-party sets and sells the resulting viewing measurement to brands seeking to establish whether a television advertisement drove a purchase.\nWHY IT MATTERS: Linking viewing to later buying is materially more identifying than content recommendation, and it is the use case the manufacturer menu label does not describe.\n(evidence: ACR vendor reporting, 2025-2026)", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] The consumer has no relationship with Samba TV and cannot easily find out they have one\nWHAT THE TERMS SAY: Samba's collection reaches consumers through manufacturer partnerships; on Sony sets the control appears under a Samba Interactive TV label inside Sony's menus.\nWHY IT MATTERS: You cannot exercise a right against a company whose existence the purchase never disclosed.\n(evidence: Sony support documentation for Samba Interactive TV; secondary)", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Samba TV publishes policies, but nothing at the point of TV purchase tells a buyer that a separate company will be measuring their household.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Samba TV  <-  Samba TV, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Samba TV you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Samba TV is a company almost no consumer has heard of that may be measuring their household anyway. It supplies the content-recognition layer inside televisions sold under OTHER manufacturers' names -- on Sony sets the control is buried under a \"Samba Interactive TV\" label -- and its actual product is selling advertisers proof that a TV ad you saw was followed by a purchase you made. You never bought anything from Samba TV, never agreed to its terms at a checkout, and would have no reason to know it exists. Which means the practical first step in exercising any privacy right against it is finding out it is there.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Smart TVs & TV Platforms", "_row_id": 1077, "_entity_id": 1455, "_entity_slug": "samba-tv", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Inscape (Vizio / Walmart data arm)", "Category": "ACR / Viewing-Data Vendor", "Terms & Conditions URL": "vizio.com/en/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "vizio.com/en/viewing-data", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Inscape is the ACR and viewing-data business inside Vizio, and it is the asset Walmart's December 2024 acquisition was built around alongside the SmartCast operating system. Its lineage runs directly back to the conduct the FTC settled in February 2017. Post-acquisition, Inscape's output feeds Walmart Connect, Walmart's retail-media advertising business -- placing television viewing data and retail purchase data under a single corporate roof.", "Arbitration / Class Action Waiver": "Not verified this pass; the operative terms after the Walmart acquisition should be re-fetched, since the contracting entity changed on 2024-12-03.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Broken out from the Vizio row on purpose. The schema guide forbids encoding two facts in one column, and the same logic applies to rows: Vizio-the-manufacturer and Inscape-the-data-business have different counterparties, different buyers, and after December 2024 a different strategic purpose. Tracking them separately is what will make a future diff legible.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Irvine", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Walmart Inc. (via Vizio Holding Corp.)", "Years Referenced in Finding (heuristic)": "2017, 2024, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Walmart Inc. (via Vizio Holding Corp.)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SALE · FL-1] Inscape is the specific asset that made a $2.3 billion retailer acquisition make sense\nWHAT THE TERMS SAY: Walmart acquired Vizio in December 2024 for roughly $2.3 billion, citing SmartCast and its 19 million-plus active accounts, with the Inscape data arm supplying advertiser targeting into Walmart Connect.\nWHY IT MATTERS: The valuation was placed on the data business, not the televisions, which tells you which one the company considers the product.\n(evidence: Walmart acquisition announcement 2024-12-03 and deal analysis)", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Viewing data and grocery purchase data now sit inside one company\nWHAT THE TERMS SAY: Inscape viewing signal feeds Walmart Connect, the retailer’s closed-loop advertising business built on first-party shopper data.\nWHY IT MATTERS: No sale to a third party is required for a household profile spanning what you watch and what you buy to exist.\n(evidence: Walmart Connect / Vizio integration reporting, 2024-2026)", "Top Troubling #3": "[REGULATORY_ACTION_PRIVACY · FL-2] This is the same data operation the FTC settled with in 2017\nWHAT THE TERMS SAY: The 2017 FTC and New Jersey settlement concerned Vizio’s ACR collection and its sale of viewing data, the business line that became Inscape.\nWHY IT MATTERS: The entity has a documented enforcement history, which is directly relevant to how much weight to give its current disclosures.\n(evidence: FTC v. Vizio, February 2017)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The acquisition rationale is publicly stated and the enforcement history is documented; what is not disclosed is how far the viewing-and-purchase join actually goes.", "Exposure Score (0-100)": 23, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 11/20 (severity3+8, penalty+3) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Inscape (Vizio / Walmart data arm)  <-  Walmart Inc. (via Vizio Holding Corp.)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Inscape (Vizio / Walmart data arm) you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Inscape is the reason Walmart paid $2.3 BILLION for a television company. The panels were not the asset -- SmartCast and Inscape were, and Walmart said so. Inscape is also the direct descendant of the exact data operation the FTC settled with in 2017 over collecting from 11 million sets by default. Now its output feeds Walmart Connect, the retailer's ad business, which means what plays on your Vizio and what goes through your Walmart checkout sit inside one company. Nothing has to be SOLD to anybody for that profile to exist. It just has to be joined.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Smart TVs & TV Platforms", "_row_id": 1078, "_entity_id": 1457, "_entity_slug": "inscape-vizio-walmart-data-arm", "_issuer": "Walmart Inc.", "_issuer_slug": "walmart-inc", "_ticker": "WMT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "LG Ad Solutions (formerly Alphonso)", "Category": "ACR / Viewing-Data Vendor", "Terms & Conditions URL": "lgads.tv/terms/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "lgads.tv/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "LG Ad Solutions is LG's in-house connected-TV advertising business, built on the Alphonso acquisition, and it is the commercial destination for the Live Plus viewing signal collected on LG panels. Because collector and buyer sit in one corporate group, LG can accurately describe itself as not selling data to outside parties while the same data is fully monetised internally. The May 2026 Texas Agreed Final Judgment now requires express consent before that collection happens -- but only for Texas consumers.", "Arbitration / Class Action Waiver": "Not verified this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recorded separately from the LG hardware row for the same reason as Inscape: the manufacturer and the ad-tech arm answer to different regulators, publish different policies, and would be sued differently. Keeping them as one row would hide the vertical integration that is the actual finding.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "LG Electronics Inc.", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: LG Electronics Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-1] Vertical integration lets a \"we do not sell your data\" statement be true and meaningless at once\nWHAT THE TERMS SAY: LG operates both the Live Plus ACR feature on its panels and LG Ad Solutions, its in-house CTV advertising arm, within one corporate group.\nWHY IT MATTERS: Statutory opt-out-of-SALE rights are keyed to transfers to third parties, so an internal transfer can sidestep the right entirely.\n(evidence: LG corporate structure and CTV market reporting; not confirmed against LG contract text)", "Top Troubling #2": "[REGULATORY_ACTION_PRIVACY · FL-2] The May 2026 Texas judgment constrains the collection feeding this business, in Texas only\nWHAT THE TERMS SAY: The Agreed Final Judgment of 11 May 2026 requires LG to obtain express consent before ACR collection and to display a pop-up disclosure with a clear opt-out.\nWHY IT MATTERS: Outside Texas the collection into LG Ad Solutions continues under the pre-settlement flow.\n(evidence: State of Texas v. LG Electronics U.S.A., Inc., 2026-05-11)", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The corporate relationship is public; the internal data-flow terms between panel and ad arm are not disclosed anywhere a consumer can read them.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "LG Ad Solutions (formerly Alphonso)  <-  LG Electronics Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using LG Ad Solutions (formerly Alphonso) you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "LG Ad Solutions is the answer to a question consumers rarely think to ask: who BUYS the viewing data your TV collects? For LG, the answer is LG. The ad business grew out of the Alphonso acquisition and sits in the same corporate group as the Live Plus feature that gathers the signal. That matters legally, because Maryland's and Virginia's privacy rights are largely keyed to opting out of a SALE -- a transfer to somebody else. When the collector and the buyer are the same company, there is no sale to opt out of, and the right you were given quietly does not apply.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Smart TVs & TV Platforms", "_row_id": 1079, "_entity_id": 1458, "_entity_slug": "lg-ad-solutions-formerly-alphonso", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Nielsen / Gracenote", "Category": "ACR / Audience Measurement", "Terms & Conditions URL": "nielsen.com/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "nielsen.com/legal/privacy-statement/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "No consumer contract: Nielsen and its Gracenote unit sell audience measurement and content metadata to broadcasters, platforms and advertisers, and the ordinary household has no direct agreement with either. Included here because the tab would otherwise imply that viewing measurement began with smart TVs, when panel-based audience measurement long predates ACR and now sits alongside it. No specific adverse finding was identified for Nielsen this pass.", "Arbitration / Class Action Waiver": "N/A - no consumer contract. A household that is not a Nielsen panel member has no agreement to opt out of.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Deliberately recorded as a clean-but-B2B row rather than omitted, so that a reader comparing ACR against traditional measurement can see both in one place. Absence of a finding here reflects that Nielsen's consumer-facing surface is small, not that its data practices were audited.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer relationship", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "N/A - no consumer contract", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Nielsen Holdings / TNC (private)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Nielsen Holdings / TNC (private)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[B2B_NO_CONSUMER_TERMS · FL-3] No consumer contract exists, so no consumer clause can be assessed\nWHAT THE TERMS SAY: Nielsen and Gracenote sell measurement and metadata services to media businesses rather than to households.\nWHY IT MATTERS: Consumer privacy rights aimed at controllers do not attach in the ordinary case, so the route for a household concern is the platform that hired them.\n(evidence: Business-model classification; no adverse finding identified this pass)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "No consumer terms of service exists for this company, per the row’s own finding.", "Opacity Basis": "Nothing is obscured because nothing consumer-facing is offered; the row is present for comparative context.", "Exposure Score (0-100)": 2, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "Company", "Ownership Path": "Nielsen / Gracenote  <-  Nielsen Holdings / TNC (private)", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Included as a contrast rather than an accusation: Nielsen measures what America watches and has done so for decades, but it does it by RECRUITING households that agree to be measured and PAYING them. ACR inverted that entirely -- the modern television measures every household by default, discloses it in a setup screen people click through, pays nobody, and asks afterwards if at all. The older, slower, opt-in model is the baseline against which the last decade should be read. No adverse finding was identified for Nielsen this pass.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1080, "_entity_id": 1460, "_entity_slug": "nielsen-gracenote", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sceptre (non-smart display range)", "Category": "TV Hardware (no smart platform)", "Terms & Conditions URL": "sceptre.com/Terms-of-Use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "sceptre.com/Privacy-Policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Sceptre continues to sell large-format displays with no smart operating system -- no app store, no account, no network stack to run content recognition on. A television that never connects to the internet cannot fingerprint your screen, and there is no ACR product, no platform advertising business, and no Texas action associated with the brand. This is the practical escape hatch from the rest of this tab and is recorded as a genuine finding rather than an omission.", "Arbitration / Class Action Waiver": "No consumer platform account exists to attach arbitration terms to; the relationship is an ordinary goods sale governed by warranty law. The absence of an account is the absence of the contract.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Verify at the individual model level before recommending: Sceptre and similar vendors sell both smart and non-smart lines, and a model number is the only reliable indicator. The general point stands for the category -- commercial-signage and hospitality displays from several vendors are also sold without consumer smart platforms, and pairing one with a streaming device the buyer chooses is the only configuration on this tab where the household picks its own controller.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "City of Industry", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Sceptre Incorporated", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Sceptre Incorporated). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[NO_ADVERSE_FINDING · FL-1] A display with no operating system has no ACR, no account and no platform advertising business\nWHAT THE TERMS SAY: Sceptre sells large-format displays without a smart platform: no app store, no user account, and no networked content-recognition capability.\nWHY IT MATTERS: It is the only configuration on this tab where the buyer, not the manufacturer, chooses which company sees what plays on the screen.\n(evidence: Product-line classification; no ACR product or enforcement action identified for the brand)", "Top Troubling #2": "[SCOPE_LIMITATION · FL-3] Model-level verification is required because the same brand also sells smart sets\nWHAT THE TERMS SAY: Vendors in this segment sell both smart and non-smart lines under one brand.\nWHY IT MATTERS: A recommendation made at brand level will be wrong for some models; check the specific model number.\n(evidence: Scope note)", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=N; biometric=N; aitrain=N; location=N; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "There is no smart platform to be opaque about; the absence is structural rather than undisclosed.", "Exposure Score (0-100)": 0, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "Company", "Ownership Path": "Sceptre (non-smart display range)  <-  Sceptre Incorporated", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your data shared corporate-wide.\n\nNOT YET DETERMINED (8 of 13): a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Sceptre (non-smart display range) takes nothing from the list this tracker checks - but 8 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The most actionable row on this tab is the one with nothing to report. Sceptre still sells large panels with NO smart operating system at all -- no app store, no account, no network stack -- and a display that never connects to the internet cannot fingerprint what is on it, cannot build a household profile and cannot be sued in Texas for doing so. Pair one with a streaming device you picked yourself and you become the only person in this workbook who chose which company gets to watch you watch. Check the specific model number, because the same brands sell smart sets too.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1081, "_entity_id": 1462, "_entity_slug": "sceptre-non-smart-display-range", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Telly (ad-subsidised dual-screen TV)", "Category": "Smart TV Platform", "Terms & Conditions URL": "telly.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "telly.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Telly's model makes the whole tab's economics explicit rather than implicit: the television is given away and a permanently attached second screen runs advertising, with the data relationship as the consideration. The terms were NOT fetched this pass, so the specific collection, retention and resale provisions are unverified and this row must not be cited for them. It is recorded now because the model is the logical endpoint of the trend every other row on this tab describes, and because a free-TV offer is exactly the kind of thing a Mid-Atlantic reader will encounter and ask about.", "Arbitration / Class Action Waiver": "Not verified this pass. Queued for Tranche 2 with fetch priority, since a zero-price product makes the terms the entire consideration and therefore the only thing worth reading.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Flagged as the highest-value unfetched row on this tab. Where a product's price is zero, the contract IS the price, and the tracker should hold the text before recommending anything about it either way.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Santa Monica", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Telly Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Telly Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SALE · FL-2] A free television makes the data relationship the purchase price rather than a side effect\nWHAT THE TERMS SAY: Telly distributes televisions at no hardware cost with a permanently attached secondary advertising screen, funding the device through advertising and data rather than a sale price.\nWHY IT MATTERS: Every other row on this tab hides this trade inside a purchase; here it is the transaction itself.\n(evidence: Product-model reporting; Telly terms NOT fetched this pass)", "Top Troubling #2": "[SCOPE_LIMITATION · FL-2] The terms have not been retrieved, so the specific provisions are unknown rather than benign\nWHAT THE TERMS SAY: Telly consumer terms and privacy policy were not fetched during this pass.\nWHY IT MATTERS: Absence of a recorded finding here measures the audit, not the company — do not read this row as a clean result.\n(evidence: Research-queue status note)", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "Nothing has been retrieved. The opacity rating reflects the state of the audit for this row, and it is queued for fetch in the next tranche.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Telly (ad-subsidised dual-screen TV)  <-  Telly Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Telly (ad-subsidised dual-screen TV) you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Telly gives the television away and keeps a second screen running ads underneath the one you are watching -- which makes it the only product on this tab where the data relationship is openly the purchase price rather than a clause you did not read. Every other row hides that same trade inside a normal-looking retail transaction. IMPORTANT CAVEAT: this tracker has NOT retrieved Telly's actual terms, so nothing here should be read as a finding about what they say. When a product costs zero dollars, the contract is the entire price, and this row is queued as the highest-priority fetch on the tab precisely because we do not yet hold the text.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Smart TVs & TV Platforms", "_row_id": 1082, "_entity_id": 1464, "_entity_slug": "telly-ad-subsidised-dual-screen-tv", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Insignia (Best Buy house brand)", "Category": "TV Hardware (licensed badge / OS tenant)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "No independent manufacturer: Insignia is Best Buy's private-label television brand, and its sets run Amazon's Fire TV OS. The privacy controller for viewing and app telemetry is therefore Amazon, under the Amazon privacy notice, not Best Buy. Best Buy is a Fortune 500 retailer already carried elsewhere in this workbook; its exposure here is as a badge licensor rather than as a platform operator.", "Arbitration / Class Action Waiver": "Insignia televisions ship Fire TV OS. A consumer disputing viewing-data collection is disputing with Amazon; a consumer disputing a defective panel is disputing with Best Buy. Two different companies, two different processes, one product.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Best Buy's private-label TV is the cleanest illustration of split responsibility on this tab: warranty goes one way, data goes another, and nothing at the shelf says so.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Richfield", "HQ State": "Minnesota", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Best Buy Co., Inc. (NYSE: BBY) — badge; Amazon.com, Inc. — platform", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Best Buy Co., Inc. (NYSE: BBY) — badge; Amazon.com, Inc. — platform). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] The badge on the bezel is not the company holding the viewing data\nWHAT THE TERMS SAY: Insignia televisions ship Fire TV OS. A consumer disputing viewing-data collection is disputing with Amazon; a consumer disputing a defective panel is disputing with Best Buy. Two different companies, two different processes, one product.\nWHY IT MATTERS: Best Buy's private-label TV is the cleanest illustration of split responsibility on this tab: warranty goes one way, data goes another, and nothing at the shelf says so.\n(evidence: TV platform licensing reporting, 2024-2026; brand-level, not confirmed against a licence agreement)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — this row answers one question (who actually operates the platform) and does not audit the brand’s own terms, which were not fetched.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The licensing arrangement is reported in the trade press but is not disclosed at the point of sale, so a buyer cannot determine the actual controller from the box.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Insignia (Best Buy house brand)  <-  Best Buy Co., Inc. (NYSE: BBY) — badge; Amazon.com, Inc. — platform", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Insignia (Best Buy house brand) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Insignia is Best Buy's own store brand, which most shoppers read as \"the retailer stands behind it.\" For the panel, that is true. For your viewing history it is not: Insignia sets run AMAZON'S Fire TV OS, so the company holding what you watch is Amazon, under Amazon's privacy notice, not Best Buy's. Return the TV to Best Buy; ask about the data and you are asking the wrong company. Nothing on the shelf tag explains that.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1083, "_entity_id": 1466, "_entity_slug": "insignia-best-buy-house-brand", "_issuer": "Best Buy Co., Inc.  — badge; Amazon.com, Inc. — platform", "_issuer_slug": "best-buy-co-inc-badge-amazon-com-inc-platform", "_ticker": "BBY", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "onn. (Walmart house brand)", "Category": "TV Hardware (licensed badge / OS tenant)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "onn. is Walmart's private-label electronics brand; its televisions have shipped predominantly on Roku OS, with Google TV on some lines. Since Walmart's December 2024 acquisition of Vizio, Walmart occupies an unusual double position -- it is simultaneously a customer of Roku's platform on its own house brand and the OWNER of a competing platform (SmartCast) plus its data arm (Inscape).", "Arbitration / Class Action Waiver": "onn. sets place the viewing-data relationship with Roku, a company facing an active COPPA action brought by the Michigan Attorney General, while the retail relationship stays with Walmart.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The double position is the finding worth watching: a retailer that owns a rival TV operating system has an obvious incentive to migrate its own house brand onto it, which would silently move millions of households from one controller to another with no consumer notice beyond a new model year.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Bentonville", "HQ State": "Arkansas", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Walmart Inc. (NYSE: WMT) — badge and Vizio owner; Roku, Inc. — platform", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Walmart Inc. (NYSE: WMT) — badge and Vizio owner; Roku, Inc. — platform). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] The badge on the bezel is not the company holding the viewing data\nWHAT THE TERMS SAY: onn. sets place the viewing-data relationship with Roku, a company facing an active COPPA action brought by the Michigan Attorney General, while the retail relationship stays with Walmart.\nWHY IT MATTERS: The double position is the finding worth watching: a retailer that owns a rival TV operating system has an obvious incentive to migrate its own house brand onto it, which would silently move millions of households from one controller to another with no consumer notice beyond a new model year.\n(evidence: TV platform licensing reporting, 2024-2026; brand-level, not confirmed against a licence agreement)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — this row answers one question (who actually operates the platform) and does not audit the brand’s own terms, which were not fetched.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The licensing arrangement is reported in the trade press but is not disclosed at the point of sale, so a buyer cannot determine the actual controller from the box.", "Exposure Score (0-100)": 12, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "onn. (Walmart house brand)  <-  Walmart Inc. (NYSE: WMT) — badge and Vizio owner; Roku, Inc. — platform", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using onn. (Walmart house brand) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Walmart's house-brand TVs have mostly run ROKU's operating system -- the same Roku facing an active children's-privacy case from the Michigan Attorney General. But since December 2024 Walmart also OWNS Vizio's SmartCast platform and its Inscape data business outright. So Walmart is currently paying a competitor to collect viewing data from its own house-brand TVs while owning a rival platform that would rather collect it itself. Watch for onn. sets to quietly move to SmartCast: that would shift millions of households to a different data controller, and the only notice anyone would get is a new model number.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1084, "_entity_id": 1468, "_entity_slug": "onn-walmart-house-brand", "_issuer": "Walmart Inc.  — badge and Vizio owner; Roku, Inc. — platform", "_issuer_slug": "walmart-inc-badge-and-vizio-owner-roku-inc-platform", "_ticker": "WMT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Toshiba (US television brand licence)", "Category": "TV Hardware (licensed badge / OS tenant)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Toshiba-badged televisions sold in the United States are not built by Toshiba Corporation: the US TV brand licence is held by Hisense, and the sets ship on Amazon's Fire TV OS or Google TV depending on line. Hisense is an unsettled defendant in the December 2025 Texas ACR action.", "Arbitration / Class Action Waiver": "A buyer choosing a Japanese brand over a Chinese one on privacy grounds gets, in this case, a Hisense platform decision wearing a Toshiba badge.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is the row to cite when explaining why brand-of-origin reasoning fails in televisions. Consumers routinely make a country-of-origin privacy judgment at the shelf; the licence structure defeats it entirely and is disclosed nowhere the shopper looks.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Qingdao", "HQ State": "China (Shandong)", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Hisense Group Holdings Co., Ltd. (US brand licensee)", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Hisense Group Holdings Co., Ltd. (US brand licensee)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] The badge on the bezel is not the company holding the viewing data\nWHAT THE TERMS SAY: A buyer choosing a Japanese brand over a Chinese one on privacy grounds gets, in this case, a Hisense platform decision wearing a Toshiba badge.\nWHY IT MATTERS: This is the row to cite when explaining why brand-of-origin reasoning fails in televisions. Consumers routinely make a country-of-origin privacy judgment at the shelf; the licence structure defeats it entirely and is disclosed nowhere the shopper looks.\n(evidence: TV platform licensing reporting, 2024-2026; brand-level, not confirmed against a licence agreement)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — this row answers one question (who actually operates the platform) and does not audit the brand’s own terms, which were not fetched.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The licensing arrangement is reported in the trade press but is not disclosed at the point of sale, so a buyer cannot determine the actual controller from the box.", "Exposure Score (0-100)": 12, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Toshiba (US television brand licence)  <-  Hisense Group Holdings Co., Ltd. (US brand licensee)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Toshiba (US television brand licence) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Buying a Toshiba to avoid a Chinese-owned television does not work. The US Toshiba TV brand is LICENSED TO HISENSE -- one of the five manufacturers Texas sued in December 2025 and one of the three that has NOT settled -- and those sets run Amazon's Fire TV OS or Google TV. So a shopper deliberately choosing the Japanese nameplate over Hisense on privacy grounds is buying a Hisense platform decision with a Toshiba badge on it, plus Amazon's or Google's telemetry underneath. None of that is on the box.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1085, "_entity_id": 1469, "_entity_slug": "toshiba-us-television-brand-licence", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Panasonic (US television range)", "Category": "TV Hardware (licensed badge / OS tenant)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Panasonic withdrew from the US television market for several years and re-entered via Amazon's Fire TV OS rather than by rebuilding its own smart platform. Panasonic was NOT among the five manufacturers named in the December 2025 Texas ACR action.", "Arbitration / Class Action Waiver": "Panasonic's US sets place platform telemetry with Amazon; the absence of Panasonic from the Texas defendant list reflects its small recent US installed base rather than a distinct privacy posture.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recorded so the tab does not imply that being un-sued is the same as being audited. Panasonic's absence from the Texas action has an obvious market-share explanation and should not be read as a finding in its favour.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Newark", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Panasonic Holdings Corporation — badge; Amazon.com, Inc. — platform", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Panasonic Holdings Corporation — badge; Amazon.com, Inc. — platform). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] The badge on the bezel is not the company holding the viewing data\nWHAT THE TERMS SAY: Panasonic's US sets place platform telemetry with Amazon; the absence of Panasonic from the Texas defendant list reflects its small recent US installed base rather than a distinct privacy posture.\nWHY IT MATTERS: Recorded so the tab does not imply that being un-sued is the same as being audited. Panasonic's absence from the Texas action has an obvious market-share explanation and should not be read as a finding in its favour.\n(evidence: TV platform licensing reporting, 2024-2026; brand-level, not confirmed against a licence agreement)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — this row answers one question (who actually operates the platform) and does not audit the brand’s own terms, which were not fetched.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The licensing arrangement is reported in the trade press but is not disclosed at the point of sale, so a buyer cannot determine the actual controller from the box.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Panasonic (US television range)  <-  Panasonic Holdings Corporation — badge; Amazon.com, Inc. — platform", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Panasonic (US television range) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Panasonic left the US TV market and came back by renting somebody else's platform: its US sets run Amazon's Fire TV OS. It was not among the five brands Texas sued in December 2025 -- but the honest reading of that is market share, not virtue. A manufacturer with a small recent US installed base is a less attractive defendant, and this tracker has not audited Panasonic's own terms. Not being sued is not the same as being clean, and this row exists to say so rather than to quietly bank the absence as a good result.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1086, "_entity_id": 1471, "_entity_slug": "panasonic-us-television-range", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Philips (US television brand licence)", "Category": "TV Hardware (licensed badge / OS tenant)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "The Philips television brand is licensed rather than operated by Koninklijke Philips N.V., which exited consumer TV manufacturing; US Philips-badged sets are produced under licence and ship on Roku OS or Google TV depending on model. Philips itself was not named in the Texas action.", "Arbitration / Class Action Waiver": "The health-technology company whose name is on the set has no operational role in what the set collects; the platform operator does.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Worth pairing with the Toshiba row when explaining the licensing pattern, because Philips is the clearer case of a brand whose corporate parent has genuinely left the category rather than sub-licensed within it.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Amsterdam", "HQ State": "Netherlands", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Koninklijke Philips N.V. — brand licensor; Roku, Inc. / Alphabet Inc. — platform", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Koninklijke Philips N.V. — brand licensor; Roku, Inc. / Alphabet Inc. — platform). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] The badge on the bezel is not the company holding the viewing data\nWHAT THE TERMS SAY: The health-technology company whose name is on the set has no operational role in what the set collects; the platform operator does.\nWHY IT MATTERS: Worth pairing with the Toshiba row when explaining the licensing pattern, because Philips is the clearer case of a brand whose corporate parent has genuinely left the category rather than sub-licensed within it.\n(evidence: TV platform licensing reporting, 2024-2026; brand-level, not confirmed against a licence agreement)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — this row answers one question (who actually operates the platform) and does not audit the brand’s own terms, which were not fetched.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The licensing arrangement is reported in the trade press but is not disclosed at the point of sale, so a buyer cannot determine the actual controller from the box.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Philips (US television brand licence)  <-  Koninklijke Philips N.V. — brand licensor; Roku, Inc. / Alphabet Inc. — platform", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Philips (US television brand licence) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Koninklijke Philips is a health-technology company that got out of consumer televisions -- but the name still appears on TVs, under licence, built by others and running Roku OS or Google TV. So the reassurance a shopper takes from a long-established European medical-devices brand attaches to a nameplate rental. The company that decides what your Philips-badged TV collects is Roku or Google, and Philips has no operational role in it at all.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1087, "_entity_id": 1473, "_entity_slug": "philips-us-television-brand-licence", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sharp (US television brand)", "Category": "TV Hardware (licensed badge / OS tenant)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "The Sharp television brand in the United States has moved between licensees over the past decade, including a period under Hisense, and current US sets ship on Roku OS or Google TV. The licensee history means that two Sharp sets bought a few years apart can have entirely different corporate data controllers behind them.", "Arbitration / Class Action Waiver": "Sharp is the clearest example of controller drift over time: the badge is stable while the entity holding the viewing data has changed more than once.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This row is included specifically because the tracker's stated moat is longitudinal. A brand whose data controller changed twice while the logo stayed identical is the strongest available argument for why version capture and dated rows matter.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Sakai", "HQ State": "Japan (Osaka)", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Sharp Corporation — brand; licensee and platform vary by model year", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Sharp Corporation — brand; licensee and platform vary by model year). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] The badge on the bezel is not the company holding the viewing data\nWHAT THE TERMS SAY: Sharp is the clearest example of controller drift over time: the badge is stable while the entity holding the viewing data has changed more than once.\nWHY IT MATTERS: This row is included specifically because the tracker's stated moat is longitudinal. A brand whose data controller changed twice while the logo stayed identical is the strongest available argument for why version capture and dated rows matter.\n(evidence: TV platform licensing reporting, 2024-2026; brand-level, not confirmed against a licence agreement)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — this row answers one question (who actually operates the platform) and does not audit the brand’s own terms, which were not fetched.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The licensing arrangement is reported in the trade press but is not disclosed at the point of sale, so a buyer cannot determine the actual controller from the box.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Sharp (US television brand)  <-  Sharp Corporation — brand; licensee and platform vary by model year", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Sharp (US television brand) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Two Sharp televisions bought a few years apart can have completely different companies holding your viewing data, because the US Sharp TV brand has changed licensee hands more than once -- including a spell under Hisense -- while the logo never changed at all. Current sets run Roku OS or Google TV. There is no way for an owner to tell which corporate entity is behind their particular set from anything printed on it, and no notice was ever sent when the answer changed underneath them.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1088, "_entity_id": 1475, "_entity_slug": "sharp-us-television-brand", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Element Electronics", "Category": "TV Hardware (licensed badge / OS tenant)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Element Electronics is a US-assembling budget brand whose smart sets ship on Roku OS or Fire TV OS. The brand operates no platform of its own, and no ACR product, advertising business or enforcement action was identified for it this pass.", "Arbitration / Class Action Waiver": "Element's sets are platform tenants; the viewing-data controller is Roku or Amazon depending on model.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "No adverse finding identified. Per the schema guide, that absence is recorded as measuring the disclosure regime for small brands rather than as a clean result -- a company with no platform business simply generates less public record, not necessarily fewer practices.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Winnsboro", "HQ State": "South Carolina", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Element Electronics — badge; Roku, Inc. / Amazon.com, Inc. — platform", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Element Electronics — badge; Roku, Inc. / Amazon.com, Inc. — platform). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] The badge on the bezel is not the company holding the viewing data\nWHAT THE TERMS SAY: Element's sets are platform tenants; the viewing-data controller is Roku or Amazon depending on model.\nWHY IT MATTERS: No adverse finding identified. Per the schema guide, that absence is recorded as measuring the disclosure regime for small brands rather than as a clean result -- a company with no platform business simply generates less public record, not necessarily fewer practices.\n(evidence: TV platform licensing reporting, 2024-2026; brand-level, not confirmed against a licence agreement)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — this row answers one question (who actually operates the platform) and does not audit the brand’s own terms, which were not fetched.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The licensing arrangement is reported in the trade press but is not disclosed at the point of sale, so a buyer cannot determine the actual controller from the box.", "Exposure Score (0-100)": 4, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Element Electronics  <-  Element Electronics — badge; Roku, Inc. / Amazon.com, Inc. — platform", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Element Electronics you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Element is a budget brand with no platform of its own: its smart sets run Roku OS or Fire TV OS, so the company holding your viewing data is Roku or Amazon. No ACR product, advertising business or enforcement action was found for Element itself this pass -- but that silence mostly reflects how little public record small brands generate. This tracker has not fetched Element's terms, and a brand nobody has sued is not the same as a brand somebody has checked.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1089, "_entity_id": 1477, "_entity_slug": "element-electronics", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Westinghouse (consumer electronics brand licence)", "Category": "TV Hardware (licensed badge / OS tenant)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "The Westinghouse name on consumer televisions is a trademark licence unconnected to the original Westinghouse Electric operating businesses; licensed sets ship on third-party platforms. The brand licensor typically holds no data role at all -- it collects a royalty.", "Arbitration / Class Action Waiver": "Where a badge is a pure trademark licence, there may be no corporate entity that both bears the consumer-facing name and holds the data, which complicates service of process for anyone trying to bring a claim.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Included as the extreme case of the licensing spectrum. It matters procedurally: a consumer who identifies their television by brand may find that the named entity is a licensor with no privacy role and no relevant records, which wastes the demand letter and the clock.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Not verified this pass", "HQ State": "Not verified this pass", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Trademark licensor — not verified this pass; platform varies by model", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Trademark licensor — not verified this pass; platform varies by model). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] The badge on the bezel is not the company holding the viewing data\nWHAT THE TERMS SAY: Where a badge is a pure trademark licence, there may be no corporate entity that both bears the consumer-facing name and holds the data, which complicates service of process for anyone trying to bring a claim.\nWHY IT MATTERS: Included as the extreme case of the licensing spectrum. It matters procedurally: a consumer who identifies their television by brand may find that the named entity is a licensor with no privacy role and no relevant records, which wastes the demand letter and the clock.\n(evidence: TV platform licensing reporting, 2024-2026; brand-level, not confirmed against a licence agreement)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — this row answers one question (who actually operates the platform) and does not audit the brand’s own terms, which were not fetched.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The licensing arrangement is reported in the trade press but is not disclosed at the point of sale, so a buyer cannot determine the actual controller from the box.", "Exposure Score (0-100)": 4, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Westinghouse (consumer electronics brand licence)  <-  Trademark licensor — not verified this pass; platform varies by model", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Westinghouse (consumer electronics brand licence) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Westinghouse on a television is a trademark rental with no connection to the industrial company the name came from. The licensor collects a royalty and typically has no data role whatsoever, while the actual platform belongs to somebody else again. That is a procedural trap, not just trivia: a consumer who sends a privacy demand to the brand on the bezel can burn the response clock writing to an entity that holds no records, has no controller obligations and cannot answer the question.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1090, "_entity_id": 1479, "_entity_slug": "westinghouse-consumer-electronics-brand-licence", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Hitachi (consumer television brand licence)", "Category": "TV Hardware (licensed badge / OS tenant)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Hitachi, Ltd. has substantially exited consumer televisions in Western markets; sets carrying the name are produced under licence and run third-party platforms. No ACR product or enforcement action was identified for Hitachi in the consumer TV context this pass.", "Arbitration / Class Action Waiver": "The industrial parent's reputation does not transfer to the platform decisions made by whoever holds the badge licence.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recorded to complete the licensing map rather than because a finding exists. The honest statement is that the tracker has not audited any Hitachi-badged consumer TV terms and the brand's presence in the category is now marginal in the US.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Tokyo", "HQ State": "Japan", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Hitachi, Ltd. — brand licensor; platform varies by licensee", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Hitachi, Ltd. — brand licensor; platform varies by licensee). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 1 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] The badge on the bezel is not the company holding the viewing data\nWHAT THE TERMS SAY: The industrial parent's reputation does not transfer to the platform decisions made by whoever holds the badge licence.\nWHY IT MATTERS: Recorded to complete the licensing map rather than because a finding exists. The honest statement is that the tracker has not audited any Hitachi-badged consumer TV terms and the brand's presence in the category is now marginal in the US.\n(evidence: TV platform licensing reporting, 2024-2026; brand-level, not confirmed against a licence agreement)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — this row answers one question (who actually operates the platform) and does not audit the brand’s own terms, which were not fetched.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The licensing arrangement is reported in the trade press but is not disclosed at the point of sale, so a buyer cannot determine the actual controller from the box.", "Exposure Score (0-100)": 4, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Hitachi (consumer television brand licence)  <-  Hitachi, Ltd. — brand licensor; platform varies by licensee", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Hitachi (consumer television brand licence) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Hitachi is an industrial conglomerate that has largely left Western consumer televisions, so a Hitachi-badged set is a licensed nameplate running somebody else's platform. No ACR product or enforcement action was found for Hitachi in this context. That is a thin result and it is stated thinly on purpose: the tracker has not fetched any Hitachi-badged consumer TV terms, and the brand's US presence is now marginal enough that the absence of a public record proves very little either way.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1091, "_entity_id": 1481, "_entity_slug": "hitachi-consumer-television-brand-licence", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Skyworth", "Category": "TV Hardware (licensed badge / OS tenant)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Skyworth is a PRC-headquartered television manufacturer supplying its own brand and acting as a contract manufacturer for others; its US-market sets ship on Google TV or Roku OS. Skyworth was not named in the December 2025 Texas action.", "Arbitration / Class Action Waiver": "Skyworth's larger significance in this workbook is as an ODM: sets it builds appear under other companies' badges, so its manufacturing footprint is wider than its brand footprint.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The ODM point generalises: contract manufacturing means the physical set behind several unrelated badges can be the same product line, while the data controller differs by whichever OS the badge holder licensed. Hardware provenance and data provenance are independent variables and consumers conflate them constantly.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Shenzhen", "HQ State": "China (Guangdong)", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Skyworth Group Limited", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Skyworth Group Limited). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] The badge on the bezel is not the company holding the viewing data\nWHAT THE TERMS SAY: Skyworth's larger significance in this workbook is as an ODM: sets it builds appear under other companies' badges, so its manufacturing footprint is wider than its brand footprint.\nWHY IT MATTERS: The ODM point generalises: contract manufacturing means the physical set behind several unrelated badges can be the same product line, while the data controller differs by whichever OS the badge holder licensed. Hardware provenance and data provenance are independent variables and consumers conflate them constantly.\n(evidence: TV platform licensing reporting, 2024-2026; brand-level, not confirmed against a licence agreement)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — this row answers one question (who actually operates the platform) and does not audit the brand’s own terms, which were not fetched.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The licensing arrangement is reported in the trade press but is not disclosed at the point of sale, so a buyer cannot determine the actual controller from the box.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Skyworth  <-  Skyworth Group Limited", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Skyworth you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Skyworth matters less as a brand than as a factory: it builds televisions that reach US shelves under OTHER companies' badges, while its own-brand sets run Google TV or Roku OS. That decouples two things shoppers routinely treat as one. The company that BUILT your panel and the company that HOLDS your viewing data are independent variables -- the same physical set can appear under three badges with three different data controllers, and a different set under one badge can share a controller with a competitor.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1092, "_entity_id": 1483, "_entity_slug": "skyworth", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Xiaomi (Mi TV / Xiaomi TV)", "Category": "TV Hardware (licensed badge / OS tenant)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Xiaomi sells televisions running Google TV in Western markets and its own MIUI-derived platform elsewhere, so the applicable controller depends on the market a set was sold into rather than on the brand. Xiaomi was not among the Texas defendants; its US television presence is limited compared with its position in other regions.", "Arbitration / Class Action Waiver": "A Xiaomi set bought abroad and used in the US may be running an entirely different platform, and therefore a different privacy regime, from a US-market equivalent.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Flagged because grey-market and relocated-household devices are a genuine Mid-Atlantic issue in an immigrant-heavy region: a television carried from another country keeps the privacy regime it was provisioned under, not the one its owner now lives in.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Beijing", "HQ State": "China", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Xiaomi Corporation (HKEX: 1810)", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Partial audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Xiaomi Corporation (HKEX: 1810)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] The badge on the bezel is not the company holding the viewing data\nWHAT THE TERMS SAY: A Xiaomi set bought abroad and used in the US may be running an entirely different platform, and therefore a different privacy regime, from a US-market equivalent.\nWHY IT MATTERS: Flagged because grey-market and relocated-household devices are a genuine Mid-Atlantic issue in an immigrant-heavy region: a television carried from another country keeps the privacy regime it was provisioned under, not the one its owner now lives in.\n(evidence: TV platform licensing reporting, 2024-2026; brand-level, not confirmed against a licence agreement)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — this row answers one question (who actually operates the platform) and does not audit the brand’s own terms, which were not fetched.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The licensing arrangement is reported in the trade press but is not disclosed at the point of sale, so a buyer cannot determine the actual controller from the box.", "Exposure Score (0-100)": 6, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Xiaomi (Mi TV / Xiaomi TV)  <-  Xiaomi Corporation (HKEX: 1810)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Xiaomi (Mi TV / Xiaomi TV) you gave up your data shared corporate-wide. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A Xiaomi television bought overseas and brought to the United States keeps the platform and the privacy regime it was provisioned with -- Google TV in Western markets, Xiaomi's own platform elsewhere -- so two identical-looking sets in two DMV living rooms can be governed by different companies under different regimes. That is a real issue for an immigrant-heavy region where households routinely relocate with their electronics. The set does not re-provision itself to local law when its owner moves, and no one tells the owner that.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Smart TVs & TV Platforms", "_row_id": 1093, "_entity_id": 1485, "_entity_slug": "xiaomi-mi-tv-xiaomi-tv", "_issuer": "Xiaomi Corporation", "_issuer_slug": "xiaomi-corporation", "_ticker": "1810", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Pluto TV (Paramount Skydance)", "Category": "Streaming Service (free, ad-supported)", "Terms & Conditions URL": "pluto.tv/en/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "pluto.tv/en/privacy-policy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Diaz et al. v. Paramount Skydance Corporation et al., No. 5:25-cv-02945 (C.D. Cal., filed 4 November 2025). Five parents of children under 13, from California, Illinois, New Jersey and Indiana, allege that Pluto TV's website carries GOOGLE AND MICROSOFT tracking pixels that capture and transmit personally identifiable video-viewing information about children watching the platform's KIDS section, and that the data is used to build advertising profiles on minors without parental consent. The 72-page complaint pleads the VPPA among other federal and state privacy claims and alleges the tracking tools were intentionally configured. The federal Video Privacy Protection Act (18 U.S.C. § 2710) carries $2,500 statutory damages per violation, and its scope is now before the Supreme Court in Salazar v. Paramount Global, cert granted 2026-01-26.", "Arbitration / Class Action Waiver": "Not verified this pass. Note the procedural asymmetry the complaint navigates: consumer arbitration clauses are routinely enforced against adult account holders, while claims brought on behalf of minors who never formed a contract raise separate enforceability questions. That gap is a live reason children’s claims sometimes reach court when adults’ do not.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Pluto TV is the sharpest single illustration of the free-tier bargain in this workbook: the service has no subscription price, so the advertising infrastructure IS the product, and the complaint alleges that infrastructure was left running inside the children's section. Paramount also owns Paramount+, which appears separately in Consumer Apps and is itself the respondent in the Supreme Court VPPA case -- one corporate group, two independent video-privacy exposures, one of them setting national precedent.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Los Angeles", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.classaction.org/news/paramount-lawsuit-claims-pluto-tv-harvests-personal-info-from-videos-watched-by-children", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Paramount Skydance Corporation", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Paramount Skydance Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-1] Parents allege Google and Microsoft tracking pixels were running inside Pluto TV's children's section\nWHAT THE TERMS SAY: The November 2025 complaint alleges Pluto TV embedded Google and Microsoft tracking tools, including pixels and third-party cookies, that captured and transmitted the video-viewing data of children using the platform's Kids section, for use in targeted advertising.\nWHY IT MATTERS: Children under 13 cannot consent and their parents allege they were never asked, so the ordinary defence that a user accepted the terms does not reach these plaintiffs.\n(evidence: Diaz v. Paramount Skydance Corp., No. 5:25-cv-02945 (C.D. Cal.), filed 2025-11-04)", "Top Troubling #2": "[DATA_SALE · FL-2] A free service prices itself in advertising data, and the kids section was inside the same pipe\nWHAT THE TERMS SAY: Pluto TV is distributed at no subscription cost and monetised through advertising; the complaint alleges the viewing data captured included that of minors viewing child-directed programming.\nWHY IT MATTERS: Where the price is zero, the data flow is the consideration, and there is no premium tier a parent can buy to opt out of it.\n(evidence: Complaint allegations and Pluto TV business model)", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Claims brought for children can reach a courtroom that the same claims for adults would not\nWHAT THE TERMS SAY: The action is brought by parents on behalf of minors, a posture that raises contract-formation questions distinct from those facing adult account holders bound by consumer arbitration terms.\nWHY IT MATTERS: It is one of the few routes in this workbook where a video-privacy claim reaches a judge rather than an arbitrator.\n(evidence: Procedural observation; the operative Pluto arbitration clause was not fetched this pass)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "A 72-page filed complaint with a case number, named plaintiffs and dated allegations makes the claim fully checkable.", "Exposure Score (0-100)": 58, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 15, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 15/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 5/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "VIDEO PRIVACY (VPPA) → 18 U.S.C. § 2710 gives a private right of action with $2,500 statutory damages per violation and is NOT preempted by state law; scope is before the Supreme Court in Salazar v. Paramount Global (cert granted 2026-01-26), so consumer standing may widen or narrow within the year\nCHILDREN’S DATA → Federal COPPA (amended rule, compliance 2026-04-22) now requires SEPARATE verifiable parental consent before a child’s data goes to advertisers or AI training, and bans indefinite retention; MD bars targeted advertising to consumers a controller knows are under 18; state AGs have express COPPA parens patriae standing (confirmed in the Roku ruling)\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Pluto TV (Paramount Skydance)  <-  Paramount Skydance Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Pluto TV (Paramount Skydance) you gave up your personal data sold onward, your data shared corporate-wide, your right to sue, and your right to join a class action. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Five parents sued Paramount in November 2025 alleging that Pluto TV's KIDS SECTION had Google and Microsoft tracking pixels running inside it -- capturing which cartoons children under 13 watched and sending that to two of the largest advertising companies on earth to build profiles on them. Pluto TV is free, which is exactly the point: with no subscription price, the advertising data IS the price, and there is no paid tier a parent can buy to get out of it. The 72-page complaint alleges the tracking tools were intentionally configured that way. Paramount is simultaneously the respondent in the Supreme Court case that will decide how far the federal video-privacy law reaches at all.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Streaming Services (v59)", "_row_id": 1094, "_entity_id": 1487, "_entity_slug": "pluto-tv-paramount-skydance", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Crunchyroll (Sony Pictures Entertainment)", "Category": "Streaming Service (anime, subscription)", "Terms & Conditions URL": "crunchyroll.com/tos", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "crunchyroll.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "TWO separate 2026 actions, plus a repeat-conduct history. (1) Cabonios v. Crunchyroll, LLC, No. 2:26-cv-02373 (C.D. Cal., filed 5 March 2026) alleges Crunchyroll embedded the BRAZE software development kit in its mobile app and systematically transmitted users' email addresses, persistent device identifiers and the specific titles they watched to Braze, a third-party marketing and analytics firm, without consent -- seeking $2,500 per VPPA violation plus punitive damages. (2) A class action filed later in March 2026 alleges a breach at TELUS, an outsourced customer-support partner, exposed roughly 6.8 MILLION users' full names, usernames, email addresses, IP addresses and partial payment information drawn from support tickets. (3) Crunchyroll previously settled a materially similar VPPA claim for $16 MILLION in 2023 over Facebook Pixel disclosure, paying roughly $30 per affected user.", "Arbitration / Class Action Waiver": "Not verified this pass. The repeat pattern is the point: a company that settles a pixel-based VPPA claim and then faces an SDK-based VPPA claim three years later has, on the plaintiffs’ account, changed the vendor rather than the practice.", "Fees / Billing Flags": "Not itemized this pass beyond the subscription model; auto-renewal is standard for the tier structure and flagged accordingly.", "Notes": "This row is the strongest repeat-conduct example in the streaming category, and it belongs beside the Sony TV row on the Smart TVs tab: one ultimate parent, two unrelated video-privacy exposures, one on the panel and one in the app. It is also a clean illustration that the VPPA plaintiff bar has migrated from web pixels to mobile SDKs, which is where the next wave of these cases will land.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation + Data breach", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://topclassactions.com/lawsuit-settlements/lawsuit-news/crunchyroll-accused-of-sharing-users-video-viewing-data-without-consent/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Sony Group Corporation (NYSE: SONY)", "Years Referenced in Finding (heuristic)": "2023, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Sony Group Corporation (NYSE: SONY)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "[DATA_SALE · FL-1] A marketing SDK allegedly carried email addresses, device IDs and exact episode titles off the app\nWHAT THE TERMS SAY: The March 2026 complaint alleges the Braze SDK embedded in the Crunchyroll mobile app transmitted users’ email addresses, persistent device identifiers and the titles of specific videos watched to a third-party marketing company without consent.\nWHY IT MATTERS: Email plus title is directly identifying — it is not aggregate analytics, it is a named person and what they watched. The federal Video Privacy Protection Act (18 U.S.C. § 2710) carries $2,500 statutory damages per violation, and its scope is now before the Supreme Court in Salazar v. Paramount Global, cert granted 2026-01-26.\n(evidence: Cabonios v. Crunchyroll, LLC, No. 2:26-cv-02373 (C.D. Cal.), filed 2026-03-05)", "Top Troubling #2": "[DATA_BREACH · FL-1] A separate March 2026 suit alleges roughly 6.8 million users were exposed through an outsourced support vendor\nWHAT THE TERMS SAY: A class action alleges a security failure at Telus, Crunchyroll’s customer-support outsourcing partner, exposed approximately 6.8 million users’ names, usernames, email addresses, IP addresses and partial payment data held in support tickets.\nWHY IT MATTERS: It is the shared-vendor pattern from Cross-Cutting Finding #1 again: the exposure sat with a contractor the subscriber never chose or heard of.\n(evidence: Class action filings, March 2026; allegations not yet adjudicated)", "Top Troubling #3": "[REGULATORY_ACTION_PRIVACY · FL-2] Crunchyroll already paid $16 million in 2023 for materially similar video-privacy conduct\nWHAT THE TERMS SAY: A 2023 settlement resolved VPPA claims over Facebook Pixel disclosure for $16 million, paying roughly $30 per affected user.\nWHY IT MATTERS: The 2026 claim alleges the same category of disclosure through a different vendor, which is what makes it a repeat-conduct allegation rather than a novel one.\n(evidence: Peiffer Wolf settlement announcement and 2023 settlement coverage)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=Y; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Two docketed 2026 cases and a completed 2023 settlement give dates, dollar figures and named vendors.", "Exposure Score (0-100)": 58, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 16/20 (severity4+14, litigation+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "VIDEO PRIVACY (VPPA) → 18 U.S.C. § 2710 gives a private right of action with $2,500 statutory damages per violation and is NOT preempted by state law; scope is before the Supreme Court in Salazar v. Paramount Global (cert granted 2026-01-26), so consumer standing may widen or narrow within the year\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Crunchyroll (Sony Pictures Entertainment)  <-  Sony Group Corporation (NYSE: SONY)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Crunchyroll (Sony Pictures Entertainment) you gave up your personal data sold onward, your data shared corporate-wide, your right to sue, your right to join a class action, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Crunchyroll paid $16 MILLION in 2023 to settle claims it leaked subscribers' viewing data through the Facebook Pixel -- about $30 a person. In MARCH 2026 it was sued again, this time over the Braze marketing SDK inside its mobile app, allegedly shipping out users' EMAIL ADDRESSES, device IDs and the exact anime episodes they watched. Plaintiffs want $2,500 per violation. Weeks later came a second suit: a breach at TELUS, Crunchyroll's outsourced customer-support vendor, allegedly exposing roughly 6.8 MILLION users' names, emails, IP addresses and partial payment details from support tickets. Same parent as the Sony televisions Texas is still suing.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Streaming Services (v59)", "_row_id": 1095, "_entity_id": 1488, "_entity_slug": "crunchyroll-sony-pictures-entertainment", "_issuer": "Sony Group Corporation", "_issuer_slug": "sony-group-corporation", "_ticker": "SONY", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Samsung TV Plus", "Category": "Streaming Service (free, ad-supported, OEM)", "Terms & Conditions URL": "samsung.com/us/Legal/SamsungLegal-SmartTV/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "samsung.com/us/account/privacy-policy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Samsung TV Plus is the free ad-supported channel service preinstalled on Samsung televisions, and it is inseparable from the ACR question: the same platform that operates Viewing Information Services also operates the channel service, so the content you watch and the ad inventory sold against it sit with one controller. The February 2026 Texas settlement constrains the ACR collection feeding this business for Texas consumers only.", "Arbitration / Class Action Waiver": "Not verified this pass; see the Samsung Electronics America row on the Smart TVs & TV Platforms tab for the settlement posture.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Broken out from the hardware row because a consumer can use TV Plus on a phone or a third-party device without owning a Samsung television, which puts them inside the same data relationship with none of the hardware context. That is the kind of boundary the tracker exists to make legible.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Ridgefield Park", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Samsung Electronics Co., Ltd.", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Samsung Electronics Co., Ltd.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SALE · FL-2] The platform that recognises what you watch also sells the advertising against it\nWHAT THE TERMS SAY: Samsung TV Plus is operated by the same platform entity as Viewing Information Services, Samsung’s ACR feature, which the Texas AG alleged was enabled through a dark-pattern setup flow.\nWHY IT MATTERS: Content service and measurement service being one company means an opt-out has to be found in the TV settings rather than in the app.\n(evidence: Samsung platform structure and Texas AG filings, Dec 2025)", "Top Troubling #2": "[REGULATORY_ACTION_PRIVACY · FL-2] The February 2026 Texas consent remedy reaches Texas consumers only\nWHAT THE TERMS SAY: Samsung agreed on 26 February 2026 to require express consent before ACR collection and to rebuild its consent screens, with no monetary penalty and no nationwide obligation.\nWHY IT MATTERS: A DMV household using TV Plus is governed by the pre-settlement default.\n(evidence: Texas AG settlement, 2026-02-26)", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The ACR conduct is documented through the Texas action, but Samsung does not publish a TV Plus-specific data disclosure separating channel viewing from platform ACR.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Samsung TV Plus  <-  Samsung Electronics Co., Ltd.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Samsung TV Plus you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Samsung TV Plus is free television that comes preinstalled, and it is run by the same part of Samsung that operates Viewing Information Services -- the ACR system Texas sued over for capturing what is on screen. So the company recommending the channel, the company recognising what plays on it, and the company selling the ads against it are one company, and the only opt-out lives in a TV settings menu rather than in the app you are actually using. If you watch TV Plus on a phone or another maker's device, you are in the same data relationship with none of the context.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Streaming Services (v59)", "_row_id": 1096, "_entity_id": 1489, "_entity_slug": "samsung-tv-plus", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "LG Channels", "Category": "Streaming Service (free, ad-supported, OEM)", "Terms & Conditions URL": "lg.com/us/terms-of-use", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "lg.com/us/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "LG Channels is the free ad-supported service on LG webOS televisions, monetised through LG Ad Solutions -- the same in-house advertising arm that receives the Live Plus ACR signal. The 11 May 2026 Texas Agreed Final Judgment now requires express consent before that ACR collection, for Texas consumers.", "Arbitration / Class Action Waiver": "Not verified this pass; see the LG Electronics U.S.A. row for settlement detail.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recorded separately from the hardware row so that the closed loop is visible in one place: LG makes the panel, LG collects the viewing signal, LG programmes the free channels, and LG sells the advertising. Four roles, one company, and no third party in the chain against whom a sale-based opt-out right would attach.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Englewood Cliffs", "HQ State": "New Jersey", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "LG Electronics Inc.", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: LG Electronics Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-1] One company holds all four roles: panel, measurement, programming and ad sales\nWHAT THE TERMS SAY: LG manufactures the television, operates the Live Plus ACR feature, programmes the LG Channels free service and monetises it through LG Ad Solutions.\nWHY IT MATTERS: Opt-out-of-sale rights key on transfers to third parties, and a fully in-house loop contains no such transfer.\n(evidence: LG corporate structure; not confirmed against LG contract text this pass)", "Top Troubling #2": "[REGULATORY_ACTION_PRIVACY · FL-2] A Texas Agreed Final Judgment now governs the collection feeding this service in one state\nWHAT THE TERMS SAY: The 11 May 2026 judgment requires express consent before ACR collection and a pop-up disclosure with a clear opt-out.\nWHY IT MATTERS: It is the only jurisdiction where that consent is mandatory, so identical LG hardware behaves differently by state.\n(evidence: State of Texas v. LG Electronics U.S.A., Inc., 2026-05-11)", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The corporate loop is publicly evident but LG publishes no consumer-facing statement of how Live Plus data reaches LG Ad Solutions.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 13, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 13/20 (severity3+8, penalty+3, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "LG Channels  <-  LG Electronics Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using LG Channels you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "LG Channels closes a loop that most viewers never see the shape of. LG builds the panel, Live Plus recognises what is on it, LG programmes the free channels, and LG Ad Solutions sells the advertising -- four roles, one company, zero third parties. That structure matters because Maryland's and Virginia's privacy rights largely give you the power to stop a SALE of your data to someone else. When nobody else is involved, there is no sale, and the right simply has nothing to attach to. The Texas consent order fixes this for Texans only.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Streaming Services (v59)", "_row_id": 1097, "_entity_id": 1490, "_entity_slug": "lg-channels", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Vizio WatchFree+ (Walmart)", "Category": "Streaming Service (free, ad-supported, OEM)", "Terms & Conditions URL": "vizio.com/en/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "vizio.com/en/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "WatchFree+ is the free ad-supported service on Vizio SmartCast televisions. Since Walmart's December 2024 acquisition, the advertising sold against it feeds Walmart Connect, so a household's free-TV viewing and its Walmart purchase history now sit inside one company. The underlying ACR business, Inscape, is the direct descendant of the operation the FTC settled with in 2017.", "Arbitration / Class Action Waiver": "Not verified this pass; the contracting entity changed on 2024-12-03 and the current terms should be re-fetched before reliance.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The reason to carry this as its own row rather than folding it into Vizio: WatchFree+ is where the acquisition thesis actually touches the consumer. The hardware row explains what Walmart bought; this row explains what it does with it.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Irvine", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Walmart Inc. (NYSE: WMT)", "Years Referenced in Finding (heuristic)": "2017, 2024, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Walmart Inc. (NYSE: WMT)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-1] Free viewing on a Vizio now sits in the same company as your grocery receipts\nWHAT THE TERMS SAY: WatchFree+ advertising is monetised through Walmart Connect following Walmart’s December 2024 acquisition of Vizio, SmartCast and the Inscape data business.\nWHY IT MATTERS: The join between viewing and retail purchasing happens internally, so no consumer consent to a data sale is required for it to exist.\n(evidence: Walmart acquisition announcement 2024-12-03 and Walmart Connect integration reporting)", "Top Troubling #2": "[DATA_SALE · FL-2] The ACR business underneath this service is the one the FTC settled with in 2017\nWHAT THE TERMS SAY: Inscape, which supplies the viewing signal, is the continuation of the Vizio data business that the FTC and New Jersey settled with in February 2017 for $2.2 million.\nWHY IT MATTERS: A documented enforcement history is directly relevant to how much weight to give current assurances.\n(evidence: FTC v. Vizio, February 2017)", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=Y; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=Y; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The corporate facts are public; the extent of the viewing-to-purchase join inside Walmart is not disclosed.", "Exposure Score (0-100)": 23, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 11, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 0/20 (none) | Record 11/20 (severity3+8, penalty+3) | flags stated 4/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ACR / VIEWING DATA → Treat the panel and the OS as separate controllers: an app-layer consent does not bind the TV platform capturing the same screen. MD/VA opt-out-of-sale rights reach the OS operator; Texas obtained express-consent orders against Samsung and LG that competitors have not matched, so a DMV household must still switch ACR off by hand\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Vizio WatchFree+ (Walmart)  <-  Walmart Inc. (NYSE: WMT)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Vizio WatchFree+ (Walmart) you gave up your personal data sold onward and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "WatchFree+ is the free channel service on Vizio sets, and since December 2024 the advertising on it runs through Walmart Connect -- because Walmart bought Vizio. Which means the record of the free television you watched to save money now sits in the same company as the record of what you bought at Walmart. No sale to an outside party is needed for that profile to exist; it only has to be joined internally. And the ACR engine underneath it, Inscape, is the same data business the FTC settled with in 2017 for tracking 11 million televisions by default.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Streaming Services (v59)", "_row_id": 1098, "_entity_id": 1491, "_entity_slug": "vizio-watchfree-walmart", "_issuer": "Walmart Inc.", "_issuer_slug": "walmart-inc", "_ticker": "WMT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "The Roku Channel", "Category": "Streaming Service (free, ad-supported, OEM)", "Terms & Conditions URL": "roku.com/legal/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "roku.com/legal/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The Roku Channel is the free ad-supported service inside Roku OS, and it is squarely inside the Michigan Attorney General's COPPA action: the complaint alleges Roku collects children's personal information both within and outside the Kids and Family section of the Roku channel, and that Roku offers no dedicated child profiles at all -- so a child watching the free channel is tracked on adult terms. In April 2026 the court dismissed the state video-privacy counts but allowed the COPPA claims to proceed.", "Arbitration / Class Action Waiver": "Roku consumer terms have historically carried binding arbitration with a class waiver; not re-fetched this pass. The Michigan action is an AG enforcement matter and was never subject to it.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Carried separately from the Roku platform row because the Kids and Family section is specifically named in the surviving COPPA claims, and because a parent's practical question -- is it safe to leave a child on the free channel -- is answered here rather than in the OS row.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Jose", "HQ State": "California", "CEO": null, "Ticker": "ROKU", "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Regulatory action + Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (ROKU). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Roku, Inc.", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Roku, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-1] Michigan alleges children's data is collected inside and outside the Kids and Family section\nWHAT THE TERMS SAY: The Michigan AG complaint alleges Roku collects children’s device identifiers, IP addresses, cookies, account and browsing information, precise geolocation and visual and audio information both within and outside the Kids and Family section of the Roku channel.\nWHY IT MATTERS: A section labelled for children that applies no different data rules is a labelling problem, not a protection.\n(evidence: Nessel v. Roku, No. 2:25-cv-11221 (E.D. Mich.), complaint 2025-04-29)", "Top Troubling #2": "[REGULATORY_ACTION_PRIVACY · FL-1] The COPPA claims survived a motion to dismiss in April 2026\nWHAT THE TERMS SAY: The court held COPPA’s express parens patriae provision gives the state standing and that the alleged collection could identify individuals, while dismissing the state video-privacy theories.\nWHY IT MATTERS: The surviving claim is the children’s one, which is the route a Mid-Atlantic parent would realistically use.\n(evidence: April 2026 opinion in Nessel v. Roku)", "Top Troubling #3": "[DATA_SALE · FL-2] Free viewing is funded by the same advertising pipeline named in the complaint\nWHAT THE TERMS SAY: The complaint alleges Roku enables third-party channels to collect children’s information to attract content providers and increase advertising revenue, and points to relationships with web trackers and data brokers.\nWHY IT MATTERS: The economics of the free tier are what the complaint says drove the collection.\n(evidence: Michigan AG press release, 2025-04-29)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "A live federal docket with a dated partial ruling fixes both what is alleged and what survived.", "Exposure Score (0-100)": 62, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 19, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 19/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 0/20 (none) | Record 16/20 (severity4+14, litigation+2) | flags stated 6/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "VIDEO PRIVACY (VPPA) → 18 U.S.C. § 2710 gives a private right of action with $2,500 statutory damages per violation and is NOT preempted by state law; scope is before the Supreme Court in Salazar v. Paramount Global (cert granted 2026-01-26), so consumer standing may widen or narrow within the year\nCHILDREN’S DATA → Federal COPPA (amended rule, compliance 2026-04-22) now requires SEPARATE verifiable parental consent before a child’s data goes to advertisers or AI training, and bans indefinite retention; MD bars targeted advertising to consumers a controller knows are under 18; state AGs have express COPPA parens patriae standing (confirmed in the Roku ruling)\nDATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "The Roku Channel  <-  Roku, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using The Roku Channel you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, and your right to join a class action. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The Roku Channel is free, comes built into the operating system, and is named in Michigan's children's-privacy case against Roku. The complaint alleges Roku collects children's precise location, voice recordings and browsing identifiers BOTH INSIDE AND OUTSIDE the Kids and Family section -- because, unlike Netflix or Disney+, Roku offers no child profiles at all. A section labelled for kids that applies no different rules is a label, not a protection. In April 2026 a federal judge threw out the video-privacy counts and let the children's claims go forward, which makes COPPA the live route for a parent in Maryland, Virginia or DC.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Streaming Services (v59)", "_row_id": 1099, "_entity_id": 1492, "_entity_slug": "the-roku-channel", "_issuer": "Roku, Inc.", "_issuer_slug": "roku-inc", "_ticker": "ROKU", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "YouTube TV (Google/Alphabet)", "Category": "Streaming Service (live TV, subscription)", "Terms & Conditions URL": "tv.youtube.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "YouTube TV runs under the general Google privacy policy rather than a service-specific notice, which means live-television viewing joins the same account graph as Search, Android, Maps and YouTube. There is no separate YouTube TV data control. The relevance of the Rodriguez v. Google verdict is direct: a jury found in September 2025 that Google continued collecting activity from users who had switched Web & App Activity off, which is the same class of control a YouTube TV subscriber would be told to use.", "Arbitration / Class Action Waiver": "Google does not impose mandatory consumer arbitration in its general US terms and litigates privacy class actions to verdict. Recorded as an advantage on the dispute-rights axis — YouTube TV subscribers retain court access that Netflix, Paramount+ and Roku customers do not.", "Fees / Billing Flags": "Auto-renewing monthly subscription with repeated price increases since launch; specific current terms not itemized this pass.", "Notes": "The interesting asymmetry: Google is one of the worst rows in this workbook on data practices and one of the better ones on dispute rights. Those are independent axes and the Exposure Score is built to keep them separate rather than averaging them into a single misleading verdict.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Bruno", "HQ State": "California", "CEO": null, "Ticker": "GOOGL", "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (GOOGL). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alphabet Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-1] Live TV viewing lands in the same account graph as Search, Maps and Android\nWHAT THE TERMS SAY: YouTube TV operates under the general Google privacy policy with no service-specific data notice, so viewing data is processed within the same account as other Google services.\nWHY IT MATTERS: What you watch on live television becomes an input to the same profile that shapes your search results and advertising.\n(evidence: Google policy structure; no YouTube TV-specific notice identified)", "Top Troubling #2": "[UNILATERAL_CHANGES · FL-2] A jury has found a Google privacy toggle did not stop the collection it described\nWHAT THE TERMS SAY: In Rodriguez v. Google LLC a jury awarded $425.7 million on 3 September 2025 over collection that continued after users disabled Web & App Activity.\nWHY IT MATTERS: It bears directly on how much protection the recommended opt-out actually delivers.\n(evidence: Rodriguez v. Google LLC, N.D. Cal., verdict 2025-09-03)", "Top Troubling #3": "[FORCED_ARBITRATION · FL-3] Court access is preserved here where most streaming competitors foreclose it\nWHAT THE TERMS SAY: Google does not impose mandatory consumer arbitration in its general US Terms of Service.\nWHY IT MATTERS: A YouTube TV subscriber can join a class action; a Netflix or Paramount+ subscriber generally cannot.\n(evidence: Google Terms of Service structure; recorded as a consumer advantage)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Google publishes extensive policies but none that isolate live-television viewing as a distinct, separately-controllable category.", "Exposure Score (0-100)": 31, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 10/20 (severity3+8, litigation+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "VIDEO PRIVACY (VPPA) → 18 U.S.C. § 2710 gives a private right of action with $2,500 statutory damages per violation and is NOT preempted by state law; scope is before the Supreme Court in Salazar v. Paramount Global (cert granted 2026-01-26), so consumer standing may widen or narrow within the year\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "YouTube TV (Google/Alphabet)  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (6 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using YouTube TV (Google/Alphabet) you gave up your physical movements, your data shared corporate-wide, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "YouTube TV has no privacy policy of its own. Your live-television viewing -- every channel, every timestamp -- lands in the same Google account graph as your searches, your Maps history and your Android activity, and there is no YouTube TV-specific control to separate it. The recommended fix is Google's own activity toggle, which is awkward, because in September 2025 a federal jury awarded $425.7 MILLION after finding Google kept collecting app activity from people who had already turned that toggle off. One genuine credit: Google does not force arbitration, so unlike Netflix or Roku subscribers, you can still sue.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Streaming Services (v59)", "_row_id": 1100, "_entity_id": 1493, "_entity_slug": "youtube-tv-google-alphabet", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fubo / Hulu + Live TV (Disney-controlled)", "Category": "Streaming Service (live TV, subscription)", "Terms & Conditions URL": "fubo.tv/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "fubo.tv/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Disney and Fubo completed the combination of Fubo with Hulu + Live TV in October 2025, creating a virtual pay-TV business with close to 6 million North American subscribers under Disney control. The privacy consequence for existing subscribers on both sides is a change of controller by corporate transaction rather than by consent: the entity holding a Fubo subscriber's viewing history in September 2025 was not the entity holding it in November 2025, and no subscriber was asked.", "Arbitration / Class Action Waiver": "Not verified this pass. The specific question to resolve in Tranche 2 is which entity’s arbitration clause now governs legacy Fubo subscribers, since that determines whether a claim goes to AAA under Fubo’s old terms or under Disney’s.", "Fees / Billing Flags": "Auto-renewing subscription; sports-heavy live tiers carry regional fees not itemized this pass.", "Notes": "Included specifically as the change-of-controller case in streaming, matching the Walmart/Vizio case in hardware. Both show the same gap: privacy policies describe what a company will do with your data, and say almost nothing about what happens when a different company acquires it.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "The Walt Disney Company (NYSE: DIS) — controlling interest", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: The Walt Disney Company (NYSE: DIS) — controlling interest). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] Subscribers changed data controllers by merger, without being asked\nWHAT THE TERMS SAY: Disney and Fubo completed their combination with Hulu + Live TV in October 2025, forming a virtual pay-TV business with nearly 6 million North American subscribers under Disney control.\nWHY IT MATTERS: The corporate-transaction clause in a privacy policy is the one provision that can transfer everything about you to a company you never chose.\n(evidence: Merger completion reporting, October 2025)", "Top Troubling #2": "[FORCED_ARBITRATION · FL-2] Which arbitration clause now binds a legacy Fubo subscriber is unresolved on this record\nWHAT THE TERMS SAY: The combination places legacy Fubo subscribers under Disney control while the operative dispute-resolution terms for those accounts were not fetched this pass.\nWHY IT MATTERS: A subscriber cannot exercise an opt-out window without first knowing whose clause applies and when it started running.\n(evidence: Open question flagged for Tranche 2)", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The transaction is public and dated; its effect on legacy subscriber terms is not disclosed in any consumer-facing document retrieved this pass.", "Exposure Score (0-100)": 46, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "VIDEO PRIVACY (VPPA) → 18 U.S.C. § 2710 gives a private right of action with $2,500 statutory damages per violation and is NOT preempted by state law; scope is before the Supreme Court in Salazar v. Paramount Global (cert granted 2026-01-26), so consumer standing may widen or narrow within the year\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Fubo / Hulu + Live TV (Disney-controlled)  <-  The Walt Disney Company (NYSE: DIS) — controlling interest", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Fubo / Hulu + Live TV (Disney-controlled) you gave up your physical movements, your data shared corporate-wide, your right to sue, your right to join a class action, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "In October 2025 Fubo and Hulu + Live TV were combined under Disney control, moving nearly 6 MILLION subscribers to a new corporate owner. Nobody was asked. The corporate-transaction clause buried in almost every privacy policy is the single provision that can hand your entire viewing history to a company you never chose -- and it fires without notice, consent or an opt-out. The unresolved practical question is whose arbitration clause now binds a legacy Fubo subscriber, because an opt-out window you cannot identify is a window you cannot use.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Streaming Services (v59)", "_row_id": 1101, "_entity_id": 1495, "_entity_slug": "fubo-hulu-live-tv-disney-controlled", "_issuer": "The Walt Disney Company  — controlling interest", "_issuer_slug": "the-walt-disney-company-controlling-interest", "_ticker": "DIS", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sling TV (EchoStar/DISH)", "Category": "Streaming Service (live TV, subscription)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Sling TV is EchoStar's virtual pay-TV service. Its terms and privacy policy were NOT retrieved this pass. The structural point that can be stated without them: EchoStar also operates satellite television and a wireless network, so a Sling subscriber may sit inside a group holding viewing, location and telecom records under related policies.", "Arbitration / Class Action Waiver": "NOT FETCHED THIS PASS. Recorded as unknown, not as absent. Queued in ROSTER - RESEARCH QUEUE for Tranche 2 with the standard checklist: fetch both policy URLs, extract the arbitration clause and any opt-out window, then re-score.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Queued because the multi-service parent is what makes the row worth auditing properly — a pure streaming policy is a narrower question than a policy inside a telecom group, and this tracker already documents (Carriers tab) how much carriers collect.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Englewood", "HQ State": "Colorado", "CEO": null, "Ticker": "SATS", "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (SATS). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "EchoStar Corporation", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: EchoStar Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SCOPE_LIMITATION · FL-2] Row created for coverage; the policy text has not been retrieved\nWHAT THE TERMS SAY: Sling TV is EchoStar's virtual pay-TV service. Its terms and privacy policy were NOT retrieved this pass. The structural point that can be stated without them: EchoStar also operates satellite television and a wireless network, so a Sling subscriber may sit inside a group holding viewing, location and telecom records under related policies.\nWHY IT MATTERS: Blank is never clean in this workbook — the absence of a finding here measures the audit, not the company.\n(evidence: v59 coverage pass; fetch queued)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — coverage row. Two further troubling-terms slots are deliberately left unfilled rather than filled speculatively.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No policy document was retrieved for this row this pass, so the opacity rating describes the state of the audit rather than a measured property of the company.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "VIDEO PRIVACY (VPPA) → 18 U.S.C. § 2710 gives a private right of action with $2,500 statutory damages per violation and is NOT preempted by state law; scope is before the Supreme Court in Salazar v. Paramount Global (cert granted 2026-01-26), so consumer standing may widen or narrow within the year", "Entity Type": "App / Service", "Ownership Path": "Sling TV (EchoStar/DISH)  <-  EchoStar Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Sling TV (EchoStar/DISH) you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Sling TV's terms have NOT been retrieved by this tracker, so nothing here is a finding about them. What can be said is structural: Sling sits inside EchoStar, a group that also runs satellite television and a wireless network. This workbook's Carriers tab documents how much telecom operators collect, and a viewing record held next to a location and billing record inside one corporate group is a materially different object from a streaming policy standing alone. That is why this row is queued rather than quietly scored as clean.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Streaming Services (v59)", "_row_id": 1102, "_entity_id": 1497, "_entity_slug": "sling-tv-echostar-dish", "_issuer": "EchoStar Corporation", "_issuer_slug": "echostar-corporation", "_ticker": "SATS", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Philo", "Category": "Streaming Service (live TV, subscription)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Philo is a low-cost entertainment-channel live service. Neither its terms nor its privacy policy were retrieved this pass, so no clause-level finding is recorded.", "Arbitration / Class Action Waiver": "NOT FETCHED THIS PASS. Recorded as unknown, not as absent. Queued in ROSTER - RESEARCH QUEUE for Tranche 2 with the standard checklist: fetch both policy URLs, extract the arbitration clause and any opt-out window, then re-score.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Included for category completeness with an explicit unknown, rather than omitted. The tracker's coverage claim for streaming is only honest if the services it has not read are visible as unread.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Philo, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Philo, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SCOPE_LIMITATION · FL-2] Row created for coverage; the policy text has not been retrieved\nWHAT THE TERMS SAY: Philo is a low-cost entertainment-channel live service. Neither its terms nor its privacy policy were retrieved this pass, so no clause-level finding is recorded.\nWHY IT MATTERS: Blank is never clean in this workbook — the absence of a finding here measures the audit, not the company.\n(evidence: v59 coverage pass; fetch queued)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — coverage row. Two further troubling-terms slots are deliberately left unfilled rather than filled speculatively.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No policy document was retrieved for this row this pass, so the opacity rating describes the state of the audit rather than a measured property of the company.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "VIDEO PRIVACY (VPPA) → 18 U.S.C. § 2710 gives a private right of action with $2,500 statutory damages per violation and is NOT preempted by state law; scope is before the Supreme Court in Salazar v. Paramount Global (cert granted 2026-01-26), so consumer standing may widen or narrow within the year", "Entity Type": "App / Service", "Ownership Path": "Philo  <-  Philo, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Philo you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Philo appears here with an explicit unknown attached. This tracker has not fetched its terms or privacy policy, so there is no finding — and, per this workbook's own standard, no finding is not a clean result. It is listed rather than omitted because a coverage claim about streaming services is only honest if the services nobody has read yet are visible as unread rather than silently missing from the list.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Streaming Services (v59)", "_row_id": 1103, "_entity_id": 1499, "_entity_slug": "philo", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Plex", "Category": "Streaming Service (media server + free ad-supported)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Plex occupies an unusual position: it is both a personal media server that indexes a user's OWN library and an ad-supported streaming service. Policy text was not retrieved this pass. The structural concern that follows from the product design, and which the fetch should resolve, is what metadata about privately-owned files is transmitted for matching and how long it is retained.", "Arbitration / Class Action Waiver": "NOT FETCHED THIS PASS. Recorded as unknown, not as absent. Queued in ROSTER - RESEARCH QUEUE for Tranche 2 with the standard checklist: fetch both policy URLs, extract the arbitration clause and any opt-out window, then re-score.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Priority fetch. Most services in this category learn what you watched from their own catalogue; a media server can learn what you OWN, which is a broader and more revealing category, and the tracker should establish which side of that line Plex's policy falls on.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Los Gatos", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Plex GmbH / Plex Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Plex GmbH / Plex Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SCOPE_LIMITATION · FL-2] Row created for coverage; the policy text has not been retrieved\nWHAT THE TERMS SAY: Plex occupies an unusual position: it is both a personal media server that indexes a user's OWN library and an ad-supported streaming service. Policy text was not retrieved this pass. The structural concern that follows from the product design, and which the fetch should resolve, is what metadata about privately-owned files is transmitted for matching and how long it is retained.\nWHY IT MATTERS: Blank is never clean in this workbook — the absence of a finding here measures the audit, not the company.\n(evidence: v59 coverage pass; fetch queued)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — coverage row. Two further troubling-terms slots are deliberately left unfilled rather than filled speculatively.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No policy document was retrieved for this row this pass, so the opacity rating describes the state of the audit rather than a measured property of the company.", "Exposure Score (0-100)": 8, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "VIDEO PRIVACY (VPPA) → 18 U.S.C. § 2710 gives a private right of action with $2,500 statutory damages per violation and is NOT preempted by state law; scope is before the Supreme Court in Salazar v. Paramount Global (cert granted 2026-01-26), so consumer standing may widen or narrow within the year", "Entity Type": "App / Service", "Ownership Path": "Plex  <-  Plex GmbH / Plex Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Plex takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 16.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Plex is different from everything else on this tab and that is why it is flagged for priority fetch rather than scored. Other services know what you watched from THEIR catalogue. A personal media server can learn what you OWN — the contents of your own drives, matched against a remote database for artwork and metadata. That is a broader and more revealing category of knowledge, and this tracker has not yet retrieved the policy that would say what is transmitted, what is retained, or for how long. Recorded as an open question, not as a finding.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Streaming Services (v59)", "_row_id": 1104, "_entity_id": 1501, "_entity_slug": "plex", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Starz", "Category": "Streaming Service (subscription)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Starz operates as a standalone premium subscription service following its separation from Lionsgate. Policy documents were not retrieved this pass.", "Arbitration / Class Action Waiver": "NOT FETCHED THIS PASS. Recorded as unknown, not as absent. Queued in ROSTER - RESEARCH QUEUE for Tranche 2 with the standard checklist: fetch both policy URLs, extract the arbitration clause and any opt-out window, then re-score.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The separation from Lionsgate is the audit-relevant fact: a corporate separation, like an acquisition, moves subscriber data between entities under a corporate-transaction clause, and the tracker should establish which entity now holds legacy records.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Englewood", "HQ State": "Colorado", "CEO": null, "Ticker": "STRZ", "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (STRZ). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Starz Entertainment Corp.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Starz Entertainment Corp.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SCOPE_LIMITATION · FL-2] Row created for coverage; the policy text has not been retrieved\nWHAT THE TERMS SAY: Starz operates as a standalone premium subscription service following its separation from Lionsgate. Policy documents were not retrieved this pass.\nWHY IT MATTERS: Blank is never clean in this workbook — the absence of a finding here measures the audit, not the company.\n(evidence: v59 coverage pass; fetch queued)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — coverage row. Two further troubling-terms slots are deliberately left unfilled rather than filled speculatively.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No policy document was retrieved for this row this pass, so the opacity rating describes the state of the audit rather than a measured property of the company.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "VIDEO PRIVACY (VPPA) → 18 U.S.C. § 2710 gives a private right of action with $2,500 statutory damages per violation and is NOT preempted by state law; scope is before the Supreme Court in Salazar v. Paramount Global (cert granted 2026-01-26), so consumer standing may widen or narrow within the year", "Entity Type": "App / Service", "Ownership Path": "Starz  <-  Starz Entertainment Corp.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Starz you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Starz was separated from Lionsgate into a standalone company, and that is the part worth auditing rather than anything in the marketing. Corporate separations move subscriber data between legal entities under the same quiet corporate-transaction clause that mergers use — the one provision nobody negotiates and nobody is notified about. This tracker has not yet retrieved the policies that would establish which entity now holds legacy subscriber viewing records, so the row is queued with that specific question attached.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Streaming Services (v59)", "_row_id": 1105, "_entity_id": 1503, "_entity_slug": "starz", "_issuer": "Starz Entertainment Corp.", "_issuer_slug": "starz-entertainment-corp", "_ticker": "STRZ", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "AMC+ / Shudder / Acorn TV (AMC Networks)", "Category": "Streaming Service (subscription bundle)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "AMC Networks operates several distinct subscription services -- AMC+, Shudder, Acorn TV and others -- under one corporate group. Policy text was not retrieved this pass.", "Arbitration / Class Action Waiver": "NOT FETCHED THIS PASS. Recorded as unknown, not as absent. Queued in ROSTER - RESEARCH QUEUE for Tranche 2 with the standard checklist: fetch both policy URLs, extract the arbitration clause and any opt-out window, then re-score.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Grouped deliberately: these are separately branded, separately purchased services under a single controller, which means a subscriber who cancels one and keeps another has not changed who holds their data. Whether the policies are shared or distinct is the specific question queued for fetch.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": "AMCX", "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AMCX). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "AMC Networks Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: AMC Networks Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SCOPE_LIMITATION · FL-2] Row created for coverage; the policy text has not been retrieved\nWHAT THE TERMS SAY: AMC Networks operates several distinct subscription services -- AMC+, Shudder, Acorn TV and others -- under one corporate group. Policy text was not retrieved this pass.\nWHY IT MATTERS: Blank is never clean in this workbook — the absence of a finding here measures the audit, not the company.\n(evidence: v59 coverage pass; fetch queued)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — coverage row. Two further troubling-terms slots are deliberately left unfilled rather than filled speculatively.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No policy document was retrieved for this row this pass, so the opacity rating describes the state of the audit rather than a measured property of the company.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "VIDEO PRIVACY (VPPA) → 18 U.S.C. § 2710 gives a private right of action with $2,500 statutory damages per violation and is NOT preempted by state law; scope is before the Supreme Court in Salazar v. Paramount Global (cert granted 2026-01-26), so consumer standing may widen or narrow within the year", "Entity Type": "App / Service", "Ownership Path": "AMC+ / Shudder / Acorn TV (AMC Networks)  <-  AMC Networks Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using AMC+ / Shudder / Acorn TV (AMC Networks) you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "AMC+, Shudder and Acorn TV are sold as separate subscriptions with separate branding, separate audiences and separate checkout flows — but they sit under one corporate controller. That means cancelling one and keeping another does not change who holds your viewing history; it only changes what you are billed for. Whether these services run on one shared privacy policy or genuinely distinct ones is exactly the question this tracker has not yet answered, which is why the row is queued rather than scored.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Streaming Services (v59)", "_row_id": 1106, "_entity_id": 1505, "_entity_slug": "amc-shudder-acorn-tv-amc-networks", "_issuer": "AMC Networks Inc.", "_issuer_slug": "amc-networks-inc", "_ticker": "AMCX", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "DirecTV Stream", "Category": "Streaming Service (live TV, subscription)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "DirecTV Stream is the internet-delivered service of DIRECTV, which was separated from AT&T and is now under private-equity control. Policy text was not retrieved this pass.", "Arbitration / Class Action Waiver": "NOT FETCHED THIS PASS. Recorded as unknown, not as absent. Queued in ROSTER - RESEARCH QUEUE for Tranche 2 with the standard checklist: fetch both policy URLs, extract the arbitration clause and any opt-out window, then re-score.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Audit-relevant because this workbook already carries AT&T (Carriers tab, severity 3, arbitration used to block a location-data class action). Legacy DIRECTV subscriber data crossing from a telecom parent into a private-equity-controlled entity is precisely the controller-change pattern the POLICY CHANGES tab exists to catch.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "El Segundo", "HQ State": "California", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "DIRECTV Entertainment Holdings LLC (TPG-controlled)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: DIRECTV Entertainment Holdings LLC (TPG-controlled)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SCOPE_LIMITATION · FL-2] Row created for coverage; the policy text has not been retrieved\nWHAT THE TERMS SAY: DirecTV Stream is the internet-delivered service of DIRECTV, which was separated from AT&T and is now under private-equity control. Policy text was not retrieved this pass.\nWHY IT MATTERS: Blank is never clean in this workbook — the absence of a finding here measures the audit, not the company.\n(evidence: v59 coverage pass; fetch queued)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — coverage row. Two further troubling-terms slots are deliberately left unfilled rather than filled speculatively.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No policy document was retrieved for this row this pass, so the opacity rating describes the state of the audit rather than a measured property of the company.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "VIDEO PRIVACY (VPPA) → 18 U.S.C. § 2710 gives a private right of action with $2,500 statutory damages per violation and is NOT preempted by state law; scope is before the Supreme Court in Salazar v. Paramount Global (cert granted 2026-01-26), so consumer standing may widen or narrow within the year", "Entity Type": "App / Service", "Ownership Path": "DirecTV Stream  <-  DIRECTV Entertainment Holdings LLC (TPG-controlled)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using DirecTV Stream you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "DIRECTV came out of AT&T and now sits under private-equity control, which makes it a controller-change case this tracker should have caught already. AT&T appears elsewhere in this workbook with a documented history of using its arbitration clause to block a class action over alleged location-data sales. Subscriber records that moved from a telecom parent to a private-equity-owned entity moved under a corporate-transaction clause, with no consent step for anybody. The policies have not been fetched, so this is a flagged question rather than a finding.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Streaming Services (v59)", "_row_id": 1107, "_entity_id": 1507, "_entity_slug": "directv-stream", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Tubi (Fox Corporation)", "Category": "Streaming Service (free, ad-supported)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Tubi already appears in this workbook on the Consumer Apps tab (scored 30, Elevated, last verified 2026-08-13) and is NOT duplicated here. This row exists only to record a v59 development requiring re-verification: reporting during this pass referenced a Fox-Roku transaction, which if completed would place a major free streaming service and a major TV operating system under one owner.", "Arbitration / Class Action Waiver": "NOT FETCHED THIS PASS. Recorded as unknown, not as absent. Queued in ROSTER - RESEARCH QUEUE for Tranche 2 with the standard checklist: fetch both policy URLs, extract the arbitration clause and any opt-out window, then re-score.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Flagged as a WATCH ITEM rather than a finding. The transaction was referenced in current reporting during this pass but was NOT independently verified, and no detail here should be relied on. If it completes, the existing Tubi row and every Roku row in this workbook need re-scoring together, because platform-plus-service concentration is the pattern that made the Walmart/Vizio deal significant.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": "FOXA", "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (FOXA). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Fox Corporation", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Fox Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SCOPE_LIMITATION · FL-2] Row created for coverage; the policy text has not been retrieved\nWHAT THE TERMS SAY: Tubi already appears in this workbook on the Consumer Apps tab (scored 30, Elevated, last verified 2026-08-13) and is NOT duplicated here. This row exists only to record a v59 development requiring re-verification: reporting during this pass referenced a Fox-Roku transaction, which if completed would place a major free streaming service and a major TV operating system under one owner.\nWHY IT MATTERS: Blank is never clean in this workbook — the absence of a finding here measures the audit, not the company.\n(evidence: v59 coverage pass; fetch queued)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — coverage row. Two further troubling-terms slots are deliberately left unfilled rather than filled speculatively.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No policy document was retrieved for this row this pass, so the opacity rating describes the state of the audit rather than a measured property of the company.", "Exposure Score (0-100)": 11, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "VIDEO PRIVACY (VPPA) → 18 U.S.C. § 2710 gives a private right of action with $2,500 statutory damages per violation and is NOT preempted by state law; scope is before the Supreme Court in Salazar v. Paramount Global (cert granted 2026-01-26), so consumer standing may widen or narrow within the year", "Entity Type": "App / Service", "Ownership Path": "Tubi (Fox Corporation)  <-  Fox Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Tubi (Fox Corporation) you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "WATCH ITEM, NOT A FINDING. During this pass, current reporting referenced a Fox-Roku transaction. This tracker did NOT verify it and states no detail about it. It is recorded because of what it would mean if true: Fox owns Tubi, one of the largest free streaming services, and Roku operates the TV operating system running on TCL, Hisense, Philips, Sharp and Walmart onn sets. Putting a major service and a major platform under one owner is the same concentration pattern that made Walmart's purchase of Vizio consequential. Verify before citing; re-score the Tubi and Roku rows together if it completes.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Streaming Services (v59)", "_row_id": 1108, "_entity_id": 1508, "_entity_slug": "tubi-fox-corporation", "_issuer": "Fox Corporation", "_issuer_slug": "fox-corporation", "_ticker": "FOXA", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Twitch (Amazon)", "Category": "Streaming Service (live, user-generated)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Twitch is a live user-generated streaming platform inside Amazon. Policy text was not retrieved this pass. Two structural features distinguish it from every other row on this tab: viewers are also broadcasters, so the same person can be both data subject and publisher; and chat is a persistent, largely public record tied to an account.", "Arbitration / Class Action Waiver": "NOT FETCHED THIS PASS. Recorded as unknown, not as absent. Queued in ROSTER - RESEARCH QUEUE for Tranche 2 with the standard checklist: fetch both policy URLs, extract the arbitration clause and any opt-out window, then re-score.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Queued with a specific question: how the video-privacy analysis applies when the 'viewing history' includes a user's own live broadcasts and their chat participation. That is not the situation the 1988 statute contemplated, and it is not the situation the other rows on this tab present.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "San Francisco", "HQ State": "California", "CEO": null, "Ticker": "AMZN", "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AMZN). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Amazon.com, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Amazon.com, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SCOPE_LIMITATION · FL-2] Row created for coverage; the policy text has not been retrieved\nWHAT THE TERMS SAY: Twitch is a live user-generated streaming platform inside Amazon. Policy text was not retrieved this pass. Two structural features distinguish it from every other row on this tab: viewers are also broadcasters, so the same person can be both data subject and publisher; and chat is a persistent, largely public record tied to an account.\nWHY IT MATTERS: Blank is never clean in this workbook — the absence of a finding here measures the audit, not the company.\n(evidence: v59 coverage pass; fetch queued)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — coverage row. Two further troubling-terms slots are deliberately left unfilled rather than filled speculatively.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No policy document was retrieved for this row this pass, so the opacity rating describes the state of the audit rather than a measured property of the company.", "Exposure Score (0-100)": 15, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 3/20 (broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "VIDEO PRIVACY (VPPA) → 18 U.S.C. § 2710 gives a private right of action with $2,500 statutory damages per violation and is NOT preempted by state law; scope is before the Supreme Court in Salazar v. Paramount Global (cert granted 2026-01-26), so consumer standing may widen or narrow within the year\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Twitch (Amazon)  <-  Amazon.com, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Twitch (Amazon) you gave up a broad licence to your own content and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Twitch breaks the model the rest of this tab uses. Everywhere else, the company watches and you are watched. On Twitch the same person is often both — a viewer of others and a broadcaster themselves, with a chat history that is a persistent, largely public record attached to a named account. The federal video-privacy law was written in 1988 about rented videotapes; it has nothing to say about a user whose own live broadcasts and typed messages are the viewing record. This tracker has not fetched Twitch's terms, and the row is queued with that specific unanswered question rather than a guessed answer.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Streaming Services (v59)", "_row_id": 1109, "_entity_id": 1509, "_entity_slug": "twitch-amazon", "_issuer": "Amazon.com, Inc.", "_issuer_slug": "amazon-com-inc", "_ticker": "AMZN", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "SiriusXM / Pandora", "Category": "Streaming Service (audio, subscription + ad-supported)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "SiriusXM operates satellite radio, an internet audio service and Pandora under one group. Policy text was not retrieved this pass. The audit-relevant structural fact is that satellite radio subscriptions have historically drawn consumer complaints about cancellation friction, which is a fee-and-billing question rather than a data question, and the tracker's Fees column is where it would land.", "Arbitration / Class Action Waiver": "NOT FETCHED THIS PASS. Recorded as unknown, not as absent. Queued in ROSTER - RESEARCH QUEUE for Tranche 2 with the standard checklist: fetch both policy URLs, extract the arbitration clause and any opt-out window, then re-score.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Queued with the cancellation-friction question flagged explicitly, because this workbook's Fees column is 'Not itemized' on the large majority of rows and audio subscriptions are one of the few categories where the fee behaviour, not the data behaviour, is the primary consumer harm.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "New York", "HQ State": "New York", "CEO": null, "Ticker": "SIRI", "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (SIRI). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Sirius XM Holdings Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Sirius XM Holdings Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SCOPE_LIMITATION · FL-2] Row created for coverage; the policy text has not been retrieved\nWHAT THE TERMS SAY: SiriusXM operates satellite radio, an internet audio service and Pandora under one group. Policy text was not retrieved this pass. The audit-relevant structural fact is that satellite radio subscriptions have historically drawn consumer complaints about cancellation friction, which is a fee-and-billing question rather than a data question, and the tracker's Fees column is where it would land.\nWHY IT MATTERS: Blank is never clean in this workbook — the absence of a finding here measures the audit, not the company.\n(evidence: v59 coverage pass; fetch queued)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — coverage row. Two further troubling-terms slots are deliberately left unfilled rather than filled speculatively.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No policy document was retrieved for this row this pass, so the opacity rating describes the state of the audit rather than a measured property of the company.", "Exposure Score (0-100)": 11, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "SiriusXM / Pandora  <-  Sirius XM Holdings Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using SiriusXM / Pandora you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "SiriusXM is one of the few rows in this workbook where the money, not the data, is likely to be the story — satellite radio has drawn long-running consumer complaints about how hard it is to cancel. That matters because this tracker's own Fees column reads 'Not itemized' on the overwhelming majority of its rows, a gap the scoring README explicitly admits skews auto-renewal scoring toward zero everywhere. This row is queued as a deliberate test of that blind spot rather than scored on data practices it has not read.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Streaming Services (v59)", "_row_id": 1110, "_entity_id": 1510, "_entity_slug": "siriusxm-pandora", "_issuer": "Sirius XM Holdings Inc.", "_issuer_slug": "sirius-xm-holdings-inc", "_ticker": "SIRI", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Criterion Channel / Kanopy / Hoopla (library and arthouse distribution)", "Category": "Streaming Service (subscription / library-funded)", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Grouped as the non-advertising streaming segment. Kanopy and Hoopla are distributed through PUBLIC LIBRARIES, which is legally distinct from every other row on this tab: library borrowing records carry specific statutory confidentiality protection in Maryland, Virginia and DC, separate from and generally stronger than consumer privacy law. Policy text was not retrieved this pass.", "Arbitration / Class Action Waiver": "NOT FETCHED THIS PASS. Recorded as unknown, not as absent. Queued in ROSTER - RESEARCH QUEUE for Tranche 2 with the standard checklist: fetch both policy URLs, extract the arbitration clause and any opt-out window, then re-score.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is the highest-value queued row in the streaming set for a Mid-Atlantic audience, and it belongs beside the existing Library, Fitness & Home tab. If a library patron streams a film through Kanopy, the question of whether that record is a LIBRARY record (protected by state library-confidentiality statutes) or a VENDOR record (governed by ordinary consumer terms) is unresolved here and consequential.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Various", "HQ State": "Various", "CEO": null, "Ticker": null, "Website (Corporate)": null, "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "No confirmed finding (unverified, not clean)", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Janus Films; Kanopy (a ProQuest/Clarivate company); Hoopla (Midwest Tape)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Janus Films; Kanopy (a ProQuest/Clarivate company); Hoopla (Midwest Tape)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SCOPE_LIMITATION · FL-2] Row created for coverage; the policy text has not been retrieved\nWHAT THE TERMS SAY: Grouped as the non-advertising streaming segment. Kanopy and Hoopla are distributed through PUBLIC LIBRARIES, which is legally distinct from every other row on this tab: library borrowing records carry specific statutory confidentiality protection in Maryland, Virginia and DC, separate from and generally stronger than consumer privacy law. Policy text was not retrieved this pass.\nWHY IT MATTERS: Blank is never clean in this workbook — the absence of a finding here measures the audit, not the company.\n(evidence: v59 coverage pass; fetch queued)", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "1 of 3 identified — coverage row. Two further troubling-terms slots are deliberately left unfilled rather than filled speculatively.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "No policy document was retrieved for this row this pass, so the opacity rating describes the state of the audit rather than a measured property of the company.", "Exposure Score (0-100)": 5, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 3/20 (auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 1/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Criterion Channel / Kanopy / Hoopla (library and arthouse distribution)  <-  Janus Films; Kanopy (a ProQuest/Clarivate company); Hoopla (Midwest Tape)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (12 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Criterion Channel / Kanopy / Hoopla (library and arthouse distribution) you gave up your right to stop paying by inaction. 12 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 20.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Kanopy and Hoopla are streamed through your PUBLIC LIBRARY, and that raises a question no other row on this tab does. Maryland, Virginia and DC all give library borrowing records specific statutory confidentiality — protection that is separate from, and generally stronger than, ordinary consumer privacy law. But the film is delivered by a commercial vendor under commercial terms. So is your viewing a library record or a vendor record? This tracker has not resolved it, and it is the single most consequential unanswered question in the streaming set for a Mid-Atlantic reader.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Streaming Services (v59)", "_row_id": 1111, "_entity_id": 1512, "_entity_slug": "criterion-channel-kanopy-hoopla-library-and-arthouse-distribution", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Apple — Siri (voice assistant)", "Category": "Voice Assistant", "Terms & Conditions URL": "apple.com/legal/internet-services/terms/site.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "apple.com/legal/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Lopez et al. v. Apple Inc. (N.D. Cal.) settled for $95 MILLION. The class covered US owners of Siri-enabled devices whose private communications were captured through UNINTENDED Siri activations between 17 September 2014 and 31 December 2024 -- the period beginning when the always-listening 'Hey Siri' wake phrase was introduced. Plaintiffs alleged recordings were disclosed to third-party human contractors for grading and, in some accounts, that discussed products produced matching advertisements; two named plaintiffs described ads following mentions of specific brands, and another described ads for a surgical treatment discussed with his doctor. Apple denied wrongdoing throughout, stating Siri data has never been used to build marketing profiles and has never been sold. Judge Jeffrey S. White granted approval; CHECKS WERE DISTRIBUTED 23-26 JANUARY 2026, averaging about $8.02 per device against a stated maximum of $20 per device and five devices per claimant.", "Arbitration / Class Action Waiver": "Apple does not impose mandatory consumer arbitration in its US media services terms, which is why this case reached a federal jury trial posture and a court-supervised settlement rather than disappearing into individual arbitrations. Recorded as a genuine and material consumer advantage.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The number to hold onto is not $95 million, it is $8.02. A settlement widely reported as a major privacy victory delivered roughly the price of a sandwich per affected device, against plaintiffs' own estimate that trial exposure ran to about $1.5 billion. This row is the clearest available answer to the question 'what is a privacy violation actually worth to me' and it belongs in any consumer-facing writeup about whether to rely on class actions as a remedy.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cupertino", "HQ State": "California", "CEO": null, "Ticker": "AAPL", "Website (Corporate)": "apple.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AAPL). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://www.courthousenews.com/judge-approves-95-million-apple-settlement-over-siri-privacy-case/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Apple Inc.", "Years Referenced in Finding (heuristic)": "2014, 2019, 2024, 2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Apple Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-1] The class period starts the day always-listening wake-word detection shipped, and ran a full decade\nWHAT THE TERMS SAY: The Lopez class covers unintended Siri activations from 17 September 2014 to 31 December 2024, the decade beginning with the introduction of the always-listening wake phrase, with recordings alleged to have been disclosed to third-party human graders.\nWHY IT MATTERS: A ten-year class period means the alleged capture ran for the entire useful life of most of the devices involved.\n(evidence: Lopez v. Apple Inc., N.D. Cal.; settlement approval coverage 2025)", "Top Troubling #2": "[REGULATORY_ACTION_PRIVACY · FL-1] Payouts landed in January 2026 at roughly $8 per device\nWHAT THE TERMS SAY: Checks were distributed between 23 and 26 January 2026, averaging about $8.02 per device against a stated cap of $20 per device and five devices per claimant.\nWHY IT MATTERS: It is the realistic market rate for a decade of alleged voice capture, and it is the number to quote when someone asks whether a class action is a remedy.\n(evidence: Settlement distribution reporting, January 2026)", "Top Troubling #3": "[FORCED_ARBITRATION · FL-2] The case existed at all because Apple does not force arbitration on consumers\nWHAT THE TERMS SAY: Apple’s US consumer media services terms do not impose mandatory arbitration, so the claim proceeded in federal court.\nWHY IT MATTERS: The identical allegations against a company with a standard arbitration and class-waiver clause would have produced no public record and no settlement fund.\n(evidence: Apple terms structure; recorded as a consumer advantage)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=Y; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "A settled federal class action with an approved distribution provides dates, dollar amounts and a defined class.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 14, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 14/30 (biometric_collection+6, ai_training_on_user_data+5, sensitive_exposure_tag+3) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 10/20 (severity3+8, litigation+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "Company", "Ownership Path": "Apple — Siri (voice assistant)  <-  Apple Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (6 of 13): your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Apple — Siri (voice assistant) you gave up your content used as AI training data, your biometric identifiers, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Apple settled the Siri eavesdropping class action for $95 million covering a decade of alleged accidental recordings — 17 September 2014 to 31 December 2024, starting the day always-listening wake-word detection shipped. Plaintiffs said conversations reached third-party human contractors, and two of them described mentioning products aloud and then seeing ads for those exact products; another described ads for a surgical treatment he thought he had discussed privately with his doctor. The checks went out 23–26 January 2026. The average payment was $8.02 PER DEVICE. Plaintiffs had estimated trial exposure at around $1.5 billion. Apple denied wrongdoing throughout.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Apple Ecosystem (deep)", "_row_id": 1112, "_entity_id": 1513, "_entity_slug": "apple-siri-voice-assistant", "_issuer": "Apple Inc.", "_issuer_slug": "apple-inc", "_ticker": "AAPL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Apple Advertising (Personalized Ads) + App Tracking Transparency", "Category": "Advertising Platform", "Terms & Conditions URL": "apple.com/legal/internet-services/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "apple.com/legal/privacy/data/en/apple-advertising/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Apple was sued for approximately $2.7 BILLION over its App Tracking Transparency regime in a claim reported on 3 September 2026 -- days before this pass. The structural allegation across ATT challenges is self-preferencing: third-party apps must show the ATT prompt before tracking users across other companies' apps and websites, while Apple's own first-party data collection -- including recording App Store downloads and using them for its own recommendations and advertising -- does not trigger that prompt, because it is not cross-app tracking as ATT defines it. Apple's Personalized Ads business runs on that first-party data.", "Arbitration / Class Action Waiver": "No mandatory consumer arbitration identified in the relevant Apple consumer terms.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This row is deliberately paired rather than split, because ATT and Apple Advertising are the same fact viewed from two sides: the privacy feature that materially reduced third-party tracking, and the definition of 'tracking' that exempts the company that wrote it. Both halves are true and the tracker should say both. ATT genuinely and measurably cut cross-app tracking; it also handed the resulting advertising advantage to the party who set the rule.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cupertino", "HQ State": "California", "CEO": null, "Ticker": "AAPL", "Website (Corporate)": "apple.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AAPL). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://macrumors.com/2026/09/03/apple-hit-with-lawsuit-over-app-tracking", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Apple Inc.", "Years Referenced in Finding (heuristic)": "2021, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Apple Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[UNILATERAL_CHANGES · FL-1] The company that defines \"tracking\" wrote a definition its own data collection falls outside of\nWHAT THE TERMS SAY: Under ATT, third-party apps must obtain permission via a system prompt before tracking users across other companies’ apps and websites, while Apple’s own first-party collection — such as recording App Store downloads for its own recommendations — does not trigger the prompt.\nWHY IT MATTERS: A privacy rule set by a participant in the market it regulates will tend to bind competitors more tightly than its author, whatever its merits.\n(evidence: ATT structure and the September 2026 claim reporting)", "Top Troubling #2": "[DATA_SHARING_AFFILIATES_BROKERS · FL-2] A roughly $2.7 billion claim over the ATT regime was reported on 3 September 2026\nWHAT THE TERMS SAY: Reporting dated 3 September 2026 describes Apple facing a claim of approximately $2.7 billion concerning its app tracking rules.\nWHY IT MATTERS: It is three days old at the time of this pass and should be re-verified before publication; the amount and posture may move.\n(evidence: MacRumors reporting, 2026-09-03; NOT independently confirmed against a filed complaint)", "Top Troubling #3": "[NO_ADVERSE_FINDING · FL-3] ATT did measurably reduce third-party cross-app tracking, and that belongs in the record too\nWHAT THE TERMS SAY: The ATT prompt requires affirmative permission before third-party apps may track users across other companies’ apps and sites.\nWHY IT MATTERS: This workbook’s standard requires saying so when a company does better than its peers; ATT is the largest single reduction in mobile cross-app tracking any platform has imposed.\n(evidence: ATT policy structure; recorded as a consumer benefit)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=Y; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Apple publishes a dedicated advertising privacy notice, but the boundary between first-party collection and the tracking ATT regulates is defined by Apple and is not independently auditable.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 10/20 (severity3+8, litigation+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "Company", "Ownership Path": "Apple Advertising (Personalized Ads) + App Tracking Transparency  <-  Apple Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (7 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Apple Advertising (Personalized Ads) + App Tracking Transparency you gave up your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "App Tracking Transparency is simultaneously the biggest cut to mobile cross-app tracking any platform has ever imposed AND the most elegant piece of rule-writing in this workbook. Third-party apps must ask permission before following you across other companies' apps. Apple's own first-party collection — including logging what you download from the App Store and using it for its own recommendations and advertising — does not trigger that prompt, because under Apple's definition it is not 'tracking'. Apple was reported on 3 September 2026 to be facing a roughly $2.7 BILLION claim over exactly that asymmetry. That report is three days old and needs re-verification before anyone cites it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Apple Ecosystem (deep)", "_row_id": 1113, "_entity_id": 1514, "_entity_slug": "apple-advertising-personalized-ads-app-tracking-transparency", "_issuer": "Apple Inc.", "_issuer_slug": "apple-inc", "_ticker": "AAPL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Apple ID / iCloud (account + cloud storage)", "Category": "Cloud Storage / Account", "Terms & Conditions URL": "apple.com/legal/internet-services/icloud/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "apple.com/legal/privacy/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The Apple ID is the single point of failure for the entire ecosystem: it holds device backups, Photos, Messages in iCloud, Keychain credentials, Health data where synced, Find My location and purchase history. Apple offers Advanced Data Protection, which extends end-to-end encryption to most iCloud categories and is a genuine and unusual consumer protection -- but it is OFF BY DEFAULT and must be affirmatively enabled. An active iCloud monopoly lawsuit remained unresolved as of this pass, alongside the DOJ antitrust action; neither is a privacy case, but both concern the cost of leaving the ecosystem.", "Arbitration / Class Action Waiver": "No mandatory consumer arbitration identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The default state is the finding. Advanced Data Protection is materially stronger than anything comparable at Google or Microsoft, and almost nobody has it on, because it is buried in settings, requires setting up account recovery first, and is presented as an advanced option rather than a recommended one. A protection that exists but is off is a design choice, not a feature.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cupertino", "HQ State": "California", "CEO": null, "Ticker": "AAPL", "Website (Corporate)": "apple.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AAPL). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Apple Inc.", "Years Referenced in Finding (heuristic)": "2024, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Apple Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-1] One account holds backups, photos, messages, passwords, location and health data\nWHAT THE TERMS SAY: The Apple ID governs iCloud device backups, Photos, Messages in iCloud, Keychain credentials, Find My location and synced Health data under a single credential.\nWHY IT MATTERS: Compromise or lawful compulsion of one account reaches every category at once, which is a different risk shape from any single-purpose service in this workbook.\n(evidence: Apple iCloud service structure)", "Top Troubling #2": "[DARK_PATTERN_CONSENT · FL-1] Advanced Data Protection is genuinely strong and shipped switched off\nWHAT THE TERMS SAY: Apple offers Advanced Data Protection extending end-to-end encryption across most iCloud data categories; it is not enabled by default and must be turned on by the user after configuring account recovery.\nWHY IT MATTERS: The strongest consumer protection Apple offers is the one most users will never find, which makes the default rather than the capability the real policy.\n(evidence: Apple iCloud security documentation)", "Top Troubling #3": "[TERMINATION_CONFISCATION · FL-2] Account termination reaches purchases, backups and the devices at once\nWHAT THE TERMS SAY: Apple ID terms govern access to purchased media, cloud backups and device services under one account relationship.\nWHY IT MATTERS: Losing the account is not losing a service, it is losing the library and the backups together.\n(evidence: Apple ID terms structure; specific clause not re-fetched this pass)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=Y; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=Y; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Apple documents its encryption architecture unusually well; what it does not surface is that the strongest option is opt-in and unadvertised.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 17, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 13/30 (biometric_collection+6, precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 17/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4, auto_renewal_or_fee_trap+3) | Record 10/20 (severity3+8, litigation+2) | flags stated 10/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "Company", "Ownership Path": "Apple ID / iCloud (account + cloud storage)  <-  Apple Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  6. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (4 of 13): your content used as AI training data; a broad licence to your own content; your data shared corporate-wide; your right to a jury. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Apple ID / iCloud (account + cloud storage) you gave up your biometric identifiers, your physical movements, your right to keep what you paid for, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 4 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 60.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Apple's Advanced Data Protection is the strongest consumer cloud encryption any major platform offers — it extends end-to-end encryption across most of iCloud, including backups, so even Apple cannot read them. It ships TURNED OFF. You have to know it exists, go find it in settings, and set up account recovery before you can enable it. So the honest description of Apple's default posture is not 'strong encryption', it is 'strong encryption that almost nobody has switched on'. Meanwhile that one account holds your backups, photos, messages, passwords, location and health data behind a single credential.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Apple Ecosystem (deep)", "_row_id": 1114, "_entity_id": 1515, "_entity_slug": "apple-id-icloud-account-cloud-storage", "_issuer": "Apple Inc.", "_issuer_slug": "apple-inc", "_ticker": "AAPL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Apple Health / Fitness (HealthKit + Apple Watch)", "Category": "Health / Fitness", "Terms & Conditions URL": "apple.com/legal/internet-services/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "apple.com/legal/privacy/data/en/health/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Apple Health data is stored encrypted on device and, where synced, in iCloud, and Apple states it does not sell it. The exposure that matters is not Apple's own practice but the THIRD-PARTY APP boundary: any app granted HealthKit read permission receives that data under ITS OWN privacy policy, not Apple's, and Apple's protections stop at the permission grant. A menstrual-cycle, fertility or mental-health app holding data sourced from Apple Health is governed by that app's terms and is generally NOT a HIPAA covered entity.", "Arbitration / Class Action Waiver": "No mandatory consumer arbitration identified for Apple; the third-party app receiving the data will have its own clause, which is the one that would actually bind a dispute about it.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is the row to hand to anyone who believes health data on an iPhone is protected by medical privacy law. It generally is not. HIPAA binds covered entities and their business associates -- providers, plans, clearinghouses -- and a consumer fitness or cycle-tracking app is usually none of those, regardless of how clinical the data feels.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cupertino", "HQ State": "California", "CEO": null, "Ticker": "AAPL", "Website (Corporate)": "apple.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AAPL). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Apple Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Apple Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-1] Apple's protection ends at the permission prompt; the receiving app's policy takes over\nWHAT THE TERMS SAY: Third-party apps granted HealthKit read access receive Health data governed by their own privacy policies rather than by Apple’s.\nWHY IT MATTERS: The permission grant is a one-time decision that transfers an ongoing stream to a controller with entirely different rules.\n(evidence: HealthKit permission architecture)", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Health data in a consumer app is generally outside HIPAA entirely\nWHAT THE TERMS SAY: HIPAA obligations attach to covered entities and business associates; consumer fitness and cycle-tracking applications are typically neither.\nWHY IT MATTERS: Data that feels medical is protected by ordinary consumer contract terms, and in MD and VA by the sensitive-data consent rules, not by medical privacy law.\n(evidence: Regulatory scope; general legal framework, not a finding about Apple)", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=?; datasale=N; affiliates=N; biometric=Y; aitrain=?; location=Y; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Apple documents the HealthKit permission model clearly; the gap is consumer understanding of where its protection stops, not a failure to disclose.", "Exposure Score (0-100)": 20, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 13/30 (biometric_collection+6, precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 2/20 (severity2+2) | flags stated 7/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "Company", "Ownership Path": "Apple Health / Fitness (HealthKit + Apple Watch)  <-  Apple Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your data shared corporate-wide; your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (6 of 13): your content used as AI training data; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Apple Health / Fitness (HealthKit + Apple Watch) you gave up your biometric identifiers, your physical movements, and your right to meaningful compensation. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Health data on an iPhone is not protected by medical privacy law, and this is the most common misunderstanding in the whole workbook. Apple encrypts it and does not sell it — that part is real. But the moment you grant a third-party app HealthKit access, that app receives an ongoing stream governed by ITS privacy policy, not Apple's, and a consumer fitness or cycle-tracking app is generally NOT a HIPAA covered entity. HIPAA binds doctors, insurers and clearinghouses. It does not bind the period-tracker you gave permission to once, in 2019, and forgot about.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apple Ecosystem (deep)", "_row_id": 1115, "_entity_id": 1516, "_entity_slug": "apple-health-fitness-healthkit-apple-watch", "_issuer": "Apple Inc.", "_issuer_slug": "apple-inc", "_ticker": "AAPL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Apple Wallet / Apple Pay / Apple Cash", "Category": "Payments / Fintech", "Terms & Conditions URL": "apple.com/legal/apple-pay/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "apple.com/legal/privacy/data/en/apple-pay/", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Apple Pay uses a device-specific account number and per-transaction cryptogram rather than transmitting the card number, and Apple states it does not retain transaction details tied to the user in a form that can be shared back to merchants -- a genuinely stronger architecture than card-network defaults. Apple Cash, by contrast, is a stored-value money-transmission product operated with a partner bank, which places it under a DIFFERENT regulatory regime including GLBA and money-transmitter rules, with different data-sharing defaults. The arbitration position may also differ between the two: partner-bank agreements commonly carry clauses Apple's own terms do not.", "Arbitration / Class Action Waiver": "NOT VERIFIED and specifically flagged: the operative dispute clause for Apple Cash may be the PARTNER BANK’s rather than Apple’s, which is a different answer from the one on every other Apple row in this workbook. Do not generalise Apple’s no-arbitration posture to its bank-partnered products without fetching the partner agreement.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Carried separately from the other Apple rows because the regulatory regime genuinely differs. This workbook already documents (Banks (DMV), Credit Card Companies tabs) how much weaker consumer positions are under bank-partnered agreements, and the Apple brand on the front of a product does not carry Apple's terms through to the back of it.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Cupertino", "HQ State": "California", "CEO": null, "Ticker": "AAPL", "Website (Corporate)": "apple.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (AAPL). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Apple Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Apple Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "[FORCED_ARBITRATION · FL-1] Apple's no-arbitration posture may not survive into its bank-partnered products\nWHAT THE TERMS SAY: Apple Cash is a stored-value money-transmission product operated with a partner bank under GLBA and money-transmitter regimes, and partner-bank agreements commonly include arbitration clauses.\nWHY IT MATTERS: A consumer who reasons \"Apple does not force arbitration\" may be wrong about the specific Apple-branded product they are actually disputing.\n(evidence: Product-structure analysis; the partner agreement was NOT fetched this pass)", "Top Troubling #2": "[NO_ADVERSE_FINDING · FL-2] The Apple Pay token architecture is genuinely better than the card-network default\nWHAT THE TERMS SAY: Apple Pay substitutes a device account number and per-transaction cryptogram for the card number, so the merchant does not receive the underlying card credential.\nWHY IT MATTERS: It removes a whole class of merchant-side breach exposure that this workbook documents repeatedly elsewhere.\n(evidence: Apple Pay security architecture; recorded as a consumer benefit)", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "2 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=Y; biometric=Y; aitrain=?; location=Y; unilateral=?; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Apple documents the payment architecture well; the partner-bank terms governing Apple Cash are a separate document that this pass did not retrieve.", "Exposure Score (0-100)": 21, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 14, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 14/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, precise_location_tracking+4) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "Company", "Ownership Path": "Apple Wallet / Apple Pay / Apple Cash  <-  Apple Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Apple Wallet / Apple Pay / Apple Cash you gave up your biometric identifiers, your physical movements, your data shared corporate-wide, and your right to meaningful compensation. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Apple Pay's architecture is genuinely good — the merchant never gets your actual card number, which removes an entire category of breach exposure this workbook documents over and over. But do not let that carry across the whole Wallet. Apple Cash is a stored-value money-transmission product run with a PARTNER BANK, under a different regulatory regime with different data-sharing defaults — and partner-bank agreements routinely carry mandatory arbitration clauses that Apple's own consumer terms do not. So the Apple logo on the front of a product does not guarantee Apple's terms on the back of it, and this tracker has not yet fetched the agreement that would tell you which applies.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apple Ecosystem (deep)", "_row_id": 1116, "_entity_id": 1517, "_entity_slug": "apple-wallet-apple-pay-apple-cash", "_issuer": "Apple Inc.", "_issuer_slug": "apple-inc", "_ticker": "AAPL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google Account — Web & App Activity (Rodriguez verdict)", "Category": "Account / Activity Controls", "Terms & Conditions URL": "policies.google.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Rodriguez v. Google LLC (N.D. Cal.): jury verdict 3 September 2025, $425.7 million compensatory, roughly 98 million US class members across two classes and about 174 million devices. The jury found Google unlawfully collected activity data from users who had turned Web & App Activity (and/or Supplemental Web & App Activity) OFF or paused, with the collection flowing through GOOGLE ANALYTICS, THE FIREBASE SDK AND THE GOOGLE MOBILE ADS SDK embedded inside NON-GOOGLE apps. The class window runs 1 July 2016 to 23 September 2024. The jury found invasion of privacy under the California constitution and common-law intrusion upon seclusion, but found NO MALICE, so no punitive damages were awarded. Plaintiffs had sought more than $31 billion. Jurors characterised the disclosure regime as confusing for an ordinary user. Google moved to VACATE the judgment and has said it may appeal; there is NO CLAIM FORM and no money available. With interest the judgment stood at $440,345,685.40 as of 2 March 2026 and continues to accrue. Damages break down to roughly $247 million for Android class members and $178 million for non-Android members -- about $4 per person.", "Arbitration / Class Action Waiver": "Google does not impose mandatory consumer arbitration in its general US Terms of Service, which is the only reason a jury ever heard this case. Recorded as a material consumer advantage: the identical conduct at a company with a standard arbitration and class-waiver clause would have produced no verdict, no public record and no finding of fact.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "This is the most important single row added in v59 and it should be cross-referenced from every Google row in the workbook, because it is an adjudicated finding about whether GOOGLE'S OPT-OUT CONTROLS DO WHAT THEY SAY. Every other row in this tracker that advises a consumer to 'turn off the setting' at Google is now qualified by a jury verdict holding that turning off this particular setting did not stop the collection. Note carefully what it is NOT: not final, not payable, and under challenge.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": "GOOGL", "Website (Corporate)": "abc.xyz", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (GOOGL). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://openclassactions.com/settlements/google-web-and-app-activity-privacy-class-action-lawsuit.php", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "2016, 2024, 2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alphabet Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-1] A jury found collection continued from users who had switched the control off\nWHAT THE TERMS SAY: Rodriguez v. Google LLC (N.D. Cal.): jury verdict 3 September 2025, $425.7 million compensatory, roughly 98 million US class members across two classes and about 174 million devices. The jury found Google collected activity from non-Google apps after users disabled Web & App Activity, via Google Analytics, the Firebase SDK and the Google Mobile Ads SDK, over a class window from 1 July 2016 to 23 September 2024.\nWHY IT MATTERS: It is an adjudicated finding about the reliability of a privacy control, which is the mechanism every opt-out recommendation in this workbook depends on.\n(evidence: Rodriguez v. Google LLC, verdict 2025-09-03; case-site FAQ via openclassactions)", "Top Troubling #2": "[UNILATERAL_CHANGES · FL-1] No claim form exists and the judgment is under challenge, so nobody has been paid\nWHAT THE TERMS SAY: Google moved to vacate the judgment and may appeal; with interest the award stood at $440,345,685.40 as of 2 March 2026, with no claims process open.\nWHY IT MATTERS: A verdict is not a settlement fund — the practical recovery for a class member today is zero and may remain zero.\n(evidence: Case-site FAQ and status reporting through mid-2026)", "Top Troubling #3": "[FORCED_ARBITRATION · FL-2] The absence of an arbitration clause is why this finding exists at all\nWHAT THE TERMS SAY: Google does not impose mandatory consumer arbitration in its general US consumer terms, so the claim proceeded to a jury.\nWHY IT MATTERS: The same conduct at an arbitration-bound competitor would have generated no adjudicated record whatsoever.\n(evidence: Google Terms of Service structure; recorded as a consumer advantage)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "A jury verdict with a docket, a class definition, a damages breakdown and a dated interest calculation is as checkable as this workbook gets.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 16/20 (severity4+14, litigation+2) | flags stated 8/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "Company", "Ownership Path": "Google Account — Web & App Activity (Rodriguez verdict)  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Google Account — Web & App Activity (Rodriguez verdict) you gave up your physical movements, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A federal jury decided on 3 September 2025 that Google kept collecting activity from roughly 98 MILLION Americans across about 174 MILLION DEVICES who had already switched Web & App Activity OFF — the setting Google markets as the way to stop exactly that. The data flowed through Google Analytics, the Firebase SDK and the Google Mobile Ads SDK sitting inside OTHER companies' apps. Jurors found the disclosures confusing for an ordinary user. Damages: $425.7 million, about $4 a person, against the $31 billion plaintiffs asked for. And you will probably never see it: Google moved to vacate, there is no claim form, and the judgment — $440,345,685.40 with interest as of 2 March 2026 — remains unpaid.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "Yes", "_tab": "Google Ecosystem (deep)", "_row_id": 1117, "_entity_id": 1518, "_entity_slug": "google-account-web-app-activity-rodriguez-verdict", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google Firebase + AdMob (Google Mobile Ads SDK)", "Category": "Embedded SDK / Ad Network", "Terms & Conditions URL": "firebase.google.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "This is the layer that explains a large fraction of the findings elsewhere in this workbook. Firebase analytics and the Google Mobile Ads SDK are Google code embedded inside OTHER COMPANIES' apps, and they were the identified transmission path in the Rodriguez verdict: the jury found data reached Google from non-Google apps even after users disabled Web & App Activity. This workbook's Duolingo row records Duolingo among the apps named in that context, alongside Uber, Venmo, Shazam, the New York Times and Instagram -- none of which is a finding about those companies' own first-party practices so much as a finding about the SDK inside them.", "Arbitration / Class Action Waiver": "Not verified this pass. The consumer-facing problem is more basic than the clause: the SDK is a business-to-business product, the consumer has no contract with it, and in most cases no way to learn it is present short of decompiling the app.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Created as its own row deliberately. The tracker has repeatedly recorded SDK-mediated exposure as a finding against the HOST app (Duolingo, and the VPPA cases against Crunchyroll via Braze and Pluto TV via Google and Microsoft pixels). Naming the SDK layer once, properly, lets those rows point here instead of each re-explaining the mechanism, and it makes the shared-vendor pattern from Cross-Cutting Finding #1 visible in mobile software rather than only in breach vendors.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": "GOOGL", "Website (Corporate)": "abc.xyz", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (GOOGL). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "2016, 2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alphabet Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-1] Google code inside other companies’ apps was the identified transmission path in a $425.7 million verdict\nWHAT THE TERMS SAY: The Rodriguez jury found data reached Google from non-Google apps through Google Analytics, the Firebase SDK and the Google Mobile Ads SDK, including from users who had disabled Web & App Activity.\nWHY IT MATTERS: Choosing which apps to install does not control this, because the collector is a component inside apps chosen for unrelated reasons.\n(evidence: Rodriguez v. Google LLC, verdict 2025-09-03)", "Top Troubling #2": "[DARK_PATTERN_CONSENT · FL-1] A consumer has no contract with the SDK and generally no way to know it is there\nWHAT THE TERMS SAY: Firebase and the Google Mobile Ads SDK are licensed to app developers, not to end users, and their presence is not ordinarily disclosed in a way a consumer can check.\nWHY IT MATTERS: Privacy rights are exercised against controllers a consumer can identify, and this one is structurally invisible at the point of use.\n(evidence: SDK distribution model; structural analysis)", "Top Troubling #3": "[SENSITIVE_DATA_EXPOSURE · FL-2] The amended COPPA Rule now requires naming the third parties that receive a child’s data\nWHAT THE TERMS SAY: The amended COPPA Rule, with a compliance date of 22 April 2026, requires separate verifiable parental consent before disclosing a child’s data to third parties for advertising or AI training, and requires operators to identify those recipients specifically rather than generically.\nWHY IT MATTERS: Any children’s app carrying an ad SDK now has a naming obligation it previously did not, which makes this the compliance pressure point for the whole category.\n(evidence: FTC COPPA Rule amendments, adopted January 2025, compliance date 2026-04-22)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "The SDK layer is documented for developers and effectively undisclosed to the people it collects from; a consumer cannot determine which apps on their phone contain it.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 11, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 16, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 11/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 16/20 (severity4+14, litigation+2) | flags stated 5/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "CHILDREN’S DATA → Federal COPPA (amended rule, compliance 2026-04-22) now requires SEPARATE verifiable parental consent before a child’s data goes to advertisers or AI training, and bans indefinite retention; MD bars targeted advertising to consumers a controller knows are under 18; state AGs have express COPPA parens patriae standing (confirmed in the Roku ruling)\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "Company", "Ownership Path": "Google Firebase + AdMob (Google Mobile Ads SDK)  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Google Firebase + AdMob (Google Mobile Ads SDK) you gave up your physical movements, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "This is the row that explains dozens of others. Firebase and the Google Mobile Ads SDK are GOOGLE'S CODE RUNNING INSIDE OTHER COMPANIES' APPS — and they were the identified pipe in the $425.7 million Rodriguez verdict, carrying data to Google from non-Google apps even when users had switched Web & App Activity off. You cannot opt out of a component you cannot see, in an app you installed for an unrelated reason, under a contract you are not party to. From 22 April 2026 the amended COPPA Rule requires children's apps to NAME the third parties receiving kids' data rather than saying 'our partners' — which makes this layer the single biggest compliance pressure point in children's software.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Google Ecosystem (deep)", "_row_id": 1118, "_entity_id": 1519, "_entity_slug": "google-firebase-admob-google-mobile-ads-sdk", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Android OS + Google Play Services", "Category": "Mobile Operating System", "Terms & Conditions URL": "play.google.com/about/play-terms/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Android carries a structural feature no other row in this workbook has: GOOGLE PLAY SERVICES is a privileged system component that updates independently of the operating system and of the handset manufacturer, and it is the layer through which advertising identifiers, location services and the SDK infrastructure operate. The Rodriguez damages split -- roughly $247 million to Android class members against $178 million to non-Android members -- reflects that Android users were found to be more exposed than users of the same apps on other platforms.", "Arbitration / Class Action Waiver": "No mandatory consumer arbitration in Google’s general US consumer terms. Note that the handset manufacturer (Samsung, Motorola and others) may impose its own clause separately, so an Android user can face a manufacturer arbitration clause and no Google one on the same device.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "The two-controller structure is the point and it mirrors the smart-TV finding on the new TV tab exactly: the badge on the hardware and the operator of the data layer are different companies with different terms, different opt-outs and different dispute clauses. This tracker now documents the same pattern on televisions and on phones.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": "GOOGL", "Website (Corporate)": "abc.xyz", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Private litigation", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (GOOGL). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alphabet Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[DATA_SHARING_AFFILIATES_BROKERS · FL-1] Android class members were found more exposed than non-Android members for the same conduct\nWHAT THE TERMS SAY: The Rodriguez damages allocation was roughly $247 million to Android class members and $178 million to non-Android members.\nWHY IT MATTERS: The platform materially changed how much was collected from users of the same third-party apps.\n(evidence: Rodriguez v. Google LLC damages breakdown, 2025)", "Top Troubling #2": "[UNILATERAL_CHANGES · FL-2] Play Services updates independently of both the OS and the phone maker\nWHAT THE TERMS SAY: Google Play Services is a privileged system component updated separately from Android releases and outside the handset manufacturer’s update cycle.\nWHY IT MATTERS: The data layer on the device can change without an OS update, a manufacturer update or any user-visible event.\n(evidence: Android platform architecture)", "Top Troubling #3": "[FORCED_ARBITRATION · FL-2] The handset maker may impose arbitration where Google does not\nWHAT THE TERMS SAY: Google’s general US terms carry no mandatory consumer arbitration, but device manufacturers apply their own terms to the same handset.\nWHY IT MATTERS: Which clause binds a dispute depends on whether the complaint is about the phone or the platform, and consumers rarely draw that line correctly.\n(evidence: Terms structure across device and platform)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=Y; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=?; breach=?; penalty=?; litigation=Y; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Android is extensively documented for developers; the division of data responsibility between Google, Play Services and the handset maker is not stated anywhere a consumer would look.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 14, "Sub: Contract Asymmetry /20": 14, "Sub: Track Record /20": 10, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 14/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, precise_location_tracking+4) | Contract 14/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4) | Record 10/20 (severity3+8, litigation+2) | flags stated 10/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "Company", "Ownership Path": "Android OS + Google Play Services  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (5 of 13): your personal data sold onward; your content used as AI training data; a broad licence to your own content; your right to a jury; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Android OS + Google Play Services you gave up your biometric identifiers, your physical movements, your data shared corporate-wide, your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 5 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 60.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Google Play Services is a privileged component that updates itself independently of Android AND of whoever made your phone — so the data layer on your handset can change without an operating system update, a manufacturer update, or anything you would notice. It is also the layer carrying advertising identifiers, location services and the SDK infrastructure. The Rodriguez jury allocated roughly $247 MILLION to Android class members against $178 million to everyone else, which is a court's way of saying Android users were more exposed than other people using the same apps. Same split-controller problem as your television: two companies, two sets of terms, one device.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Google Ecosystem (deep)", "_row_id": 1119, "_entity_id": 1520, "_entity_slug": "android-os-google-play-services", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Google Nest / Google Home (cameras, doorbells, thermostats, speakers)", "Category": "Smart Home / Security", "Terms & Conditions URL": "policies.google.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "policies.google.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "This workbook already carries a Nest row (Consumer Apps, scored 45, Elevated). This row is added for the DEVICE-CLASS issues that the app-level row does not reach: cameras and doorbells record NON-CONSENTING THIRD PARTIES -- visitors, neighbours, delivery workers, children of guests -- who have no account, no terms relationship and no way to exercise a right. Familiar-face detection is a biometric feature with materially different legal treatment across states. And subscription tiers gate retention: the recording history a household believes it has depends on an active Nest Aware subscription, so a lapsed payment silently shortens the evidentiary record.", "Arbitration / Class Action Waiver": "No mandatory consumer arbitration in Google’s general US consumer terms. Note the asymmetry: the people most affected by a doorbell camera — those recorded by it — have no contract with Google at all, so neither arbitration nor its absence is available to them. They have only state law.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recorded separately from the existing Nest row because the existing row assesses the account holder's position and this one assesses everybody else's. That distinction is not cosmetic: the bystander has no terms, no opt-out, no deletion route and no dispute forum, and no row in this workbook covered that population before v59.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Mountain View", "HQ State": "California", "CEO": null, "Ticker": "GOOGL", "Website (Corporate)": "abc.xyz", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (GOOGL). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Alphabet Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alphabet Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-1] The people most recorded by a doorbell camera have no contract, no rights route and no forum\nWHAT THE TERMS SAY: Nest cameras and doorbells capture visitors, neighbours, delivery workers and other non-account-holders who have no terms relationship with Google.\nWHY IT MATTERS: Every consumer remedy in this workbook runs through a contract or a controller relationship, and the bystander has neither.\n(evidence: Device-class analysis; structural finding)", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-2] Familiar-face detection is a biometric feature whose legality varies sharply by state\nWHAT THE TERMS SAY: Face-grouping and familiar-face features process facial data, which several states regulate as biometric identifiers requiring consent.\nWHY IT MATTERS: The consent that matters would have to come from the person at the door, who was never asked.\n(evidence: Biometric regulatory framework; MD and VA treat biometric identifiers as sensitive data)", "Top Troubling #3": "[AUTORENEWAL_FEE_TRAP · FL-2] Recording history is gated on an active subscription, so a lapsed payment shortens the record\nWHAT THE TERMS SAY: Nest Aware subscription tiers determine how much event and video history is retained.\nWHY IT MATTERS: A household that believes it has weeks of footage may have days, and will discover which only when it needs the footage.\n(evidence: Subscription tier structure; specific current retention windows not fetched this pass)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=N; jurywaiver=?; optout=Y; datasale=N; affiliates=Y; biometric=Y; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "Google documents account-holder controls; nothing addresses the position of recorded non-users, which is the population this row exists to name.", "Exposure Score (0-100)": 42, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 17, "Sub: Contract Asymmetry /20": 17, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 0/30 (none) | Data 17/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 17/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 11/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "Company", "Ownership Path": "Google Nest / Google Home (cameras, doorbells, thermostats, speakers)  <-  Alphabet Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  7. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue; your right to join a class action.\n\nNOT YET DETERMINED (3 of 13): your content used as AI training data; a broad licence to your own content; your right to a jury. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Google Nest / Google Home (cameras, doorbells, thermostats, speakers) you gave up your biometric identifiers, your physical movements, your data shared corporate-wide, your right to keep what you paid for, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 3 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 63.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Every privacy remedy in this workbook assumes you have a contract with the company. A Nest doorbell breaks that assumption completely. The people it records most — your neighbours, the delivery driver, a child walking past, a visitor at the door — have NO account, NO terms, NO opt-out, NO deletion route and NO dispute forum. They cannot exercise a right against Google because they were never given one. Familiar-face detection processes facial data that several states treat as biometric and requiring consent, and the only person who could meaningfully consent is standing on the doorstep, unasked. Meanwhile the footage you think you have is gated behind an active subscription.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Google Ecosystem (deep)", "_row_id": 1120, "_entity_id": 1521, "_entity_slug": "google-nest-google-home-cameras-doorbells-thermostats-speakers", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Duolingo English Test (DET)", "Category": "Education (high-stakes remote proctored exam)", "Terms & Conditions URL": "englishtest.duolingo.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "englishtest.duolingo.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Per Duolingo's own published security and proctoring documentation, the DET collects from every test taker: PHOTOS OF PASSPORTS AND/OR GOVERNMENT-ISSUED IDs, legal names, date of birth, IP ADDRESS AND LOCATION DATA, and VIDEO OF THE TEST TAKER'S SCREEN AND FACE throughout the session. Test takers must enable camera, microphone, screen recording and KEYBOARD MONITORING. During onboarding the test taker is required to CONSENT TO BIOMETRIC SIGNALS derived from the audio and video of the session, and Duolingo's documentation states the test taker CANNOT PROCEED WITH THE TEST WITHOUT PROVIDING IT. The desktop application AUTOMATICALLY CLOSES NON-ESSENTIAL SOFTWARE on the test taker's own computer. Proctoring is remote and ASYNCHRONOUS: human proctors review the recorded session afterwards. ID photos are stated to be retained for four days in encrypted storage. Duolingo states GDPR compliance and will share or delete collected data on request, EXCEPT where doing so would compromise test security -- screen recordings are given as the example, because releasing them would leak test items.", "Arbitration / Class Action Waiver": "Duolingo terms carry binding arbitration with class and jury waivers and a 30-day email opt-out. The consent problem here is more fundamental than the clause: this is a HIGH-STAKES ADMISSIONS TEST, so a candidate whose university requires a DET score has no practical ability to decline any term — biometric consent, screen recording or arbitration — and still obtain the credential. Consent that is a precondition of a credential is not a meaningful choice, whatever the contract calls it.", "Fees / Billing Flags": "Per-test fee; not itemized this pass. Note the asymmetry: score cancellation for suspected misconduct is determined by the vendor through asynchronous review, and the fee consequences of that determination were not fetched.", "Notes": "This row is why 'go deeper on Duolingo' was the right instinct. The consumer language app and the DET are the same brand carrying entirely different risk: the app collects voice from volunteers, and the DET collects passport images, faces, keystrokes and screen video from people who cannot say no because a university admission depends on it. It is arguably the highest per-user biometric exposure of any row in this workbook, and v58 did not carry it at all.\n\nFor a Mid-Atlantic readership specifically: this reaches international students at UMD, Georgetown, GWU, Howard, George Mason, Johns Hopkins, VCU and UVA, a population that is both large here and unusually poorly positioned to object.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Pittsburgh", "HQ State": "Pennsylvania", "CEO": null, "Ticker": "DUOL", "Website (Corporate)": "duolingo.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (DUOL). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://go.duolingo.com/securitywhitepaper", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Duolingo, Inc.", "Years Referenced in Finding (heuristic)": "2025, 2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Duolingo, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-1] Biometric consent is mandatory: the documentation states the test cannot proceed without it\nWHAT THE TERMS SAY: Duolingo’s published proctoring documentation states test takers are asked to consent to biometric signals used from the audio and video of the session, that this consent is required by law in various jurisdictions, and that the test taker cannot proceed with the test without providing it.\nWHY IT MATTERS: A consent that gates a credential a university requires is not declinable, so the legal formality of consent and the practical reality of choice diverge completely.\n(evidence: Duolingo English Test security and proctoring whitepaper)", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-1] Passport images, face and screen video, location and keystrokes are captured from every candidate\nWHAT THE TERMS SAY: The DET collects photos of passports and government-issued IDs, legal names, date of birth, IP address and location data, and video of the test taker’s screen and face, with camera, microphone, screen recording and keyboard monitoring enabled during the session.\nWHY IT MATTERS: That is an identity-document-grade dataset on a population of largely non-citizen candidates, held by a consumer software company rather than a testing agency with statutory duties.\n(evidence: Duolingo English Test security and proctoring whitepaper)", "Top Troubling #3": "[TERMINATION_CONFISCATION · FL-2] Deletion rights are expressly limited where deletion would compromise test security\nWHAT THE TERMS SAY: Duolingo states it will share or delete collected data on request except where doing so would compromise the security of the test, giving screen recordings as the example because their release would leak test items.\nWHY IT MATTERS: The exception is reasonable on its face and still means the most invasive artefact — video of your own screen — is the one you cannot get deleted.\n(evidence: Duolingo English Test security and proctoring whitepaper)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=N; affiliates=Y; biometric=Y; aitrain=?; location=Y; unilateral=Y; liabcap=?; contentlic=?; confiscation=Y; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Clear Skies", "Opacity Basis": "Duolingo publishes this in its own whitepaper in unusual detail; the finding here is what the disclosed practice IS, not that it is hidden.", "Exposure Score (0-100)": 67, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 17, "Sub: Contract Asymmetry /20": 9, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_30d+3) | Data 17/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, precise_location_tracking+4, sensitive_exposure_tag+3) | Contract 9/20 (unilateral_modification+5, termination_or_confiscation+4) | Record 14/20 (severity4+14) | flags stated 10/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Duolingo English Test (DET)  <-  Duolingo, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n  6. Your right to a jury.\n  7. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  8. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (4 of 13): your content used as AI training data; a broad licence to your own content; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Duolingo English Test (DET) you gave up your biometric identifiers, your physical movements, your data shared corporate-wide, your right to sue, your right to join a class action, your right to a jury, your right to keep what you paid for, and your right to be consulted before terms change. 4 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 63.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "To take the Duolingo English Test, you must hand over a PHOTO OF YOUR PASSPORT, your legal name, your date of birth, your IP address and location, and VIDEO OF YOUR FACE AND YOUR SCREEN while software monitors your keystrokes and FORCIBLY CLOSES OTHER PROGRAMS ON YOUR OWN COMPUTER. You must consent to biometric processing of that audio and video — and Duolingo's own documentation says you CANNOT TAKE THE TEST WITHOUT CONSENTING. Human proctors watch the recording afterwards. You can request deletion, except for the screen video, which is withheld because releasing it would leak test questions. And you cannot walk away, because a university admission depends on the score. That is the highest per-person biometric exposure in this entire workbook, and it falls hardest on international students at Maryland, Georgetown, GWU, Howard, Hopkins, George Mason, VCU and UVA.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Duolingo (deep)", "_row_id": 1121, "_entity_id": 1522, "_entity_slug": "duolingo-english-test-det", "_issuer": "Duolingo, Inc.", "_issuer_slug": "duolingo-inc", "_ticker": "DUOL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Duolingo Max / Video Call (Lily) + Math Tutor", "Category": "Education (AI conversational features)", "Terms & Conditions URL": "duolingo.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "duolingo.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "The AI conversational tier is where voice collection stops being a pronunciation check and becomes open-ended recorded speech. Per ConductAtlas tracking of the current policy: a MATH TUTOR feature processes audio THROUGH APPLE for transcription, with the audio deleted but the TEXT TRANSCRIPTS potentially RETAINED AND SHARED WITH AI VENDORS; the Video Call feature description was reworded from an offering to a possible offering; and FullStory session-replay recording of in-app activity can be disabled via a Tracking toggle in Settings, which means it is enabled unless the user finds and changes it. ConductAtlas also flags the unresolved question directly: whether Duolingo's voice recordings meet the statutory definition of a biometric identifier under Illinois BIPA, Texas CUBI, Washington's My Health My Data Act or GDPR Article 9 is NOT settled by the policy language alone and has been actively litigated in comparable contexts.", "Arbitration / Class Action Waiver": "Binding arbitration with class and jury waivers, 30-day email opt-out to legal@duolingo.com. Relevant here because BIPA-style biometric statutes are among the few claim types that have historically produced meaningful consumer recoveries, and an arbitration clause with a class waiver is precisely what forecloses that route for anyone who missed the window.", "Fees / Billing Flags": "Subscription tier (Max) above the Super tier; auto-renewing. Not itemized further this pass.", "Notes": "The audio-deleted-but-transcripts-retained pattern is the one to watch across this whole workbook. Deleting the recording sounds like a strong privacy measure and is much weaker than it sounds: a transcript of what a child said aloud, retained and shared with AI vendors, carries nearly all of the content and none of the deletion.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Pittsburgh", "HQ State": "Pennsylvania", "CEO": null, "Ticker": "DUOL", "Website (Corporate)": "duolingo.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (DUOL). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": "https://conductatlas.com/platform/duolingo/duolingo-privacy-policy/voice-recording-collection-and-use/", "Source Verification Status": "Verified - primary source confirmed", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Duolingo, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Duolingo, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[AI_TRAINING_ON_USER_DATA · FL-1] The audio is deleted; the transcript of what you said may be kept and shared with AI vendors\nWHAT THE TERMS SAY: Per tracked policy language, the Math Tutor feature processes audio through Apple for transcription, with audio deleted while text transcripts may be retained and shared with AI vendors.\nWHY IT MATTERS: Deleting a recording while keeping a verbatim transcript preserves almost all the content and disposes of almost none of the sensitivity.\n(evidence: ConductAtlas voice-recording change tracking, retrieved 2026-09-06)", "Top Troubling #2": "[SENSITIVE_DATA_EXPOSURE · FL-1] Whether these voice recordings are legally biometric is unresolved and actively litigated\nWHAT THE TERMS SAY: Independent analysis flags that whether the recordings meet the definition of a biometric identifier under Illinois BIPA, Texas CUBI, Washington’s My Health My Data Act or GDPR Article 9 is not resolved by the policy language alone.\nWHY IT MATTERS: The answer determines whether a whole class of statutory damages applies, and neither the company nor the user can settle it unilaterally.\n(evidence: ConductAtlas institutional analysis, retrieved 2026-09-06)", "Top Troubling #3": "[DARK_PATTERN_CONSENT · FL-2] Session-replay recording of in-app activity runs unless the user finds the Tracking toggle\nWHAT THE TERMS SAY: FullStory session-replay activity recording is described as disableable through a Tracking toggle in app Settings.\nWHY IT MATTERS: A recording that must be switched off was switched on for everybody who never looked.\n(evidence: ConductAtlas policy tracking, retrieved 2026-09-06)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=?; affiliates=Y; biometric=Y; aitrain=Y; location=?; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The features are disclosed, but the legal characterisation of the voice data and the identity of the downstream AI vendors are not.", "Exposure Score (0-100)": 61, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 18, "Sub: Contract Asymmetry /20": 8, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_30d+3) | Data 18/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, ai_training_on_user_data+5, sensitive_exposure_tag+3) | Contract 8/20 (unilateral_modification+5, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 9/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "CHILDREN’S DATA → Federal COPPA (amended rule, compliance 2026-04-22) now requires SEPARATE verifiable parental consent before a child’s data goes to advertisers or AI training, and bans indefinite retention; MD bars targeted advertising to consumers a controller knows are under 18; state AGs have express COPPA parens patriae standing (confirmed in the Roku ruling)\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Duolingo Max / Video Call (Lily) + Math Tutor  <-  Duolingo, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n  6. Your right to a jury.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  8. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (5 of 13): your personal data sold onward; your physical movements; a broad licence to your own content; your right to keep what you paid for; your right to meaningful compensation. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Duolingo Max / Video Call (Lily) + Math Tutor you gave up your content used as AI training data, your biometric identifiers, your data shared corporate-wide, your right to sue, your right to join a class action, your right to a jury, your right to be consulted before terms change, and your right to stop paying by inaction. 5 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 60.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Duolingo's AI tier turns a pronunciation checker into an open-ended recorder. The Math Tutor feature sends your audio through Apple for transcription — the audio is then deleted, which sounds protective, except the TEXT TRANSCRIPT may be RETAINED AND SHARED WITH AI VENDORS. Deleting the recording while keeping a verbatim transcript of what a child said out loud disposes of almost nothing. Session-replay recording of your in-app activity runs unless you go find a Tracking toggle in Settings. And whether any of these voice recordings legally count as BIOMETRIC data under Illinois, Texas or Washington law is genuinely unsettled — which matters enormously, because that is one of the few claim types that has ever produced real money for consumers, and the 30-day arbitration opt-out is what stands between users and that route.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Duolingo (deep)", "_row_id": 1122, "_entity_id": 1523, "_entity_slug": "duolingo-max-video-call-lily-math-tutor", "_issuer": "Duolingo, Inc.", "_issuer_slug": "duolingo-inc", "_ticker": "DUOL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Duolingo ABC / Duolingo for Schools (child accounts)", "Category": "Education (children under 13)", "Terms & Conditions URL": "schools.duolingo.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": "duolingo.com/privacy", "Privacy Direct PDF?": "NO (HTML only)", "Data Sharing/Selling Flags": "Duolingo's child-user protections are real and should be recorded as such: the standard minimum age is 13; under-13 accounts require a parent's email for consent; child-user profiles bar real names, location, contact information and profile pictures in favour of avatars; and advertising for child users is set to non-personalised, family-safe inventory. Duolingo states it applies higher age thresholds where EU member-state digital-consent ages require it, alongside COPPA and the UK Age Appropriate Design Code.\n\nThe open question is voice. The amended COPPA Rule, adopted January 2025 with a compliance date of 22 April 2026, added VOICEPRINTS and other biometric identifiers to the categories of protected children’s personal information, requires SEPARATE verifiable parental consent before a child’s data is disclosed for advertising or AI training, requires operators to name the specific recipients rather than referring to partners generically, and bans indefinite retention. Duolingo's speaking exercises record children's voices, and the 27 May 2026 policy update REMOVED the explicit voice-collection disclosure and removed the carve-out that had exempted Android and web users from audio collection. Whether separate parental consent is now obtained for any downstream disclosure of a child's recorded speech to advertising or AI-training recipients was NOT established this pass and is the single highest-priority question queued for Tranche 2.", "Arbitration / Class Action Waiver": "Binding arbitration with class and jury waivers and a 30-day email opt-out applies to all users regardless of age. A minor cannot form the contract in the ordinary way, which raises the same enforceability question that let the Pluto TV children’s claims proceed; a parent who wants to preserve court access should send the opt-out in their own name within the window.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Recorded as a mixed row on purpose. The profile-level protections are among the better ones in this workbook and the schema guide requires saying so. The voice question is genuinely open and is stated as open rather than resolved in either direction — this tracker has no evidence that Duolingo is out of compliance with the amended COPPA Rule and does not suggest it is.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": "Pittsburgh", "HQ State": "Pennsylvania", "CEO": null, "Ticker": "DUOL", "Website (Corporate)": "duolingo.com", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": 30, "Corporate Legal Notice Address (public cos.)": "PUBLIC COMPANY (DUOL). Service route: c/o General Counsel / Corporate Secretary — the corporate address on the SEC Form 10-K cover page is the official address of record. Confirm the exact street address on the current 10-K at sec.gov/edgar, and check the state-of-incorporation registered agent (usually Delaware) via the Secretary of State business-entity search. A registered agent MUST accept service, which is why it is the reliable channel when a company publishes no privacy address.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "HQ state 'Pennsylvania' is a non-DMV US state", "Parent / Ultimate Owner": "Duolingo, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "Full audit", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Duolingo, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "[SENSITIVE_DATA_EXPOSURE · FL-1] Children's voices are recorded, and the disclosure describing that collection was removed five weeks after voiceprints became protected\nWHAT THE TERMS SAY: The amended COPPA Rule effective 22 April 2026 added voiceprints to protected children’s data and requires separate parental consent for disclosure to advertising or AI-training recipients; Duolingo’s 27 May 2026 update removed the explicit voice-collection disclosure and the Android/web audio carve-out.\nWHY IT MATTERS: This tracker states the sequence and asserts no causation — but it is the exact combination the amended Rule was written to govern, and the disclosure that would let a parent evaluate it is the one that was removed.\n(evidence: FTC COPPA Rule amendments (compliance 2026-04-22) and ConductAtlas change history, retrieved 2026-09-06)", "Top Troubling #2": "[NO_ADVERSE_FINDING · FL-2] The profile-level child protections are genuinely above the workbook average\nWHAT THE TERMS SAY: Child-user profiles bar real names, location, contact details and profile pictures in favour of avatars, and advertising to child users is set to non-personalised family-safe inventory, with higher age thresholds applied where local digital-consent ages require.\nWHY IT MATTERS: Compared with Roku, which Michigan alleges offers no child profiles at all, this is a materially better design and should be credited as one.\n(evidence: Duolingo privacy policy child-user provisions; third-party evaluation)", "Top Troubling #3": "[FORCED_ARBITRATION · FL-2] The arbitration clause binds children who cannot form the contract\nWHAT THE TERMS SAY: The arbitration, class-waiver and jury-waiver terms apply to all users regardless of age, with a 30-day email opt-out.\nWHY IT MATTERS: A parent who wants to preserve a court route should send the opt-out themselves inside the window rather than assume a minor’s inability to contract will be enough.\n(evidence: Duolingo Terms of Service; carried forward from v58)", "Troubling Terms Coverage Note": "3 of 3 distinct harms identified from researched source text.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=N; affiliates=Y; biometric=Y; aitrain=?; location=N; unilateral=Y; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "The child-profile protections are documented; whether separate parental consent is obtained for downstream disclosure of recorded child speech is not stated in retrievable text.", "Exposure Score (0-100)": 53, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "A", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_30d+3) | Data 13/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, sensitive_exposure_tag+3) | Contract 5/20 (unilateral_modification+5) | Record 8/20 (severity3+8) | flags stated 9/17 -> confidence A", "Mid-Atlantic Legal Hooks (v58)": "CHILDREN’S DATA → Federal COPPA (amended rule, compliance 2026-04-22) now requires SEPARATE verifiable parental consent before a child’s data goes to advertisers or AI training, and bans indefinite retention; MD bars targeted advertising to consumers a controller knows are under 18; state AGs have express COPPA parens patriae standing (confirmed in the Roku ruling)\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "Company", "Ownership Path": "Duolingo ABC / Duolingo for Schools (child accounts)  <-  Duolingo, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to a jury.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your physical movements.\n\nNOT YET DETERMINED (5 of 13): your content used as AI training data; a broad licence to your own content; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Duolingo ABC / Duolingo for Schools (child accounts) you gave up your biometric identifiers, your data shared corporate-wide, your right to sue, your right to join a class action, your right to a jury, and your right to be consulted before terms change. 5 further clauses are unresolved.", "Last Checked (Full)": "Never - no full-row verification pass has been run against this row", "Last Checked Coverage (%)": 56.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Duolingo's child protections are better than most of this workbook — no real names, no location, no photos, avatars only, non-personalised family-safe ads, higher age gates where local law demands them. Credit where it is due. Then there is the voice. On 22 April 2026 the amended federal COPPA Rule took effect and added VOICEPRINTS to protected children's data, requiring SEPARATE parental consent before a child's data goes to advertisers or AI training. On 27 May 2026 Duolingo removed the explicit voice-collection disclosure from its policy, and removed the carve-out that had kept Android and web users out of audio collection entirely. This tracker claims no connection between those two dates and has no evidence of one. It notes only that the document a parent would need in order to judge it is the document that got shorter.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Duolingo (deep)", "_row_id": 1123, "_entity_id": 1524, "_entity_slug": "duolingo-abc-duolingo-for-schools-child-accounts", "_issuer": "Duolingo, Inc.", "_issuer_slug": "duolingo-inc", "_ticker": "DUOL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "ChatGPT", "Category": "AI Tools - Chat & Assistants", "Terms & Conditions URL": "https://openai.com/policies/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: uses content as AI training material. 9 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to OpenAI Group PBC (under OpenAI Foundation). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://chatgpt.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "OpenAI Group PBC (under OpenAI Foundation)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: OpenAI Group PBC (under OpenAI Foundation)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=Y; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "First-draft row. 9 of 18 clauses unresolved; structural posture recorded, clause detail pending fetch.", "Exposure Score (0-100)": 58, "Exposure Band": "High", "Sub: Dispute Rights /30": 26, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 26/30 (forced_arbitration+12, class_action_waiver+9, jury_trial_waiver+3, optout_window_unverified+2) | Data 5/30 (ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 8/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "ChatGPT  <-  OpenAI Group PBC (under OpenAI Foundation)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to a jury.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using ChatGPT you gave up your content used as AI training data, a broad licence to your own content, your right to sue, your right to join a class action, your right to a jury, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Consumer conversations are used to improve the models by default; turning that off is a setting, not the starting position. The consumer terms carry arbitration with a class-action waiver and a time-limited opt-out that has to be sent, not clicked. The asymmetry worth naming is that the thing you type is simultaneously the product you paid for and the raw material the seller keeps.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Chat & Assistants", "_row_id": 1124, "_entity_id": 1527, "_entity_slug": "chatgpt", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Claude", "Category": "AI Tools - Chat & Assistants", "Terms & Conditions URL": "https://www.anthropic.com/legal/consumer-terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Anthropic PBC. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://claude.ai/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Anthropic PBC", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Anthropic PBC). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=Y; datasale=?; affiliates=?; biometric=?; aitrain=N; location=?; unilateral=Y; liabcap=Y; contentlic=N; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 41, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 23, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 23/30 (forced_arbitration+12, class_action_waiver+9, optout_window_unverified+2) | Data 0/30 (none) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Claude  <-  Anthropic PBC", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to take them to court. Disputes go to private arbitration.\n  2. Your right to join with other people harmed the same way. You must sue alone.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your content used as AI training data; a broad licence to your own content.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Claude you gave up your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The consumer terms state that conversations are not used to train the models by default, which is the opposite of the category norm and should be recorded as such. This tracker credits that. Note the auditor is not neutral here: this row describes the vendor that operates the assistant which compiled it, and it should be verified by a human against the primary document before it is relied on.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Chat & Assistants", "_row_id": 1125, "_entity_id": 1528, "_entity_slug": "claude", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Gemini", "Category": "AI Tools - Chat & Assistants", "Terms & Conditions URL": "https://policies.google.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material; collects precise location. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "No arbitration clause identified in the material reviewed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Google LLC (Alphabet Inc.). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://gemini.google.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "No arbitration clause identified", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Google LLC (Alphabet Inc.)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Google LLC (Alphabet Inc.)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=N; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=Y; biometric=?; aitrain=Y; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 13/30 (shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 14/20 (severity4+14) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Gemini  <-  Google LLC (Alphabet Inc.)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your right to sue.\n\nNOT YET DETERMINED (6 of 13): your biometric identifiers; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Gemini you gave up your content used as AI training data, your physical movements, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Gemini activity can be reviewed by human raters and retained separately from the account history, so deleting a conversation does not necessarily delete the copy a reviewer saw. It also inherits the single Google account graph, meaning the assistant is not a fresh context but an extension of everything else the account already knows about the person.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Chat & Assistants", "_row_id": 1126, "_entity_id": 1530, "_entity_slug": "gemini", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Microsoft Copilot", "Category": "AI Tools - Chat & Assistants", "Terms & Conditions URL": "https://www.microsoft.com/servicesagreement", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Microsoft Corporation. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://copilot.microsoft.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Microsoft Corporation", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Microsoft Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 54, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 9/30 (shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Microsoft Copilot  <-  Microsoft Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Microsoft Copilot you gave up your content used as AI training data, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Governed by the Microsoft Services Agreement, a single contract spanning Xbox, Outlook, OneDrive and the assistant. A consumer accepting it for one product accepts it for all of them, and the arbitration clause in that agreement reaches disputes about services the person never used.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Chat & Assistants", "_row_id": 1127, "_entity_id": 339, "_entity_slug": "microsoft-copilot", "_issuer": "Microsoft Corporation", "_issuer_slug": "microsoft-corporation", "_ticker": "MSFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Perplexity", "Category": "AI Tools - Chat & Assistants", "Terms & Conditions URL": "https://www.perplexity.ai/hub/legal/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: uses content as AI training material. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Perplexity AI, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.perplexity.ai/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Perplexity AI, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Perplexity AI, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 50, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 5/30 (ai_training_on_user_data+5) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Perplexity  <-  Perplexity AI, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Perplexity you gave up your content used as AI training data, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The product answers by summarising other publishers work, which places the consumer in the middle of an unsettled copyright question they did not choose to enter. Publishers have raised claims about that model; the consumer-facing exposure is that the answer relied on may be withdrawn or changed as those disputes resolve.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Chat & Assistants", "_row_id": 1128, "_entity_id": 1531, "_entity_slug": "perplexity", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Grok", "Category": "AI Tools - Chat & Assistants", "Terms & Conditions URL": "https://x.ai/legal/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to xAI (consolidated with X Corp., 2025). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://grok.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "xAI (consolidated with X Corp., 2025)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: xAI (consolidated with X Corp., 2025)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 63, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 9/30 (shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Grok  <-  xAI (consolidated with X Corp., 2025)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Grok you gave up your content used as AI training data, a broad licence to your own content, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The assistant and the social network are now the same corporate entity, so posts written for an audience and prompts written in private sit inside one owner. Public X content has been used as training material, which makes the boundary between publishing and contributing to a model thinner here than in any other product in this category.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Chat & Assistants", "_row_id": 1129, "_entity_id": 1533, "_entity_slug": "grok", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Meta AI", "Category": "AI Tools - Chat & Assistants", "Terms & Conditions URL": "https://www.facebook.com/legal/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material; collects precise location. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Meta Platforms, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.meta.ai/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Meta Platforms, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Meta Platforms, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=Y; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 13/30 (shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Meta AI  <-  Meta Platforms, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A continuous record of everywhere you physically go.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Meta AI you gave up your content used as AI training data, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The assistant is embedded inside Instagram, WhatsApp and Messenger rather than sold separately, so people interact with it without ever having agreed to a distinct AI product. Public posts have been used as training material, and in the assistant surface the line between a message to a friend and an input to a model depends on which thread the person happens to be in.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Chat & Assistants", "_row_id": 1130, "_entity_id": 1534, "_entity_slug": "meta-ai", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Poe", "Category": "AI Tools - Chat & Assistants", "Terms & Conditions URL": "https://poe.com/tos", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Quora, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://poe.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Quora, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Quora, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 49, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Poe  <-  Quora, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Poe you gave up your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Poe is a broker, not a model: a prompt entered here is passed to a third-party provider whose own terms then apply to it. The consumer is therefore agreeing to two contracts at once and only one of them was presented at sign-up.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Chat & Assistants", "_row_id": 1131, "_entity_id": 1536, "_entity_slug": "poe", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "You.com", "Category": "AI Tools - Chat & Assistants", "Terms & Conditions URL": "https://you.com/legal/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: uses content as AI training material. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to You.com (Ought-independent). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://you.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "You.com (Ought-independent)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: You.com (Ought-independent)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 41, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 5/30 (ai_training_on_user_data+5) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "You.com  <-  You.com (Ought-independent)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using You.com you gave up your content used as AI training data, your right to sue, your right to meaningful compensation, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Markets itself on privacy relative to mainstream search, which makes the specific wording of its retention and training clauses the whole basis of the claim. A privacy-positioned product carries more consumer risk from a quiet clause change than a product nobody trusted to begin with.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Chat & Assistants", "_row_id": 1132, "_entity_id": 1537, "_entity_slug": "you-com", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "NotebookLM", "Category": "AI Tools - Chat & Assistants", "Terms & Conditions URL": "https://policies.google.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Google LLC (Alphabet Inc.). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://notebooklm.google.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Google LLC (Alphabet Inc.)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Google LLC (Alphabet Inc.)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=N; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 22, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "NotebookLM  <-  Google LLC (Alphabet Inc.)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your content used as AI training data.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using NotebookLM you gave up your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Users upload their most sensitive documents here by design - contracts, medical records, private notes - because the product only works if they do. That makes the upload corpus categorically more sensitive than ordinary search history, and the retention terms correspondingly more consequential.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Chat & Assistants", "_row_id": 1133, "_entity_id": 1538, "_entity_slug": "notebooklm", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Midjourney", "Category": "AI Tools - Image Generation", "Terms & Conditions URL": "https://docs.midjourney.com/docs/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: uses content as AI training material. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Midjourney, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.midjourney.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Midjourney, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Midjourney, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 59, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 5/30 (ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Midjourney  <-  Midjourney, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Midjourney you gave up your content used as AI training data, a broad licence to your own content, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Images generated by non-paying users are public by default and licensed for others to use and remix. People routinely discover this after generating something personal. Paid tiers change the default, which means privacy here is a purchased feature rather than a baseline.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Image Generation", "_row_id": 1134, "_entity_id": 1540, "_entity_slug": "midjourney", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "DALL-E", "Category": "AI Tools - Image Generation", "Terms & Conditions URL": "https://openai.com/policies/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: uses content as AI training material. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to OpenAI Group PBC. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://openai.com/dall-e-3/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "OpenAI Group PBC", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: OpenAI Group PBC). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 53, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 5/30 (ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "DALL-E  <-  OpenAI Group PBC", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using DALL-E you gave up your content used as AI training data, a broad licence to your own content, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Sits under the same OpenAI terms as ChatGPT, so a consumer who opted out of training for text has to check whether that choice carried across to uploaded images. One contract governing several modalities makes a per-modality choice hard to reason about.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Image Generation", "_row_id": 1135, "_entity_id": 1541, "_entity_slug": "dall-e", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Adobe Firefly", "Category": "AI Tools - Image Generation", "Terms & Conditions URL": "https://www.adobe.com/legal/terms.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 9 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Adobe Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://firefly.adobe.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Adobe Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Adobe Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=N; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "First-draft row. 9 of 18 clauses unresolved; structural posture recorded, clause detail pending fetch.", "Exposure Score (0-100)": 61, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 14/20 (severity4+14) | flags stated 8/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Adobe Firefly  <-  Adobe Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  7. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your content used as AI training data.\n\nNOT YET DETERMINED (5 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Adobe Firefly you gave up a broad licence to your own content, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 5 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "In 2024 a terms update was read by customers as claiming rights to review and use their cloud content; Adobe subsequently rewrote it after sustained professional backlash. The durable lesson for this tracker is that the clause was live before it was noticed, and that noticing depended on a professional community reading the diff.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Image Generation", "_row_id": 1136, "_entity_id": 1543, "_entity_slug": "adobe-firefly", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Stable Diffusion", "Category": "AI Tools - Image Generation", "Terms & Conditions URL": "https://stability.ai/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: uses content as AI training material. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Stability AI Ltd (UK). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://stability.ai/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Stability AI Ltd (UK)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Stability AI Ltd (UK)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 5/30 (ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Stable Diffusion  <-  Stability AI Ltd (UK)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Stable Diffusion you gave up your content used as AI training data, a broad licence to your own content, your right to meaningful compensation, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The model weights are distributed for local use, so a consumer can run it entirely offline and no terms bind that use. This is one of the few products in the category where the person can genuinely exit the contract while keeping the tool, and that deserves recording as a positive.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Image Generation", "_row_id": 1137, "_entity_id": 1545, "_entity_slug": "stable-diffusion", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Leonardo AI", "Category": "AI Tools - Image Generation", "Terms & Conditions URL": "https://leonardo.ai/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: uses content as AI training material. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Canva Pty Ltd (acquired 2024). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://leonardo.ai/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Canva Pty Ltd (acquired 2024)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Canva Pty Ltd (acquired 2024)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 5/30 (ai_training_on_user_data+5) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Leonardo AI  <-  Canva Pty Ltd (acquired 2024)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Leonardo AI you gave up your content used as AI training data, a broad licence to your own content, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Acquired by Canva, so the governing terms and the destination of uploaded work now sit with a different company than the one users signed up with. Acquisition is the most common way a privacy promise changes hands without any clause being edited.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Image Generation", "_row_id": 1138, "_entity_id": 1547, "_entity_slug": "leonardo-ai", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ideogram", "Category": "AI Tools - Image Generation", "Terms & Conditions URL": "https://ideogram.ai/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: uses content as AI training material. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Ideogram AI, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://ideogram.ai/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Ideogram AI, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Ideogram AI, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 5/30 (ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Ideogram  <-  Ideogram AI, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ideogram you gave up your content used as AI training data, a broad licence to your own content, your right to meaningful compensation, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Free-tier generations are public by default in the shared feed, repeating the Midjourney pattern in a product where the type-setting focus attracts brand and signage work that users may assume is confidential.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Image Generation", "_row_id": 1139, "_entity_id": 1549, "_entity_slug": "ideogram", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Canva AI", "Category": "AI Tools - Image Generation", "Terms & Conditions URL": "https://www.canva.com/policies/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Canva Pty Ltd (Australia). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.canva.com/ai-image-generator/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Canva Pty Ltd (Australia)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Canva Pty Ltd (Australia)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Canva AI  <-  Canva Pty Ltd (Australia)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Canva AI you gave up a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "An Australian-domiciled company holding design files for small businesses worldwide, which places the governing law and the data location outside the jurisdiction most of its users would assume. It now also owns Leonardo, consolidating two generative pipelines under one privacy policy.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Image Generation", "_row_id": 1140, "_entity_id": 1550, "_entity_slug": "canva-ai", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Playground AI", "Category": "AI Tools - Image Generation", "Terms & Conditions URL": "https://playground.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: uses content as AI training material. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Playground (independent). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://playground.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Playground (independent)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Playground (independent)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 5/30 (ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Playground AI  <-  Playground (independent)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Playground AI you gave up your content used as AI training data, a broad licence to your own content, your right to meaningful compensation, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A small independent operator holding a generative image corpus. Company size is itself a consumer risk factor: there is no separate legal entity to inherit the obligations if it winds down, and the terms typically say nothing about what happens to stored images in that event.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Image Generation", "_row_id": 1141, "_entity_id": 909, "_entity_slug": "playground-ai", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sora", "Category": "AI Tools - Video Generation", "Terms & Conditions URL": "https://openai.com/policies/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: uses content as AI training material; collects biometric identifiers. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to OpenAI Group PBC. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://sora.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "OpenAI Group PBC", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: OpenAI Group PBC). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 65, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 11, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 11/30 (biometric_collection+6, ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Sora  <-  OpenAI Group PBC", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your personal data sold onward; your physical movements; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Sora you gave up your content used as AI training data, your biometric identifiers, a broad licence to your own content, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Likeness features mean a user can upload a face - frequently not their own - and the terms shift a consent problem onto the consumer that the consumer has no mechanism to satisfy. The person whose face is used never sees the agreement at all.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Video Generation", "_row_id": 1142, "_entity_id": 1552, "_entity_slug": "sora", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Runway", "Category": "AI Tools - Video Generation", "Terms & Conditions URL": "https://runwayml.com/terms-of-use/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: uses content as AI training material. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Runway AI, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://runwayml.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Runway AI, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Runway AI, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 47, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 5/30 (ai_training_on_user_data+5) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Runway  <-  Runway AI, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  6. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Runway you gave up your content used as AI training data, a broad licence to your own content, your right to sue, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Credit-based billing means unused purchased credits can expire, which is a fee-trap structure wearing the clothes of a usage meter. The consumer pays in advance for a quantity that the seller may reclaim by the passage of time.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Video Generation", "_row_id": 1143, "_entity_id": 1554, "_entity_slug": "runway", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Pika", "Category": "AI Tools - Video Generation", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 17 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Pika Labs, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://pika.art/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Pika Labs, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Pika Labs, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 17 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 8, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Pika  <-  Pika Labs, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Pika takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 16.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "No terms of service document could be located during this pass for a product that accepts uploaded photographs and video of real people. The absence is the finding: a face-processing consumer product with no locatable governing document is a higher-risk posture than a bad document.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Video Generation", "_row_id": 1144, "_entity_id": 1556, "_entity_slug": "pika", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Kling AI", "Category": "AI Tools - Video Generation", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 17 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Kuaishou Technology (Beijing). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://klingai.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Kuaishou Technology (Beijing)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Kuaishou Technology (Beijing)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 17 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 14, "Exposure Band": "Insufficient data", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 0/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Kling AI  <-  Kuaishou Technology (Beijing)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nNOT YET DETERMINED (13 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Kling AI takes nothing from the list this tracker checks - but 13 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 16.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Operated by a Chinese listed video platform, so uploaded faces and video are processed under a jurisdiction whose data-transfer rules differ materially from the assumptions of most Western users. No English terms document was located in this pass.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Video Generation", "_row_id": 1145, "_entity_id": 1558, "_entity_slug": "kling-ai", "_issuer": "Kuaishou Technology", "_issuer_slug": "kuaishou-technology", "_ticker": "1024", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Luma AI", "Category": "AI Tools - Video Generation", "Terms & Conditions URL": "https://lumalabs.ai/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: uses content as AI training material. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Luma AI, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://lumalabs.ai/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Luma AI, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Luma AI, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 5/30 (ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Luma AI  <-  Luma AI, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Luma AI you gave up your content used as AI training data, a broad licence to your own content, your right to meaningful compensation, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The capture products build three-dimensional scans of real physical places, typically homes. That is a spatial map of a private interior, a data category with no established consumer-protection vocabulary and no clear retention norm.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Video Generation", "_row_id": 1146, "_entity_id": 1560, "_entity_slug": "luma-ai", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Synthesia", "Category": "AI Tools - Video Generation", "Terms & Conditions URL": "https://www.synthesia.io/legal/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: collects biometric identifiers. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Synthesia Limited (UK). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.synthesia.io/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Synthesia Limited (UK)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Synthesia Limited (UK)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 33, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 6/30 (biometric_collection+6) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered", "Entity Type": "App / Service", "Ownership Path": "Synthesia  <-  Synthesia Limited (UK)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Synthesia you gave up your biometric identifiers, a broad licence to your own content, your right to meaningful compensation, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Custom avatars are built from recorded video of a real person, creating a durable synthetic likeness that outlives the engagement. The consumer question the terms must answer, and which should be verified against the primary document, is whether revoking consent actually destroys the avatar.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Video Generation", "_row_id": 1147, "_entity_id": 1562, "_entity_slug": "synthesia", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "HeyGen", "Category": "AI Tools - Video Generation", "Terms & Conditions URL": "https://www.heygen.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: collects biometric identifiers. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to HeyGen, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.heygen.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "HeyGen, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: HeyGen, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 36, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 6/30 (biometric_collection+6) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered", "Entity Type": "App / Service", "Ownership Path": "HeyGen  <-  HeyGen, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using HeyGen you gave up your biometric identifiers, a broad licence to your own content, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Sells face and voice cloning to consumers with self-serve onboarding, meaning verification that the uploaded likeness belongs to the uploader rests on a checkbox. Illinois BIPA and Texas CUBI exposure here is a live question rather than a theoretical one.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Video Generation", "_row_id": 1148, "_entity_id": 1564, "_entity_slug": "heygen", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Veo", "Category": "AI Tools - Video Generation", "Terms & Conditions URL": "https://policies.google.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Google LLC (Alphabet Inc.). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://deepmind.google/models/veo/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Google LLC (Alphabet Inc.)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Google LLC (Alphabet Inc.)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 9/30 (shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Veo  <-  Google LLC (Alphabet Inc.)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Veo you gave up your content used as AI training data, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Distributed through general Google surfaces under the same account-wide terms, so a consumer generating video is doing so under an agreement written for search and mail. The specific provisions for synthetic video sit in product policies that can change without a terms amendment.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Video Generation", "_row_id": 1149, "_entity_id": 1565, "_entity_slug": "veo", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "ElevenLabs", "Category": "AI Tools - Voice & Audio", "Terms & Conditions URL": "https://elevenlabs.io/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: collects biometric identifiers. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to ElevenLabs, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://elevenlabs.io/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "ElevenLabs, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: ElevenLabs, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 36, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 6/30 (biometric_collection+6) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered", "Entity Type": "App / Service", "Ownership Path": "ElevenLabs  <-  ElevenLabs, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using ElevenLabs you gave up your biometric identifiers, a broad licence to your own content, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Voice cloning from a short sample makes a voiceprint - the same category of identifier that the amended COPPA Rule brought under protection from 22 April 2026. A cloned voice is portable, permanent and cannot be reissued the way a password can.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Voice, Audio & Music", "_row_id": 1150, "_entity_id": 1567, "_entity_slug": "elevenlabs", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Suno", "Category": "AI Tools - Music Generation", "Terms & Conditions URL": "https://suno.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: uses content as AI training material. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Suno, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://suno.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Suno, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Suno, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 62, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 5/30 (ai_training_on_user_data+5) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 14/20 (severity4+14) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Suno  <-  Suno, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  7. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (6 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Suno you gave up your content used as AI training data, a broad licence to your own content, your right to sue, your right to join a class action, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Ownership of generated tracks varies by paid tier, so the same act of creation produces different property rights depending on billing status at that moment. Recording-industry litigation over the training corpus also means a consumer commercial release rests on an unsettled foundation.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Voice, Audio & Music", "_row_id": 1151, "_entity_id": 1569, "_entity_slug": "suno", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Udio", "Category": "AI Tools - Music Generation", "Terms & Conditions URL": "https://www.udio.com/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: uses content as AI training material. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Uncharted Labs, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.udio.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Uncharted Labs, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Uncharted Labs, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 50, "Exposure Band": "High", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 5/30 (ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Udio  <-  Uncharted Labs, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Udio you gave up your content used as AI training data, a broad licence to your own content, your right to sue, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Faces the same industry copyright challenge over training data as its closest competitor, and the consumer-facing consequence is identical: tracks a user has already published could become encumbered by a settlement they were not party to and cannot influence.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Voice, Audio & Music", "_row_id": 1152, "_entity_id": 1571, "_entity_slug": "udio", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Descript", "Category": "AI Tools - Voice & Audio", "Terms & Conditions URL": "https://www.descript.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: collects biometric identifiers. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Descript, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.descript.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Descript, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Descript, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 6/30 (biometric_collection+6) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered", "Entity Type": "App / Service", "Ownership Path": "Descript  <-  Descript, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Descript you gave up your biometric identifiers, a broad licence to your own content, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Overdub builds a synthetic version of the user own voice from recorded speech, and the editing workflow means the platform holds raw recordings of everyone who happened to be in the room, not only the account holder who consented.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Voice, Audio & Music", "_row_id": 1153, "_entity_id": 1573, "_entity_slug": "descript", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Adobe Podcast", "Category": "AI Tools - Voice & Audio", "Terms & Conditions URL": "https://www.adobe.com/legal/terms.html", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Adobe Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://podcast.adobe.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Adobe Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Adobe Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 52, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Adobe Podcast  <-  Adobe Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Adobe Podcast you gave up a broad licence to your own content, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Audio enhancement requires uploading the full unedited recording, including everything said before and after the intended take. The governing Adobe terms treat that upload as cloud content under the same general provisions as a design file.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Voice, Audio & Music", "_row_id": 1154, "_entity_id": 1574, "_entity_slug": "adobe-podcast", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Otter.ai", "Category": "AI Tools - Transcription", "Terms & Conditions URL": "https://otter.ai/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material; collects biometric identifiers. 9 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Otter.ai, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://otter.ai/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Otter.ai, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Otter.ai, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 5 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "First-draft row. 9 of 18 clauses unresolved; structural posture recorded, clause detail pending fetch.", "Exposure Score (0-100)": 75, "Exposure Band": "Severe", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 15, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 15/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 20/20 (severity5+20) | flags stated 8/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Otter.ai  <-  Otter.ai, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to take them to court. Disputes go to private arbitration.\n  6. Your right to join with other people harmed the same way. You must sue alone.\n  7. Your right to be made whole. Their liability is capped, often at what you paid.\n  8. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (5 of 13): your personal data sold onward; your physical movements; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Otter.ai you gave up your content used as AI training data, your biometric identifiers, a broad licence to your own content, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 5 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 50.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The product records meetings, which means it captures the speech of people who never installed it, never saw the terms and never consented. In two-party-consent states that structure puts the account holder, not the vendor, in legal jeopardy - the consumer is the one exposed by the design.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Voice, Audio & Music", "_row_id": 1155, "_entity_id": 1576, "_entity_slug": "otter-ai", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Notion AI", "Category": "AI Tools - Writing & Productivity", "Terms & Conditions URL": "https://www.notion.so/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Notion Labs, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.notion.so/product/ai", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Notion Labs, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Notion Labs, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=N; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Notion AI  <-  Notion Labs, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your content used as AI training data.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Notion AI you gave up a broad licence to your own content, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The assistant reads the entire workspace to answer, so enabling it grants processing access to every document in it at once rather than to the page in front of the user. Consent is granted per account, but exercised per document.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Writing & Producti", "_row_id": 1156, "_entity_id": 1578, "_entity_slug": "notion-ai", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Grammarly", "Category": "AI Tools - Writing & Productivity", "Terms & Conditions URL": "https://www.grammarly.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Grammarly, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.grammarly.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Grammarly, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Grammarly, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 63, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 9/30 (shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Grammarly  <-  Grammarly, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Grammarly you gave up your content used as AI training data, a broad licence to your own content, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The browser extension reads text as it is typed, which includes drafts abandoned before sending, medical portal fields and messages to a lawyer. The scope of collection is defined by where the extension is installed rather than by what the user intended to submit.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Writing & Producti", "_row_id": 1157, "_entity_id": 272, "_entity_slug": "grammarly", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Jasper", "Category": "AI Tools - Writing & Productivity", "Terms & Conditions URL": "https://www.jasper.ai/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Jasper AI, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.jasper.ai/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Jasper AI, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Jasper AI, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 42, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Jasper  <-  Jasper AI, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Jasper you gave up a broad licence to your own content, your right to sue, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Sold on annual plans to individuals and very small businesses, where auto-renewal on a yearly cycle means a forgotten subscription costs twelve months rather than one before anyone notices.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Writing & Producti", "_row_id": 1158, "_entity_id": 1580, "_entity_slug": "jasper", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Writesonic", "Category": "AI Tools - Writing & Productivity", "Terms & Conditions URL": "https://writesonic.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Writesonic, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://writesonic.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Writesonic, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Writesonic, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Writesonic  <-  Writesonic, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Writesonic you gave up a broad licence to your own content, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Credit expiry combined with tier changes means the practical value of a paid plan can fall without any price rise, a form of repricing that never appears as a price change on a statement.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Writing & Producti", "_row_id": 1159, "_entity_id": 1582, "_entity_slug": "writesonic", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Copy.ai", "Category": "AI Tools - Writing & Productivity", "Terms & Conditions URL": "https://www.copy.ai/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Copy.ai, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.copy.ai/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Copy.ai, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Copy.ai, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Copy.ai  <-  Copy.ai, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Copy.ai you gave up a broad licence to your own content, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Marketing copy submitted for rewriting routinely contains unreleased product details and pricing, so the input corpus is commercially sensitive in a way the consumer-grade terms do not specifically address.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Writing & Producti", "_row_id": 1160, "_entity_id": 1584, "_entity_slug": "copy-ai", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "QuillBot", "Category": "AI Tools - Writing & Productivity", "Terms & Conditions URL": "https://quillbot.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Learneo, Inc. (formerly Course Hero). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://quillbot.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Learneo, Inc. (formerly Course Hero)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Learneo, Inc. (formerly Course Hero)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 33, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 9/30 (shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "QuillBot  <-  Learneo, Inc. (formerly Course Hero)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  6. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using QuillBot you gave up your content used as AI training data, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Owned by the education company behind Course Hero, so student work submitted for paraphrasing sits inside a corporate family whose other products hold academic-integrity records on the same students.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Writing & Producti", "_row_id": 1161, "_entity_id": 1586, "_entity_slug": "quillbot", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Sudowrite", "Category": "AI Tools - Writing & Productivity", "Terms & Conditions URL": "https://www.sudowrite.com/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Sudowrite, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.sudowrite.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Sudowrite, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Sudowrite, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=N; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Sudowrite  <-  Sudowrite, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your content used as AI training data.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Sudowrite you gave up a broad licence to your own content, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Novelists upload complete unpublished manuscripts, which is the highest-value single-document upload of any product in this category. Whether the manuscript is used for training is the entire question for this user base and must be verified against the primary document.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Writing & Producti", "_row_id": 1162, "_entity_id": 1588, "_entity_slug": "sudowrite", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "GitHub Copilot", "Category": "AI Tools - Code Assistants", "Terms & Conditions URL": "https://docs.github.com/en/site-policy/github-terms/github-terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to GitHub, Inc. (Microsoft Corporation). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://github.com/features/copilot", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "GitHub, Inc. (Microsoft Corporation)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: GitHub, Inc. (Microsoft Corporation)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 54, "Exposure Band": "High", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 9/30 (shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "GitHub Copilot  <-  GitHub, Inc. (Microsoft Corporation)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using GitHub Copilot you gave up your content used as AI training data, a broad licence to your own content, your data shared corporate-wide, your right to sue, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Suggestions are generated from public repository code whose licences impose obligations, so a consumer can absorb a copyleft obligation into proprietary work without ever seeing a licence. The indemnity position differs between free and paid tiers, meaning protection is a purchased good.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Code Assistants", "_row_id": 1163, "_entity_id": 1590, "_entity_slug": "github-copilot", "_issuer": "Microsoft Corporation", "_issuer_slug": "microsoft-corporation", "_ticker": "MSFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cursor", "Category": "AI Tools - Code Assistants", "Terms & Conditions URL": "https://www.cursor.com/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: uses content as AI training material. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Anysphere, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://cursor.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Anysphere, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Anysphere, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 5/30 (ai_training_on_user_data+5) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Cursor  <-  Anysphere, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Cursor you gave up your content used as AI training data, a broad licence to your own content, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The editor indexes the whole local repository to give context, which sends far more than the open file. Privacy Mode exists but is a setting, so the default posture transmits code the developer may be contractually forbidden from disclosing.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Code Assistants", "_row_id": 1164, "_entity_id": 1592, "_entity_slug": "cursor", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Windsurf", "Category": "AI Tools - Code Assistants", "Terms & Conditions URL": "https://windsurf.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Cognition AI, Inc. (following 2025 transaction). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://windsurf.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Cognition AI, Inc. (following 2025 transaction)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Cognition AI, Inc. (following 2025 transaction)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Windsurf  <-  Cognition AI, Inc. (following 2025 transaction)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Windsurf you gave up a broad licence to your own content, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Changed corporate hands during 2025 in a widely reported and unusually structured transaction. For this tracker the point is not the deal but the consequence: the entity holding indexed customer source code is not the entity users originally contracted with.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Code Assistants", "_row_id": 1165, "_entity_id": 1594, "_entity_slug": "windsurf", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Replit", "Category": "AI Tools - Code Assistants", "Terms & Conditions URL": "https://replit.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: uses content as AI training material. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Replit, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://replit.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Replit, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Replit, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=Y; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 33, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 5, "Sub: Contract Asymmetry /20": 20, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 5/30 (ai_training_on_user_data+5) | Contract 20/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, termination_or_confiscation+4, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Replit  <-  Replit, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  6. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Replit you gave up your content used as AI training data, a broad licence to your own content, your right to keep what you paid for, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Free-tier projects are public by default and hosting can be suspended, so a consumer can lose both the privacy and the availability of work they consider theirs. Students are a large share of this user base and are least likely to read the default.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Code Assistants", "_row_id": 1166, "_entity_id": 1596, "_entity_slug": "replit", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Amazon Q Developer", "Category": "AI Tools - Code Assistants", "Terms & Conditions URL": "https://aws.amazon.com/service-terms/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Amazon.com, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://aws.amazon.com/q/developer/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Amazon.com, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Amazon.com, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 27, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 9/30 (shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Amazon Q Developer  <-  Amazon.com, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Amazon Q Developer you gave up your content used as AI training data, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Governed by the AWS Service Terms, a document written for enterprise procurement and applied unchanged to individual developers on free tiers. The reading burden is calibrated to a customer with counsel, not to the person actually clicking accept.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Code Assistants", "_row_id": 1167, "_entity_id": 1597, "_entity_slug": "amazon-q-developer", "_issuer": "Amazon.com, Inc.", "_issuer_slug": "amazon-com-inc", "_ticker": "AMZN", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Tabnine", "Category": "AI Tools - Code Assistants", "Terms & Conditions URL": "https://www.tabnine.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Tabnine Ltd (Israel). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.tabnine.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Tabnine Ltd (Israel)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Tabnine Ltd (Israel)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=N; location=?; unilateral=Y; liabcap=Y; contentlic=N; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 15, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Tabnine  <-  Tabnine Ltd (Israel)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to be made whole. Their liability is capped, often at what you paid.\n  2. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your content used as AI training data; a broad licence to your own content.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Tabnine you gave up your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Positions itself on not training from customer code and on supporting fully local models. If the primary document confirms it, this is the strongest consumer posture in the code-assistant category and should be recorded as a positive rather than buried.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Code Assistants", "_row_id": 1168, "_entity_id": 1599, "_entity_slug": "tabnine", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Elicit", "Category": "AI Tools - Research", "Terms & Conditions URL": "https://elicit.com/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Elicit Research, PBC. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://elicit.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Elicit Research, PBC", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Elicit Research, PBC). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 18, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Elicit  <-  Elicit Research, PBC", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Elicit you gave up a broad licence to your own content, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A public benefit corporation serving researchers, where the uploaded corpus is often unpublished work under embargo. The PBC form is a governance signal worth recording but it is not a contractual commitment to the user and should not be read as one.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Research & Automate", "_row_id": 1169, "_entity_id": 1601, "_entity_slug": "elicit", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Consensus", "Category": "AI Tools - Research", "Terms & Conditions URL": "https://consensus.app/terms", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 14 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Consensus NLP, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://consensus.app/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Consensus NLP, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Consensus NLP, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 14 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 15, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Consensus  <-  Consensus NLP, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to be made whole. Their liability is capped, often at what you paid.\n  2. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Consensus you gave up your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Summarises scientific literature into plain conclusions, which consumers increasingly use for medical decisions. The liability limitation sits in tension with the confidence of the output, and that gap is the consumer risk.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Research & Automate", "_row_id": 1170, "_entity_id": 1603, "_entity_slug": "consensus", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "SciSpace", "Category": "AI Tools - Research", "Terms & Conditions URL": "https://scispace.com/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to SciSpace (Pubgenius, Inc.). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://scispace.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "SciSpace (Pubgenius, Inc.)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: SciSpace (Pubgenius, Inc.)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 18, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "SciSpace  <-  SciSpace (Pubgenius, Inc.)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using SciSpace you gave up a broad licence to your own content, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Users upload paywalled papers they have licensed access to but not redistribution rights over, so ordinary use may breach a publisher agreement the consumer is separately bound by.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Research & Automate", "_row_id": 1171, "_entity_id": 1605, "_entity_slug": "scispace", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Zapier AI", "Category": "AI Tools - Automation", "Terms & Conditions URL": "https://zapier.com/legal", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Zapier, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://zapier.com/ai", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Zapier, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Zapier, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 31, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 14/20 (severity4+14) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Zapier AI  <-  Zapier, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Zapier AI you gave up your data shared corporate-wide, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Automation requires standing credentials to mail, files and payment systems at once, so a single agreement concentrates access that the user granted in separate contexts. The blast radius of one compromise here is wider than for any single connected service.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Research & Automate", "_row_id": 1172, "_entity_id": 1607, "_entity_slug": "zapier-ai", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Make", "Category": "AI Tools - Automation", "Terms & Conditions URL": "https://www.make.com/en/terms-and-conditions", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Celonis SE (Germany). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.make.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Celonis SE (Germany)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Celonis SE (Germany)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Make  <-  Celonis SE (Germany)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Make you gave up your data shared corporate-wide, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Owned by a German process-mining company, which places the data under EU governing law - generally favourable for the consumer - while the operational reality is that scenario logs retain the content of every record passed through them.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Research & Automate", "_row_id": 1173, "_entity_id": 1609, "_entity_slug": "make", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Salesforce Einstein", "Category": "AI Tools - Automation", "Terms & Conditions URL": "https://www.salesforce.com/company/legal/agreements/", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 14 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Salesforce, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.salesforce.com/artificial-intelligence/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer contract", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Salesforce, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Salesforce, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 14 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 16, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Salesforce Einstein  <-  Salesforce, Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A business-to-business product with no consumer contract, but consumers appear in it as records rather than as parties. The people whose data is processed have no relationship with the vendor and no route to the agreement that governs them.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "AI Tools - Research & Automate", "_row_id": 1174, "_entity_id": 1610, "_entity_slug": "salesforce-einstein", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "HubSpot AI", "Category": "AI Tools - Automation", "Terms & Conditions URL": "https://legal.hubspot.com/terms-of-service", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 14 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to HubSpot, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.hubspot.com/products/artificial-intelligence", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "B2B / No consumer contract", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "HubSpot, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: HubSpot, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=Y", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 14 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 16, "Exposure Band": "N/A - B2B", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 2/20 (severity2+2) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "HubSpot AI  <-  HubSpot, Inc.", "What Did I Sell (Itemised)": "Not applicable. No consumer contract was identified for this entity, so there is no consumer-facing bargain to itemise.", "What Did I Sell (One Sentence)": "Nothing - there is no consumer contract here to give anything up under.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same structural position as its larger competitor: the individuals in the database are the subject of the processing and not a party to it. Recorded here so the tracker holds the controller side of consumer marketing data, not only the consumer-facing side.", "Retail-Facing? (Y/N)": "No", "Small Business Relevant? (Y/N)": "Yes", "_tab": "AI Tools - Research & Automate", "_row_id": 1175, "_entity_id": 1612, "_entity_slug": "hubspot-ai", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Microsoft 365 Copilot", "Category": "AI Tools - Automation", "Terms & Conditions URL": "https://www.microsoft.com/servicesagreement", "T&C Direct PDF?": "NO (HTML only)", "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Microsoft Corporation. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.microsoft.com/microsoft-365/copilot", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "Candidate - not yet fetched", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Microsoft Corporation", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Microsoft Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=N; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Microsoft 365 Copilot  <-  Microsoft Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your content used as AI training data.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Microsoft 365 Copilot you gave up your data shared corporate-wide, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Reads the tenant mail and documents to answer, so an employee using it exposes correspondence belonging to colleagues and external parties who never agreed to the assistant. Consent is given by the account holder and spent on everyone in the mailbox.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "AI Tools - Research & Automate", "_row_id": 1176, "_entity_id": 1613, "_entity_slug": "microsoft-365-copilot", "_issuer": "Microsoft Corporation", "_issuer_slug": "microsoft-corporation", "_ticker": "MSFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "TikTok", "Category": "Social - TikTok & ByteDance", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; uses content as AI training material; collects biometric identifiers; collects precise location. 7 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to ByteDance Ltd. (Cayman Islands) / US joint venture. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.tiktok.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "ByteDance Ltd. (Cayman Islands) / US joint venture", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: ByteDance Ltd. (Cayman Islands) / US joint venture). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 5 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=Y; aitrain=Y; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "First-draft row. 7 of 18 clauses unresolved; structural posture recorded, clause detail pending fetch.", "Exposure Score (0-100)": 87, "Exposure Band": "Severe", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 27, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 27/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, biometric_collection+6, ai_training_on_user_data+5, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 20/20 (severity5+20) | flags stated 10/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "TikTok  <-  ByteDance Ltd. (Cayman Islands) / US joint venture", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your content and your conversations, as raw material to train AI models.\n  3. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  4. A continuous record of everywhere you physically go.\n  5. A licence to your own photos, writing and uploads, on their terms.\n  6. Your personal information, to every company in their corporate family.\n  7. Your right to take them to court. Disputes go to private arbitration.\n  8. Your right to join with other people harmed the same way. You must sue alone.\n  9. Your right to be made whole. Their liability is capped, often at what you paid.\n  10. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (3 of 13): your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using TikTok you gave up your personal data sold onward, your content used as AI training data, your biometric identifiers, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 3 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 53.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The only platform in this workbook whose ownership was restructured by federal statute rather than by commercial choice. For the consumer the practical question is unchanged by that: the terms grant a broad licence to uploaded video, and the recommendation system infers far more than the profile discloses. Ownership changes did not reset anyone existing licence grant.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - TikTok & ByteDance", "_row_id": 1177, "_entity_id": 127, "_entity_slug": "tiktok", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "TikTok Shop", "Category": "Social - TikTok & ByteDance", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to ByteDance Ltd. / TikTok. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://shop.tiktok.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "ByteDance Ltd. / TikTok", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: ByteDance Ltd. / TikTok). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 67, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 14/20 (severity4+14) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "TikTok Shop  <-  ByteDance Ltd. / TikTok", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using TikTok Shop you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Merges a recommendation feed with a payment rail, so purchase history and watch history resolve to one profile. Buying something becomes a behavioural signal fed straight back into what the person is shown next, which is a feedback loop the consumer cannot inspect.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - TikTok & ByteDance", "_row_id": 1178, "_entity_id": 1614, "_entity_slug": "tiktok-shop", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "CapCut", "Category": "Social - TikTok & ByteDance", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material; collects biometric identifiers. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to ByteDance Ltd.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.capcut.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "ByteDance Ltd.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: ByteDance Ltd.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 42, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 15, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 15/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "CapCut  <-  ByteDance Ltd.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your physical movements; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using CapCut you gave up your content used as AI training data, your biometric identifiers, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A video editor used far beyond TikTok, including by people who avoid the social app deliberately. Editing uploads raw footage containing faces of family and children, and the licence terms reach that footage whether or not it is ever published anywhere.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - TikTok & ByteDance", "_row_id": 1179, "_entity_id": 1615, "_entity_slug": "capcut", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Lemon8", "Category": "Social - TikTok & ByteDance", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to ByteDance Ltd.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.lemon8-app.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "ByteDance Ltd.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: ByteDance Ltd.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 43, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "Lemon8  <-  ByteDance Ltd.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your content used as AI training data; your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Lemon8 you gave up your personal data sold onward, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A lifestyle app sharing the parent corporate structure with TikTok, promoted heavily to TikTok users during periods of regulatory uncertainty. Same controller, separate consent - and most users treated it as an alternative rather than the same company.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - TikTok & ByteDance", "_row_id": 1180, "_entity_id": 1616, "_entity_slug": "lemon8", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Douyin", "Category": "Social - TikTok & ByteDance", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects precise location. 15 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to ByteDance Ltd. (China domestic). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.douyin.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "ByteDance Ltd. (China domestic)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: ByteDance Ltd. (China domestic)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 15 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 22, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 0/20 (none) | Record 14/20 (severity4+14) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "Douyin  <-  ByteDance Ltd. (China domestic)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Douyin you gave up your physical movements and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The mainland China product from the same parent, operating under a wholly different regulatory and content regime. Recorded so the tracker shows that one owner runs two products with materially different rules for otherwise identical behaviour.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - TikTok & ByteDance", "_row_id": 1181, "_entity_id": 1617, "_entity_slug": "douyin", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Toutiao", "Category": "Social - TikTok & ByteDance", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material. 15 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to ByteDance Ltd.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.toutiao.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "ByteDance Ltd.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: ByteDance Ltd.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=Y; location=?; unilateral=?; liabcap=?; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 15 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 17, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 9/30 (shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5) | Contract 0/20 (none) | Record 8/20 (severity3+8) | flags stated 2/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Toutiao  <-  ByteDance Ltd.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (11 of 13): your personal data sold onward; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Toutiao you gave up your content used as AI training data and your data shared corporate-wide. 11 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 23.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The news aggregator that established the parent recommendation technology before any video product existed. Its inclusion documents where the ranking system consumers now experience originated.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - TikTok & ByteDance", "_row_id": 1182, "_entity_id": 1618, "_entity_slug": "toutiao", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Facebook", "Category": "Social - Meta Platforms", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; uses content as AI training material; collects precise location. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Meta Platforms, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.facebook.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Meta Platforms, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Meta Platforms, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 5 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=Y; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 54, "Exposure Band": "High", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 21, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 21/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 20/20 (severity5+20) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Facebook  <-  Meta Platforms, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your content and your conversations, as raw material to train AI models.\n  3. A continuous record of everywhere you physically go.\n  4. A licence to your own photos, writing and uploads, on their terms.\n  5. Your personal information, to every company in their corporate family.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Facebook you gave up your personal data sold onward, your content used as AI training data, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Collects on people who never registered, through embedded pixels and buttons across the wider web. A person with no account has no terms to read, no setting to change and no consent to withdraw, which is the clearest example in this workbook of data collection outside any contract.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Meta Platforms", "_row_id": 1183, "_entity_id": 1619, "_entity_slug": "facebook", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Instagram", "Category": "Social - Meta Platforms", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; uses content as AI training material; collects precise location. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Meta Platforms, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.instagram.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Meta Platforms, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Meta Platforms, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 5 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=Y; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 54, "Exposure Band": "High", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 21, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 21/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 20/20 (severity5+20) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Instagram  <-  Meta Platforms, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your content and your conversations, as raw material to train AI models.\n  3. A continuous record of everywhere you physically go.\n  4. A licence to your own photos, writing and uploads, on their terms.\n  5. Your personal information, to every company in their corporate family.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Instagram you gave up your personal data sold onward, your content used as AI training data, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The content licence covers photographs of children posted by parents, creating a durable grant over images of a person who will reach adulthood without ever having agreed to it and with no mechanism to revoke what was granted on their behalf.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Meta Platforms", "_row_id": 1184, "_entity_id": 1620, "_entity_slug": "instagram", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "WhatsApp", "Category": "Social - Meta Platforms", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects precise location. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Meta Platforms, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.whatsapp.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Meta Platforms, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Meta Platforms, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "WhatsApp  <-  Meta Platforms, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using WhatsApp you gave up your physical movements, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Message contents are end-to-end encrypted, which is a genuine and unusual protection worth crediting. The metadata is not: who contacted whom, when, how often and from where remains visible and is shared within the corporate family.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Meta Platforms", "_row_id": 1185, "_entity_id": 1621, "_entity_slug": "whatsapp", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Messenger", "Category": "Social - Meta Platforms", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material; collects precise location. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Meta Platforms, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.messenger.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Meta Platforms, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Meta Platforms, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=Y; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 13/30 (shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Messenger  <-  Meta Platforms, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A continuous record of everywhere you physically go.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Messenger you gave up your content used as AI training data, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Encryption arrived later and by default later still than on its sibling product, so the historical archive of a long-standing account is materially more exposed than recent messages in the same thread.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Meta Platforms", "_row_id": 1186, "_entity_id": 1622, "_entity_slug": "messenger", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Threads", "Category": "Social - Meta Platforms", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material; collects precise location. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Meta Platforms, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.threads.net/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Meta Platforms, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Meta Platforms, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=Y; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 13/30 (shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Threads  <-  Meta Platforms, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A continuous record of everywhere you physically go.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Threads you gave up your content used as AI training data, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Launched requiring an Instagram account, and deleting the Threads profile was initially entangled with deleting the Instagram one. Account coupling of that kind converts a decision to leave one product into a cost imposed on another.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Meta Platforms", "_row_id": 1187, "_entity_id": 1623, "_entity_slug": "threads", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Meta Quest", "Category": "Social - Meta Platforms", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material; collects biometric identifiers; collects precise location. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Meta Platforms, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.meta.com/quest/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Meta Platforms, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Meta Platforms, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 5 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=Y; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 52, "Exposure Band": "High", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 19, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 19/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, ai_training_on_user_data+5, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 20/20 (severity5+20) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Meta Quest  <-  Meta Platforms, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. A continuous record of everywhere you physically go.\n  4. A licence to your own photos, writing and uploads, on their terms.\n  5. Your personal information, to every company in their corporate family.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your personal data sold onward; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Meta Quest you gave up your content used as AI training data, your biometric identifiers, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Headsets capture eye movement, hand geometry and a spatial map of the room. Gaze data in particular reveals attention and reaction in a way no click can, and it is generated continuously rather than at moments the user chooses.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Meta Platforms", "_row_id": 1188, "_entity_id": 1624, "_entity_slug": "meta-quest", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ray-Ban Meta glasses", "Category": "Social - Meta Platforms", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material; collects biometric identifiers; collects precise location. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Meta Platforms, Inc. / EssilorLuxottica. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.meta.com/ai-glasses/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Meta Platforms, Inc. / EssilorLuxottica", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Meta Platforms, Inc. / EssilorLuxottica). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 5 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=Y; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 52, "Exposure Band": "High", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 19, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 19/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, ai_training_on_user_data+5, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 20/20 (severity5+20) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Ray-Ban Meta glasses  <-  Meta Platforms, Inc. / EssilorLuxottica", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. A continuous record of everywhere you physically go.\n  4. A licence to your own photos, writing and uploads, on their terms.\n  5. Your personal information, to every company in their corporate family.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your personal data sold onward; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ray-Ban Meta glasses you gave up your content used as AI training data, your biometric identifiers, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A camera and microphone worn on the face in public. Everyone in frame is recorded without any opportunity to accept terms, and the bystander has no account, no notice and no deletion route - the same structural problem as smart TV bystander capture, but mobile.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Meta Platforms", "_row_id": 1189, "_entity_id": 1625, "_entity_slug": "ray-ban-meta-glasses", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "YouTube", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material; collects precise location. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Google LLC (Alphabet Inc.). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.youtube.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Google LLC (Alphabet Inc.)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Google LLC (Alphabet Inc.)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=Y; biometric=?; aitrain=Y; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 0/30 (none) | Data 13/30 (shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "YouTube  <-  Google LLC (Alphabet Inc.)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A continuous record of everywhere you physically go.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (6 of 13): your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using YouTube you gave up your content used as AI training data, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Watch history feeds the account-wide advertising profile, so viewing on a television affects what is shown in a browser on a different device. The 2019 childrens-privacy enforcement reshaped how creators must designate content, shifting a compliance burden onto individuals.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1190, "_entity_id": 1626, "_entity_slug": "youtube", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "YouTube Shorts", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material; collects precise location. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Google LLC (Alphabet Inc.). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.youtube.com/shorts", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Google LLC (Alphabet Inc.)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Google LLC (Alphabet Inc.)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=Y; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 13/30 (shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "YouTube Shorts  <-  Google LLC (Alphabet Inc.)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A continuous record of everywhere you physically go.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using YouTube Shorts you gave up your content used as AI training data, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Shares an account and a policy with the main product but a wholly different engagement pattern, so the behavioural signal it generates is denser per minute than long-form viewing while being governed by terms written for long-form viewing.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1191, "_entity_id": 1627, "_entity_slug": "youtube-shorts", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "X (Twitter)", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; uses content as AI training material; collects precise location. 9 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to X Corp. / xAI. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://x.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "X Corp. / xAI", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: X Corp. / xAI). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 5 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=Y; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "First-draft row. 9 of 18 clauses unresolved; structural posture recorded, clause detail pending fetch.", "Exposure Score (0-100)": 77, "Exposure Band": "Severe", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 17, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 17/30 (data_sold_or_shared_for_value+8, ai_training_on_user_data+5, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 20/20 (severity5+20) | flags stated 8/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "X (Twitter)  <-  X Corp. / xAI", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your content and your conversations, as raw material to train AI models.\n  3. A continuous record of everywhere you physically go.\n  4. A licence to your own photos, writing and uploads, on their terms.\n  5. Your right to take them to court. Disputes go to private arbitration.\n  6. Your right to join with other people harmed the same way. You must sue alone.\n  7. Your right to be made whole. Their liability is capped, often at what you paid.\n  8. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (5 of 13): your biometric identifiers; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using X (Twitter) you gave up your personal data sold onward, your content used as AI training data, your physical movements, a broad licence to your own content, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 5 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Public posts are used to train the affiliated AI model, so writing on the platform contributes to a commercial product under the same ownership. Users who joined years before that model existed were moved into this arrangement by a terms update rather than by choosing it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1192, "_entity_id": 171, "_entity_slug": "x-twitter", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Reddit", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; uses content as AI training material. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Reddit, Inc. (NYSE: RDDT). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.reddit.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Reddit, Inc. (NYSE: RDDT)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Reddit, Inc. (NYSE: RDDT)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 67, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 13/30 (data_sold_or_shared_for_value+8, ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Reddit  <-  Reddit, Inc. (NYSE: RDDT)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your content and your conversations, as raw material to train AI models.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your biometric identifiers; your physical movements; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Reddit you gave up your personal data sold onward, your content used as AI training data, a broad licence to your own content, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Comments written pseudonymously over many years have been licensed in bulk to AI developers. The consumer wrote under an expectation of obscurity; the archive was later sold as a corpus, and deleting an account does not necessarily withdraw what was already licensed.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1193, "_entity_id": 287, "_entity_slug": "reddit", "_issuer": "Reddit, Inc.", "_issuer_slug": "reddit-inc", "_ticker": "RDDT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Discord", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects precise location. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Discord, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://discord.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Discord, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Discord, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 62, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Discord  <-  Discord, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Discord you gave up your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Private servers feel like closed rooms but message history is retained centrally and is accessible to the operator. Large numbers of minors use it, so the retained corpus includes childrens conversations held under an assumption of privacy the architecture does not provide.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1194, "_entity_id": 285, "_entity_slug": "discord", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Pinterest", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Pinterest, Inc. (NYSE: PINS). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.pinterest.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Pinterest, Inc. (NYSE: PINS)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Pinterest, Inc. (NYSE: PINS)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 37, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "Pinterest  <-  Pinterest, Inc. (NYSE: PINS)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your content used as AI training data; your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Pinterest you gave up your personal data sold onward, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Saved boards disclose intent well before purchase - pregnancy, weddings, moving house, illness - making the collection an unusually early and reliable predictor of major life events.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1195, "_entity_id": 289, "_entity_slug": "pinterest", "_issuer": "Pinterest, Inc.", "_issuer_slug": "pinterest-inc", "_ticker": "PINS", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "LinkedIn", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; uses content as AI training material. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Microsoft Corporation. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.linkedin.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Microsoft Corporation", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Microsoft Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 44, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 17, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 17/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "LinkedIn  <-  Microsoft Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your content and your conversations, as raw material to train AI models.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your biometric identifiers; your physical movements; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using LinkedIn you gave up your personal data sold onward, your content used as AI training data, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Members were enrolled into generative training by default in some regions, with an opt-out placed in settings after the fact. The corpus is a professional identity that people cannot practically abandon, so exit is not a real remedy here.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1196, "_entity_id": 1628, "_entity_slug": "linkedin", "_issuer": "Microsoft Corporation", "_issuer_slug": "microsoft-corporation", "_ticker": "MSFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Snapchat", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: uses content as AI training material; collects biometric identifiers; collects precise location. 9 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Snap Inc. (NYSE: SNAP). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.snapchat.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Snap Inc. (NYSE: SNAP)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Snap Inc. (NYSE: SNAP)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=Y; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "First-draft row. 9 of 18 clauses unresolved; structural posture recorded, clause detail pending fetch.", "Exposure Score (0-100)": 69, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 15, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 15/30 (biometric_collection+6, ai_training_on_user_data+5, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 8/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Snapchat  <-  Snap Inc. (NYSE: SNAP)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. A continuous record of everywhere you physically go.\n  4. A licence to your own photos, writing and uploads, on their terms.\n  5. Your right to take them to court. Disputes go to private arbitration.\n  6. Your right to join with other people harmed the same way. You must sue alone.\n  7. Your right to be made whole. Their liability is capped, often at what you paid.\n  8. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (5 of 13): your personal data sold onward; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Snapchat you gave up your content used as AI training data, your biometric identifiers, your physical movements, a broad licence to your own content, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 5 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The product is sold on disappearance, which is the strongest privacy promise in the category and also the most misunderstood. Lenses process facial geometry and the location map shares position continuously; neither disappears in the way the messages appear to.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1197, "_entity_id": 1629, "_entity_slug": "snapchat", "_issuer": "Snap Inc.", "_issuer_slug": "snap-inc", "_ticker": "SNAP", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Tumblr", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Automattic Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.tumblr.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Automattic Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Automattic Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 9, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 9/30 (shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Tumblr  <-  Automattic Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your biometric identifiers; your physical movements; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Tumblr you gave up your content used as AI training data, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Has changed corporate owner repeatedly, and each transfer carried the existing archive with it. A blog written in 2012 is now held by a company the author never chose, under terms revised several times since.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1198, "_entity_id": 1631, "_entity_slug": "tumblr", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Bluesky", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Bluesky Social, PBC. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://bsky.app/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Bluesky Social, PBC", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Bluesky Social, PBC). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=N; location=?; unilateral=Y; liabcap=Y; contentlic=N; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Bluesky  <-  Bluesky Social, PBC", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to be made whole. Their liability is capped, often at what you paid.\n  2. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your content used as AI training data; a broad licence to your own content.\n\nNOT YET DETERMINED (8 of 13): your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Bluesky you gave up your right to meaningful compensation and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Built on an open protocol where posts are public by design and portable to other providers. Exit is therefore genuinely possible rather than nominal, which is rare enough in this workbook to record as a positive, though public-by-design also means no post was ever private.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1199, "_entity_id": 320, "_entity_slug": "bluesky", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Mastodon", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Mastodon gGmbH (non-profit, Germany). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://joinmastodon.org/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Mastodon gGmbH (non-profit, Germany)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Mastodon gGmbH (non-profit, Germany)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=N; location=?; unilateral=?; liabcap=Y; contentlic=N; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 7, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 5, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 5/20 (liability_cap_or_one_way_indemnity+5) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Mastodon  <-  Mastodon gGmbH (non-profit, Germany)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to be made whole. Their liability is capped, often at what you paid.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your content used as AI training data; a broad licence to your own content.\n\nNOT YET DETERMINED (9 of 13): your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Mastodon you gave up your right to meaningful compensation. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Federated, so the governing terms are set by whichever independent server the user joined, not by the software authors. That removes the single corporate controller and replaces it with an operator who may be one unpaid individual with no legal entity behind them.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1200, "_entity_id": 1634, "_entity_slug": "mastodon", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Rumble", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Rumble Inc. (NASDAQ: RUM). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://rumble.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Rumble Inc. (NASDAQ: RUM)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Rumble Inc. (NASDAQ: RUM)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 43, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Rumble  <-  Rumble Inc. (NASDAQ: RUM)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Rumble you gave up a broad licence to your own content, your data shared corporate-wide, your right to sue, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Positioned on moderation policy rather than on data practice, which tends to mean users select it for political reasons and never read the data terms at all. The collection posture is conventional; the assumption that it is not is the risk.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1201, "_entity_id": 1636, "_entity_slug": "rumble", "_issuer": "Rumble Inc.", "_issuer_slug": "rumble-inc", "_ticker": "RUM", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Truth Social", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Trump Media & Technology Group (NASDAQ: DJT). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://truthsocial.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Trump Media & Technology Group (NASDAQ: DJT)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Trump Media & Technology Group (NASDAQ: DJT)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 48, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Truth Social  <-  Trump Media & Technology Group (NASDAQ: DJT)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Truth Social you gave up a broad licence to your own content, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A publicly listed company whose user base and share register overlap, so the same individuals are both the audience and the investors. Recorded because that alignment is unusual and affects how terms changes are likely to be received and challenged.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1202, "_entity_id": 1638, "_entity_slug": "truth-social", "_issuer": "Trump Media & Technology Group", "_issuer_slug": "trump-media-technology-group", "_ticker": "DJT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Gettr", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Gettr USA, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://gettr.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Gettr USA, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Gettr USA, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 39, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Gettr  <-  Gettr USA, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Gettr you gave up a broad licence to your own content, your right to sue, your right to meaningful compensation, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Smaller network with limited public disclosure of its data handling and no clear published record of where user data is stored. Opacity is the finding here rather than any specific clause.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1203, "_entity_id": 1640, "_entity_slug": "gettr", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Parler", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Parler (relaunched ownership). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://parler.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Parler (relaunched ownership)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Parler (relaunched ownership)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 39, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 0/30 (none) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "ARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Parler  <-  Parler (relaunched ownership)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Parler you gave up a broad licence to your own content, your right to sue, your right to meaningful compensation, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Its 2021 deplatforming demonstrated that a social product depends on infrastructure suppliers who are not party to the user agreement. A consumer contract with a platform is worth only as much as the platform hosting arrangements, which the consumer cannot see.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1204, "_entity_id": 1641, "_entity_slug": "parler", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Nextdoor", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Nextdoor Holdings, Inc. (NYSE: KIND). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://nextdoor.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Nextdoor Holdings, Inc. (NYSE: KIND)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Nextdoor Holdings, Inc. (NYSE: KIND)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 40, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "Nextdoor  <-  Nextdoor Holdings, Inc. (NYSE: KIND)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Nextdoor you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Verifies users by residential address, so the account is tied to a specific home rather than to an email. That makes the dataset a directory of who lives where, which is materially different from a pseudonymous social graph.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1205, "_entity_id": 265, "_entity_slug": "nextdoor", "_issuer": "Nextdoor Holdings, Inc.", "_issuer_slug": "nextdoor-holdings-inc", "_ticker": "KIND", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Quora", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; uses content as AI training material. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Quora, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.quora.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Quora, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Quora, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=?; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 13/30 (data_sold_or_shared_for_value+8, ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Quora  <-  Quora, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your content and your conversations, as raw material to train AI models.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Quora you gave up your personal data sold onward, your content used as AI training data, a broad licence to your own content, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Answers written years ago now train the AI products of the same owner, including its assistant aggregator. Contributors wrote for readers and were retrospectively enrolled as training labour.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1206, "_entity_id": 1642, "_entity_slug": "quora", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "9GAG", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to 9GAG Limited (Hong Kong). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://9gag.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "9GAG Limited (Hong Kong)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: 9GAG Limited (Hong Kong)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 33, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "9GAG  <-  9GAG Limited (Hong Kong)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; your physical movements; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using 9GAG you gave up your personal data sold onward, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A Hong Kong entity serving a largely Western audience, so the governing law and data location differ from user expectation. Advertising-dense products with young audiences concentrate tracking without a subscription relationship to constrain it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1207, "_entity_id": 1644, "_entity_slug": "9gag", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Imgur", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to MediaLab AI, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://imgur.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "MediaLab AI, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: MediaLab AI, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 33, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Imgur  <-  MediaLab AI, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; your physical movements; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Imgur you gave up your personal data sold onward, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Now held by an owner that has acquired several consumer apps, and a 2023 policy change deleted large volumes of older anonymous uploads. Users who uploaded without an account had no notice route at all.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1208, "_entity_id": 1646, "_entity_slug": "imgur", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "VSCO", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Visual Supply Company. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.vsco.co/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Visual Supply Company", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Visual Supply Company). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "VSCO  <-  Visual Supply Company", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using VSCO you gave up a broad licence to your own content, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Annual subscriptions billed to a young user base, where auto-renewal on a yearly cycle is the most common consumer complaint in this category and the least likely to be noticed by a teenage account holder.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1209, "_entity_id": 1648, "_entity_slug": "vsco", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Flickr", "Category": "Social - Major Networks", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to SmugMug, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.flickr.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "SmugMug, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: SmugMug, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=N; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 15, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Flickr  <-  SmugMug, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to be made whole. Their liability is capped, often at what you paid.\n  2. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: a broad licence to your own content.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Flickr you gave up your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Honours Creative Commons licensing chosen by the photographer, which preserves user-set terms through two changes of corporate owner. That continuity is unusual and is recorded here as a positive.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Major Networks", "_row_id": 1210, "_entity_id": 1650, "_entity_slug": "flickr", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Telegram", "Category": "Social - Messaging", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Telegram FZ-LLC (Dubai). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://telegram.org/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Telegram FZ-LLC (Dubai)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Telegram FZ-LLC (Dubai)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 31, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Telegram  <-  Telegram FZ-LLC (Dubai)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; your physical movements; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Telegram you gave up a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Ordinary chats are not end-to-end encrypted by default; only Secret Chats are. The product is widely believed to be private in a way the default configuration does not support, and that gap between reputation and default is itself the consumer harm.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Messaging", "_row_id": 1211, "_entity_id": 166, "_entity_slug": "telegram", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Signal", "Category": "Social - Messaging", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Signal Technology Foundation (US non-profit). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://signal.org/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 1, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Signal Technology Foundation (US non-profit)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Signal Technology Foundation (US non-profit)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 1 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=N; biometric=?; aitrain=N; location=N; unilateral=?; liabcap=?; contentlic=N; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 0, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 0, "Sub: Track Record /20": 0, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 0/20 (none) | Record 0/20 (severity1+0) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Signal  <-  Signal Technology Foundation (US non-profit)", "What Did I Sell (Itemised)": "YOU HANDED OVER: nothing confirmed on the evidence resolved so far.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your content used as AI training data; your physical movements; a broad licence to your own content; your data shared corporate-wide.\n\nNOT YET DETERMINED (8 of 13): your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "On what has been resolved so far, Signal takes nothing from the list this tracker checks - but 8 of 13 clauses are still unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Retains essentially nothing beyond an account creation date, a claim tested by subpoena responses that could disclose almost nothing. A non-profit with no advertising model has no commercial reason to collect, and this is the strongest privacy posture of any consumer product in this workbook.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Messaging", "_row_id": 1212, "_entity_id": 789, "_entity_slug": "signal", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "WeChat", "Category": "Social - Messaging", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects biometric identifiers; collects precise location. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Tencent Holdings Limited. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.wechat.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Tencent Holdings Limited", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Tencent Holdings Limited). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 5 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 47, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 14, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 14/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 20/20 (severity5+20) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "WeChat  <-  Tencent Holdings Limited", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your content used as AI training data; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using WeChat you gave up your biometric identifiers, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Combines messaging, payments, identity and government services in one account, so the behavioural record is close to a complete civic and financial life. No Western product concentrates that many functions under a single controller.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Messaging", "_row_id": 1213, "_entity_id": 1653, "_entity_slug": "wechat", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "QQ", "Category": "Social - Messaging", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects precise location. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Tencent Holdings Limited. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://im.qq.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Tencent Holdings Limited", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Tencent Holdings Limited). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=?; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 8, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 8/20 (unilateral_modification+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "QQ  <-  Tencent Holdings Limited", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using QQ you gave up your physical movements, a broad licence to your own content, your data shared corporate-wide, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The older messaging product from the same owner, still holding archives stretching back two decades for many users. Long-lived accounts accumulate exposure that no current-day setting can retroactively reduce.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Messaging", "_row_id": 1214, "_entity_id": 1654, "_entity_slug": "qq", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "LINE", "Category": "Social - Messaging", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects precise location. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to LY Corporation (SoftBank / Naver). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://line.me/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "LY Corporation (SoftBank / Naver)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: LY Corporation (SoftBank / Naver)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "LINE  <-  LY Corporation (SoftBank / Naver)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using LINE you gave up your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A 2021 disclosure that user data was accessible from outside the stated jurisdiction prompted regulatory attention in Japan. The lesson recorded here is that a stated data location is an operational claim, not a technical guarantee.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Messaging", "_row_id": 1215, "_entity_id": 1656, "_entity_slug": "line", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "KakaoTalk", "Category": "Social - Messaging", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects precise location. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Kakao Corp. (South Korea). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.kakaocorp.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Kakao Corp. (South Korea)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Kakao Corp. (South Korea)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "KakaoTalk  <-  Kakao Corp. (South Korea)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using KakaoTalk you gave up your physical movements, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Near-universal adoption in its home market means declining the terms is not a practical option for an ordinary person there. Where a messaging app becomes civic infrastructure, consent stops being meaningfully voluntary.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Messaging", "_row_id": 1216, "_entity_id": 1658, "_entity_slug": "kakaotalk", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Viber", "Category": "Social - Messaging", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects precise location. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Rakuten Group, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.viber.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Rakuten Group, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Rakuten Group, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 26, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "Viber  <-  Rakuten Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Viber you gave up your physical movements, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Owned by a commerce and financial services conglomerate, so messaging data sits in a corporate family that also runs retail, banking and loyalty programmes.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Messaging", "_row_id": 1217, "_entity_id": 1660, "_entity_slug": "viber", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Weibo", "Category": "Social - Messaging", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects precise location. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Weibo Corporation (NASDAQ: WB). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://weibo.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Weibo Corporation (NASDAQ: WB)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Weibo Corporation (NASDAQ: WB)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=?; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 8, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 8/20 (unilateral_modification+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "Weibo  <-  Weibo Corporation (NASDAQ: WB)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Weibo you gave up your physical movements, a broad licence to your own content, your data shared corporate-wide, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Real-name registration requirements mean the account is bound to a verified legal identity, removing the pseudonymity that users of comparable Western products still retain.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Messaging", "_row_id": 1218, "_entity_id": 1662, "_entity_slug": "weibo", "_issuer": "Weibo Corporation", "_issuer_slug": "weibo-corporation", "_ticker": "WB", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Xiaohongshu (RedNote)", "Category": "Social - Messaging", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects precise location. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Xingin Information Technology Co., Ltd.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.xiaohongshu.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Xingin Information Technology Co., Ltd.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Xingin Information Technology Co., Ltd.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=?; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 8, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 8/20 (unilateral_modification+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "Xiaohongshu (RedNote)  <-  Xingin Information Technology Co., Ltd.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Xiaohongshu (RedNote) you gave up your physical movements, a broad licence to your own content, your data shared corporate-wide, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Received a large influx of US users during a period of uncertainty about a competing app, most of whom accepted Chinese-language terms they could not read. Consent given without comprehension is the specific issue recorded here.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Messaging", "_row_id": 1219, "_entity_id": 1664, "_entity_slug": "xiaohongshu-rednote", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Kuaishou", "Category": "Social - Messaging", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material; collects precise location. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Kuaishou Technology (HKEX: 1024). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.kuaishou.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Kuaishou Technology (HKEX: 1024)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Kuaishou Technology (HKEX: 1024)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=Y; location=Y; unilateral=?; liabcap=?; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 30, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 13, "Sub: Contract Asymmetry /20": 3, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 13/30 (shared_with_affiliates_or_brokers+4, ai_training_on_user_data+5, precise_location_tracking+4) | Contract 3/20 (broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Kuaishou  <-  Kuaishou Technology (HKEX: 1024)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. A continuous record of everywhere you physically go.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to be consulted before terms change; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Kuaishou you gave up your content used as AI training data, your physical movements, a broad licence to your own content, and your data shared corporate-wide. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Also the operator of a generative video product sold internationally, so the same controller holds both a short-video social graph and a face-processing creative tool.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Messaging", "_row_id": 1220, "_entity_id": 1665, "_entity_slug": "kuaishou", "_issuer": "Kuaishou Technology", "_issuer_slug": "kuaishou-technology", "_ticker": "1024", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Substack", "Category": "Social - Creator & Publishing", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Substack Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://substack.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Substack Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Substack Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 28, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Substack  <-  Substack Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Substack you gave up a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Writers are told the subscriber list is theirs, which is the platform central promise and its principal competitive claim. Whether the export right survives a terms change or an acquisition is the question that determines if that promise is real.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Creator & Publishing", "_row_id": 1221, "_entity_id": 826, "_entity_slug": "substack", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Medium", "Category": "Social - Creator & Publishing", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to A Medium Corporation. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://medium.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "A Medium Corporation", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: A Medium Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Medium  <-  A Medium Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Medium you gave up a broad licence to your own content, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Has repeatedly changed how work is paywalled and distributed, altering the reach and earnings of already-published pieces without the author republishing anything.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Creator & Publishing", "_row_id": 1222, "_entity_id": 824, "_entity_slug": "medium", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Patreon", "Category": "Social - Creator & Publishing", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Patreon, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.patreon.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Patreon, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Patreon, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 58, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Patreon  <-  Patreon, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  6. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Patreon you gave up your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Holds the payment relationship between a creator and their supporters, so a policy change about permitted content can sever an income stream built over years. Creators depend on it but contract on standard consumer terms with no notice guarantee.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Creator & Publishing", "_row_id": 1223, "_entity_id": 1667, "_entity_slug": "patreon", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "OnlyFans", "Category": "Social - Creator & Publishing", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects biometric identifiers. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Fenix International Limited (UK). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://onlyfans.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Fenix International Limited (UK)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Fenix International Limited (UK)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 5 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=Y; biometric=Y; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 61, "Exposure Band": "High", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 10, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 10/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 20/20 (severity5+20) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "OnlyFans  <-  Fenix International Limited (UK)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (6 of 13): your content used as AI training data; your physical movements; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using OnlyFans you gave up your biometric identifiers, a broad licence to your own content, your data shared corporate-wide, your right to sue, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Identity verification requires government photo identification and a facial scan, linking legal identity to the most sensitive content category in this workbook. A 2021 announced policy reversal showed the content rules can change at short notice; the identity documents remain regardless.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Creator & Publishing", "_row_id": 1224, "_entity_id": 1669, "_entity_slug": "onlyfans", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cameo", "Category": "Social - Creator & Publishing", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: collects biometric identifiers. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Baron App, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.cameo.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Baron App, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Baron App, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=Y; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 27, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 6, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 6/30 (biometric_collection+6) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "BIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered", "Entity Type": "App / Service", "Ownership Path": "Cameo  <-  Baron App, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Cameo you gave up your biometric identifiers, a broad licence to your own content, your right to meaningful compensation, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Videos are personalised to a named recipient who is not the purchaser and never agreed to anything, so a third party name and details are supplied to a platform by someone else.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Creator & Publishing", "_row_id": 1225, "_entity_id": 1671, "_entity_slug": "cameo", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Triller", "Category": "Social - Creator & Publishing", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Triller Group Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://triller.co/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Triller Group Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Triller Group Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 33, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Triller  <-  Triller Group Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; your physical movements; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Triller you gave up your personal data sold onward, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Repeated corporate restructuring and public disputes with creators over payment mean the entity holding the content licence has changed several times since many users uploaded.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Creator & Publishing", "_row_id": 1226, "_entity_id": 1673, "_entity_slug": "triller", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Likee", "Category": "Social - Creator & Publishing", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to JOYY Inc. / BIGO Technology. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://likee.video/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "JOYY Inc. / BIGO Technology", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: JOYY Inc. / BIGO Technology). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=?; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 38, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 8, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 8/20 (unilateral_modification+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "Likee  <-  JOYY Inc. / BIGO Technology", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Likee you gave up your personal data sold onward, your physical movements, a broad licence to your own content, your data shared corporate-wide, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Short-video product with a young user base and beauty filters that process facial geometry, operated by a Singapore-headquartered group under a Chinese-listed parent.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Creator & Publishing", "_row_id": 1227, "_entity_id": 1675, "_entity_slug": "likee", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Bigo Live", "Category": "Social - Creator & Publishing", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to JOYY Inc. / BIGO Technology. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.bigo.tv/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "JOYY Inc. / BIGO Technology", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: JOYY Inc. / BIGO Technology). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=?; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 41, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 11, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 11/20 (unilateral_modification+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "Bigo Live  <-  JOYY Inc. / BIGO Technology", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  6. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (7 of 13): your content used as AI training data; your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Bigo Live you gave up your personal data sold onward, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to be consulted before terms change, and your right to stop paying by inaction. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Live streaming monetised through virtual gifts purchased with real money, a structure that produces substantial unintended spending, particularly by minors using a parent payment method.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Creator & Publishing", "_row_id": 1228, "_entity_id": 1676, "_entity_slug": "bigo-live", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Twitch", "Category": "Social - Creator & Publishing", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Amazon.com, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.twitch.tv/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Amazon.com, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Amazon.com, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 61, "Exposure Band": "High", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Twitch  <-  Amazon.com, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to take them to court. Disputes go to private arbitration.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your content used as AI training data; your biometric identifiers; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Twitch you gave up your personal data sold onward, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to sue, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Viewing and chat behaviour joins the retail advertising graph of the parent, so what someone watches informs what they are shown in an unrelated shopping context.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Creator & Publishing", "_row_id": 1229, "_entity_id": 1677, "_entity_slug": "twitch", "_issuer": "Amazon.com, Inc.", "_issuer_slug": "amazon-com-inc", "_ticker": "AMZN", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Kick", "Category": "Social - Creator & Publishing", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Kick Streaming Pty Ltd (Australia). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://kick.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Kick Streaming Pty Ltd (Australia)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Kick Streaming Pty Ltd (Australia)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Kick  <-  Kick Streaming Pty Ltd (Australia)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Kick you gave up a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Australian-domiciled with close commercial ties to an online gambling operator, which is material context for a platform whose audience skews young.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Creator & Publishing", "_row_id": 1230, "_entity_id": 1679, "_entity_slug": "kick", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Vimeo", "Category": "Social - Creator & Publishing", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Vimeo, Inc. (NASDAQ: VMEO). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://vimeo.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Vimeo, Inc. (NASDAQ: VMEO)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Vimeo, Inc. (NASDAQ: VMEO)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=N; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 15, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Vimeo  <-  Vimeo, Inc. (NASDAQ: VMEO)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to be made whole. Their liability is capped, often at what you paid.\n  2. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  3. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; a broad licence to your own content.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Vimeo you gave up your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Sells storage and delivery rather than attention, so it has no advertising incentive to profile viewers. A subscription business model is itself a privacy protection and is credited as one here.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Creator & Publishing", "_row_id": 1231, "_entity_id": 1681, "_entity_slug": "vimeo", "_issuer": "Vimeo, Inc.", "_issuer_slug": "vimeo-inc", "_ticker": "VMEO", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Dailymotion", "Category": "Social - Creator & Publishing", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Canal+ / Vivendi SE (France). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.dailymotion.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Canal+ / Vivendi SE (France)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Canal+ / Vivendi SE (France)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 33, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Dailymotion  <-  Canal+ / Vivendi SE (France)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; your physical movements; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Dailymotion you gave up your personal data sold onward, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "French-owned and therefore squarely inside GDPR, giving users enforceable access and erasure rights that most comparable platforms provide only as policy.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Creator & Publishing", "_row_id": 1232, "_entity_id": 1683, "_entity_slug": "dailymotion", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Odysee", "Category": "Social - Creator & Publishing", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 14 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Odysee (LBRY protocol). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://odysee.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Odysee (LBRY protocol)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Odysee (LBRY protocol)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=N; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 14 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 18, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 3/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Odysee  <-  Odysee (LBRY protocol)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to be made whole. Their liability is capped, often at what you paid.\n  2. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: a broad licence to your own content.\n\nNOT YET DETERMINED (10 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Odysee you gave up your right to meaningful compensation and your right to be consulted before terms change. 10 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 26.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Blockchain-published content is effectively permanent, so deletion is not available even to the person who posted. Permanence is presented as a feature and functions as an irreversible waiver.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Creator & Publishing", "_row_id": 1233, "_entity_id": 1684, "_entity_slug": "odysee", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "SoundCloud", "Category": "Social - Creator & Publishing", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to SoundCloud Limited. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://soundcloud.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "SoundCloud Limited", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: SoundCloud Limited). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=?; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 24, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "SoundCloud  <-  SoundCloud Limited", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using SoundCloud you gave up a broad licence to your own content, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A 2024 terms revision was widely read as permitting AI training on uploaded music and was subsequently clarified after musician objection. Independent artists hold masters here that they cannot afford to lose control of.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Creator & Publishing", "_row_id": 1234, "_entity_id": 1686, "_entity_slug": "soundcloud", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Bandcamp", "Category": "Social - Creator & Publishing", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Nothing confirmed on the flags resolved this pass. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Songtradr, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://bandcamp.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Songtradr, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Songtradr, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=?; biometric=?; aitrain=N; location=?; unilateral=Y; liabcap=Y; contentlic=N; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 12, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 0, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 0/30 (none) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 2/20 (severity2+2) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "No clause flag on this row reaches a Mid-Atlantic statutory hook. That is a statement about how little is disclosed, not a clean bill of health — see the Opacity Basis cell.", "Entity Type": "App / Service", "Ownership Path": "Bandcamp  <-  Songtradr, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your right to be made whole. Their liability is capped, often at what you paid.\n  2. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward; your content used as AI training data; a broad licence to your own content.\n\nNOT YET DETERMINED (8 of 13): your biometric identifiers; your physical movements; your data shared corporate-wide; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Bandcamp you gave up your right to meaningful compensation and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Sells downloads without digital restrictions, so a purchase survives the platform. Changed owner twice in two years, which is the live risk to a model that otherwise treats buyers unusually well.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Creator & Publishing", "_row_id": 1235, "_entity_id": 1688, "_entity_slug": "bandcamp", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Tinder", "Category": "Social - Dating & Location", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects biometric identifiers; collects precise location. 9 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Match Group, Inc. (NASDAQ: MTCH). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://tinder.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Match Group, Inc. (NASDAQ: MTCH)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Match Group, Inc. (NASDAQ: MTCH)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 5 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=Y; aitrain=?; location=Y; unilateral=Y; liabcap=?; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "First-draft row. 9 of 18 clauses unresolved; structural posture recorded, clause detail pending fetch.", "Exposure Score (0-100)": 77, "Exposure Band": "Severe", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 22, "Sub: Contract Asymmetry /20": 8, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 22/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, biometric_collection+6, precise_location_tracking+4) | Contract 8/20 (unilateral_modification+5, broad_content_license+3) | Record 20/20 (severity5+20) | flags stated 8/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Tinder  <-  Match Group, Inc. (NASDAQ: MTCH)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. A continuous record of everywhere you physically go.\n  4. A licence to your own photos, writing and uploads, on their terms.\n  5. Your personal information, to every company in their corporate family.\n  6. Your right to take them to court. Disputes go to private arbitration.\n  7. Your right to join with other people harmed the same way. You must sue alone.\n  8. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (5 of 13): your content used as AI training data; your right to a jury; your right to keep what you paid for; your right to meaningful compensation; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Tinder you gave up your personal data sold onward, your biometric identifiers, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to sue, your right to join a class action, and your right to be consulted before terms change. 5 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Holds precise location history alongside sexual orientation, which is special category data under GDPR and among the most sensitive combinations in this workbook. The same parent runs most competing apps, so switching does not change the controller.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Dating & Location", "_row_id": 1236, "_entity_id": 1689, "_entity_slug": "tinder", "_issuer": "Match Group, Inc.", "_issuer_slug": "match-group-inc", "_ticker": "MTCH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Hinge", "Category": "Social - Dating & Location", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Match Group, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://hinge.co/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Match Group, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Match Group, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 61, "Exposure Band": "High", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Hinge  <-  Match Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to take them to court. Disputes go to private arbitration.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your content used as AI training data; your biometric identifiers; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Hinge you gave up your personal data sold onward, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to sue, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Prompts elicit detailed disclosures about beliefs, family and intentions that users would not enter into a form, then store them as structured profile fields under the same parent as its competitors.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Dating & Location", "_row_id": 1237, "_entity_id": 1690, "_entity_slug": "hinge", "_issuer": "Match Group, Inc.", "_issuer_slug": "match-group-inc", "_ticker": "MTCH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "OkCupid", "Category": "Social - Dating & Location", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Match Group, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.okcupid.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Match Group, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Match Group, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 58, "Exposure Band": "High", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "OkCupid  <-  Match Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using OkCupid you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The matching questionnaire captures political views, drug use and sexual history in a machine-readable form, producing one of the most detailed voluntary self-disclosures any consumer makes online.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Dating & Location", "_row_id": 1238, "_entity_id": 1691, "_entity_slug": "okcupid", "_issuer": "Match Group, Inc.", "_issuer_slug": "match-group-inc", "_ticker": "MTCH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Match.com", "Category": "Social - Dating & Location", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Match Group, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.match.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Match Group, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Match Group, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 57, "Exposure Band": "High", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Match.com  <-  Match Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  6. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (7 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Match.com you gave up your personal data sold onward, your data shared corporate-wide, your right to sue, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Was the subject of an FTC action over billing and cancellation practices, making auto-renewal here a documented regulatory concern rather than a theoretical one.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Dating & Location", "_row_id": 1239, "_entity_id": 1692, "_entity_slug": "match-com", "_issuer": "Match Group, Inc.", "_issuer_slug": "match-group-inc", "_ticker": "MTCH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Plenty of Fish", "Category": "Social - Dating & Location", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Match Group, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.pof.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Match Group, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Match Group, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 58, "Exposure Band": "High", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Plenty of Fish  <-  Match Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Plenty of Fish you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Marketed as the free option, which means it is funded by advertising and data rather than subscription - the cost is simply moved from the statement to the profile.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Dating & Location", "_row_id": 1240, "_entity_id": 1693, "_entity_slug": "plenty-of-fish", "_issuer": "Match Group, Inc.", "_issuer_slug": "match-group-inc", "_ticker": "MTCH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Bumble", "Category": "Social - Dating & Location", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; collects biometric identifiers; collects precise location. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Bumble Inc. (NASDAQ: BMBL). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://bumble.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Bumble Inc. (NASDAQ: BMBL)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Bumble Inc. (NASDAQ: BMBL)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=?; biometric=Y; aitrain=?; location=Y; unilateral=Y; liabcap=?; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 61, "Exposure Band": "High", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 18, "Sub: Contract Asymmetry /20": 11, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 18/30 (data_sold_or_shared_for_value+8, biometric_collection+6, precise_location_tracking+4) | Contract 11/20 (unilateral_modification+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 14/20 (severity4+14) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Bumble  <-  Bumble Inc. (NASDAQ: BMBL)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. A continuous record of everywhere you physically go.\n  4. A licence to your own photos, writing and uploads, on their terms.\n  5. Your right to take them to court. Disputes go to private arbitration.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  7. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (6 of 13): your content used as AI training data; your data shared corporate-wide; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to meaningful compensation. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Bumble you gave up your personal data sold onward, your biometric identifiers, your physical movements, a broad licence to your own content, your right to sue, your right to be consulted before terms change, and your right to stop paying by inaction. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Photo verification captures a facial scan to confirm identity, a biometric collection performed for safety reasons that nonetheless creates a durable identifier held indefinitely.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Dating & Location", "_row_id": 1241, "_entity_id": 243, "_entity_slug": "bumble", "_issuer": "Bumble Inc.", "_issuer_slug": "bumble-inc", "_ticker": "BMBL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Grindr", "Category": "Social - Dating & Location", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Grindr Inc. (NYSE: GRND). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.grindr.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Grindr Inc. (NYSE: GRND)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Grindr Inc. (NYSE: GRND)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 5 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 73, "Exposure Band": "Severe", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 20/20 (severity5+20) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Grindr  <-  Grindr Inc. (NYSE: GRND)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Grindr you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Was fined by the Norwegian data protection authority for sharing user data including location with advertising partners. Sexual orientation combined with real-time position is the highest-consequence data pairing in this workbook, with documented physical safety implications.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Dating & Location", "_row_id": 1242, "_entity_id": 1695, "_entity_slug": "grindr", "_issuer": "Grindr Inc.", "_issuer_slug": "grindr-inc", "_ticker": "GRND", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Strava", "Category": "Social - Dating & Location", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects precise location. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Strava, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.strava.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Strava, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Strava, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "Strava  <-  Strava, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Strava you gave up your physical movements, your data shared corporate-wide, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Aggregated activity heatmaps publicly revealed the layout of military installations in 2018 because individually innocuous routes combined into a sensitive whole. Privacy settings applied per activity do not prevent aggregate inference.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Dating & Location", "_row_id": 1243, "_entity_id": 227, "_entity_slug": "strava", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Life360", "Category": "Social - Dating & Location", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Life360, Inc. (NASDAQ: LIF). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.life360.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Life360, Inc. (NASDAQ: LIF)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Life360, Inc. (NASDAQ: LIF)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 5 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 49, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 20/20 (severity5+20) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "Life360  <-  Life360, Inc. (NASDAQ: LIF)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  6. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (7 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Life360 you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Sold to parents for family safety while historically monetising precise location through data brokers. The people tracked are children who did not consent, and the buyer of the app is not the subject of the surveillance.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Dating & Location", "_row_id": 1244, "_entity_id": 274, "_entity_slug": "life360", "_issuer": "Life360, Inc.", "_issuer_slug": "life360-inc", "_ticker": "LIF", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Waze", "Category": "Social - Dating & Location", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects precise location. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Google LLC (Alphabet Inc.). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.waze.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Google LLC (Alphabet Inc.)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Google LLC (Alphabet Inc.)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 32, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "Waze  <-  Google LLC (Alphabet Inc.)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Waze you gave up your physical movements, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Continuous driving telemetry flows to the same account graph as search and mail, so daily commute patterns join a profile built for advertising.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Dating & Location", "_row_id": 1245, "_entity_id": 1696, "_entity_slug": "waze", "_issuer": "Alphabet Inc.", "_issuer_slug": "alphabet-inc", "_ticker": "GOOGL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Pokemon GO", "Category": "Social - Dating & Location", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects precise location. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Scopely, Inc. / Savvy Games Group (2025 transaction). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://pokemongolive.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Scopely, Inc. / Savvy Games Group (2025 transaction)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Scopely, Inc. / Savvy Games Group (2025 transaction)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in", "Entity Type": "App / Service", "Ownership Path": "Pokemon GO  <-  Scopely, Inc. / Savvy Games Group (2025 transaction)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. A licence to your own photos, writing and uploads, on their terms.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Pokemon GO you gave up your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Years of precise child location history changed corporate hands in the 2025 sale of the games division. The new owner is a Saudi sovereign-backed group, so the jurisdiction holding that movement history changed without any user action.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Dating & Location", "_row_id": 1246, "_entity_id": 1698, "_entity_slug": "pokemon-go", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Roblox", "Category": "Social - Gaming & Virtual", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects biometric identifiers; collects precise location. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Roblox Corporation (NYSE: RBLX). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.roblox.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Roblox Corporation (NYSE: RBLX)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Roblox Corporation (NYSE: RBLX)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 5 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 65, "Exposure Band": "High", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 14, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 14/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 20/20 (severity5+20) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Roblox  <-  Roblox Corporation (NYSE: RBLX)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to take them to court. Disputes go to private arbitration.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your personal data sold onward; your content used as AI training data; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Roblox you gave up your biometric identifiers, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to sue, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A majority of the user base is children, and the platform holds chat logs, voice and facial expression data from age-verification and avatar features. It is the largest single concentration of minors data in this workbook and squarely inside the amended COPPA Rule.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Gaming & Virtual", "_row_id": 1247, "_entity_id": 247, "_entity_slug": "roblox", "_issuer": "Roblox Corporation", "_issuer_slug": "roblox-corporation", "_ticker": "RBLX", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Fortnite (Epic Games)", "Category": "Social - Gaming & Virtual", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Epic Games, Inc. (Tencent minority stake). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.fortnite.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Epic Games, Inc. (Tencent minority stake)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Epic Games, Inc. (Tencent minority stake)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 34, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Fortnite (Epic Games)  <-  Epic Games, Inc. (Tencent minority stake)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Fortnite (Epic Games) you gave up a broad licence to your own content, your data shared corporate-wide, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Epic paid a record FTC settlement in 2022 over childrens privacy and over interface designs that produced unintended purchases. Both halves of that action concerned defaults rather than deception, which is the pattern this tracker exists to catch.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Gaming & Virtual", "_row_id": 1248, "_entity_id": 300, "_entity_slug": "fortnite-epic-games", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Minecraft", "Category": "Social - Gaming & Virtual", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Mojang Studios (Microsoft Corporation). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.minecraft.net/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Mojang Studios (Microsoft Corporation)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Mojang Studios (Microsoft Corporation)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=Y; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 17, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 17/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, termination_or_confiscation+4) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Minecraft  <-  Mojang Studios (Microsoft Corporation)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your right to sue; your right to join a class action; your right to a jury; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Minecraft you gave up a broad licence to your own content, your data shared corporate-wide, your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Migration to mandatory parent-company accounts meant existing owners had to accept a new agreement to keep playing software they had already bought outright.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Gaming & Virtual", "_row_id": 1249, "_entity_id": 1700, "_entity_slug": "minecraft", "_issuer": "Microsoft Corporation", "_issuer_slug": "microsoft-corporation", "_ticker": "MSFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Steam", "Category": "Social - Gaming & Virtual", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Valve Corporation. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://store.steampowered.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Valve Corporation", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Valve Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=Y; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 35, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 17, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 17/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, termination_or_confiscation+4) | Record 14/20 (severity4+14) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Steam  <-  Valve Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A licence to your own photos, writing and uploads, on their terms.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; your right to sue; your right to join a class action; your right to a jury; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Steam you gave up a broad licence to your own content, your data shared corporate-wide, your right to keep what you paid for, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A purchased library is a licence that terminates with the account, so a suspension can remove access to thousands of dollars of games. Valve removed its arbitration clause in 2024, restoring the right to sue - a rare reversal in this workbook and credited as one.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Gaming & Virtual", "_row_id": 1250, "_entity_id": 1701, "_entity_slug": "steam", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "PlayStation Network", "Category": "Social - Gaming & Virtual", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Sony Group Corporation. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.playstation.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Sony Group Corporation", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Sony Group Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 62, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 17, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 17/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4, auto_renewal_or_fee_trap+3) | Record 14/20 (severity4+14) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "PlayStation Network  <-  Sony Group Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to join with other people harmed the same way. You must sue alone.\n  4. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  7. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (6 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using PlayStation Network you gave up your data shared corporate-wide, your right to sue, your right to join a class action, your right to keep what you paid for, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Purchased digital content has been removed from libraries when licensing lapsed, demonstrating that buy does not mean own. The 2011 breach of this network remains one of the largest consumer data incidents on record.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Gaming & Virtual", "_row_id": 1251, "_entity_id": 1702, "_entity_slug": "playstation-network", "_issuer": "Sony Group Corporation", "_issuer_slug": "sony-group-corporation", "_ticker": "SONY", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Xbox Live", "Category": "Social - Gaming & Virtual", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Microsoft Corporation. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.xbox.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Microsoft Corporation", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Microsoft Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 47, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 17, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 17/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Xbox Live  <-  Microsoft Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to take them to court. Disputes go to private arbitration.\n  3. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  6. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Xbox Live you gave up your data shared corporate-wide, your right to sue, your right to keep what you paid for, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Governed by the same services agreement as the parent mail, storage and assistant products, so a child gaming account is bound by an adult enterprise-scale contract.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Gaming & Virtual", "_row_id": 1252, "_entity_id": 1703, "_entity_slug": "xbox-live", "_issuer": "Microsoft Corporation", "_issuer_slug": "microsoft-corporation", "_ticker": "MSFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Nintendo Account", "Category": "Social - Gaming & Virtual", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Nintendo Co., Ltd.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://accounts.nintendo.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Nintendo Co., Ltd.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Nintendo Co., Ltd.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=Y; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 29, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 17, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 17/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, termination_or_confiscation+4, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Nintendo Account  <-  Nintendo Co., Ltd.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to keep what you paid for. They can suspend or delete your account and its contents.\n  3. Your right to be made whole. Their liability is capped, often at what you paid.\n  4. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  5. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (8 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Nintendo Account you gave up your data shared corporate-wide, your right to keep what you paid for, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 33.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Digital purchases are tied to an account and historically to specific hardware, so a lost or banned console has meant losing the library with limited recovery options.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Gaming & Virtual", "_row_id": 1253, "_entity_id": 1705, "_entity_slug": "nintendo-account", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Discord Nitro", "Category": "Social - Gaming & Virtual", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Discord, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://discord.com/nitro", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Discord, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Discord, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 25, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Discord Nitro  <-  Discord, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  4. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (9 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Discord Nitro you gave up your data shared corporate-wide, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A subscription sold heavily to minors through gifting, where the recurring charge lands on a parent payment method with no separate parental authorisation step.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Social - Gaming & Virtual", "_row_id": 1254, "_entity_id": 1706, "_entity_slug": "discord-nitro", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Temu", "Category": "Apps - Commerce & Marketplace", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 9 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to PDD Holdings Inc. (NASDAQ: PDD). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.temu.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "PDD Holdings Inc. (NASDAQ: PDD)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: PDD Holdings Inc. (NASDAQ: PDD)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 5 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "First-draft row. 9 of 18 clauses unresolved; structural posture recorded, clause detail pending fetch.", "Exposure Score (0-100)": 76, "Exposure Band": "Severe", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3) | Record 20/20 (severity5+20) | flags stated 8/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Temu  <-  PDD Holdings Inc. (NASDAQ: PDD)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to take them to court. Disputes go to private arbitration.\n  6. Your right to join with other people harmed the same way. You must sue alone.\n  7. Your right to be made whole. Their liability is capped, often at what you paid.\n  8. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (5 of 13): your content used as AI training data; your biometric identifiers; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Temu you gave up your personal data sold onward, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 5 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "The app requests unusually broad device permissions for a shopping application, and its corporate sibling was removed from an app store in 2023 over malware findings. Aggressive referral mechanics also pull in contact lists belonging to people who never installed it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apps - Commerce & Mobility", "_row_id": 1255, "_entity_id": 133, "_entity_slug": "temu", "_issuer": "PDD Holdings Inc.", "_issuer_slug": "pdd-holdings-inc", "_ticker": "PDD", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Shein", "Category": "Apps - Commerce & Marketplace", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Roadget Business Pte. Ltd. (Singapore). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.shein.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Roadget Business Pte. Ltd. (Singapore)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Roadget Business Pte. Ltd. (Singapore)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 67, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 14/20 (severity4+14) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Shein  <-  Roadget Business Pte. Ltd. (Singapore)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Shein you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Restructured its domicile to Singapore while operations remained largely elsewhere, which changes which regulator a consumer complaint reaches without changing anything the consumer experiences.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apps - Commerce & Mobility", "_row_id": 1256, "_entity_id": 135, "_entity_slug": "shein", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "AliExpress", "Category": "Apps - Commerce & Marketplace", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Alibaba Group Holding Limited. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.aliexpress.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Alibaba Group Holding Limited", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Alibaba Group Holding Limited). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 58, "Exposure Band": "High", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "AliExpress  <-  Alibaba Group Holding Limited", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using AliExpress you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Purchase and browsing data sits within a group that also operates payments, logistics and cloud, so the record spans far more than retail.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apps - Commerce & Mobility", "_row_id": 1257, "_entity_id": 1708, "_entity_slug": "aliexpress", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Poshmark", "Category": "Apps - Commerce & Marketplace", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to NAVER Corporation. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://poshmark.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "NAVER Corporation", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: NAVER Corporation). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 48, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Poshmark  <-  NAVER Corporation", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Poshmark you gave up your personal data sold onward, your data shared corporate-wide, your right to sue, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Acquired by a South Korean internet group, moving the seller and buyer records of a US marketplace under a foreign parent without any change visible in the app.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apps - Commerce & Mobility", "_row_id": 1258, "_entity_id": 183, "_entity_slug": "poshmark", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Depop", "Category": "Apps - Commerce & Marketplace", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Etsy, Inc. (NASDAQ: ETSY). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.depop.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Etsy, Inc. (NASDAQ: ETSY)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Etsy, Inc. (NASDAQ: ETSY)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 48, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Depop  <-  Etsy, Inc. (NASDAQ: ETSY)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Depop you gave up your personal data sold onward, your data shared corporate-wide, your right to sue, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A very young seller base operating as unregistered small traders, who take on consumer-law obligations they are generally unaware of while contracting on ordinary user terms.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apps - Commerce & Mobility", "_row_id": 1259, "_entity_id": 1709, "_entity_slug": "depop", "_issuer": "Etsy, Inc.", "_issuer_slug": "etsy-inc", "_ticker": "ETSY", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Vinted", "Category": "Apps - Commerce & Marketplace", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family. 13 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Vinted UAB (Lithuania). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.vinted.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 2, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Vinted UAB (Lithuania)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Vinted UAB (Lithuania)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2028-03-06 (18mo — severity 2 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=N; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 13 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 16, "Exposure Band": "Low", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 4, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 2, "Score Confidence (A-D)": "D", "Score Basis": "Dispute 0/30 (none) | Data 4/30 (shared_with_affiliates_or_brokers+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 2/20 (severity2+2) | flags stated 4/17 -> confidence D", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook", "Entity Type": "App / Service", "Ownership Path": "Vinted  <-  Vinted UAB (Lithuania)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, to every company in their corporate family.\n  2. Your right to be made whole. Their liability is capped, often at what you paid.\n  3. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nTHE DOCUMENT DOES NOT TAKE: your personal data sold onward.\n\nNOT YET DETERMINED (9 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Vinted you gave up your data shared corporate-wide, your right to meaningful compensation, and your right to be consulted before terms change. 9 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 30.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "EU-domiciled and therefore under GDPR with enforceable erasure rights, a materially stronger default position than its US-domiciled equivalents.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apps - Commerce & Mobility", "_row_id": 1260, "_entity_id": 1711, "_entity_slug": "vinted", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Mercari", "Category": "Apps - Commerce & Marketplace", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family. 12 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Mercari, Inc. (Japan). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.mercari.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Mercari, Inc. (Japan)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Mercari, Inc. (Japan)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 12 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 48, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 5/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Mercari  <-  Mercari, Inc. (Japan)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (8 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Mercari you gave up your personal data sold onward, your data shared corporate-wide, your right to sue, your right to meaningful compensation, and your right to be consulted before terms change. 8 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Japanese parent operating a US marketplace, so dispute resolution and data location follow the parent structure rather than the market the consumer is in.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apps - Commerce & Mobility", "_row_id": 1261, "_entity_id": 184, "_entity_slug": "mercari", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Etsy", "Category": "Apps - Commerce & Marketplace", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Etsy, Inc. (NASDAQ: ETSY). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.etsy.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Etsy, Inc. (NASDAQ: ETSY)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Etsy, Inc. (NASDAQ: ETSY)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 57, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 12, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 12/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 8/20 (severity3+8) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Etsy  <-  Etsy, Inc. (NASDAQ: ETSY)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your content used as AI training data; your biometric identifiers; your physical movements; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Etsy you gave up your personal data sold onward, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Sellers are individuals whose shop is their livelihood, and fee and policy changes are imposed unilaterally on a population with no negotiating position and no alternative distribution.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apps - Commerce & Mobility", "_row_id": 1262, "_entity_id": 176, "_entity_slug": "etsy", "_issuer": "Etsy, Inc.", "_issuer_slug": "etsy-inc", "_ticker": "ETSY", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "DoorDash", "Category": "Apps - Mobility & Delivery", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 9 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to DoorDash, Inc. (NASDAQ: DASH). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.doordash.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "DoorDash, Inc. (NASDAQ: DASH)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: DoorDash, Inc. (NASDAQ: DASH)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "First-draft row. 9 of 18 clauses unresolved; structural posture recorded, clause detail pending fetch.", "Exposure Score (0-100)": 70, "Exposure Band": "Severe", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 14/20 (severity4+14) | flags stated 8/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "DoorDash  <-  DoorDash, Inc. (NASDAQ: DASH)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  8. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (5 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using DoorDash you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 5 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Holds home address, order history and real-time location for both customers and couriers. The courier side is bound by the same arbitration structure while economically dependent on the platform.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apps - Commerce & Mobility", "_row_id": 1263, "_entity_id": 143, "_entity_slug": "doordash", "_issuer": "DoorDash, Inc.", "_issuer_slug": "doordash-inc", "_ticker": "DASH", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Uber", "Category": "Apps - Mobility & Delivery", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Uber Technologies, Inc. (NYSE: UBER). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.uber.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Uber Technologies, Inc. (NYSE: UBER)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Uber Technologies, Inc. (NYSE: UBER)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 67, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 14/20 (severity4+14) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Uber  <-  Uber Technologies, Inc. (NYSE: UBER)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to join with other people harmed the same way. You must sue alone.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (6 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Uber you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A complete history of where a person went and when, retained for years. The 2016 breach and its concealment led to a criminal conviction of a former security executive, which is unusual and worth recording as a precedent about non-disclosure.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apps - Commerce & Mobility", "_row_id": 1264, "_entity_id": 1714, "_entity_slug": "uber", "_issuer": "Uber Technologies, Inc.", "_issuer_slug": "uber-technologies-inc", "_ticker": "UBER", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Lyft", "Category": "Apps - Mobility & Delivery", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects precise location. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Lyft, Inc. (NASDAQ: LYFT). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.lyft.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Lyft, Inc. (NASDAQ: LYFT)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Lyft, Inc. (NASDAQ: LYFT)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 59, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Lyft  <-  Lyft, Inc. (NASDAQ: LYFT)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Lyft you gave up your physical movements, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Same trip-history exposure as its larger competitor, with the same arbitration and class-waiver structure, so market choice between the two changes nothing about dispute rights.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apps - Commerce & Mobility", "_row_id": 1265, "_entity_id": 141, "_entity_slug": "lyft", "_issuer": "Lyft, Inc.", "_issuer_slug": "lyft-inc", "_ticker": "LYFT", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Instacart", "Category": "Apps - Mobility & Delivery", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Maplebear Inc. (NASDAQ: CART). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.instacart.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Maplebear Inc. (NASDAQ: CART)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Maplebear Inc. (NASDAQ: CART)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 61, "Exposure Band": "High", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 14/20 (severity4+14) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Instacart  <-  Maplebear Inc. (NASDAQ: CART)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  7. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (6 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Instacart you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Grocery baskets disclose health conditions, religious observance, pregnancy and addiction, and the company operates an advertising business that monetises exactly that inference.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apps - Commerce & Mobility", "_row_id": 1266, "_entity_id": 145, "_entity_slug": "instacart", "_issuer": "Maplebear Inc.", "_issuer_slug": "maplebear-inc", "_ticker": "CART", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Grubhub", "Category": "Apps - Mobility & Delivery", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: sells or shares personal information for value; shares across the corporate family; collects precise location. 10 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Wonder Group, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.grubhub.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 3, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Wonder Group, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Wonder Group, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-09-06 (12mo — severity 3 routine cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=Y; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 10 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 55, "Exposure Band": "High", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 16, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 8, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 16/30 (data_sold_or_shared_for_value+8, shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 8/20 (severity3+8) | flags stated 7/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "DATA SALE → MD: right to opt out of sale + universal opt-out signal must be honored (MODPA); VA: right to opt out of sale (VCDPA); DC: no opt-out right — CPPA unfair-practice route only\nAFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Grubhub  <-  Wonder Group, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your personal information, for value, to companies you have no relationship with.\n  2. A continuous record of everywhere you physically go.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to take them to court. Disputes go to private arbitration.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  7. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (6 of 13): your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Grubhub you gave up your personal data sold onward, your physical movements, your data shared corporate-wide, your right to sue, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 6 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 43.3, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Changed hands twice in three years, each transfer carrying customer address and order history to a new controller under a new privacy policy.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apps - Commerce & Mobility", "_row_id": 1267, "_entity_id": 735, "_entity_slug": "grubhub", "_issuer": null, "_issuer_slug": null, "_ticker": null, "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Venmo", "Category": "Apps - Commerce & Marketplace", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects precise location. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to PayPal Holdings, Inc. (NASDAQ: PYPL). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://venmo.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "PayPal Holdings, Inc. (NASDAQ: PYPL)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: PayPal Holdings, Inc. (NASDAQ: PYPL)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 5 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 65, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 20/20 (severity5+20) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Venmo  <-  PayPal Holdings, Inc. (NASDAQ: PYPL)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Venmo you gave up your physical movements, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Transactions were public by default for most of the product history, exposing who pays whom for what to anyone who looked. A payment graph is a social graph with amounts attached, and the default published it.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apps - Commerce & Mobility", "_row_id": 1268, "_entity_id": 1716, "_entity_slug": "venmo", "_issuer": "PayPal Holdings, Inc.", "_issuer_slug": "paypal-holdings-inc", "_ticker": "PYPL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Cash App", "Category": "Apps - Commerce & Marketplace", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects precise location. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver identified.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Block, Inc. (NYSE: XYZ). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://cash.app/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Block, Inc. (NYSE: XYZ)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Block, Inc. (NYSE: XYZ)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=Y; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=?; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=?; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 59, "Exposure Band": "High", "Sub: Dispute Rights /30": 27, "Sub: Data Practices /30": 8, "Sub: Contract Asymmetry /20": 10, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 27/30 (forced_arbitration+12, class_action_waiver+9, no_or_unstated_optout+6) | Data 8/30 (shared_with_affiliates_or_brokers+4, precise_location_tracking+4) | Contract 10/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Cash App  <-  Block, Inc. (NYSE: XYZ)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. A continuous record of everywhere you physically go.\n  2. Your personal information, to every company in their corporate family.\n  3. Your right to take them to court. Disputes go to private arbitration.\n  4. Your right to join with other people harmed the same way. You must sue alone.\n  5. Your right to be made whole. Their liability is capped, often at what you paid.\n  6. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your content used as AI training data; your biometric identifiers; a broad licence to your own content; your right to a jury; your right to keep what you paid for; your right to stop paying by inaction. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Cash App you gave up your physical movements, your data shared corporate-wide, your right to sue, your right to join a class action, your right to meaningful compensation, and your right to be consulted before terms change. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 40.0, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "A 2021 insider incident exposed customer records, and the same parent operates a merchant payments business, so consumer and merchant data sit under one roof.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apps - Commerce & Mobility", "_row_id": 1269, "_entity_id": 1717, "_entity_slug": "cash-app", "_issuer": "Block, Inc.", "_issuer_slug": "block-inc", "_ticker": "XYZ", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Ring", "Category": "Apps - Commerce & Marketplace", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; collects biometric identifiers; collects precise location. 9 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration clause identified. Class-action waiver not confirmed this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Amazon.com, Inc.. This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://ring.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 5, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Arbitration, opt-out window not stated", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Amazon.com, Inc.", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Amazon.com, Inc.). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 5 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=Y; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=?; location=Y; unilateral=Y; liabcap=Y; contentlic=Y; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Light Haze", "Opacity Basis": "First-draft row. 9 of 18 clauses unresolved; structural posture recorded, clause detail pending fetch.", "Exposure Score (0-100)": 68, "Exposure Band": "High", "Sub: Dispute Rights /30": 18, "Sub: Data Practices /30": 14, "Sub: Contract Asymmetry /20": 16, "Sub: Track Record /20": 20, "Score Confidence (A-D)": "B", "Score Basis": "Dispute 18/30 (forced_arbitration+12, no_or_unstated_optout+6) | Data 14/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, precise_location_tracking+4) | Contract 16/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, broad_content_license+3, auto_renewal_or_fee_trap+3) | Record 20/20 (severity5+20) | flags stated 8/17 -> confidence B", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nPRECISE LOCATION → MD/VA: precise geolocation is sensitive data requiring consent before processing; MD additionally bars sale of sensitive data outright rather than merely requiring opt-in\nARBITRATION / CLASS WAIVER → No state privacy law overrides the FAA; practical route is (1) timely written opt-out (see ACTION - OPT-OUT KIT), (2) AG complaint — AG enforcement is NOT subject to the consumer's arbitration clause", "Entity Type": "App / Service", "Ownership Path": "Ring  <-  Amazon.com, Inc.", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  2. A continuous record of everywhere you physically go.\n  3. A licence to your own photos, writing and uploads, on their terms.\n  4. Your personal information, to every company in their corporate family.\n  5. Your right to take them to court. Disputes go to private arbitration.\n  6. Your right to be made whole. Their liability is capped, often at what you paid.\n  7. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  8. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (5 of 13): your personal data sold onward; your content used as AI training data; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Ring you gave up your biometric identifiers, your physical movements, a broad licence to your own content, your data shared corporate-wide, your right to sue, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 5 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 46.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Cameras pointed at public pavement record neighbours and passers-by who never agreed to anything. An FTC action addressed employee access to customer video, and footage has been shared with police under arrangements the recorded bystander cannot see or contest.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apps - Commerce & Mobility", "_row_id": 1270, "_entity_id": 1718, "_entity_slug": "ring", "_issuer": "Amazon.com, Inc.", "_issuer_slug": "amazon-com-inc", "_ticker": "AMZN", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}, {"Company": "Duolingo (app)", "Category": "Apps - Commerce & Marketplace", "Terms & Conditions URL": null, "T&C Direct PDF?": null, "Privacy Policy URL": null, "Privacy Direct PDF?": null, "Data Sharing/Selling Flags": "Confirmed on the flags resolved this pass: shares across the corporate family; uses content as AI training material; collects biometric identifiers. 11 of 18 clauses remain unresolved.", "Arbitration / Class Action Waiver": "Arbitration posture not determined this pass.", "Fees / Billing Flags": "Not itemized this pass.", "Notes": "Added in v60. Ownership resolved to Duolingo, Inc. (NASDAQ: DUOL). This row is a first draft: the SCARY finding states structural or publicly recorded facts, and every unresolved clause is carried as \"?\" rather than assumed benign.", "Industry (Fortune 500)": null, "Revenue (Fortune 500)": null, "Market Cap": null, "Employees": null, "HQ City": null, "HQ State": null, "CEO": null, "Ticker": null, "Website (Corporate)": "https://www.duolingo.com/", "Main Mailing Address (legal/privacy notices)": null, "Legal / Privacy Contact Email": null, "Finding Type": "Structural / no discrete incident", "Severity (1-5, heuristic)": 4, "Last Verified": "2026-09-06", "Provenance (who determined this)": "AI-written v59 session — review status not recorded", "Arbitration Opt-Out Window (Days)": "Not verified this pass", "Corporate Legal Notice Address (public cos.)": "Not verified this pass. If publicly traded: SEC Form 10-K cover page gives the official corporate address; the Secretary of State business-entity search in the state of incorporation gives the registered agent, which must accept service. If private: the state registered agent is usually the only reliable route.", "URL Status": "No URL recorded", "Region Tag": "National", "Primary Source URL": null, "Source Verification Status": "Unverified - heuristic first draft", "Region Basis": "Nationally distributed consumer product; no DMV-specific entity", "Parent / Ultimate Owner": "Duolingo, Inc. (NASDAQ: DUOL)", "Years Referenced in Finding (heuristic)": "2026", "Audit Depth": "SCARY only", "Registered Agent (Name)": "Not yet looked up — use registry link in adjacent cell", "Registered Agent Address / Service Notes": "LOOKUP PATH (agent not yet verified for this row): search the exact legal entity name, not the brand name — the operating entity is frequently different from the consumer-facing brand (this row's parent/owner is recorded as: Duolingo, Inc. (NASDAQ: DUOL)). Most large US corporations use CT Corporation System (Corporation Trust Center, 1209 N. Orange St., Wilmington, DE 19801) or Corporation Service Company (2711 Centerville Rd, Suite 400, Wilmington, DE 19808), but this MUST be confirmed per entity — serving the wrong agent is non-service even if you receive a date stamp.", "Company Brief": null, "Investor Overview": null, "Major Issues Record": null, "T&C Key Provisions (paraphrased)": null, "Re-verify By": "2027-03-06 (6mo — severity 4 accelerated cadence)", "Top Troubling #1": "None identified — see coverage note", "Top Troubling #2": "None identified — see coverage note", "Top Troubling #3": "None identified — see coverage note", "Troubling Terms Coverage Note": "First-draft row; harms identified from structural analysis, not from a fetched document.", "Clause Flags (v58, AI-classified)": "arb=?; classwaiver=?; jurywaiver=?; optout=?; datasale=?; affiliates=Y; biometric=Y; aitrain=Y; location=?; unilateral=Y; liabcap=Y; contentlic=?; confiscation=?; autorenew=Y; breach=?; penalty=?; litigation=?; b2b=N", "Opacity (Taxonomy L4)": "Thick Fog", "Opacity Basis": "First-draft row. 11 of 18 clauses unresolved and the primary document has not been fetched.", "Exposure Score (0-100)": 42, "Exposure Band": "Elevated", "Sub: Dispute Rights /30": 0, "Sub: Data Practices /30": 15, "Sub: Contract Asymmetry /20": 13, "Sub: Track Record /20": 14, "Score Confidence (A-D)": "C", "Score Basis": "Dispute 0/30 (none) | Data 15/30 (shared_with_affiliates_or_brokers+4, biometric_collection+6, ai_training_on_user_data+5) | Contract 13/20 (unilateral_modification+5, liability_cap_or_one_way_indemnity+5, auto_renewal_or_fee_trap+3) | Record 14/20 (severity4+14) | flags stated 6/17 -> confidence C", "Mid-Atlantic Legal Hooks (v58)": "AFFILIATE/BROKER SHARING → MD/VA: access + deletion requests reach the controller, not downstream brokers; MD data-minimization standard (\"reasonably necessary and proportionate\") is the stronger hook\nBIOMETRIC / VOICEPRINT → MD + VA treat biometric identifiers as sensitive data requiring opt-in consent; the amended COPPA Rule (compliance date 2026-04-22) adds voiceprints to protected children’s data, so a minor’s recorded speech is now squarely covered\nAI TRAINING ON USER DATA → No DMV statute has an express AI-training opt-out; the reachable hooks are the purpose-limitation and minimization duties (MD) and the sensitive-data consent rule where the training corpus includes voice, health or minors’ data", "Entity Type": "App / Service", "Ownership Path": "Duolingo (app)  <-  Duolingo, Inc. (NASDAQ: DUOL)", "What Did I Sell (Itemised)": "YOU HANDED OVER:\n  1. Your content and your conversations, as raw material to train AI models.\n  2. Your body as an identifier - face, voice or fingerprint - not just a password you can change.\n  3. Your personal information, to every company in their corporate family.\n  4. Your right to be made whole. Their liability is capped, often at what you paid.\n  5. Your right to be asked. They can rewrite the deal and continuing to use it is your consent.\n  6. Your right to stop paying by doing nothing. Billing continues until you actively cancel.\n\nNOT YET DETERMINED (7 of 13): your personal data sold onward; your physical movements; a broad licence to your own content; your right to sue; your right to join a class action; your right to a jury; your right to keep what you paid for. Treat these as unknown, not as absent - an unresolved flag is not a clean bill of health.", "What Did I Sell (One Sentence)": "By using Duolingo (app) you gave up your content used as AI training data, your biometric identifiers, your data shared corporate-wide, your right to meaningful compensation, your right to be consulted before terms change, and your right to stop paying by inaction. 7 further clauses are unresolved.", "Last Checked (Full)": "Never - first-draft row created 2026-09-08 17:14:16 UTC; no verification pass has been run against it", "Last Checked Coverage (%)": 36.7, "URL Last Validated": "Never - no automated URL validation pass has been run", "SCARY (most astonishing T&C item)": "Cross-reference row linking the consumer app to the deep-dive tab added in v59. The 27 May 2026 policy contraction removed the advertising-sharing statement, the Do Not Sell control and the voice collection disclosure; this row exists so the app appears in the app roster and points to that finding.", "Retail-Facing? (Y/N)": "Yes", "Small Business Relevant? (Y/N)": "No", "_tab": "Apps - Commerce & Mobility", "_row_id": 1271, "_entity_id": 1719, "_entity_slug": "duolingo-app", "_issuer": "Duolingo, Inc.", "_issuer_slug": "duolingo-inc", "_ticker": "DUOL", "_cik": null, "_investment_score": null, "_investment_band": null, "_investment_confidence": null}], "sha256": "b4cdfbde5c8e3e1c325b81526d6891df9b287238ddddbe6d245af08a5b739b30"}